The Quantum Threat May Already Be Inside the Clock

The biggest cybersecurity question isn't when quantum computers will break today's encryption. It's whether the information they could expose has already been stolen.

There is an uncomfortable feature of the quantum computing revolution that gets lost amid the extraordinary promises of new drugs, advanced materials, better artificial intelligence and computational breakthroughs that would be impossible with today's machines.

Quantum computing doesn't have to arrive tomorrow to create a cybersecurity problem today.

That distinction is becoming increasingly important.

Recent reporting from Bloomberg and The Wall Street Journal has focused renewed attention on the collision taking shape between rapidly advancing quantum computing and the cryptography that protects much of the modern digital world. The concern is well established: sufficiently powerful quantum computers could eventually defeat widely deployed public-key cryptography, potentially exposing information that organizations have spent decades assuming was secure.

The natural question is when.

When will quantum computers become powerful enough? When does Q-Day arrive? How many years do organizations have left?

Those are reasonable questions. They may also be the wrong ones.

For governments, critical-infrastructure operators, healthcare organizations and companies protecting valuable intellectual property, quantum exposure is better understood as a race between three different clocks—and at least one of them may already be running.

The First Clock: How Long Does the Secret Matter?

Imagine two encrypted files stolen today.

The first contains pricing information for a transaction closing next month. The second contains intelligence about national-security infrastructure, genomic information about thousands of people, or proprietary research that could retain strategic value for twenty years.

Both are encrypted with the same technology. They do not carry the same quantum risk.

This is one of the subtleties that makes post-quantum cybersecurity different from conventional vulnerability management. The value of information has a duration, and the longer that duration extends into the future, the more today's encryption decisions matter.

Government illustrates the problem particularly well. Intelligence, military communications, biometric identifiers, personnel information and critical-infrastructure architecture can remain sensitive for decades. Healthcare faces a similar challenge because medical and genomic information does not expire when a password changes. Intellectual property can retain enormous economic value throughout the life of a technology or product.

The relevant question is therefore not simply whether the information is encrypted today.

It is whether today's encryption will remain adequate for as long as the information needs to remain secret.

The Second Clock: How Long Will It Take to Change the Locks?

This is where the quantum problem collides with the reality of modern technology infrastructure.

It is tempting to imagine post-quantum migration as a large but manageable software upgrade: replace vulnerable algorithms with NIST-standardized post-quantum cryptography, test the environment and move on.

Real enterprise environments are considerably messier.

Cryptography is woven into applications, APIs, certificates, VPNs, identity systems, databases, cloud platforms, network equipment, embedded devices and third-party software. It also exists inside operational technology, medical equipment, industrial systems and legacy applications that may have been installed long before anyone contemplated a quantum threat.

Some of it is documented. Much of it isn't.

That means organizations cannot simply migrate. They first have to find what needs to be migrated.

For a global enterprise or federal department, the resulting exercise can involve hundreds of thousands—or potentially millions—of cryptographic dependencies spread across infrastructure owned by different business units, managed by different vendors and refreshed according to different investment cycles.

The migration clock, in other words, is measured in years. And every year required to complete the transition effectively moves the organization's quantum deadline closer.

The Third Clock Is the One That Changes Everything

Now consider the most difficult possibility.

What if the encrypted information has already left the network?

This is the logic behind Harvest Now, Decrypt Later, one of the more unsettling concepts in the quantum security discussion.

A sophisticated adversary doesn't necessarily need to break encryption today. It can intercept encrypted communications, copy them, store them and wait. If sufficiently capable quantum technology eventually becomes available, historically collected information could potentially be decrypted years after it was stolen.

This produces an unusual cybersecurity asymmetry. Most vulnerabilities can be fixed prospectively. Patch the software, rotate the credentials, close the exposed port, and the organization's security posture improves.

Harvest Now, Decrypt Later does not work that way. If encrypted information was collected yesterday, upgrading the encryption tomorrow does not bring yesterday's data back.

That is what makes the third clock different.

It may have started before anyone realized they were timing it.

Stop Trying to Predict Q-Day

Put these three clocks together and the quantum threat starts to look very different.

Suppose an organization holds information that must remain confidential for fifteen years. Its technology estate is sufficiently complex that a complete cryptographic migration could reasonably require five years.

That organization isn't making a five-year security decision. It is effectively making a twenty-year decision about the cryptography protecting that information today.

And if some of the encrypted data has already been intercepted, even that calculation may understate the exposure.

This is why the industry's fascination with predicting Q-Day can become counterproductive. No CIO, CISO or government agency controls the pace of quantum research. Nor can an organization know with certainty what capabilities sophisticated nation-state adversaries possess behind closed doors.

What organizations can control is their own exposure. That begins with a deceptively difficult question:

Where is the cryptography?

You Can't Fix What You Can't See

Before organizations can replace quantum-vulnerable encryption, they need something many enterprises surprisingly do not possess: a reliable map of their cryptographic environment.

