Back to research

S&P Global Ratings — RatingsDirect

April 1, 2026

The Frontier Of Cyber Risk: Quantum Computing Is A Threat To Cryptography Today

Quantum computing's threat to encryption isn't theoretical or future-dated — "harvest now, decrypt later" attacks mean the transition to post-quantum cryptography is a present-tense governance challenge.

Contributing author:Maria Mercedes Cangueiro, Sudeep K. Kesh, Pranav Khattar
Quantum ComputingCryptographyCredit Risk

Key Takeaways

  • While quantum computing is still a new and rapidly evolving technology, related cyber threats already exist with "harvest now, decrypt later" attacks, which involve theft of data today in expectation of quantum-based decryption tomorrow.
  • Near term, management of quantum-related cyber risk is a digital transformation and governance challenge that will require existing cryptography to be catalogued and replaced with post-quantum cryptography, within an organization, through associated vendors, and across wider connected ecosystems.
  • In time, quantum computers will also transform cyberattack and defense, with greater processing power speeding attack timelines, improving threat detection, defensive resource allocation, and cyber risk management.

Quantum computing's vastly accelerated problem-solving ability promises huge advances in calculation power by using qubits, which leverage quantum physics principles such as superposition and entanglement. This should deliver significant benefits across business and society, but it also promises to upend many aspects of cybersecurity.

Quantum computers, algorithms, and software already exist, though the technology remains nascent and the ecosystem small — composed of advanced technology providers working on specific industry and research applications, primarily in chemistry, logistics, and risk management. Yet cyberthreats from quantum computing are not theoretical: attackers are already collecting data in anticipation that quantum algorithms will eventually break the encryption that protects it. Quantum processing speed will also transform cyberattack and defense, initiating an arms race between more powerful threats and nimbler response.

Quantum's Cryptography Threat Is Already A Cyber Risk

The most pressing cyber threat posed by quantum computing relates to its potential to break many of the cryptographic algorithms currently underpinning encryption — including benchmark RSA and ECC public-key encryption that protects much of today's IT systems, online communications, financial transactions, and other sensitive digital information. These algorithms rely on the difficult math of finding factors of large numbers, a task beyond the practical ability of traditional, binary, bit-based computers. Quantum machines' power lies primarily in their ability to deploy qubits in superposition — more than one state at a time — enabling them to explore many possibilities at once and solve problems, including factorization, much faster.

Quantum's cryptography-breaking ability has created the immediate risk of encrypted digital secrets being collected today for breaking in the future — a threat known as "harvest now, decrypt later," which undermines the security of data transmitted or stored using current means of encryption. Today's encryption choices will affect future confidentiality, placing the onus on organizations to plan for and identify quantum-resistant upgrades. Delays to such initiatives could prove a cybersecurity risk, with implications for credit quality.

Timeline chart: quantum-resistant cryptography should be rolled out before quantum computers become available. From 1994 (recognition that a functional quantum computer could break commonly used cryptography) through 2024 (NIST publishes post-quantum cryptography standards) and a post-quantum cryptography migration period, to eventual completion of transition to post-quantum cryptography before fault-tolerant quantum computers become available.
Chart 1 — Quantum-resistant cryptography should be rolled out before quantum computers become available. Sources: Bank for International Settlements, S&P Global Ratings.

Quantum-Proof Cybersecurity Is A Transition Management Challenge

The threat of cryptography breaking for the systems that underpin finance — including credit markets, trading, logistics, and essential services — is stark. Encryption is the basis of secure communication, identity verification, transaction authorization, and software and data integrity; without it, secure, large-scale digital interaction is impossible.

The immediate quantum cybersecurity risk is primarily a transition management issue rather than a technical hurdle. In 2024, NIST published post-quantum cryptography (PQC) standards resistant to both classical and quantum attacks, and plans to phase out quantum-vulnerable cryptography by 2030, mandating a full transition by 2035; several other governments and standards bodies are advancing PQC implementation in parallel. The challenge lies in the ubiquity and deep embedding of current cryptography norms in networks, devices, and applications — for PQC to be effective, it must be deployed and maintained not just within entities but across their digital partners and ecosystems.

