G7 Urges Urgent Shift to Post-Quantum Cryptography
The G7 cybersecurity working group is warning that quantum computing poses a near-term, real-world threat to current encryption standards, not merely a distant theoretical risk. Organizations that delay transitioning to post-quantum cryptography (PQC) face potential exposure of sensitive data through 'harvest now, decrypt later' attacks, where adversaries collect encrypted data today to decrypt once quantum capabilities mature. Critical sectors such as finance, healthcare, and government infrastructure are especially at risk given the long lifecycle of their systems and the sensitivity of their data. The uneven pace of adoption across industries creates systemic vulnerabilities, as interconnected supply chains and financial networks are only as secure as their weakest cryptographic link.
Tactical Insight
Immediate actions
- Conduct a cryptographic inventory to identify all systems, protocols, and certificates relying on RSA, ECC, or other quantum-vulnerable algorithms.
- Assess exposure to 'harvest now, decrypt later' threats by auditing long-lived sensitive data protected by current encryption.
Long-term improvements
- Develop and execute a formal PQC migration roadmap aligned with NIST's finalized post-quantum standards (FIPS 203, 204, 205).
- Prioritize crypto-agility in system architecture so cryptographic algorithms can be swapped without full system redesign.
- Engage vendors and supply chain partners to confirm their PQC transition timelines and dependencies.
Governance & compliance measures
- Establish executive-level ownership of the PQC transition and report progress to the board as a material business risk.
- Align PQC planning with emerging regulatory guidance from bodies such as ENISA, NCSC, and sector-specific regulators like financial authorities.