The Quantum Threat: What Organisations Need to Know Now
Wed 22 Apr 2026

Cybersecurity planning has long been influenced by emerging threat models. Today, quantum computing is moving from theoretical discussion into strategic risk assessment.
While the precise timeline for quantum capability remains uncertain, its implications for cryptographic systems are increasingly part of enterprise planning. From encrypted data and digital identity to the resilience of critical infrastructure, the potential exposure extends beyond IT and into broader governance and risk frameworks.
Ahead of Tech Show Frankfurt, Tommy Charles, Chief Cryptographer at HP Security Lab, outlines how organisations should approach quantum risk today. In this Q&A, he examines where understanding remains incomplete, why preparation requires cross-functional coordination, and what practical steps leaders can begin taking to strengthen long-term resilience.
– – – – – –
How is the quantum threat currently being interpreted inside organisations, and where does that understanding fall short?
Quantum threats are hard to estimate, potentially striking both fear and apathy. The quantum threat refers to the risk that quantum computers could (and will) break the cryptographic security of today’s digital systems, which could be devastating. Attackers could unseal every encrypted piece of data. But often overlooked is that signatures could be forged. This could be more damaging for many and harder to mitigate. Signatures protecting systems are often rooted in hardware, so they require slow, planned, system refreshes to upgrade –and the impact of allowing attackers a forged key to come in through the front door of every system and take them over may be unthinkable.
Since quantum computers do not exist yet, not everything is at risk right now. However, once such quantum machines exist, previously secure information and systems could be decrypted and accessed. Standardised “quantum-resistant” cryptography is already available to protect data and systems against this future risk, and this cryptography is being increasingly adopted in technologies that organisations depend on.
The majority of businesses interpret the quantum threat primarily as a future risk to current encryption and signature standards such as RSA or Elliptic Curve cryptography. This has raised awareness but often confines the issue to IT or cybersecurity teams. The understanding falls short in three key areas: first, underestimating the long lead time required for cryptographic upgrades and system migration; second, overlooking broader business impacts such as data lifecycle, regulatory exposure, and third-party dependencies; and third, treating it as a distant, technical problem rather than a strategic, enterprise-wide risk that requires planning and cross-functional coordination to ensure critical priorities are addressed as well as ultimately reaching comprehensive protection.
What would the impact look like if organisations aren’t prepared?
If organisations are not prepared, the impact of a quantum computer attack on cryptography would be immediate and far-reaching. If sensitive data is intercepted today, the data could be decrypted in the future (Harvest Now, Decrypt Later). More so, if mission-critical systems relying on vulnerable signatures are not upgraded in time, they could be compromised, risking data and system security as well as operational continuity. Systems would require urgent replacement, taking time while an organisation is prone to attackers, driving up investment costs at a later stage and at the same time disrupting operations. Being vulnerable could also cause regulatory and legal risks.
Essentially, not investing time, effort and budget into getting quantum-ready could result in loss of trust on the side of partners and customers while at the same time risking the company’s data and system security and thus its economic survival. Customers and partners will be better protected by working with businesses that invest in getting quantum-ready.
Where do you see the biggest disconnect between how the risk is discussed and how seriously it’s being treated?
No one knows when quantum computers will break cryptography. However, the likelihood, even in the next several years, is too high to be ignored by enterprises serious about security. Couple this with the high impact and the multi-year IT and Operational Technology change programme required to mitigate the threat, then this becomes a board-level risk. Big companies, critical infrastructure providers, and government bodies will be the first targets, so they should get prepared to ward off these attacks.
HP has recognised that the critical importance of defending against the quantum threat is confounded by the long time required to introduce protections in systems, and so has already upgraded the hardware foundation of our Business PCs and Printers to protect firmware from quantum computer attackers. These upgrades establish an essential foundational layer of quantum resistance from which to build out a quantum-resistant system. Without it, a quantum attacker could forge malware that compromises the entire system from the most privileged level.
There’s a lot of debate around timelines. How are organisations making decisions today in the face of that uncertainty?
The Global Risk Institute’s Quantum Threat Timeline Report 2025 surveys experts to find a 28-49% likelihood of quantum computers breaking cryptography by 2035. Moreover, the EU has issued a roadmap for transition to quantum resistance, with critical infrastructures and high-risk cases to be quantum-ready by 2030. So, the threat is looming at uncomfortably high risk levels.
Rather than trying to pinpoint when quantum computers will break current cryptography, companies should focus on the potential impact if it happens sooner than expected. Recommended actions are to inventory the cryptographic protections relied upon, to prioritise introducing quantum resistance for critical systems and high-value data and begin pilots where a procurement path to quantum-resistant cryptography cannot be established. Many are aligning with emerging standards while adopting a phased, agile approach to migration. Decision-making is not equal throughout the business landscape, though: some organisations delay action due to uncertainty (or possibly investment levels), while others amass inventories without clear prioritisation.
The more mature players treat quantum as a strategic resilience issue, integrating it into broader cybersecurity, risk, and transformation roadmaps – making it a C-level topic and not a purely IT one.
What do business leaders tend to misunderstand most about the nature of this threat?
For one, a lot of businesses see it as a remote, theoretical risk, as quantum computers are not yet available. In addition, from their point of view, they are facing a number of more immediate security threats, including malware and ransomware attacks fuelled by AI automation.
Many executives see quantum threats as a remote possibility to be dealt with at a later date, as investments are often not yet planned into their IT and security budgets. Businesses also tend to view quantum as purely a technical or IT problem, rather than a broader business risk affecting long-term data security, regulatory compliance, and customer trust. This can lead to delayed action, even though preparing – especially transitioning quickly to quantum resistance – can require significant time and coordination.
When organisations start preparing for the quantum era, where do they typically begin, and where do they struggle?
The first step to prepare for the quantum era is to raise awareness – not only within the IT team but also with regard to corporate decision-makers. All audiences need to build understanding about the topic and technology. They should also identify potential use cases and assess where quantum computing could particularly impact their industry. Companies should also contact technology providers to understand how quantum resistance can be achieved in their respective cases. HP recognised the importance of protecting customers from the quantum threat by introducing upgraded hardware, releasing Business PCs that protect firmware against quantum computer attacks in 2024, followed by Printers with similar quantum-resistant firmware integrity protections in 2025. This illustrates how HP gets ahead of security threats.
Where businesses may struggle is moving beyond the impact identification and exploration phase. Challenges can include a lack of in-house expertise, unclear business cases, rapidly evolving technology, and difficulty integrating quantum strategies into existing IT and security frameworks – technology providers are able to support in these instances, however. Moreover, companies are not sure about the investments needed to solve the challenges of quantum security. Thus, progress from experimentation to practical implementation can be a key hurdle for many organisations.
For over 20 years, the HP Security Lab has worked to proactively identify emerging threats and create solutions for HP products. We are already acting to mitigate the quantum threat in our systems, and we are here to guide our customers as they navigate this important topic.

