Quantum Decryption Threat: What UK CISOs Must Do Now in 2026
UK CISOs must now prepare for a threat that has no immediate visible impact but carries catastrophic future consequences — nation states and sophisticated criminal gangs are stealing encrypted data today, betting on quantum computing to decrypt it tomorrow.
According to the WEF Global Cybersecurity Outlook 2026, the “harvest now, decrypt later” threat has moved from theoretical concern to active intelligence priority. Nation states — particularly those with significant quantum computing investment programmes — are engaged in systematic campaigns to capture and store encrypted data from high-value targets: government systems, critical national infrastructure, financial institutions, defence contractors, and large enterprise organisations holding strategically significant intellectual property or personal data. The threat is not immediate in its impact, but it is immediate in its implication: data that is encrypted today with standard asymmetric cryptography may be decryptable within five to ten years as quantum computing matures, making the theft of that data economically rational now.
What Is the Harvest Now, Decrypt Later Threat?
Current encryption standards — including RSA, elliptic curve cryptography (ECC), and Diffie-Hellman key exchange — derive their security from mathematical problems that classical computers cannot solve in practical timeframes. Quantum computers, once sufficiently powerful and stable, will be capable of breaking these encryption standards using Shor’s algorithm — an algorithm that runs exponentially faster on a quantum processor than on any classical system. The critical point for CISOs is that adversaries do not need quantum computing capability today to benefit from quantum-enabled decryption tomorrow. They only need to capture encrypted data now and store it until the decryption capability exists.
According to SecurityWeek’s Cyber Insights 2026, quantum computing and advanced AI are increasingly being considered in combination — AI optimises the targeting and capture of high-value encrypted data, while quantum computing will eventually provide the decryption capability. The threat is not evenly distributed: organisations holding long-lived secrets — data that will still be sensitive or valuable in five to fifteen years — face substantially higher risk than those whose data has a short shelf life. UK CISOs should be particularly alert to the exposure of cryptographic keys, authentication credentials, strategic business plans, intellectual property, personal health data, and classified government information.
Executive Action
- Classify your organisation’s data by sensitivity longevity — identify which data types will still be sensitive in five, ten, and fifteen years, as these represent the highest “harvest now” targets.
- Brief your board on the harvest now, decrypt later threat — this is not a future hypothetical but an active intelligence threat that requires current investment decisions to mitigate.
- Engage your threat intelligence provider to assess whether your organisation’s profile (sector, data held, geopolitical exposure) places you in the target set for nation-state data harvesting campaigns.
Which UK Organisations and Data Types Are Most Exposed?
The harvest now, decrypt later threat is not theoretical for UK organisations. UK financial services firms hold long-lived data — customer records, transaction histories, contractual and legal documents — that will remain sensitive well beyond the current encryption lifecycle. Defence contractors and their supply chains hold classified and commercially sensitive information whose value will persist for decades. Healthcare organisations hold patient data with a fifty-year sensitivity window. Law firms hold privileged client communications and transactional records. For each of these categories, the asymmetric encryption currently protecting data in transit and at rest is vulnerable to future quantum decryption.
According to the 2026 CISO AI Risk Report from Cybersecurity Insiders, two-thirds of CISOs now rank AI-driven threats — including AI-assisted data harvesting — as their top concern, with the quantum intersection representing a long-horizon amplifier of those risks. UK organisations operating in sectors subject to the UK Cyber Security and Resilience Bill, ISO 27001:2022, and the NIS2 Regulations (for those with EU operations) face regulatory expectations of proportionate risk management — which increasingly includes emerging threats such as quantum-enabled decryption, not just current-cycle attack vectors. CISOs should note that the NCSC has been actively updating its cryptographic guidance and is expected to publish quantum-readiness guidance for UK critical national infrastructure operators in 2026. Use INFORMD’s cybersecurity assessment tools to evaluate your current cryptographic posture against emerging standards.
