Most organisations do not think about cryptography every day.
They think about client portals, remote access, cloud systems, customer records, digital signatures, APIs, payment workflows, secure documents, software updates and supplier platforms.
But cryptography sits underneath all of them.
That is why post-quantum risk is easy to underestimate. It does not usually appear as one obvious system called “encryption”. It is embedded across ordinary business operations, often inside software, infrastructure, vendor platforms and legacy applications that leadership rarely reviews through a cryptographic lens.
Post-quantum readiness therefore begins with a simple but uncomfortable question:
- Where do we rely on cryptography that may not be safe in the post-quantum era?
What does “quantum-vulnerable cryptography” mean?
Much of today’s digital trust depends on public-key cryptography.
In plain English, public-key cryptography helps systems prove identity, establish secure connections, exchange keys, verify signatures and protect information in transit. It is one of the foundations of modern digital business.
The concern is that a sufficiently powerful quantum computer could eventually break some of the public-key cryptography widely used today, including systems based on RSA and elliptic curve cryptography. NIST describes post-quantum cryptography as cryptography designed to resist attacks from both classical and quantum computers, and notes that quantum computers could threaten current methods such as RSA and elliptic curve cryptography. NIST finalised its first three post-quantum cryptography standards in August 2024: FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA digital signatures and FIPS 205 for SLH-DSA digital signatures.
For Australian organisations, this is now tied to practical transition planning. The Australian Signals Directorate recommends ceasing the use of traditional asymmetric cryptography by the end of 2030, including RSA, DH, ECDH and ECDSA primitives.
The challenge is not only choosing future algorithms. The first challenge is finding where today’s vulnerable dependencies already exist.
The “so what?” problem
A common reaction to post-quantum risk is:
- “Well, someone can read my encrypted traffic (now or in the future)… So What?”
That question is understandable. But it frames the issue too narrowly.
The problem is not only that someone may read information. The problem is what that information allows them to do.
Modern digital business depends on trust: trust that a person is who they claim to be, that a document has not been altered, that a payment instruction is genuine, that a software update came from the right source, that a contract was signed by the right party, that an API connection is legitimate, and that access to sensitive systems is controlled.
Public-key cryptography helps support that trust.
If the cryptographic foundations weaken, the consequences may go beyond confidentiality. They may affect identity, evidence, authorisation, integrity and accountability.
That creates several business risks.
First, exposed data may not belong only to the organisation. It may belong to clients, customers, employees, suppliers, patients, citizens or commercial partners. A business does not get to decide casually that this data does not matter. It holds that information under obligations of trust, contract, privacy, professional duty and, in many cases, law.
Second, sensitive information can be used to identify, profile, impersonate or manipulate people and businesses. A leaked file may contain enough detail to support fraud, social engineering, account takeover, forged instructions, targeted phishing, commercial coercion or unauthorised access to other systems.
Third, the risk is not only passive reading. Cryptography also helps verify actions: who signed, who approved, who connected, who published, who authorised and whether something was changed. If those mechanisms become unreliable, the organisation may face disputes over authenticity, integrity and accountability.
Fourth, trust can fail at infrastructure level. If certificates, digital signatures, identity systems, APIs, software updates and secure connections are no longer trusted, the issue is no longer one company’s private data. It becomes a wider problem for the modern IT-driven economy.
A business can survive an uncomfortable disclosure. It may not survive a loss of trust in its systems, approvals, customer records, software supply chain or ability to prove what happened.
That is the real “so what”.
Post-quantum risk is not only about whether secrets remain secret. It is about whether digital systems remain trustworthy enough to support business, government, finance, healthcare, law, commerce and everyday operations.
The practical leadership question is therefore not:
- “Would it matter if someone read this?”
The better question is:
- “What harm could follow if this data, identity, approval, signature, access path or trusted process could be copied, forged, replayed or challenged later?”
That is why PQC readiness belongs in business continuity, risk management and digital trust — not only in cryptography.
How mal-use can come back to a company that allowed the data-leak.
There is another reason this matters to leadership: harm does not stop with the first victim.
If information held by your organisation is later misused to harm clients, customers, employees, suppliers or partners, the consequences can return to the organisation that collected, stored, transmitted or protected that information.
This is the feedback loop of data risk.
A third party may suffer the immediate damage: fraud, impersonation, identity theft, account compromise, commercial manipulation, loss of privacy, forged approval, financial loss or reputational harm.
But the organisation that held the data may then face the second wave:
- customer complaints;
- breach notifications;
- regulatory scrutiny;
- legal claims;
- contractual disputes;
- professional negligence allegations;
- loss of cyber-insurance confidence;
- supplier or customer termination rights;
- failed procurement or due-diligence reviews;
- reputational damage;
- loss of board and executive credibility.
The question becomes:
- Did the organisation take reasonable steps to understand and manage a foreseeable area of risk?
That does not mean every organisation is expected to solve post-quantum transition overnight. It does mean that ignoring the issue becomes harder to defend as standards, guidance and transition timelines mature.
CISA, NIST and NSA have recommended that organisations begin preparing by creating quantum-readiness roadmaps, conducting inventories, applying risk assessments and engaging vendors.
For a business, the most dangerous phrase is not “we were attacked”.
It is:
- “We had no visibility, no plan and no evidence that we considered the risk.”
(read it like)
- We did not care enough we could be attacked.
This is why post-quantum readiness should be treated as a governance and continuity discipline. It helps the organisation show that it identified relevant dependencies, prioritised critical systems, engaged vendors and made reasonable decisions before pressure arrived.
New to Post-Quantum Risk?
Start With the Plain-English Guide
Post-quantum security can sound technical: public keys, private keys, PKI, certificates, digital signatures and quantum-vulnerable cryptography.
Our short executive dictionary explains the essential terms in plain English.