Guide to Managing Quantum Computing Cyber Risk
With post-quantum cryptography standards now final, organizations should begin a structured migration program to address future legal, compliance, and product liability risks.
This guide provides a multi-disciplinary roadmap for organizations to manage the risks of quantum computers breaking current public-key cryptography. It urges companies to appoint a post-quantum cryptography (PQC) owner, conduct quantum-specific risk assessments, create a complete inventory of cryptographic systems, and develop a migration plan aligned with new NIST standards (FIPS 203, 204, 205).
Sophisticated clients care because the transition to PQC is a complex, long-term initiative. Failure to prepare creates foreseeable legal and regulatory risk, exposing organizations to "Harvest Now, Decrypt Later" attacks, where adversaries steal encrypted data today to decrypt with future quantum computers. This is especially critical for technology companies with long-lived products and firms in regulated sectors.
Counsel should begin integrating PQC readiness into vendor contracts, product design, board reporting, and cyber insurance reviews. Key developments to watch are emerging PQC-related procurement requirements from government agencies and evolving guidance from bodies like CISA and the NSA, which will shape the standard of care.