powering productive workplaces
Front page
InterviewTrust & Risk52m · 12:35 BST · 4 min read

Why Businesses Need to Prepare For Quantum Cryptography Now

Kristian McCann speaks with Chris Harris, EMEA Technical Director for Data and Application Security at Thales, about why the quantum threat has shifted from a theoretical concern to a strategic priority and how organizations can prepare for the new technology

Author transcript

Hello and welcome to UC today. I'm Kristian McCann and today we're exploring one of the most pressing and underestimated threats facing enterprise security in the notsodistant future and that is the race to quantum proof our data before it's too late. Uh the prospect of a workable quantum computer is no longer science fiction. And when the moment arrives, the cryptography world relies on to protect our sensitive data currently could be rendered obsolete. But that threat doesn't start then. It starts now because obviously there's threats that we will get into. Um, if you're responsible for IT security or technology strategy, then stay with us because I'm joined by Chris Harris, a mere technical director for data and application security at Tales to unpack the quantum threat and what businesses need to do to prepare. So Chris, thanks for joining me today. No problem. Nice to be here. Right. So, as I mentioned in the introduction, Chris, um, you know, Quantum's been talked about for many years, but it really seems to be kind of, uh, picking up intensity, uh, with some of these, uh, companies and, um, you know, security firms really talking about it a lot more in depth. Um, I was wondering, can you tell us what's made this a more urgent conversation? Now, it's it's really the fact that we've moved from something that people saw as an if to something that people now understand is a when. And that is really a completely different business conversation to be having if you're you're a business looking to uh to protect yourself. Um and really what's caused that is several things have happened. So, uh, major governments have published quantum strategies. They've published guidelines that organizations should be following. Um, here in the UK, the NCSC have uh set out some timelines for organizations to create inventories to secure their high priority systems and then then to secure their their whole systems. And other countries have done the same. Those guidelines are out there now. um the the standards bodies have done their work as well. So if you've read anything about quantum over the past uh past few years, you'll have heard about the NIST. Um it was a competition initially where they were looking for algorithms that were going to be postquantum safe. Uh that's concluded. The algorithms have been reviewed, they've been standardized, they've been released, and really that's led vendors to implement some of these things into their technology. Uh, and so now organizations can get commercial products, they can upgrade their software so that they have the ability to become quantum safe. Um and and so the the change really isn't in the quantum computer in itself, although that that's accelerated. Um certainly developments are are increasing uh the pace. Uh it's that we now know what the replacement cryptography looks like, which is really the change from before. You know, five years ago it was wait and see and today the advice has moved to you really need to start doing something about it. Excellent. Well, you you mentioned wait and see, Chris. Perhaps there's some people who are listening to think, well, you know, we can wait and see. You know, quantum isn't a real threat right now. But, um, why is there still a lingering concern about quantum data security even before, you know, we have this operational quantum computer? It's a funny one. Um, but when you think about it, it kind of makes sense. uh and that's that attackers don't need to break encrypted data today. They just need to steal that encrypted data today and then if it has value in 5 years or seven years or 10 years they can decrypt it once these quantum technologies and quantum computers come along. Now, if if you watch the same kind of films that I watch, you know, you kind of think of long long live data, you know, what could that be? And you think about spies and, you know, covert cells in in different countries. And and for sure, you know, that is sensitive data that that that needs to have a long life. But it's it's quite mundane things as well. You know, it's things like medical records, it's intellectual property, it's uh defense information, it's government information, it's research for universities or uh pharmaceutical companies. You know, all of this information is information that has a value which is is very long. Um organizations really focus a lot on and rightfully so on protecting attacks that happen today. Um, so they're they're interested in protecting their networks, their systems from from things that are happening right now, things that are going to happen tomorrow. And really quantum is making us think about those kind of future secrets. Um, it's it's not just when data is moving, it's when data's been stored. And I am sure that information has been taken today even though they don't know what it is because it's encrypted with