TECHNICAL NEWS

·

Post-Quantum Cryptography

·

6 min read

The Quantum Countdown Has Started: Are You Ready

Quantum computers that can break today's encryption are still years away — but the shift to post-quantum cryptography has already begun. Here's why Australian businesses should start planning now, not later.

Quantum computers capable of breaking today's encryption may still be several years away, but the migration to post-quantum cryptography has already begun. Governments, cloud providers and major technology vendors are moving now because replacing the cryptography that underpins modern business isn't a software update — it is a long-term transformation.

BOTTOM LINE UP FRONT

Quantum computers can't break today's encryption yet — but “harvest now, decrypt later” attacks mean long-lived data is already exposed, and migrating to post-quantum cryptography takes years, not a weekend. The organisations that map where encryption lives across their systems now will spread the cost and avoid a disruptive scramble later. Start with visibility, not replacement.

Why this matters today — not in ten years

Quantum computing is coming… But cybercriminals aren't waiting to start benefiting from them.

Security researchers warn of a strategy called “harvest now, decrypt later” - sensitive information intercepted today can be stored until sufficiently powerful quantum computers exist to decrypt.

That makes any data with a long shelf life valuable — customer records, financial information, intellectual property, legal documents, engineering designs, defence supply-chain data and long-term contracts. If your business data as long term value than quantum risk has already entered the conversation.

What exactly is Post-Quantum Cryptography?

Post-Quantum Cryptography (PQC) replaces today's widely used public-key encryption algorithms—such as RSA and Elliptic Curve Cryptography (ECC)—with new mathematical algorithms designed to resist attacks from both conventional and future quantum computers.

Although the algorithms are new, they run on today's computers and networks. Organisations don't need quantum hardware to implement them; they need software and systems that support the new cryptographic standards.

Australia is aligning closely with international efforts. The U.S. National Institute of Standards and Technology (NIST) published the first standardised PQC algorithms in 2024, and those standards are now being incorporated into operating systems, web browsers, cloud platforms and security products from major technology providers.

The Australian Signals Directorate have advised organisations to identify where cryptography is used within their environments and to begin planning for cryptographic agility—the ability to replace encryption algorithms as standards evolve. For Australian organisations, particularly government agencies, critical infrastructure operators, defence suppliers and businesses handling sensitive information, preparing for post-quantum migration is increasingly viewed as a matter of prudent risk management rather than a distant technology project.

For many small-to-medium business, particularly with a majority of Software as a Service (SaaS) or cloud systems (think Microsoft 365, Azure, AWS, Google Workspace, Salesforce, Xero), then you probably won't be implementing Post-Quantum Cryptography yourself. Your role shifts to governing and verifying it.

In plain English

Think of today's encryption as a sophisticated lock. Quantum computing promises a far more powerful set of lock-picking tools. Post-Quantum Cryptography replaces those locks before the new tools arrive — so you keep protecting sensitive information without waiting for the threat.

Why migration will take years

You cannot simply “turn on” quantum-safe encryption when the time comes. In reality, encryption is woven through almost every business system — email, VPNs, cloud applications, Microsoft 365, websites, identity systems, and, increasingly, IoT devices.

Further, it can be difficult to even comprehend how many different crypto systems are running in your business. Replacing them takes careful planning, updates, compatibility testing and, sometimes, hardware replacement. Large organisations expect these programs to run for several years — so those who evolve their environment early can avoid expensive, disruptive migrations later.

Which Australian organisations should pay attention?

Not every small business faces the same urgency, but some sectors should already be preparing. Do you:

  • hold sensitive customer or financial information

  • retain records for many years

  • supply government or defence

  • operate critical manufacturing systems

  • manage intellectual property

  • work in healthcare, engineering, legal or financial services.

Even a small business may soon need to show customers it is planning for quantum-safe security — particularly as part of a larger supply chain.

Start with visibility, not replacement

The first step isn't buying new security products — it's understanding where cryptography already exists across your organisation. Identify a cryptographic inventory: where encryption is used, which algorithms protect critical systems, how certificates are managed and which applications may need upgrades.

This is the foundation of crypto-agility — the ability to swap encryption algorithms as standards evolve without rebuilding entire systems. It's a resilience capability that extends well beyond quantum computing.

What you should do next

Quantum computing isn't a reason to panic. It's a reason to plan. Practical first steps:

  • identify systems that rely on public-key cryptography

  • understand how long your sensitive information must stay confidential

  • ask software vendors about their PQC roadmap

  • factor quantum readiness into future technology procurement

  • build a cryptographic inventory before large-scale migration becomes necessary.

You don't need to replace every algorithm tomorrow — but you do need a plan. Start early and you'll spread the cost, minimise disruption, and show customers, boards and regulators you're thinking beyond the next software update. The quantum era is still emerging, but the countdown has already started.

Frequently asked questions

Will quantum computers break all encryption?

Does my small business need to act now?

What is “harvest now, decrypt later”?

Is Australia preparing for Post-Quantum Cryptography?

How can Hardrock Cyber help?

Not sure where your business stands?

Independent assessments, Australia-wide. Every enquiry is confidential.

Request a Confidential Enquiry