‘Q-Day’ Fears Grow as 65% See Quantum as Top Cyber Risk
Written by Rebecca Uffindell Thu 10 Jul 2025

The countdown to “Q-day”—the moment quantum computers are expected to break today’s cryptographic algorithms—has begun in earnest, according to a new global study from the Capgemini Research Institute.
Released on 10 July 2025, the report reveals that nearly two-thirds (65%) of organisations now see quantum computing as the most critical cybersecurity threat they will face within the next three to five years.
Titled Future Encrypted: Why Post-Quantum Cryptography Tops the New Cybersecurity Agenda, the study warned that the accelerating pace of quantum R&D is outstripping many organisations’ ability to prepare, particularly when it comes to defending against “harvest-now, decrypt-later” attacks. These involve the collection of encrypted data today with the intent of breaking it once quantum decryption becomes viable.
How Soon Is Q-Day?
Among organisations already engaging with post-quantum solutions—referred to as ‘early adopters’ in the report—16% believe Q-day will arrive within five years, while nearly 60% predict it will occur within a decade. For sectors like banking, defence and telecoms, the implications are existential.
“Quantum readiness isn’t about predicting a date—it’s about managing irreversible risk,” said Marco Pereira, Global Head of Cybersecurity at Capgemini. “Every encrypted asset today could become tomorrow’s breach.”
The report stresses that even though quantum computers cannot yet crack standard encryption protocols, data being captured today may be compromised in the near future, posing a significant risk to long-term data security and regulatory compliance.
Cryptography Is the Front Line
Around 70% of organisations surveyed are now turning to post-quantum cryptography (PQC) to protect their systems, with regulatory pressure cited as a key motivator for the shift. PQC algorithms are being prioritised over alternative quantum-defensive techniques due to their relative maturity, flexibility, and alignment with international cryptographic standards.
Among early adopters, nearly half are either piloting PQC, conducting feasibility assessments, or developing internal roadmaps. However, the report also found that 30% of surveyed organisations are still taking no action, largely due to resource constraints and competing priorities in security transformation.
Readiness Is Divided by Industry
Not all sectors are moving at the same pace. High-risk industries such as defence, finance, and telecoms are leading quantum-readiness efforts, while consumer-facing sectors—including retail and CPG—are trailing, often due to a perceived lower immediate threat and budgetary constraints.
“Quantum safety is not a discretionary spend but a strategic investment,” Pereira noted. “Those who recognise this early will be better positioned to insulate themselves from future cyberattacks.”
Global Perspective
The report draws from a survey of 1,000 organisations (each with over $1 billion in annual revenue), spanning 13 industries across North America, Europe and Asia-Pacific. About 70% of the sample was made up of ‘early adopters,’ offering a detailed picture of enterprise attitudes and adoption trajectories. Interviews with 16 senior executives further enriched the findings.
Written by Rebecca Uffindell Thu 10 Jul 2025