technology that's still valid. It's still protecting that information. But at some point in the future, somebody is going to have the ability to troll through that information uh to see what it was that they captured. And some of it won't be any use. Some of it will be pretty dull. I'm sure if anybody wants to see what's going on in my WhatsApp conversations, they're more than welcome to. They're not that interesting. Um, but some of it will be very valid data um, which impacts people and impacts organizations. And so that's why it's really important to start thinking today about how you protect that information because it's like it's like a burglar stealing a safe and knowing that a master key is going to be made in the future. They just need to sit and wait. Okay. Well, you mentioned uh obviously it's a very scary prospect that you've uh you raised even before the advent of quantum computing, but you've also mentioned a couple of sectors. You know, you mentioned uh university, uh companies of intellectual property, uh military. I was wondering um which sectors do you think are the most exposed of this uh quantum threat if indeed um it's happening soon or even even kind of initial attacks right now where they're where they're perhaps doing this kind of steal now decrypt later. It it ties in with you know the kinds of information that that is long lived. So, you know, governments will be definitely a target. Um, and certainly more exposed defense organizations. We have financial organizations, um, communication companies, you know, uh, people that protect information when people are communicating, you know, like we're talking or like you communicate with anybody. Um, you know, all kinds of information gets shared. there's cloud providers, uh the pharmaceuticals, and really that's kind of the first group of organizations who who really should be doing something about it and many of them are. I mean, you know, I don't want to scare anybody and and suggest that this has come out of nowhere. You know, this has been something that's been on the radar for a long time, but the pace is definitely growing. Um but you you can definitely broaden that out. Um if you think about things like VPNs, many organizations use VPN technology. Uh digital certificates or all organization use digital certificates in some way. Um identity systems if you think about source code, code signing. So when you install an application, when you download an application, it's signed. You know where it's come from. You know that it's come from a trusted source. uh if you can fraudulently create signatures, you can create software that people will start installing and that will be another way into an organization to to get malware out there. Uh it's, you know, APIs that that organizations have that that provide connectivity to other organizations and to customers. And so really, you kind of end up with with every organization being impacted by this. Um but really it's it's about prioritization. Um it it's it's funny that you know ideal in cryptography it's kind of what we do but very few organizations think of them as think of themselves as a cryptography company. Um but really every business that conducts business digitally is at heart a crypto company. Uh it just doesn't doesn't serve you very well when you go to the board you know and you start talking about crypto and quantum and cubits. uh you're much better off talking about risk and you know this this is a real risk. Okay. Well, it is as you mentioned it is a real risk and maybe someone listening to this would be um definitely keen to move to uh mitigate the risk or manage the risk. So what would you say they should be doing to prepare now and what does that preparation involve? I think the good news is that the path has become clearer. um it's become a lot lot more obvious what organizations can do and there's a lot better support and tools for them to to be able to do that. Uh that the starting point is really that most organizations don't know where cryptography exists. I I was looking around the room that I'm standing in my office uh at home today thinking you know well it's it's you know your standard home office. Where's where's crypto? But then I'm looking up at the the ceiling and I've got, you know, a connected smoke alarm so I know if my house is on fire when I'm outside. That's got a certificate in it that's communicating with a cloud service. I've got a printer that's cloud connected I think so that they can sell me ink to be honest. But you know that connects to a cloud service and it's sat on my home network. And so discovery is really important. You know at an enterprise scale then obviously that's much wider. It's about the certificates, the databases, the applications, the cloud connectivity, the APIs. You you've got to see what you've got that uses crypto. And then the next step is to do something of an inventory to find out how that crypto works. Um, you know, what what form it takes. So, what algorithms do you use, what key lengths they are, what does it communicate with, what certificates have you got? Because only really once you've got that picture of where the crypto is and how it's being used and and whether some of it's okay or or not okay or needs looking at uh can you then