Quantum is here. Why isn’t it on your board’s agenda? 

Quantum computing is not a nebulous future risk. It’s here now and the technology is progressing in rapid leaps, magnified and accelerated by AI. It should be on every board agenda already and, if it’s not, internal auditors must engage, challenge and explain its urgency. 

 

While apocalyptic predictions around AI make headlines, mass quantum decryption is a more immediate risk threatening every organisation. Hackers are planning ahead and stealing data now to decrypt later. If organisations are not protecting their data with post-quantum encryption algorithms, they are already exposed. 

 

You can’t wait for someone to devise a simple patch that will eliminate the risks of mass quantum-enabled data decryption. Some predict this will happen as soon as 2029. Meanwhile, many organisations could not identify all their own systems and devices that use encryption – and even fewer have adequate assurance from their suppliers. 

 

This was the message at the Internal Audit Conference session on “Q-Day”, chaired by Sheila Pancholi, Partner & National Technology Risk Assurance Leader, RSM UK. She was joined by Professor Ashley Montanaro, Professor of Quantum Computation at the University of Bristol, Dr Rachel Player, Associate Professor, Department of Information Security, Royal Holloway University, and Richard Curtis, Director, Technology and Cyber Risk Assurance at RSM UK, to discuss the evolving risks.  

 

They explained what internal audit teams must know and do now. 

 

What are the key quantum risks?

  • Complete failure of your encryption and exposure of all your data and encrypted devices.
  • Hostile actors steal your data now for decrypting later once quantum decryption is available to them.
  • Compliance failures that eliminate your business from meeting contractual obligations, exporting to other jurisdictions or supplying critical infrastructure organisations.
  • Systems shutdowns or expensive last-minute solutions could be necessary if you leave major encryption replacement projects until too late.
  • Cyber risks created by gaps in your knowledge of encryption in your organisation or failure to implement due diligence down your supply chain. 

The good news is that we already have quantum-secure encryption algorithms – and these seem to be resilient. Many organisations with critical sensitive data have already started migrating wholly to these. 

 

“I’m fairly confident that lattice-based quantum cryptography will be robust,” Player said. “We’ve been testing them rigorously for years and they’re holding up well.” 

 

What to do now 

  • Get the board engaged. Quantum risk must be on the board agenda – if it’s not, you should be asking why not. “This is a new kind of systemic risk that we’ve not seen before and it touches every part of the organisation,” warned Montanaro. “This is absolutely a board-level risk.”
  • Put a date on Q-Day. It is coming, but we can’t be sure when – Player admitted that people were saying it would take 20 years when she began her PhD and were still saying this several years later. But some experts are now saying 2029-2035 and she said this may not be unrealistic. “It’s feeling risky to bet against the 2029-25 predictions,” agreed Montanaro.
  • Put quantum on your risk register. Assess the risks your organisation faces and ask what your risk appetite should be.
  • Challenge the IT team to create a cryptography inventory for your organisation. Curtis said they probably can’t identify everywhere encryption is used across the business. Encryption is embedded in hardware as well as software, he reminded the audience. Just logging on to your laptop involves encryption. “You’ll need to look at device security as well as data storage and transfer,” he warned.
  • Map your data. What data is critical and sensitive? What data will you store for many years? This will be most useful to hackers seeking to harvest data now.
  • Ask about (or help to inform) your business’s understanding of quantum-secure encryption. Are you already migrating to quantum secure encryption? Do you have a plan to do so? 
  • Map your organisation’s progress against the National Cyber Security Centre’s (NCSC’s) timeline and check the latest advice and guidance, including takeaways from its first quantum migration workshop. This includes a section on how to engage the board and build a business case for migration.
  • Check your contracts. Which ones require, or are likely to soon require, quantum-secure encryption? Can you meet this requirement? 
  • Check your supply chain due diligence processes. What do you ask and require of suppliers? “This should be part of your onboarding process,” advised Curtis. “Look at it along with Cyber Essentials Plus and demand evidence that they have a plan in place.” 
  • Check the assurance you receive over quantum security from existing suppliers. Do you have evidence that they are using post-quantum encryption and are meeting the best, most recent security standards?
  • Monitor quantum developments. Player and Montanaro agreed that you don’t need to understand how quantum works – you just need to understand what your organisation must do to ensure data and systems are secure.
  • Monitor regulatory developments. These could develop fast once a significant threat is detected.
  • Spot the opportunities. Montanaro stressed that quantum computing brings huge possibilities in assessing multiple complex scenarios – for example, predicting UK energy needs or logistics. He pointed to projects that are already using it for testing how superconductor materials will respond to different environments. The potential for decryption is just one negative aspect, he added. 

 

Quantum will not replace conventional computers or AI, Montanaro explained. “These are specialist machines and they don’t do some things as well as standard computers, but there are synergies and AI used together with quantum could be very powerful. The pace of discovery will increase and things will get more intense,” he said. 

 

“AI is already making a big difference in quantum computing and this is only the beginning,” Player said. “It’s an exciting time to be a cryptographer.” 

 

Q-Day: What are the key risks we need to be aware of to prepare for Quantum computing is available on-demand.