Securing the Future: The Urgency of Post‑Quantum Cryptography Today

0
4

Key Takeaways

  • Quantum computing threatens current public‑key cryptography, but practical preparation focuses on visibility, inventory, and phased migration rather than immediate replacement.
  • A “Harvest Now, Decrypt Later” risk makes long‑term data protection a driver for early post‑quantum cryptography (PQC) readiness.
  • International bodies (NIST, EU, UK, US, Australia) have released timelines and standards; organisations should begin with cryptographic inventory, risk assessment, and vendor engagement.
  • Hybrid cryptography and cryptographic agility are recommended transition strategies to maintain compatibility while adding quantum resistance.
  • Hong Kong organisations can leverage global guidance, local initiatives (HKMA QPI, RIQT QKD demo), and Mainland China’s ecosystem efforts to build long‑term cyber resilience.

Image generated by generative AI and reviewed under professional human supervision.
Overview of Quantum Computing and Its Cybersecurity Implications
Quantum computing has progressed rapidly, offering unprecedented computational power that could revolutionise fields such as drug discovery and AI training. At the same time, its ability to solve the mathematical problems underlying today’s public‑key cryptography (RSA, ECC, Diffie‑Hellman) raises serious concerns. A sufficiently powerful quantum computer could break these algorithms in a short time, jeopardising the confidentiality of data protected by current encryption schemes. Consequently, quantum technology is viewed as a double‑edged sword: a source of breakthrough innovation and a potential threat to the digital security landscape.

Image generated by generative AI and reviewed under professional human supervision.
What Is Post‑Quantum Cryptography (PQC)?
Post‑Quantum Cryptography refers to cryptographic algorithms designed to resist both classical attacks and known quantum attacks, including those from future cryptographically relevant quantum computers. Standards bodies worldwide encourage organisations to identify where cryptography is used, pinpoint systems reliant on quantum‑vulnerable public‑key algorithms, and plan for future upgrades. The goal is not to replace every algorithm overnight but to establish a structured, long‑term transition that maintains security while accommodating evolving standards.

Image generated by generative AI and reviewed under professional human supervision.
The “Harvest Now, Decrypt Later” Risk
Even though quantum‑capable computers are not yet available, adversaries can today intercept and store communications protected by RSA, ECC, or similar algorithms, intending to decrypt them later when quantum technology matures. This risk is especially relevant for data that must remain confidential for many years—customer records, intellectual property, financial statements, government information, and other long‑term sensitive assets. Early PQC readiness activities, such as building cryptographic inventories and planning migration roadmaps, help mitigate this future exposure without waiting for an imminent quantum threat.

Image generated by generative AI and reviewed under professional human supervision.
Global Timelines for Post‑Quantum Readiness
Several jurisdictions have published official migration timelines:

  • European Union: Coordination of Member States’ transition begins by end‑2026; critical infrastructure should complete migration by end‑2030, with a broader migration target of 2035.
  • United Kingdom: Define migration goals, asset inventories, and initial plans by 2028; finish highest‑priority activities by 2031; migrate all systems, services, and products to PQC by 2035.
  • United States: Federal agencies must migrate high‑value assets for key establishment by end‑2030 and for digital signatures by end‑2031; the remaining systems target completion by 2035.
  • Australia: Recommends ceasing use of traditional asymmetric algorithms by end‑2030 and transitioning to PQC to reduce future quantum risks.

These timelines underscore that migration is a multi‑year effort requiring early planning.

Image generated by generative AI and reviewed under professional human supervision.
International Standards and Guidance
In 2024, the U.S. National Institute of Standards and Technology (NIST) finalised its first three PQC standards:

  • FIPS 203 – ML‑KEM: a module‑lattice‑based key‑encapsulation mechanism for key establishment.
  • FIPS 204 – ML‑DSA: a module‑lattice‑based digital signature standard.
  • FIPS 205 – SLH‑DSA: a stateless hash‑based digital signature standard.

These standards affect technologies such as TLS, VPNs, PKI, digital signatures, code signing, and identity systems. Guidance promotes a phased approach: discover where vulnerable public‑key cryptography resides, assess data sensitivity and lifespan, and plan upgrades in a risk‑based manner. Hybrid cryptography—combining a classical algorithm with a PQC algorithm—is highlighted as a viable interim solution, provided it is rigorously tested.

