Post-quantum risk is difficult to brief at board level.
Handled badly, it sounds either too technical or too speculative.
- Too technical, and directors disengage.
- Too speculative, and the message sounds like fear-based cyber marketing.
- Too urgent, and leadership may ask why the organisation is not already acting.
- Too relaxed, and the issue gets pushed into the “future technology” pile.
- The right approach is different.
Boards do not need a lecture on quantum mechanics. They need a clear explanation of business exposure, decision timing, accountability and practical next steps.
The role of the CIO, CISO, CTO, risk leader or technology adviser is not to create panic.
The role is to create informed readiness.
Start with the business issue, not the technology
The wrong opening is:
“Quantum computers may break RSA and elliptic-curve cryptography.”
That statement may be true, but it is not the best place to start with a board.
A stronger opening is:
“Some of the cryptography that protects our systems, customer data, digital signatures, certificates, APIs and trusted connections will need to change over the coming years. We need to understand where we depend on it and plan the transition before it becomes urgent.”
That immediately moves the conversation from science to governance.
Post-quantum cryptography, or PQC, matters because modern organisations rely on public-key cryptography across ordinary business systems: websites, portals, APIs, identity systems, VPNs, certificates, digital signatures, remote access, vendor platforms, cloud services, software updates and document workflows.
The board does not need to understand every algorithm.
It needs to know whether the organisation can identify what depends on those algorithms.
Explain the risks without exaggeration
A useful board briefing should be calm and precise.
Do not say:
“Quantum computers will destroy cybersecurity.”
Instead, say:
“Future quantum computers may weaken or break some public-key cryptography widely used today. That creates a transition risk for systems and data that depend on it.”
NIST finalised three post-quantum cryptography standards in August 2024: FIPS 203, FIPS 204 and FIPS 205. These cover key establishment and digital signatures, two functions that sit behind many trusted digital systems. (NIST)
For Australian organisations, the issue also has a practical transition timeline. The Australian Signals Directorate states that the Information Security Manual recommends ceasing use of traditional asymmetric cryptography by the end of 2030 and positions planning, education and transition management as part of organisational readiness. (Cyber Security Australia)
Those facts are enough to make the issue real without overstating it.
The message should be:
“This is not a crisis today. It is a transition program we should start preparing for now.”
Avoid the "Algorithm Trap"
Many PQC briefings fail because they go too quickly into algorithm names, standards, key sizes, hybrid modes or detailed migration mechanics.
That may be appropriate for technical teams. It is not usually the right first board conversation.
Boards should first understand:
- what business data may be exposed;
- which systems may be affected;
- which vendors are involved;
- which systems may be hard to change;
- what the organisation is expected to know by when;
- what evidence the board may need later.
The board-level question is not:
“Which post-quantum algorithm should we use?”
The board question is really:
“Do we know where cryptographic change may affect our business?”
That difference matters.
One is a technical design question.
The other is a governance question.
Use the “measured preparation” frame
The best tone for a board briefing is neither alarmist nor dismissive.
Use this frame:
“Post-quantum transition is a foreseeable technology change affecting digital trust. Our first responsibility is to understand our exposure, prioritise what matters and prepare a practical roadmap.”
This gives directors a role they understand.
They are not being asked to approve a major technology rebuild immediately. They are being asked to support sensible visibility, prioritisation and planning.
That is a much easier and more credible ask.
The simple Board Briefing structure
A strong first briefing can be structured around six slides.
Slide 1 — The issue in one sentence
Suggested message:
Post-quantum cryptography is the transition required because future quantum computers may weaken or break some of the public-key cryptography that protects digital systems today.
Speaker note:
Keep this short. Do not explain quantum mechanics. Do not open with fear. Explain that this is a transition in the security foundations of modern systems.
Slide 2 — Why this matters to our organisation
Suggested message:
We use public-key cryptography across systems that support trust: secure websites, customer or member portals, APIs, identity systems, digital signatures, certificates, remote access, cloud platforms, vendor systems and software updates.
Speaker note:
Bring the issue into familiar business systems. Directors should hear systems they recognise, not abstract cryptographic terms.
Slide 3 — The “so what?” risk
Suggested message:
The risk is not only that information may be read later. It is also that weakened trust mechanisms may affect identity, access, approvals, signatures, system connections, software integrity and evidence.
Speaker note:
This is the turning point. PQC is not just secrecy. It is trust in digital action.
Who logged in?
Who approved?
Who signed?
Which system connected?
Which vendor accessed what?
Can we prove it later?
Slide 4 — Why timing matters
Suggested message:
Transition will take time because the organisation must identify cryptographic dependencies, assess sensitive data, engage vendors, review legacy systems, test changes and plan implementation without disrupting operations.
Speaker note:
This is where urgency becomes rational. The point is not that everything must be changed now. The point is that discovery and planning cannot wait until the deadline.
ASD guidance points Australian organisations toward a 2030 transition away from traditional asymmetric cryptography, and its planning guidance emphasises communication, education and transition preparation. (Cyber Security Australia)
Slide 5 — What we do not yet know
Suggested message:
At this stage, the key unknowns are likely to be:
- where public-key cryptography is used;
- which data must remain confidential long-term;
- which systems are business-critical;
- which vendors control transition dependencies;
- which bespoke or legacy systems may be difficult to change;
- what evidence we can provide if asked.