NIST has made cryptographic discovery and inventory foundational to post-quantum migration, while the federal government's latest guidance increasingly emphasizes automated discovery and continuously updated inventories.

The emerging concept is the Cryptographic Bill of Materials, or CBOM.

If the Software Bill of Materials helped organizations understand what software components exist inside their technology, the CBOM applies a similar logic to cryptography.

Which algorithms are being used?

Where are the certificates?

Which protocols depend upon vulnerable cryptography?

Which applications rely on them?

What information do those applications protect?

How long must that information remain confidential?

Which vendor controls the upgrade path?

The answers allow an organization to move from a vague understanding that quantum computing represents a future cybersecurity threat to something far more useful:

a prioritized map of actual exposure.

That is the beginning of a strategy. But it isn't the end.

What If You Can't Wait Five Years?

There is a practical problem hiding inside every cryptographic inventory.

Some vulnerable systems will be relatively easy to migrate. Others won't.

Consider a water utility operating industrial-control equipment expected to remain in service for another decade, a hospital dependent upon specialized medical devices, a federal agency running mission-critical legacy applications, or a defense environment where operational continuity takes precedence over technology refresh schedules.

These organizations may discover something uncomfortable. They know where the vulnerability is. They know it needs to migrate. They also know they cannot replace it anytime soon.

This is where the post-quantum conversation becomes more interesting.

The industry has understandably focused on migration—moving applications and infrastructure from vulnerable public-key cryptography toward standardized PQC.

But organizations may increasingly need to think about mitigation while migration occurs.

The distinction is important.

Protect the Data Path, Then Modernize the Infrastructure

The national-security community has spent decades designing systems around an uncomfortable assumption: the underlying network cannot always be trusted.

That thinking offers an instructive model for the quantum transition.

Rather than waiting for every application, device and endpoint to become natively post-quantum capable, organizations can potentially introduce additional quantum-resistant protection around sensitive communications while the underlying technology estate migrates over time.

Think of it as creating a protected corridor around information whose secrecy requirements exceed the useful life of the cryptography currently protecting it. This does not eliminate the need for PQC migration. Standardized post-quantum cryptography remains the destination.

But it changes the sequencing.

An organization doesn't necessarily have to choose between being exposed today and waiting years for every legacy system to be replaced.

For governments and critical infrastructure in particular, that could become a consequential distinction. Many of the systems carrying the most sensitive information are also among the hardest systems to modernize quickly.

Quantum Security Is Becoming a Visibility Problem

There is a larger idea emerging from all of this.

Post-quantum cryptography is usually described as a cryptography problem.

Increasingly, it looks like a visibility problem first, a risk-management problem second and a migration problem third.

Organizations need to see their cryptographic environment before they can understand it. They need to understand which cryptographic assets protect information with the longest secrecy requirements. They need to identify which systems will take the longest to migrate. They need to determine where immediate protection may be required because the exposure window is already open.

Only then does migration become an intelligently prioritized exercise rather than an enterprise-wide scavenger hunt.

The operating model begins to look something like this:

Discover → Understand → Prioritize → Protect → Migrate → Monitor

And importantly, the last step matters almost as much as the first.

Technology estates do not stand still. Applications change, certificates rotate, vendors release new software, cloud environments expand and new devices enter the network continuously. A CBOM that is accurate today but obsolete six months from now provides little comfort.

Cryptographic visibility therefore needs to become persistent.

The Real Quantum Race

There are actually two quantum races underway.

The first is the one attracting billions of dollars in investment: the race to build increasingly capable quantum computers and unlock entirely new classes of computation.

The second is quieter. Governments, technology companies and infrastructure operators are racing to identify and replace the cryptography those machines could eventually compromise.

The two races are moving on different clocks. That is what makes the current moment so important.

For an executive trying to determine the organization's quantum exposure, the most useful questions are no longer particularly technical:

How long must our most valuable information remain secret?

How long will it take us to migrate the systems protecting it?

And when might that information already have left our control?

The answers will be different for every organization. But they lead toward the same conclusion.

The quantum transition does not begin with replacing an algorithm. It begins with visibility—understanding where cryptography exists, what it protects and how much time remains to do something about it.

From there, the strategy becomes clearer: build the cryptographic inventory, create the CBOM, identify the longest-lived secrets, prioritize the largest exposures, protect what cannot afford to wait and migrate the underlying infrastructure systematically.

Because ultimately, Q-Day may not be the date that matters most.

For some information, the clock may have started years ago.

Parkwood Intelligence

Parkwood Intelligence examines the intersection of capital, innovation, infrastructure, energy, cybersecurity and emerging technology, focusing on the structural shifts shaping the next generation of resilient infrastructure.

Previous
Previous

The Next Megawatt May Already Exist

Next
Next

The Capacity Hidden in Our Cities