Image generated by generative AI and reviewed under professional human supervision.
Industry Exploration and Ecosystem Development in China
Mainland China’s industry bodies, telecom operators, financial institutions, research organisations, and cybersecurity vendors are actively preparing for quantum‑resistant security. The Institute of Commercial Cryptography Standards (ICCS) issued a global call for next‑generation commercial cryptographic algorithms, covering public‑key, hash, and block‑cipher designs, with evaluation criteria including security, performance, and technical characteristics.

Migration studies, such as the Post‑Quantum Cryptography Migration White Paper (2024), involve participants from China Telecom, Huaxia Bank, Xidian University, Fudan University, Shanghai Jiao Tong University, and others, describing PQC migration as a systems‑engineering process encompassing discovery, risk assessment, secure implementation, orderly deployment, compatibility testing, interoperability evaluation, and ecosystem development.

Telecom operators are exploring quantum‑secure communication scenarios, including PQC chips, Optical Transport Network (OTN) combined with Quantum Key Distribution (QKD), and commercial systems integrating QKD and PQC. These efforts illustrate a shift from pure algorithm research to real‑world communication, transmission, and product implementations.

Image generated by generative AI and reviewed under professional human supervision.
Hong Kong Is Beginning to Advance Post‑Quantum Readiness
Although Hong Kong has not yet imposed comprehensive mandatory PQC migration requirements, regulators, research institutions, and industry stakeholders have started promoting quantum‑security readiness. The Hong Kong Monetary Authority (HKMA) released the Whitepaper on Quantum Preparedness of Hong Kong’s Banking Sector and the first Quantum Preparedness Index (QPI) in 2026. The QPI scores the banking sector on Awareness, Planning, Pilots, and Practical Preparedness, yielding an initial score of 2.3/10, indicating early‑stage readiness. About 32 % of surveyed banks had not begun quantum‑related activities, and roughly half lacked formal PQC planning. HKMA intends to improve sector‑wide readiness by 2030 through guidance, training, and engagement.

Hong Kong’s research community is also advancing quantum‑secure technologies. In 2025, the Research Institute for Quantum Technology (RIQT) at The Hong Kong Polytechnic University demonstrated Hong Kong’s first chip‑based quantum communication network, performing a QKD test over ~55 km of existing optical fibre. While QKD and PQC differ—QKD secures key exchange via quantum mechanics, PQC relies on new algorithms resistant to quantum attacks—both are viewed as complementary pillars of a future quantum‑security ecosystem.

Image generated by generative AI and reviewed under professional human supervision.
PQC Is Promising, But the Field Continues to Evolve
Confidence in any cryptographic algorithm stems from open evaluation, standardisation, implementation experience, and ongoing research. Even after NIST’s standards are released, further analysis may lead to additional algorithms, revised parameters, or updated deployment recommendations. Organisations should treat PQC readiness as a capability to monitor developments, evaluate practical options, and adjust as the cryptographic landscape evolves, rather than seeking a single “final answer.”

Image generated by generative AI and reviewed under professional human supervision.
Why Cryptographic Inventory Matters More Than Algorithm Names
For most organisations, the most valuable immediate action is understanding where cryptography is used, not deploying PQC everywhere. A cryptographic inventory records which systems employ cryptography, the algorithms in use, key lengths, certificate types, owners, vendors, upgrade possibilities, and system lifetimes. This visibility enables organisations to identify critical dependencies, prioritise long‑life systems, and avoid unpleasant surprises when migration becomes urgent. Even a basic inventory can illuminate exposure and support risk‑based planning.

Image generated by generative AI and reviewed under professional human supervision.
What Hong Kong Organisations Can Learn
As an international business and technology hub, Hong Kong organisations benefit from integrating global standards, Mainland China’s ecosystem developments, and local initiatives. The common lesson across these sources is to begin with discovery, identify quantum‑affected cryptographic assets, prioritise high‑risk systems, and establish migration plans. Hong Kong’s banking‑sector QPI, maturity‑building efforts, and quantum‑secure communication research reinforce that readiness is a governance, planning, and technology‑management issue, not merely a research topic.

Organisations should avoid assuming rapid migration will be possible when urgency arises, reject the notion that any “post‑quantum” label guarantees suitability, focus on inventory and agility rather than algorithm names alone, and take low‑risk preparatory steps even without perfect certainty. These activities also strengthen general cybersecurity governance.