Speaker note:
This is a useful board slide because it does not pretend the organisation already has all answers. It positions the next step as responsible discovery.
Slide 6 — Recommended next step
Suggested message:
We recommend a PQC readiness snapshot to establish governance, discover key systems and vendors, identify likely cryptographic touchpoints, and define whether deeper analysis or planning is required.
Speaker note:
Make the ask proportionate. Do not ask for a full transformation program if the board has not yet been educated. Ask for visibility.
Five Questions Directors Must Ask
A good board conversation should leave directors with practical questions.
1. What sensitive data must remain confidential for years?
This includes customer records, member data, employee records, legal files, health information, financial records, identity information, intellectual property, contracts, board papers and archived records.
The issue is not only what data is sensitive today. It is what data would still be damaging if exposed later.
2. Where do we rely on public-key cryptography today?
The answer may include certificates, TLS, VPNs, APIs, identity systems, digital signatures, software updates, cloud services, payment systems, SaaS platforms and bespoke applications.
If the organisation does not know where cryptography is used, it cannot prioritise transition.
3. Which systems would be hardest to change?
Legacy systems, bespoke software, custom integrations, older portals, operational platforms, certificate-pinned applications and vendor-controlled systems may all require early attention.
These systems can become transition blockers.
4. Which vendors do we depend on?
Vendors will matter. Cloud providers, SaaS platforms, identity providers, payment providers, managed service providers, security tools and software suppliers will all play roles.
But vendor roadmaps do not remove the organisation’s responsibility to understand dependency, testing, configuration, evidence and customer impact.
5. What evidence would we show if asked?
Boards should assume that customers, insurers, auditors, regulators or partners may eventually ask about PQC readiness.
A strong answer is not:
“We are waiting for our vendors.”
A stronger answer is:
“We have identified priority systems, reviewed sensitive data, mapped vendor dependencies and created a staged readiness plan.”
What shouldn't be said on the Board
Avoid language that reduces credibility.
Do not say:
“We need to become quantum-proof.”
Say:
“We need to prepare for post-quantum transition using standards-aligned, risk-prioritised planning.”
Do not say:
“Quantum computers will break everything.”
Say:
“Some widely used public-key cryptography will need to be transitioned over time.”
Do not say:
“This is only an IT problem.”
Say:
“This affects data protection, vendor assurance, identity, access control, business continuity and digital trust.”
Do not say:
“The vendors will handle it.”
Say:
“Vendors will play a major role, but we still need visibility over our systems, responsibilities and evidence.”
Do not say:
“We need a massive project immediately.”
Say:
“We recommend starting with governance and discovery so we understand our exposure before committing to a larger program.”
How to make the issue Real without creating Fear
Use examples that directors recognise.
For a member-based organisation:
- member records;
- loyalty systems;
- payment flows;
- gaming-related platforms;
- venue systems;
- customer portals;
- employee records;
- vendor platforms;
- board papers.
For a professional services firm:
- client files;
- legal or financial records;
- confidential advice;
- identity documents;
- digital signatures;
- matter-management systems;
- secure document exchange;
- archived records.
For a technology company:
- APIs;
- customer data;
- code-signing;
- software updates;
- identity providers;
- SaaS platforms;
- cloud infrastructure;
- customer assurance obligations.
The point is to show that PQC is not an abstract future science issue. It is connected to systems the organisation already depends on.
The right Board-Level recommendation
For most organisations, the right first recommendation is not implementation.
It is not algorithm selection.
It is not buying a new product.
The right first recommendation is:
“Approve a short PQC readiness process covering governance, discovery and initial prioritisation.”
That process should identify:
- ownership;
- scope;
- critical systems;
- sensitive data;
- long-life confidentiality needs;
- vendor dependencies;
- likely cryptographic touchpoints;
- systems requiring deeper analysis;
- whether a formal transition roadmap is required.
This is measured, defensible and proportionate.
How Ariadne Helps
Ariadne Thread Solutions helps organisations talk about post-quantum risk in a way boards can understand and act on.
Our executive PQC awareness briefing is designed for boards, CEOs, general managers, CIOs, CTOs, CISOs and risk leaders who need a practical introduction without technical noise.
The briefing covers:
- what post-quantum risk means in plain English;
- where cryptography hides in ordinary systems;
- why access control, identity and vendor dependency matter;
- what questions leadership should ask;
- what a sensible readiness pathway looks like;
- how to move from awareness to governance, discovery, analysis and transition planning.
The objective is not to create panic.
The objective is to help leadership make better decisions earlier.
The Practical Conclusion
Post-quantum risk should not be sold to the board as a crisis.
It should be presented as a foreseeable transition that affects digital trust.
The board does not need to know how quantum computing works in detail. It needs to know whether the organisation understands its exposure, has identified its dependencies and has a credible pathway to prepare.
The best first board conversation is calm, clear and practical:
- here is the issue;
- here is why it matters to us;
- here is what we do not yet know;
- here is the timeline;
- here is the first sensible step.
That is how to talk about post-quantum risk without creating panic.
CTA: Book an Executive PQC Awareness Briefing.
Not sure where PQC touches your access-control systems?
Start with visibility.
Ariadne’s PQC Readiness Snapshot helps leadership identify sensitive data, critical systems, vendor dependencies and cryptographic touchpoints before transition decisions become urgent.