move on to prioritizing which is really your next step. You need to figure out what needs to be replaced first. Um quantum protection postquantum cryptography is one of these funny things where where doing a little bit of it is better than doing nothing. You don't have to be completely quantum safe or not quantum safe. You know, there's definitely a prioritization, an order in which you should approach these things. And so, you should be looking for these long-term secrets, this information that needs to be protected for a long ter the long term uh and start there. And then once you kind of move through that, you can start looking at more mundane systems within your organization where uh the impact would be less or the information is very short-lived. then you can you can really kind of wait until until that kind of technology exists. Um but certainly you can't migrate what you can't see. So you need to find it and then start testing. You know begin some tests on postquantum to make sure that it it works in your environment that you're comfortable using it and that you can create a kind of repeatable process for all those pockets within your organization where you're going to need to do something. Okay. Well, that was a great sort of uh basis for, you know, what you should really be looking at for um quantum securing um your enterprise and its different um arteries. But I was wondering, you gave us some good examples, but um what does a migration to post quantum involve beyond just knowing right what needs to go first and what's most important? Uh how long does it take and what are the kind of challenges that you imagine many organizations might see? Well, for sure the challenge is is, you know, as I've said, most organizations genuinely don't know where cryptography is used within their organization. Certainly, they don't know everywhere that it's used. Um, the second challenge is really probably dependencies. Uh, if you think about an organization, you know, there will be very few organizations where everything that they use is something that they've created themselves. And it's really only those things you create yourself that you've got the ability to update, to change, to to, you know, figure out how you're going to address this this quantum threat. The other, I don't know, 80% or whatever an organization has belongs to software vendors. It's software that you've purchased. It's hardware that you've purchased. It's software as a service, cloud services that you use. And it's those vendors and those partners that are going to need to do the work. And so for you as an organization, you need to start working with those partners. You need to start asking them the questions, the difficult questions about, you know, how are you protecting this? Are you protecting it? What's your postquantum road map? So that you can start crossing some things off your list in your inventory so that you can, you know, end up in a situation where you feel comfortable. Um, it's it's a little bit like I don't know when they replace lead pl in plumbing. You know, all the pipes in old cities used to be lead and uh obviously that's not very good for you and so they need to replace them. They can't turn the water off, replace all the pipes and then turn it back on. It's it's a process which is bit by bit, little by little. And very much that's the approach here. It's about identifying something that needs to be changed, thinking about how you're going to change it, changing it, and then moving on to the next part of of what really is a big map, an infrastructure or an architecture diagram. Yeah, absolutely. And it being such a big map, um maybe some people might think, well, where where should I even start first? Um for companies wanting to get ahead and start to prepare now, what would you say is the uh the biggest single piece of advice you could give them? you need to begin understanding where your cryptography lives because everything else depends on that. Um I I'd say that trust is much harder to rebuild than cryptography is. So uh that that's something to be aware of and I would say that this is an opportunity for organizations. Um again when you read about quantum you you might see the phrase crypto agility is one that we use a lot and that means that what you want to replace this with is not something else which is fixed and then some number of years down the line we're going to go through this all over again when somebody needs to change the algorithm to a longer key length or a different algorithm. You need to put something in place which is configurable and updatable so that in the future it doesn't require this whole discovery journey and re-engineering effort. It just requires configuration changes. It requires small updates. You know what you've got and uh and then you can very quickly be yeah crypto agile. And so that would really be my best advice. Okay. Well, that's good good piece of advice to end it on. Thank you for joining us today, Chris. No problem at all. Thank you. And thank you to the audience for watching. If you've enjoyed this, as always, don't forget to like, comment, and subscribe to stay in touch with more great videos like this. I'm Christian from UC Today, and until next time, we'll see you then. [music] [music]