Image generated by generative AI and reviewed under professional human supervision.
Build Cryptographic Agility Into Future Systems
Cryptographic agility—the ability to replace or update cryptographic algorithms without redesigning the entire system—is essential for PQC readiness. Systems with hard‑coded RSA or ECC dependencies impede upgrades, whereas agile designs allow algorithm, library, certificate type, or protocol changes through supported update paths, configuration changes, or software updates.

When procuring or modernising systems, organisations should avoid hard‑coded cryptography, unsupported libraries, products unable to change certificate types, and lack of clear upgrade paths. Preferred solutions use modern, supported cryptographic libraries, permit algorithm and key‑length updates, support certificate lifecycle management, provide vendor roadmaps for future standards, and enable safe testing before deployment. For SMEs, agility means asking vendors better questions, avoiding lock‑in, and ensuring realistic upgrade routes for critical systems.

Image generated by generative AI and reviewed under professional human supervision.
Questions to Ask Vendors and Service Providers
Relying on suppliers, managed service providers, cloud platforms, and software vendors necessitates detailed inquiries beyond a simple “post‑quantum” label. Key questions include:

  • Which product components use public‑key cryptography?
  • Does the product employ RSA, ECC, Diffie‑Hellman, ECDH, or ECDSA?
  • Is there a roadmap for PQC or hybrid cryptography support?
  • Will PQC support require software updates, configuration changes, licence changes, or hardware replacement?
  • Will the product support NIST‑standardised algorithms (ML‑KEM, ML‑DSA, SLH‑DSA) where appropriate?
  • How will interoperability with legacy clients, browsers, devices, or applications be handled?
  • Will certificate types, trust stores, or PKI integrations need to change?
  • What testing guidance will be provided before production deployment?
  • Will performance, bandwidth, storage, or hardware requirements change?
  • What is the vendor’s long‑term support plan for cryptographic updates?

Including these questions in procurement, renewal, and architecture discussions ensures that PQC readiness is addressed as a vendor‑management and technology‑lifecycle issue, not solely a cybersecurity concern.

Image generated by generative AI and reviewed under professional human supervision.
PQC Readiness for Large Enterprises and SMEs
All organisations, regardless of size, rely on digital systems that may be affected by the PQC transition. The difference lies in preparation approach:

  • Large enterprises manage complex IT environments, extensive cryptographic estates, and long system lifecycles. Priorities include building comprehensive cryptographic inventories, conducting risk assessments, and developing phased migration roadmaps.
  • SMEs often depend more on commercial products, cloud platforms, and managed services. Their focus should be on understanding critical systems, engaging vendors about PQC roadmaps, and avoiding products lacking future‑upgrade capability.

Both groups benefit from cryptographic agility, vendor engagement, and incremental, risk‑based planning.

Image generated by generative AI and reviewed under professional human supervision.
Security Recommendations: A HKCERT Suggested Timeline for PQC Readiness
While Hong Kong lacks a specific PQC migration schedule, local organisations should act proactively. Cryptographic migration can span many years, so readiness planning should be driven by the practical time needed for system migration, supplier coordination, and technology refresh—not by predictions of an imminent quantum breakthrough.

Referencing international roadmaps and the HKMA’s goal to improve banking‑sector quantum readiness by 2030, a reasonable timeline could be:

  • 2027: Initiate cryptographic inventories and risk assessments.
  • 2028‑2030: Develop migration roadmaps, vendor‑engagement plans, and technical evaluations.
  • Post‑2030: Progressively migrate higher‑priority, longer‑lifecycle systems based on business risk and technology maturity.

The objective is not to meet a rigid deadline but to ensure visibility, planning capabilities, and technical readiness when migration becomes necessary, allowing orderly management of quantum‑related risks.

Image generated by generative AI and reviewed under professional human supervision.
How Organisations of Different Sizes Can Start Preparing for PQC
PQC readiness applies to any organisation using computer systems, cloud services, online communications, or third‑party software. Recommended actions include:

  • Review Long‑Term Sensitive Data: Identify information that must stay confidential for years (personal data, health records, financial records, IP, legal documents, strategic information). Such data faces “Harvest Now, Decrypt Later” risk; the longer the confidentiality requirement, the earlier it should be included in PQC planning.
  • Monitor Standards and Industry Developments: Track NIST updates, browser and OS support, cloud platform changes, network device evolutions, identity services, certificate services, and security products. Avoid basing long‑term decisions on isolated product claims; rely on public standards and major platform developments.
  • Assign Responsibility and Establish Follow‑Up Arrangements: Designate a responsible party (IT, cybersecurity, risk management, procurement, or compliance) to monitor vendor notifications, product updates, regulatory guidance, and industry trends. This coordination prevents fragmented efforts and supports cross‑functional alignment.
  • Adopt a Cautious and Phased Approach: Recognise that PQC standards and product support are still maturing. Begin with basic awareness and follow‑up, then proceed in phases guided by data sensitivity, business criticality, system lifespan, vendor support, and available resources.

