Council Post: Quantum Cyberattacks Are Now A CIO Deadline, Not A Research Topic

Adi Karisik, Vice President and Chief Technology Officer, Intelligence & Cyber, Amentum.

getty

​​The enterprise cybersecurity playbook is facing an impending mathematical cliff. Chief information officers (CIOs) have operated under a comfortable assumption: While encryption algorithms will eventually need upgrading, the sheer computational shielding around our current data architectures would buy us years, if not decades, to adapt.

That assumption is no longer valid. Driven by massive nation-sponsored investments and a series of historic engineering breakthroughs, quantum computing is accelerating at a rate that catches many leaders off guard. The quantum threat to public-key cryptography is transitioning from a theoretical future to an immediate risk.

To understand the urgency of the threat, one must look at how rapidly quantum processing power is scaling. In 2019, Google’s 53-qubit Sycamore processor made global headlines by achieving "quantum supremacy," completing a highly specific, abstract calculation in roughly 200 seconds that would have taken a supercomputer an estimated 10,000 years.​

The launch of Google's next-generation Willow processor demonstrates how aggressively this technology is moving. Equipped with 105 qubits, Willow solved a benchmark problem in under five minutes that would take a leading classical supercomputer an estimated 10 septillion years. Beyond raw speed, Willow's logical error rate is a staggering 20 times lower than Sycamore’s.

This massive leap forward is explained by a fundamental law of quantum mechanics. Unlike classical computers, where adding more processing elements increases capacity incrementally, each additional qubit expands the number of possible computational states exponentially.​

This exponential scaling directly targets the heart of modern enterprise security. Current foundational encryption protocols, specifically Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC), secure every aspect of modern society: from national security, banking, healthcare and cloud databases to VPNs and digital signatures.​

RSA and ECC are entirely dependent on a mathematical asymmetry: the near impossibility for classical computers to factor massive, multi-hundred-digit prime numbers or solve discrete logarithms within a human lifetime. Quantum computers running Shor’s algorithm bypass this mathematical barrier completely. Because of the rapid hardware acceleration seen in systems like Willow, quantum architectures are rapidly approaching the scale necessary to factor both RSA and ECC public keys in a matter of minutes, rendering current public-key infrastructure obsolete.​

This technological surge is also being turbocharged by intense geopolitical competition. Public policy data indicates that China has made quantum technology a major strategic priority, with government-backed investments among the largest in the world.​ With an estimated commitment surpassing $15 billion, Beijing has transitioned quantum engineering from an academic research objective into a core industrial imperative. By constructing sprawling dedicated infrastructure hubs like Hefei’s "Quantum Avenue" and the National Laboratory for Quantum Information Sciences, these investments are accelerating the development of quantum capabilities with significant implications for future cryptography, national security and technological competitiveness.​

For years, intelligence agencies have warned of a passive espionage strategy known as "harvest now, decrypt later" (HNDL). Foreign adversaries actively intercept and store massive amounts of encrypted data. They do not need to break the encryption immediately; they simply store the data, waiting for fault-tolerant quantum systems to mature.

The arrival of below-threshold error correction and advanced chips is causing timelines to compress. CIOs can no longer afford to view HNDL as a problem for the next decade. The paradigm has shifted to "harvest now, decrypt soon." The proprietary IP, all data and strategic roadmaps transmitted over public networks today are highly vulnerable to being exposed in the near, predictable future.​

​To mount an effective defense, CIOs must align with verified global standards. The National Institute of Standards and Technology (NIST) finalized its first official standards for post-quantum cryptography (PQC), including lattice-based mathematical algorithms like ML-KEM (for key establishment) and ML-DSA (for digital signatures). These algorithms rely on geometric complexities that are equally intractable for both classical and quantum architectures.

​CIOs should also distinguish between PQC and quantum key distribution (QKD). While QKD uses the quantum properties of light to secure dedicated point-to-point links, its reliance on specialized hardware and fiber infrastructure makes it difficult to deploy across most enterprise environments. It also does not replace the need to protect data at rest or data moving through conventional routed networks. For these reasons, organizations such as NIST and the National Security Agency have prioritized the transition to standardized PQC algorithms for broad enterprise use, while QKD remains a niche technology suited to specific, tightly controlled scenarios rather than general-purpose network security.​

​The gravity of the quantum threat has triggered a wave of government interventions worldwide, establishing delivery schedules. The White House issued a series of Executive Orders (14412/14413) targeting critical protections against foreign cyber threats, compelling federal agencies and their commercial partners to accelerate their migration plans and secure high-value assets. French standardization bodies (ANSSI) are actively phasing out and refusing to certify any IT solutions that do not demonstrate robust, quantum-resistant cryptographic capabilities.

Under the NSA's Commercial National Security Algorithm Suite (CNSA) 2.0 guidance, new acquisitions for U.S. National Security Systems are generally expected to support quantum-resistant cryptography beginning in 2027. This requirement affects vendors and contractors supplying those systems and marks the beginning of a broader, phased transition to post-quantum cryptography that extends into the early 2030s.​​

​The federal guidance increasingly emphasizes cryptographic inventories, interoperability and crypto agility, enabling organizations to migrate systematically rather than relying on isolated fixes. This rule is designed to eliminate the gaps, configuration errors and vulnerabilities that occur when legacy systems are updated piecemeal, ensuring absolute cryptographic agility across the full enterprise stack.

The luxury of treating quantum preparation as a long-term research project is officially over. The transition to a post-quantum architecture cannot be handled like a slow-moving software upgrade cycle. It is a fundamental reengineering of data security that requires immediate execution.

With stringent regulatory deadlines arriving, CIOs must initiate a comprehensive cryptographic audit; map your digital networks, inventory every dependency relying on RSA or ECC, demand native end-to-end PQC compliance from technology vendors and implement agile frameworks capable of swapping out algorithms seamlessly. The window for proactive defense is closing fast, and those who fail to secure their data infrastructure today risk discovering that sensitive data protected today may no longer be secure tomorrow.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?