Jurassic Park showed us how a mosquito trapped in amber can hold a perfect genetic record for 65 million years. The information sat there, intact and useless, until someone finally created the technology to read it. That is quantum risk; it does not bite you today. Instead, it waits in the amber until something can decode it and let it run amok.
Picture a Tuesday in 2029. One of your clients calls. Their data is being published online, and it is data they lost in 2020. Employee records. Private board papers. Internal HR investigations. Years of correspondence with their regulator. At the time the data was originally lost, the incident looked survivable as the files were encrypted.
But when your client calls in a panic over a breach, the last thing they’re thinking about is quantum computing. They are asking a simpler and much harder question. How has an almost decade old, previously resolved cyberattack created a new point of exposure?
This scenario is where our article series on quantum computing starts, because it changes what preparing for the future means. The event your clients need to plan for is not a quantum attack. It is an ordinary theft, happening now, that a quantum computer can unlock later. This process is commonly referred to as harvest now, decrypt later.
For many clients who’s data has previously been stolen it may already be too late.
Dan Brown, Tech E&O underwriter explained “The simple explanation is that quantum represents a huge increase in computing power. Traditional computers work in binary, using ones and zeroes to process information. Quantum computing is different because it can work with far more possible states at the same time, which dramatically increases the number of calculations and answers that can be considered simultaneously.
The practical implication is speed. Problems that would take a classical computer an unrealistic amount of time to solve could become much more achievable with a sufficiently advanced quantum computer. That matters for encryption because today’s security assumptions are built around the limits of classical computing. Encryption is effective because the time and effort required to break it are beyond reach. Quantum changes that calculation, which is why there is so much focus on post-quantum cryptography and getting systems ready before the capability becomes available.”
When we last wrote about quantum computing and encryption, the working assumption across the market was that this technology would become commonplace around 2035. That has been revised by a couple of years.
In March 2026, Google set 2029 as its deadline for migrating its own products and infrastructure to
post-quantum cryptography (PQC). This doesn’t necessarily mean that encryption will definitely break in 2029.
It is one of the world’s largest quantum research programmes deciding it cannot afford to work to the US government timetable, which runs to 2030, 2031 and 2033 depending on the system. Cloudflare followed
with the same 2029 target a month later.
The organisations closest to the technology have shortened their own deadlines, and they have done it in public.
Tim Hodgkins, our Cyber Underwriting Consultant, points to where the real progress has been made; “The main technology change has been around the volume of qubits that can be processed, and the number of errors that get thrown up alongside them. While the number is still important, the usefulness drops off if those qubits are too noisy and error-prone.
“Other areas of focus include reducing error rates, developing quantum correction, creating logical qubits (i.e. error-corrected qubits) rather than simply increasing the number of physical qubits. Additionally, advances have been made in achieving fault-tolerant quantum computing, where errors can be detected and corrected faster than they accumulate.”
Governments have also responded. On 22 June 2026, two executive orders were signed in the United States, one on quantum innovation and one titled Securing the Nation Against Advanced Cryptographic Attacks.
The second sets a deadline of 31 December 2030 for federal agencies to move their most sensitive systems
to post-quantum encryption, 31 December 2031 for post-quantum authentication, and requires federal contractors to meet post-quantum standards by the end of 2030.
Closer to home, the NCSC gives UK organisations three deadlines: complete discovery and assessment by 2028, migrate the highest-risk systems by 2031, and retire vulnerable cryptography entirely by 2035.
These government and private timelines indicate that this once hypothetical risk now has dates attached to it. When any of your clients supply into contracts, those dates can and will be linked to commercial requirements rather than security theory.
There has not yet been a reported real-world cyberattack carried out using a quantum computer.. And it would be easy to use that as a reason to delay planning for post-quantum encryption. The problem is what attackers are doing in the meantime.
The strategy is known as harvest now, decrypt later. An attacker breaks in using entirely conventional methods, takes encrypted data they cannot read, and stores it. Storage is cheap and patience is free. The wait is only worthwhile if the data still matters when the encryption eventually gives way, and a great deal of data does.