Image generated by generative AI and reviewed under professional human supervision.
Actions for Large Organisations
Large entities should emphasise:

  • Build and Maintain a Cryptographic Inventory: Capture systems using RSA, ECC, Diffie‑Hellman, ECDH, ECDSA; record owners, business purpose, vendors, algorithms, certificate types, product versions, upgrade paths, dependencies, data types, compliance needs, key‑management arrangements, and third‑party integrations.
  • Prioritise Systems Based on Risk and Lifespan: Rank systems by criticality, data sensitivity, external exposure, technology lifecycle, and upgrade complexity. Prioritise those protecting sensitive data, supporting core processes, facing the internet, or expected to remain in service for many years.
  • Plan a Phased Migration Roadmap: Structure the roadmap around asset discovery, risk classification, proof‑of‑concept, test‑environment deployment, vendor coordination, certificate and key‑management changes, production rollout, and rollback plans. This reduces operational disruption and maintains compatibility.
  • Design for Cryptographic Agility: Avoid hard‑coded cryptography; favour modular designs that allow future algorithm, certificate, or key‑length adjustments without major rewrites.
  • Test Before Deployment: Conduct compatibility, performance, and security testing in controlled environments, covering applications, browsers, network devices, identity systems, APIs, certificate management, logging, monitoring, backups, and third‑party integrations. Assess impacts of larger keys or signatures on bandwidth, latency, and storage.
  • Avoid Premature Lock‑In: Prefer solutions based on public standards, clear documentation, testability, reversibility, and interoperability. Preserve flexibility to change algorithms, products, or vendors as standards evolve.

Image generated by generative AI and reviewed under professional human supervision.
SMEs Should Stay Informed About PQC
For small and medium enterprises, immediate PQC migration may not be a priority, but awareness is essential. A practical, phased approach helps minimise cost and operational impact. SMEs can:

  • Identify critical business systems and services.
  • Engage vendors and managed service providers about their PQC roadmaps and upgrade plans.
  • Incorporate PQC considerations into future procurement and contract‑renewal processes.
  • Maintain visibility of key systems and supplier dependencies to align gradually with forthcoming cryptographic requirements while avoiding unnecessary complexity.

Image generated by generative AI and reviewed under professional human supervision.
Common Misconceptions

  • Myth: Quantum computers will immediately break all encryption.
    Reality: The primary threat lies with specific public‑key algorithms; well‑implemented symmetric encryption remains relatively unaffected, though best practices should still be followed.
  • Myth: PQC migration means replacing every system now.
    Reality: For most organisations, the immediate focus is inventory, planning, vendor engagement, and building cryptographic agility—not mass deployment.
  • Myth: Selecting one PQC algorithm solves the problem forever.
    Reality: Cryptography continues to evolve; standards bodies, researchers, and industry will keep evaluating algorithms, implementation approaches, and deployment models.
  • Myth: PQC readiness is solely a technical issue.
    Reality: It also involves governance, procurement, vendor management, asset management, risk assessment, system architecture, and long‑term technology planning.

Image generated by generative AI and reviewed under professional human supervision.
Conclusion
Post‑quantum cryptography is emerging as a practical, long‑term cybersecurity challenge. International standards and guidance clarify how organisations should prepare, while industry bodies and technology vendors explore algorithms, architectures, interoperability, and deployment models. The central lesson is not that every organisation must rush to deploy PQC, but that they must understand where cryptography is used, identify systems vulnerable to future quantum attacks, and ensure that future technology decisions do not impede migration.

For Hong Kong organisations, this presents an opportunity to adopt a balanced, practical approach: leverage globally recognised standards, learn from Mainland China’s ecosystem progress, and build on local initiatives such as the HKMA’s QPI and RIQT’s QKD demonstration. By cultivating cryptographic inventories, fostering agility, engaging vendors, protecting long‑term sensitive data, and monitoring evolving standards, organisations can strengthen their cyber resilience and be ready to adapt when the quantum landscape shifts. In the post‑quantum era, the strongest organisations will be those that grasp their cryptographic foundations and retain the flexibility to evolve alongside technological change.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here