The risk posed by quantum computing is not yet the collapse of the Internet. It is more subtle—and therefore more dangerous: data captured today could become readable tomorrow. For businesses, the question is no longer whether quantum computers already exist, but how long their secrets must remain secure.
Some threats announce themselves with a clatter. This one creeps forward in the silence of the archives. A medical record, a diplomatic conversation, banking data, a genetic report: all of this information can be intercepted today, patiently stored, and then decrypted once a machine capable of breaking current encryption is available.
That is the paradox of quantum risk. The danger is not entirely in the future. It begins the very moment the information is stolen.
Time becomes a vulnerability
Asymmetric encryption—which secures much of authentication, digital signatures, and sensitive communications—still relies heavily on mathematical problems that are beyond the capabilities of classical computers. RSA and certain elliptic curves have built their credibility on this asymmetry: easy to use, yet nearly impossible to reverse.
Shor’s algorithm changes the game. It doesn’t yet break systems in production, due to the lack of a sufficiently powerful quantum computer. But it already points to the method. The lock hasn’t been picked yet; its vulnerability is known.
That’s what makes waiting dangerous. Organizations often reason as if the threat begins the day the quantum computer becomes operational. In reality, it begins with the required period of confidentiality. Data that will be worthless in three months can wait. Data that must remain secret for ten or twenty years cannot.
The issue is therefore not just technological. It is temporal. How much is a secret worth if we know it may be revealed later?
Inventory: The First Line of Defense
The first mistake would be to treat all data the same way. The second would be to believe that we know exactly where vulnerable encryption is being used.
In large organizations, systems have been stacked in layers: legacy applications, certificates, APIs, internal data flows, third-party providers, and hybrid architectures. Encryption is everywhere, but it is rarely mapped with the precision required for a post-quantum transition.
The priority, therefore, is not to replace everything. It is to take stock.
Where is RSA still used? Which data flows rely on asymmetric cryptography? What data must remain confidential beyond five, ten, or twenty years? Which systems can be migrated without disruption? Which products require certification? What export restrictions apply?
This work may not seem very spectacular. Yet it is crucial. In quantum security, maturity begins with an almost administrative question: Do you really know how you’re protected?
The False Comfort of “Not Yet”
Current quantum computers are not yet capable of breaking the major cryptographic systems used on an industrial scale. They remain limited, prone to errors, and still far from the level of quantum computing required for cryptanalysis.
But this caution should not be confused with inaction. Progress is being made on several fronts: the number of qubits, error correction, interconnecting machines, and integration with high-performance computing. There is no single path to a useful quantum computer, but rather several competing trajectories.
This uncertainty complicates investment decisions. It does not preclude them. For sectors that handle sensitive data—finance, healthcare, defense, infrastructure, public services, and critical technologies—five years is not a distant horizon. It is sometimes less than the time required to audit, validate, test, certify, and deploy a new security architecture.
The cost of delay is not merely financial; it can become irreversible.
Details
The so-called “quantum-safe” transition relies primarily on two categories of solutions.
Post-quantum cryptography replaces vulnerable algorithms with new mathematical constructs designed to withstand quantum attacks. It operates on classical infrastructure but requires a coordinated migration, testing, certification, and, in some cases, additional computing resources.
Quantum key distribution uses the properties of quantum physics to enable two parties to exchange a secret key while detecting any attempt at interception. It offers very strong security in principle, but requires rigorous integration with existing networks and cryptographic systems.
In practice, the most robust solution will often be a hybrid approach: not pitting mathematics against physics, but methodically combining the two.
Security as Governance
The transition to post-quantum security is more than just a software update. It is a governance issue. It involves the legal department, IT, compliance, procurement, business units, and sometimes even corporate strategy.
Standards already exist to some extent, particularly in the United States through the work of NIST, while European and national agencies are refining their requirements. But standardization itself is becoming a matter of sovereignty. Those who participate in standard-setting influence how future systems will be designed, certified, exported, and adopted.
For Europe, therefore, the issue is twofold. Data must be protected. Europe must also avoid becoming merely a user of standards, tools, and infrastructure designed elsewhere.
Quantum computing raises the same question here as artificial intelligence: who controls the technical framework of the future?
What Leaders Must Do Now
The answer is not to give in to panic. It is to stop treating quantum computing as a conference for specialists.
Three steps are essential.
First, map out the uses of asymmetric cryptography and data requiring long-term confidentiality. Next, test post-quantum or hybrid solutions in controlled environments, without waiting for a full-scale migration. Finally, budget for the transition as a multi-year program, taking into account its hidden costs: additional computing power, compatibility, certification, training, and vendor lock-in.
Cybersecurity has always suffered from a human bias: it is funded too late—after the incident, when the evidence has become visible. Quantum risk reverses this logic. The damage may be done today, but revealed ten years from now.
Perhaps that is the real novelty. Encryption is no longer just a matter of strength. It is becoming a matter of duration.
The safe may still hold. But some already know that one day they’ll have the key.
Cette publication est également disponible en :
