Post-Quantum Cryptography: The Board-Level Migration No One Can Defer

 

By the Daneborg Times Technology Desk

Somewhere in the next decade, a sufficiently powerful quantum computer will be able to break the public-key cryptography that protects almost everything digital — banking, government communications, medical records, the software update mechanisms inside critical infrastructure. The date is uncertain. The obligation to prepare, argues Professor Kai London, is not.

“Post-quantum migration is now a board-level programme, not a research footnote,” London says. “And it is the rare cyber risk where doing nothing today guarantees you fail later. The data an attacker steals now can be decrypted the moment the hardware arrives. That is why the clock has already started.”

Harvest now, decrypt later

The threat London refers to has an unglamorous but chilling name: “harvest now, decrypt later.” Adversaries do not need a quantum computer today to benefit from one tomorrow. They simply capture encrypted traffic and archives now — diplomatic cables, intellectual property, health data, anything with a long shelf life — and store it until the day the mathematics that protects it can be undone.

“If your data still needs to be confidential in ten or fifteen years, it is already exposed,” London warns. “For a government, a bank, a defence contractor or a hospital, that is most of the data that matters.”

The standards have arrived

What has changed, and why London says the excuse for inaction has evaporated, is that the standards now exist. The United States' National Institute of Standards and Technology has finalised its first post-quantum cryptography standards, giving organisations concrete algorithms to adopt rather than a vague warning to heed. Regulators and national cyber agencies are beginning to publish migration timelines. “We have moved from ‘someday’ to ‘here is the algorithm and here is the deadline,’” London notes.

Why migration is a multi-year programme

The hard part is not choosing an algorithm; it is finding all the places cryptography is used. “Most organisations have no idea where their cryptography lives,” London says. “It is embedded in applications, in network appliances, in hardware security modules, in vendor products, in code signing, in decades-old systems nobody wants to touch. You cannot migrate what you have not inventoried.”

His recommended first step is therefore not a technology purchase but a discovery exercise: build a cryptographic inventory, and with it a sense of “crypto-agility” — the ability to swap algorithms without re-architecting the whole system. Organisations that hard-coded a single algorithm deep into their products face the most painful road; those that abstracted cryptography behind clean interfaces can move far faster.

A board-level roadmap

London frames the migration as a sequence a board can actually govern. First, discover: inventory where and how cryptography is used, and classify data by how long it must stay secret. Second, prioritise: protect the long-lived, high-value secrets first, starting with anything an adversary would harvest today. Third, engage the supply chain: demand post-quantum roadmaps from vendors, because much of the exposure sits in products an organisation does not build itself. Fourth, pilot hybrid schemes that combine classical and post-quantum algorithms, so security is not weakened during the transition. Fifth, build crypto-agility into everything new, so the next transition — and there will be one — is a configuration change rather than a crisis.

Not a reason to panic — a reason to plan

London is careful to separate urgency from alarmism. “No one should be ripping systems out this quarter in a panic,” he says. “But every board should be able to answer three questions: do we know where our cryptography is, do we know which of our data must survive the quantum transition, and do we have a funded, phased plan? If the answer to any of those is no, that is the work for this year.”

For sectors that underpin national resilience — finance, energy, defence, healthcare, critical infrastructure — the migration is also becoming a matter of regulatory expectation and, increasingly, competitive credibility. The organisations that can demonstrate a credible post-quantum plan will be the ones that keep the trust of regulators, partners and customers as the transition unfolds.

“Quantum will not break your security overnight,” London concludes. “Complacency will. The winners will be the organisations that treated this as a programme, started early, and could prove it.”


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Comments

Popular posts from this blog

No Logs, No Launch: Professor Kai London on Why Most Enterprise AI Dies at the Boardroom Table

The Invisible Airborne Perimeter: Professor Kai London on the Wireless Threat to Remote and Arctic Operations