Quantum Computing

Quantum Computing emerges as top cybersecurity threat – study

Share

Mumbai: A new report from the Capgemini Research Institute warns that Quantum Computing is no longer a distant threat — it’s an urgent cybersecurity priority. According to the study, titled “Future Encrypted: Why Post-Quantum Cryptography Tops the New Cybersecurity Agenda,” nearly two-thirds (65%) of global organisations now view quantum computing as the most critical cybersecurity risk over the next three to five years.

At the heart of growing concern is the potential arrival of “Q-day”—the moment when quantum computers become capable of breaking classical encryption algorithms that currently secure everything from banking systems to government data. Among so-called early adopters of quantum-safe technologies, one in six believes Q-day could arrive in under five years, while six in ten expect it within a decade.

‘Harvest-Now, Decrypt-Later’ Attacks Fueling Urgency
The report highlights a specific threat already shaping security strategies: harvest-now, decrypt-later (HNDL) attacks. These involve malicious actors collecting encrypted data today with the intent of decrypting it once quantum capabilities mature.

“Quantum readiness isn’t about predicting a date–it’s about managing irreversible risk,” said Marco Pereira, Global Head of Cybersecurity, Cloud Infrastructure Services – Capgemini. “Every encrypted asset today could become tomorrow’s breach if organisations delay adopting post-quantum protections. Transitioning early ensures business continuity, regulatory alignment, and long-term trust.”

Post-Quantum Cryptography Leading Defence Strategy
To counteract future quantum risks, 70% of 1,000 surveyed organisations with annual revenue of at least $1 billion across 13 sectors and 13 countries in Asia–Pacific, Europe, and North America, are actively adopting or piloting post-quantum cryptographic (PQC) solutions. These algorithms are designed to be resistant to attacks from quantum computers and are increasingly viewed as the most viable near-term defence.

Capgemini‘s data reveals that regulatory pressure is playing a significant role: seven in ten organisations say compliance mandates are a primary driver for adopting quantum-safe protocols.

Despite progress among tech-forward sectors like defence and banking, other industries—particularly in retail and consumer products—are lagging in quantum readiness. Roughly 30% of organisations still report minimal investment in quantum-safe transitions, citing budget constraints and lack of skilled personnel as primary obstacles.

The Cost of Waiting
While practical quantum decryption remains years away, the consensus among cybersecurity leaders is that the transition to quantum-safe infrastructure must start now to avoid retroactive breaches and regulatory fallout.

“Quantum safety is not a discretionary spend but a strategic investment, which can turn a looming risk into a competitive advantage. The organisations that recognise this fact early will best insulate themselves against future cyberattacks,” added Pereira.

Key Findings from the Capgemini Report:

65% of organisations are concerned about ‘harvest-now, decrypt-later’ threats
60% of early adopters believe Q-day will occur within 5–10 years
70% of organisations are already pursuing PQC strategies
30% of organisations are underprepared for quantum threats due to resource constraints