Something small is going to change the world in a big way. And while we know it’s coming, a recent survey reveals we’re not prepared for it.
The problem is quantum computing, the road map is clear, but the people who should be the most interested aren’t paying attention.
According to the 2025 Quantum Computing Pulse Poll from international controls nonprofit ISACA, almost two-thirds (62%) of technology and cybersecurity professionals are worried that quantum computing will break today's internet encryption. Yet only 5% say it's a high priority for the near future, with the same low number possessing a defined quantum computing strategy. Only 15% have it on a long-term road map, while one in five have discussed it but made no formal plans. Another 37% haven't talked about the issue internally at all.
These respondents aren't lay people. They're highly capable practitioners and strategists.
ISACA, which conducts annual surveys on data privacy and other security concerns, is for the first time taking a deep dive into the question of quantum readiness with this study. The group queried over 2,600 of those professionals around the world working in digital trust, including people in cybersecurity and governance roles. These experts know the impact quantum computing will have on classical cryptography more than anyone.
Which is what makes these survey results so troubling.
A quantum storm is coming
The puzzling part about this complacency is that we know “Q-day” is coming. That's the time when we'll be able to break classic encryption using quantum computers.
By manipulating quantum forms of classic computing bits, called “qubits,” quantum computers will rewrite the rules of security from the ground up. Unlike a regular bit, a qubit can represent both a zero and a one at once. That enables it to perform some stupendous sums at speed, including cracking the math at the heart of the RSA algorithm.
RSA is the encryption routine (named for its inventors, Ron Rivest, Adi Shamir, and Leonard Adleman) that allows computers to encode and exchange information with each other, safe in the knowledge that the data hasn't been tampered with. They can also use it to verify the identity of the sender.
The mathematics to crack RSA is well understood and theoretically proven. The thing that's missing are the qubits themselves. They're digital snowflakes: rare, fleeting, and extremely fragile. They only operate at near-zero temperatures, and they collapse in milliseconds.
[Read also: Quantum computing is advancing fast – here’s your cybersecurity pocket guide]
Companies are struggling to create and sustain sufficient qubits to do meaningful math, but they're getting better at it every year. Eventually they'll be good enough to crack the 2,048 bits that are now the de facto standard in RSA encryption.
The ‘harvest now, decrypt later’ threat
When will it happen? No one is entirely sure, but 25% of ISACA's survey respondents believe that the "full potential" of quantum computing will be realized in five years or less. Some 39% say between six and ten years.
So they understand it's happening, and at least some understand the urgency. Over half (56%) of the respondents cite “harvest now, decrypt later” (HNDL) attacks as a concern. This is where cyber criminals collect encrypted data now so that they can decrypt it once quantum computing becomes viable.
"Already, malicious actors can intercept and store confidential, classically encrypted data with the intention of decrypting it later when quantum machines become powerful enough to do so," says Rob Clyde, a past ISACA chair who now advises in the quantum encryption space.
Even though many see the threat looming, 41% say they do not plan to address quantum computing at this time and 40% are not aware of their company's plans.
[Read also: 3 ways banks can prep for the coming quantum threat]
Those responsible for protecting their organizations seem to be a little like the mysterious qubits themselves: stuck in two states at once. They're simultaneously aware of the risk and not doing anything serious about it.
New quantum computing standards are here
Clyde is exasperated by this head-in-the-sand attitude because after ten years of waiting, we now have standards for new encryption algorithms that quantum computers will be less likely to crack. The U.S. National Institute of Standards and Technology (NIST) released the first three last August.
The standards took years to develop because of the intense mathematical scrutiny involved. One candidate standard was cracked and eliminated during the process. However, that delay might be part of the problem, Clyde muses. For the last decade, people have been told to wait while the standards evolved. Now they're here, there's a certain inertia. It's hard to get people motivated.
"This wait-and-see approach is just persisting,” he says. “Only about half were aware that we have these new standards, and only 7% admitted that they actually understood them – and these are the experts."
Many seem more focused on immediate threats. With ransomware thieves and nation-state attackers coming after their infrastructure, there are plenty of clear and present dangers to choose from. They might simply be too busy focusing on those other immediate issues to pay attention to something with no clear future date.
Your quantum computing to-do list
On the positive side, 55% of ISACA's survey respondents have taken some kind of action to prepare for Q-day. Granted, a lot of this has been regulatory box-ticking. The main focus, at 46%, has been assessing quantum's compliance implications.
“Regulators will begin to fail devices and software [that lack] post-quantum cryptography.”Clyde
Just 38% of companies are exploring quantum-safe cryptography in preparation for a time when RSA no longer protects us. At 28%, fewer than one in three are actually collaborating with technology vendors to put something in place by investing in proof-of-concept projects. Roughly the same number are investing in staff training.
ISACA has a three-step road map to help people get on track and begin preparing for the quantum tsunami. The first involves simple education and awareness raising. With 30% of survey respondents failing to grasp quantum computing's capabilities, this must be an imperative. You can't care about what you don't understand.
The second is to develop a quantum computing encryption strategy. You must root out all the encrypted data you already have, counsels ISACA, understanding where it's stored, and how sensitive or critical it is.
Then, define a clear road map to quantum-safe encryption. This will be phased so that you can tackle the most important data first. A base of stakeholders well-versed in quantum issues will be useful here.
[Read also: What is NIST compliance?]
These quantum policies must be codified into your security and compliance policies, Clyde adds, predicting regulatory scrutiny before long. "Regulators will begin to fail devices and software and actually say that by [a certain] date, it needs to have post-quantum cryptography in it," he warns.
Start talking to your vendors
Working with vendors will be especially important during these steps given that many legacy systems won't be able to cope with the new requirements, warns the Project Leap report. Project Leap is an initiative by the Bank for International Settlements to establish quantum-safe data exchange between central banks that has already successfully tested the new, quantum-resistant technology in its initial phase.
"The lack of flexibility in legacy systems means that a major transition effort will be necessary," says the report. Companies might also find that equipment purchased recently lacking those capabilities needs an early replacement.
[Read also: Seeing is believing – how enterprises are using AI to improve cybersecurity]
Clyde advises companies to start talking with technology suppliers now. He outlines some possible vendor conversations: "Are you going to be providing post-quantum cryptography in your product? Are you going to be able to just get simple updates that will suddenly move to that? What are your plans?"
The final stage will involve sticking to those coming compliance requirements. Regular audits for quantum readiness will become important, says the ISACA road map. That means testing cryptographic resilience and factoring the quantum threat into risk assessments.
As Clyde says, waiting until Q-day to do something about the quantum threat is far too late. The time is narrowing to protect yourself against quantum-powered decryption. In fact, when we take HNDL attacks into account, you might say that the horse has already bolted.