Diagram: example quantum readiness journey. Five steps — quantum-readiness roadmap, cryptographic inventory, cryptographic agility, hybrid cryptography, and operational rollout and coordination — represented as icons along a horizontal timeline.
Chart 2 — Example quantum readiness journey. Source: Palo Alto Networks.

The execution of that plan must be managed across thousands of specialized systems — manufacturing execution platforms, supply chain authentication, payment terminals, connected vehicle fleets, and medical device networks — each with individual technology challenges, and risks and impacts that vary meaningfully by sector.

Quantum transition challenges and threats vary by sector
SectorExamples of current cryptography usesHow quantum could increase risksPotential negative impacts
UtilitiesGrid control networks, substation communicationsData theft and controls hackingPower/water supply disruption with safety and national infrastructure implications, and regulatory, financial, and societal consequences
TelecommunicationsPhone networks, user identification, private company networksHarvest now, decrypt later (calls and text)Disclosure of government, financial, and critical-infrastructure communications at huge scale
ManufacturingCommunications, including authenticated commands to production systemsTheft of trade secrets, forgery of production commandsIntellectual property loss, introduction of systematic defects leading to recalls and liability risk
Financial servicesMessaging and authentication in payment and settlement systems (e.g., SWIFT)Interception and decryption of financial messages, message forgeryFinancial loss, systemic disruption with cascading effects across credit markets and trade finance
Pharmaceutical supply chainsDigital signatures for chain-of-custody and product authenticationAuthentication record forgery enabling counterfeitingProduct integrity and safety issues, with regulatory, legal, and public health consequences
Global shipping and logisticsCryptographically signed bills of lading and cargo ownership recordsDocument forgery enabling cargo diversion or theftFinancial and product loss, with knock-on effects for insurers, lenders, and counterparties
RetailE-commerce, online payment, and customer data managementInterception and decryption of payment informationBreaches exposing customer payment information

We expect the transition period will also include a period of hybrid cryptography — combining classical and post-quantum algorithms to facilitate migration and minimize operational disruption while systems gain quantum resistance at different speeds. PQC will be key to maintaining cybersecurity, but it will not be the only piece of the puzzle; complementary quantum cryptography technologies are emerging to further strengthen security in some sectors.

The Threat Of Quantum-Enhanced Cyberattacks

In time, quantum computing will also reshape cybersecurity by accelerating computational tasks central to cyberattacks. Rather than creating new types of attacks, its impact is likely to principally be a factor of faster processing — speeding attacks, making them more scalable, and decreasing defenders' ability to detect or stop intrusions. Quantum algorithms could, in theory, solve optimization problems — such as identifying the weakest attack path through a complex network — more efficiently than classical systems, allowing attackers to plan and adapt more rapidly, and could significantly reduce the time required for brute-force password-cracking attacks.

While these risks are theoretically possible, their near-term application may prove limited: an attacker would require large-scale, fault-tolerant quantum computers integrated with classical systems, along with significant operational expertise. Until such systems exist, quantum-enabled cyberattacks remain a future rather than a present threat.

The Promise Of Quantum-Enhanced Cyber Defenses

The same quantum computing capabilities that could enhance cyber offense may also strengthen cyber defense. Quantum-enhanced machine learning could, in theory, detect complex patterns or correlations in vast volumes of log, network, and behavioral data that classical systems struggle to identify in real time, improving early warning capabilities. Quantum computing may also support better cyber risk modeling and optimization, helping defenders weigh trade-offs between cost, coverage, and resilience, stress-test systems against extreme scenarios, and prioritize controls more effectively.

Throughout this shift, quantum computing's impact on cybersecurity will unfold unevenly. Distinguishing between actions required today and issues that merely require monitoring for tomorrow will position entities to better manage the transition, and help them avoid the twin traps of overreacting, or reacting too late.

The views expressed are those of the authors and do not necessarily reflect the opinions of S&P Global.