Get ahead of the Q

The ‘scary’ cyber threat posed by quantum computing requires urgent action

By Miranda Maxwell

The clamour is growing for businesses to prepare for “Q-Day” – the moment when quantum computers become powerful enough to break public key encryption methods, sparking a global data breach.

Reserve Bank of Australia governor Michele Bullock says it is “certainly something I worry about. If you believe what they say on the tin of quantum computing, what takes 200 years to decrypt now, to break, will take a matter of minutes. It is a big threat.”  

Quantum computers are expected to be in operation within a decade, and Australian experts warn businesses must start reinforcing cybersecurity now to guard against criminal use of the tech.  

While quantum computing is expected to benefit society enormously – bringing opportunities for medical breakthroughs and computationally intensive portfolio-based insurance pricing – it will also render ineffective the mathematics that keep data safe online.

Standard encryption algorithms are used to secure payments and transactions worldwide, but they won’t stand up to quantum processing.

Ms Bullock notes advanced encryption standards have been developed to meet the quantum computing challenge, but still “it’s scary”.

“We trust our financial institutions to keep our data safe, and they do that through encryption,” she says. “So it is a worry that we need to make sure we keep up with that quantum computing situation – because otherwise it’s not safe.”

Currently, all the digital data we consume – text, images and videos – is built from huge sequences of bits – binary digits, which combine to form kilobytes, megabytes and gigabytes.

These bits – the most basic unit of information, or the “atoms” of computing – have only two possible values, 0 or 1, limiting the speed at which calculations can be performed.

Computer science was shaken up in 1994 when an algorithm by US mathematician Peter Shor demonstrated the potential power of “qubits”.

These can exist in a superposition of 0 and 1 at the same time, allowing simultaneous processing of a huge number of possibilities.

Professor Shor’s algorithm overcame problems that prove hard for classical computers, and it showed how a quantum computer could break much of the encryption that protects online banking, emails, government communications and more, all of which rely on the near-impossibility of factoring big numbers.  

This public key or asymmetric encryption involves a large prime number, kept as a private key, and one of its large multiples combined with other data, which forms a key that is shared publicly.     

The Shor algorithm allows a large number to be factored into prime numbers with a relatively small number of steps, making it quicker than classical algorithms.

By 2019, a qubit processor owned by Google, called Sycamore, had performed a calculation that would take a classical computer thousands of years.

Now, cybercriminals are busy stealing and storing sensitive data, waiting for the time when computing breakthroughs will allow them to waltz past current cybersecurity encryption methods.  

Andrew Scott, the Melbourne-based founder of tech consultancy Far Phase, says quantum computers will “break the foundation” of secure web and virtual private network sessions.

“Malicious actors are capturing these secure sessions with the intent of breaking them when it becomes possible, exposing the data inside,” Mr Scott told the latest CyberCon conference in Melbourne. “This ‘store now, decrypt later’ attack is the present-day threat from future quantum computers.

“Everyone needs to start [preparing] – in fact, start yesterday.”

Fortunately, post-quantum encryption algorithms have been developed, based on different mathematical problems that neither conventional nor quantum computers can solve efficiently, and Mr Scott advises swift migration.

“Organisations with highly sensitive, long-lived data need to begin this immediately. Some of the data may already be exposed.

“Many experts think such computers are likely within a decade, and highly sensitive, long-lived data that was sent over the internet could then be in the hands of cybercriminals. It is a data breach in slow motion.”

The Actuaries Institute says acquisition of a cryptographically relevant quantum computer by a rogue government or organisation will not be “loudly announced”.

“They will simply use it, leaving the data breach undetectable until after its harm has been done,” the institute says. “The situation is particularly urgent for organisations whose data is likely to remain sensitive up to seven or more years into the future.”  

The institute agrees hackers, typically supported by rogue states, are already running “harvest-now-decrypt-later” attacks.

“If your organisation uses data sensitive for that long, then your transition to post-quantum cryptography is already running late.”

The Australian Signals Directorate has also warned of looming challenges, saying effective transition plans are critical for operating in 2030 and beyond – in a “post-quantum” world – and “planning must start now”.

The agency’s information security manual was updated in 2024 with guidelines that require organisations with government and large corporate customers to migrate to post-quantum cryptography by 2030.

Texas-based Hewlett Packard Enterprise executive Ken Rich told CyberCon that Q-Day will mean authentication and authorisation is no longer a barrier.  

“It’s more of a suggestion – adversaries can break into your networks …  It’s going to undermine the trust in our institutions that need cryptography to create that trust. Real estate transactions, banking, all kinds of stuff,” he said.

“You think we’re going to know when Q-Day happens? No, nobody’s going to know. Weird things are going to start happening. They would break into your network, bypass that one piece … with the quantum computer, then go into the network and start doing all kinds of weird things.”

For example, access cards to buildings could be disrupted, and blockchain-based smart contracts compromised.  

“Think about if you can’t trust your bank or your financial transactions any more – if all the digitally signed documents you use couldn’t be verified because they determine somebody has infiltrated the system by which that trust is created.”

Experts recommend a thorough audit of encryption-related processes and encrypted data at businesses of all sizes, and say where encryption is upgraded, careful planning and testing are required to flag unexpected effects on system performance.

Actuaries say few organisations outside the cybersecurity industry appreciate that moving to new encryption standards will be a long process.

“Organisations should assess their data time sensitivity and begin their transition to post-quantum cryptography now,” the institute says.