J. Foster Davis is Co-Founder and COO of BreachBits, a Brit partner that simulates threat actor behaviour and translates the results into risk and exposure insights for insurers and businesses. He is blunt about how widespread the practice already is; “If any hacker is not applying ‘steal now, decrypt later’, they should be fired from their hacking job. It is so easy, it is so inexpensive. They have what they need today to go and do that.”
He draws a useful distinction between data that ages out and data that does not. Nobody cares about an email from ten years ago about where to have lunch. National insurance numbers, health records, biometric data and intellectual property are a different proposition. ’Evergeen’ data will still be valuable in 2029, and still valuable in 2039.
There is a second consequence that is easy to miss. An attacker running this strategy has every reason to stay quiet. A breach that is never announced generates no press, no remediation and no closed door. Tim highlights that this is similar to a logic bomb attack where hidden malicious code lies dormant in a network until a specific condition is met, at which point it executes its payload.
Continuing to gather data and retaining it is worth more than extortion when you are playing a long game. And access to quantum computing may be the key to winning that long game.
It is tempting to picture a future in which anyone can rent quantum decryption by the hour. While we don’t expect something like that to happen, the timing of quantum availability is something your clients should plan for.
Start with who can build a quantum computer. These machines are enormously expensive, incredibly complex, and few in number. Foster expects them to sit with a small group of heavily funded institutions; “It is going to be under highly controlled, well-funded organisations. Maybe it is a mix of private, but I am sure nation states want a play in this as well, or at least they want some control of it.” He adds that it is highly doubtful a hacker in a basement with limited funding will be building one.
Tim makes the same point from the attacker’s side. The commercially motivated groups behind most cyber claims are economical by nature: they want to get in, get out and go on holiday for the rest of the year. A warehouse holding a machine that costs hundreds of thousands does not fit that business model.
He also expects access to be rationed in much the same way we are already watching happen with frontier AI. Tim explains; “It is not as if it is going to be handed out to everyone straight away. I suspect the nation states will have an equivalent, but it will not be widespread. You will not be able to just sign in and use this quantum capability. I think it will be very reserved, in a similar way to what we are seeing with AI breakthroughs.”
That parallel is worth holding on to. The most capable AI models are already restricted by tier, by vetting and increasingly by nationality. Tim expects export controls and executive orders to do the same job for quantum, on the reasonable logic that no government builds a capability like this and then sells it to the highest bidder. Where the outputs are sold commercially, Foster expects the providers to be hardened, and their customers carefully vetted. As he puts it, a hacker cannot walk up to a kiosk and ask a quantum computer to do something illegal.
The first phase belongs to nation states and their approved suppliers. The second phase is the more uncomfortable one. Tim does not expect the capability to stay contained, and he expects it to travel through proxies rather than the open market and find itself in the wrong hands. This means it would be used for good and bad in the short to medium term.
Tim also expects the earliest uses to be quiet and highly selective, because announcing the capability would trigger the very defensive scramble its holder wants to avoid. On that logic the first targets are critical national infrastructure, government departments, defence contractors holding weapons designs and pharmaceutical intellectual property, rather than the general commercial market.
The uncomfortable truth is that the interval between a capability existing and it reaching commercially motivated attackers (the planning window), will end, and nobody will announce when it closes.
The quantum risk timeline has tightened and nobody can tell you the exact date the threat will become real. What we can be sure of is that this has stopped being a subject for a future risk register. Forward-think attackers will consider collecting encrypted data now on the assumption they will be able to access it later. The organisations building the technology have moved their own deadlines forward. Governments have started setting dates for PQC readiness.
What has not changed is that cyber and data fundamentals still carry your clients a long way. Knowing what data matters, understanding who holds it, what level of encryption it has and having a process for adapting as the picture develops are the same disciplines that already sit behind good cyber risk management.
In our next article in this series, we look at how the insurance market is responding to this threat. And what happens when the breach and loss are separated by years.
To talk through quantum readiness with your clients, explore our cyber risk management services or speak to the Cyber team today