Threats, opportunities and the need for post-quantum cryptography

Issue 1 2025 AI & Data Analytics, Infrastructure


Carrie Peter

The first quantum computer was created almost three decades ago, in 1998. Yet the topic still seems to illicit images of ‘Back to the Future’ for most. While its applications are still unknown to many, this advanced field combines computer science, physics, and mathematics to deliver solutions the world has been trying to find for aeons – and those it does not yet know it needs.

Rivalling classical computers and coming out on top, quantum computing uses quantum mechanics to find fast and complete answers to complex problems. According to Carrie Peter, Managing Director at Impression Signatures and Advocacy Committee Vice-Chair at the Cloud Signature Consortium, “Although it sounds futuristic, quantum computing is advancing at a rapid rate – certainly faster than expected. Today, many countries already possess their own quantum computers, with quantum computing even being available as a SaaS solution.”

As is the case with most technological developments, however, the opportunities offered by quantum computing are equalled by the threats this advanced computer science introduces. “The evolution of quantum computing puts the security of any data available in the digital space in jeopardy,” warns Peter.

IBM recently published an article about quantum computing noting that “quantum technology will soon be able to solve complex problems that supercomputers can’t solve, or can’t solve fast enough.” But what if the problem it’s trying to solve, is breaking through security firewalls or encryptions?

“This poses a massive threat to encryption as a quantum computer could decrypt traditional encryption in a fraction of the time. While this surely won’t halt the evolution of the quantum computer, it does mean that security must be bolstered,” adds Peter. Thankfully, global standards and security bodies have been hard at work developing and testing a new set of post-quantum encryption algorithms, with the first three standards being released on 13 August 2024.

As published by the National Institute of Standards and Technology (NIST), these new standards include the Federal Information Processing Standard (FIPS) 203, intended as the primary standard for general encryption; FIPS 204, intended as the primary standard for protecting digital signatures; and FIPS 205, also designed for digital signatures and employing the Sphincs+ algorithm.

Prepare for the risks of quantum computing

In parallel, as standards and security measures are fortified against the threats of quantum computing, it is essential that organisations begin paying attention to post-quantum cryptography (PQC). “Somewhat short-sightedly, many business leaders are countering the argument for PQC with the misguided belief that we are ‘years’ away from commercially available quantum computers,” says Peter. “The reality is that these computers are already being miniaturised and will likely come to market much sooner than expected.”

Additionally, putting PQC measures in place now will protect data from nefarious strategies such as Store-Now Decrypt-Later (SNDL). “This cyber threat entails storing large amounts of encrypted data now, in an effort to decode and use it later, once quantum computers become more widely available.”

In a recent blog entry, HP put it like this, “A sufficiently powerful quantum computer will break the cryptography we rely on in our digital lives. An attacker can intercept and store encrypted data today, and when quantum computers become feasible, the attacker could decrypt the stored data.”

Lastly, Peter motivated that companies need to start thinking about PQC now, because some devices (such as cars) that are being produced today will most certainly be on the road when quantum computing is proliferated. “In 2023, the US government already put out a mandate that companies must transition onto PQC as soon as possible. Now, with the release of the new standards, it is critical to take the need to transition onto PQC seriously.”

Of course, with many global standards being incorporated into these algorithms, any standards-based organisation or solution (such as digital signature providers) will be forced to adopt and comply with PQC. This means for users of these solutions, the switch to the more secure standard will be seamless.

However, it is important for companies to note that encryption is only as good as the authentication they apply while using encryption. “For organisations to guarantee that they are, in fact, secure, they must ensure appropriate access management, authentication, and zero trust within their organisations.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security industry embraces mobile credentials, biometrics and AI
AI & Data Analytics Access Control & Identity Management Integrated Solutions
As organisations navigate an increasingly complex threat landscape, security leaders are making strategic shifts toward unified platforms and emerging technologies, according to the newly released 2025 State of Security and Identity Report from HID.

Read more...
AI for retail risk management
Surveillance Retail (Industry) AI & Data Analytics
As businesses face mounting challenges in a volatile economic environment, Ares-i remains an essential tool for proactively identifying, assessing, and mitigating risks that threaten operational stability and customer satisfaction.

Read more...
Five tech trends shaping business in 2025
Information Security Infrastructure
From runaway IT costs to the urgent need for comprehensive AI strategies that drive sustainable business impact, executives must be prepared to navigate a complex and evolving technology environment to extract maximum value from their investments.

Read more...
Top five AIoT trends for 2025
Hikvision South Africa IoT & Automation AI & Data Analytics Facilities & Building Management
Hikvision highlights that with technological advances, AIoT (AI-powered Internet of Things) is transforming industries not just by enhancing security, but also by making the world smarter and more efficient.

Read more...
The impact of AI on video analytics
Secutel Technologies AI & Data Analytics
Artificial intelligence (AI) has become part of any discussion around security, primarily in video surveillance, but its scope is expanding across more solutions and into integrated systems – where it holds the potential to offer the greatest impact.

Read more...
AI's promise for African economies
AI & Data Analytics
When it comes to transforming the economic potential of Africa, artificial intelligence (AI) is anticipated to contribute up to $1,5 trillion to the gross domestic product (GDP) of the continent.

Read more...
Navigating today’s cloud security challenges
Information Security Infrastructure
While the cloud certainly enables enterprises to quickly adapt to today’s evolving demands, it also introduces unique challenges that security teams must recognise and manage. Vincent Hwang offers insights from the 2025 State of Cloud Security Report.

Read more...
The algorithm of trust
Information Security AI & Data Analytics
Artificial intelligence is not just enhancing threats, it is providing organisations with a smart line of agile and detectable defence.

Read more...
Avoiding the trap of deepfake scams
AI & Data Analytics IoT & Automation
As cybersecurity technology evolves to block traditional attacks, cybercriminals are increasingly turning to social engineering—manipulative psychological tactics that exploit human trust and emotion—to achieve their goals.

Read more...
New AI advisor for robot selection
News & Events Industrial (Industry) AI & Data Analytics
Igus’ new AI chatbot has been added to its online platform to enable companies with little previous experience and technological expertise to quickly and reliably put together Low-Cost Automation (LCA) solutions to become more competitive.

Read more...