Quantum computing has long been discussed as a transformative technology, but the conversation is increasingly shifting away from possibility and toward preparation. While fully capable quantum computers have yet to arrive, the cybersecurity industry is warning that organizations need to begin adapting today if they want to protect sensitive information in the years ahead.
In this episode of UC Today, Kristian McCann is joined by Chris Harris, EMEA Technical Director for Data and Application Security at Thales, to explore why quantum readiness is becoming a pressing issue for enterprise security teams. Harris explains why businesses should no longer view quantum computing as a distant concern and outlines the practical steps organizations can take before existing cryptographic protections become obsolete.
Rather than focusing on technical theory, the discussion examines the real-world business implications of post-quantum security. From government guidance and emerging standards to changing risk assessments, Harris offers practical insight into why organizations should begin planning now instead of waiting for quantum computers to become commercially viable.
From βIfβ to βWhenβ
One of the biggest changes, Harris explains, is that quantum computing is no longer viewed as a hypothetical development. Governments, standards bodies, and technology vendors have all made significant progress in preparing for a post-quantum world, fundamentally changing the conversation for enterprise leaders. Thatβs because, as Harris says,
βItβs really the fact that weβve moved from something that people saw as an if to something that people now understand is a when.β
He points to several developments driving that urgency. National cybersecurity agencies, including the UKβs National Cyber Security Centre (NCSC), have begun publishing migration timelines, while the U.S. National Institute of Standards and Technology (NIST) has completed the standardization of post-quantum cryptographic algorithms. As a result, vendors are increasingly embedding quantum-resistant encryption into commercial products, giving organizations the tools they need to begin transitioning.
Perhaps the most concerning aspect of the discussion is the so-called βharvest now, decrypt laterβ threat. Rather than waiting for quantum computers to become operational, attackers can steal encrypted information today and simply store it until future technology enables them to decrypt it. That makes data with a long lifespanβincluding intellectual property, government records, medical information, defense data, and pharmaceutical researchβparticularly vulnerable, even if current encryption remains secure today.
Building a Road Map for Quantum Readiness
While the risks may sound daunting, Harris argues that organizations should approach quantum migration as a structured risk management exercise rather than an overwhelming technology project.
The first step, he says, is understanding where cryptography exists across the business. Many organizations simply do not know how extensively encryption underpins their applications, devices, cloud services, APIs, databases, certificates, and identity systems. Without that visibility, planning any migration becomes nearly impossible.
Once that inventory has been established, businesses can prioritize the systems protecting their most valuable long-term information. Harris stresses that organizations do not need to become fully quantum safe overnight. Instead, they should focus first on the assets whose confidentiality must be preserved for many years before gradually expanding their efforts across the wider environment.
Migration also depends heavily on technology partners. Most organizations rely on software, hardware, and cloud services developed by third parties, meaning vendors play a crucial role in enabling post-quantum security. Harris encourages organizations to begin asking suppliers about their post-quantum road maps while simultaneously testing new cryptographic approaches within their own environments.
Finally, Harris advocates designing for βcrypto agilityβ rather than simply replacing one algorithm with another. Future cryptographic standards will inevitably continue evolving, so businesses should aim to build systems that can be updated through configuration rather than requiring another large-scale migration project. As he summarizes:
βYou need to begin understanding where your cryptography lives because everything else depends on that.β
Preparing Today for Tomorrowβs Security Challenges
Quantum computing may not yet have broken todayβs encryption, but the interview makes clear that preparation cannot wait until that moment arrives. Organizations responsible for protecting long-lived data face a unique challenge because information stolen today could become readable years from now.
Rather than creating panic, Harris presents quantum readiness as an opportunity to strengthen long-term security strategy. By identifying cryptographic assets, prioritizing critical systems, engaging technology vendors, and building more agile security architectures, organizations can reduce future disruption while improving resilience against emerging threats.
The message throughout the discussion is ultimately one of proactive planning rather than reactive security. As quantum computing moves steadily closer to reality, businesses that begin laying the groundwork today will be significantly better positioned than those that wait for the technology to mature before taking action.