Quantum computing has long been discussed as a transformative technology, but the conversation is increasingly shifting away from possibility and toward preparation. While fully capable quantum computers have yet to arrive, the cybersecurity industry is warning that organizations need to begin adapting today if they want to protect sensitive information in the years ahead.

In this episode of UC Today, Kristian McCann is joined by Chris Harris, EMEA Technical Director for Data and Application Security at Thales, to explore why quantum readiness is becoming a pressing issue for enterprise security teams. Harris explains why businesses should no longer view quantum computing as a distant concern and outlines the practical steps organizations can take before existing cryptographic protections become obsolete.

Rather than focusing on technical theory, the discussion examines the real-world business implications of post-quantum security. From government guidance and emerging standards to changing risk assessments, Harris offers practical insight into why organizations should begin planning now instead of waiting for quantum computers to become commercially viable.

From 'If' to 'When'

One of the biggest changes, Harris explains, is that quantum computing is no longer viewed as a hypothetical development. Governments, standards bodies, and technology vendors have all made significant progress in preparing for a post-quantum world, fundamentally changing the conversation for enterprise leaders.

"It's really the fact that we've moved from something that people saw as an if to something that people now understand is a when," Harris says. "That is really a completely different business conversation."

He points to several developments driving that urgency. National cybersecurity agencies, including the UK's National Cyber Security Centre (NCSC), have begun publishing migration timelines, while the U.S. National Institute of Standards and Technology (NIST) has completed the standardization of post-quantum cryptographic algorithms. As a result, vendors are increasingly embedding quantum-resistant encryption into commercial products, giving organizations the tools they need to begin transitioning.

Perhaps the most concerning aspect of the discussion is the so-called "harvest now, decrypt later" threat. Rather than waiting for quantum computers to become operational, attackers can steal encrypted information today and simply store it until future technology enables them to decrypt it. That makes data with a long lifespan—including intellectual property, government records, medical information, defense data, and pharmaceutical research—particularly vulnerable, even if current encryption remains secure today.

Building a Road Map for Quantum Readiness

While the risks may sound daunting, Harris argues that organizations should approach quantum migration as a structured risk management exercise rather than an overwhelming technology project.

The first step, he says, is understanding where cryptography exists across the business. Many organizations simply do not know how extensively encryption underpins their applications, devices, cloud services, APIs, databases, certificates, and identity systems. Without that visibility, planning any migration becomes nearly impossible.

Once that inventory has been established, businesses can prioritize the systems protecting their most valuable long-term information. Harris stresses that organizations do not need to become fully quantum safe overnight. Instead, they should focus first on the assets whose confidentiality must be preserved for many years before gradually expanding their efforts across the wider environment.

Migration also depends heavily on technology partners. Most organizations rely on software, hardware, and cloud services developed by third parties, meaning vendors play a crucial role in enabling post-quantum security. Harris encourages organizations to begin asking suppliers about their post-quantum road maps while simultaneously testing new cryptographic approaches within their own environments.

Finally, Harris advocates designing for "crypto agility" rather than simply replacing one algorithm with another. Future cryptographic standards will inevitably continue evolving, so businesses should aim to build systems that can be updated through configuration rather than requiring another large-scale migration project. As he summarizes: "You need to begin understanding where your cryptography lives because everything else depends on that."

Preparing Today for Tomorrow's Security Challenges

Quantum computing may not yet have broken today's encryption, but the interview makes clear that preparation cannot wait until that moment arrives. Organizations responsible for protecting long-lived data face a unique challenge because information stolen today could become readable years from now.

Rather than creating panic, Harris presents quantum readiness as an opportunity to strengthen long-term security strategy. By identifying cryptographic assets, prioritizing critical systems, engaging technology vendors, and building more agile security architectures, organizations can reduce future disruption while improving resilience against emerging threats.

The message throughout the discussion is ultimately one of proactive planning rather than reactive security. As quantum computing moves steadily closer to reality, businesses that begin laying the groundwork today will be significantly better positioned than those that wait for the technology to mature before taking action.

rate this story
helps rank stories across uc today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
picked for this story

OpenAI Expands Daybreak With GPT-5.6-Cyber as Autonomous Threats Grow

11 Aug 2026
picked for this storyCornerstone Finds HR and IT Need to Coordinate on AI as Employees Struggle to Prepare for Change13 Aug 2026picked for this storyGeopolitical Tensions Are Reshaping European Tech Decisions, Study Finds6 Aug 2026