Executive Action
- Conduct a cryptographic inventory: identify every system, protocol, and service in your estate that relies on RSA, ECC, or Diffie-Hellman key exchange — this is the starting point for quantum-safe migration planning.
- Prioritise systems holding long-lived sensitive data — customer records, IP, health data, financial records — for quantum-safe migration ahead of systems processing transient, low-sensitivity data.
- Review your supply chain cryptographic exposure — third-party systems that handle your most sensitive data may have their own cryptographic weaknesses that fall outside your direct control.
What Is Post-Quantum Cryptography and What Must UK CISOs Know?
Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to be secure against both classical and quantum computer attacks. In August 2024, the US National Institute of Standards and Technology (NIST) finalised its first set of post-quantum cryptographic standards — CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for digital signatures — marking the beginning of the transition from classical to quantum-resistant cryptography. The UK’s NCSC has endorsed migration to NIST’s PQC standards as the appropriate path for UK organisations, aligning UK cryptographic guidance with the international standards framework.
The transition to PQC is not simply a software update — it is an enterprise-wide migration programme affecting every system, protocol, and service that performs encryption, authentication, or digital signing. For large organisations, this migration will take three to seven years to complete fully, which means planning must begin now for quantum-safe posture to be achieved before quantum decryption threats become operationally real. According to SecurityWeek’s 2026 analysis, organisations should adopt a “crypto-agility” approach — designing systems to support multiple cryptographic algorithms simultaneously, enabling rapid algorithm switching as standards evolve, rather than hardcoding a single cryptographic standard that becomes a migration dependency. Review INFORMD’s technology briefing library for ongoing NCSC and NIST guidance updates as PQC standards mature.
Executive Action
- Include NIST PQC standards (CRYSTALS-Kyber and CRYSTALS-Dilithium) in your cryptographic standards policy — update procurement requirements to mandate PQC-readiness for all new technology acquisitions.
- Adopt a crypto-agility design principle for all new system development and major system upgrades — build in algorithm switching capability rather than hardcoding single cryptographic dependencies.
- Monitor NCSC quantum-readiness guidance publications — the NCSC is expected to provide sector-specific migration guidance for UK CNI operators in 2026 that will set supervisory expectations.
How Should UK CISOs Build a Quantum-Safe Migration Roadmap?
A quantum-safe migration roadmap should be structured as a multi-year programme with clear phases, prioritised by data sensitivity and system criticality. Phase one — assessment — involves completing the cryptographic inventory, classifying data by sensitivity longevity, and identifying the highest-priority migration targets. Phase two — remediation planning — involves designing quantum-safe replacements for each identified cryptographic dependency, assessing vendor roadmaps for PQC support, and establishing the budget and resource requirements for migration. Phase three — execution — involves prioritised migration of the highest-risk systems, with crypto-agility built into all new and upgraded systems from this point forward. Phase four — continuous assurance — involves ongoing monitoring of quantum computing capability development and cryptographic standard evolution to ensure the migration roadmap remains appropriately paced.
CISOs should present this roadmap to their boards as a strategic resilience investment with a defined risk timeline — not as an abstract technology exercise. According to the WEF Global Cybersecurity Outlook 2026, 2026 will be the year accountability becomes non-negotiable for CISOs: security leaders are expected to lead with clarity, communicate risk in business terms, and prove that investment translates into resilience. The quantum threat provides exactly the kind of long-horizon risk narrative that allows a CISO to demonstrate strategic foresight to the board and executive committee — and to secure investment for quantum-safe migration ahead of the threat becoming operationally critical. Explore INFORMD’s cybersecurity briefing library and assessment tools to support your board quantum risk communication.
Executive Action
- Initiate a quantum-safe migration programme with four phases: assessment, remediation planning, execution, and continuous assurance — present the programme plan and funding requirements to the board within Q3 2026.
- Engage your technology vendors to obtain their post-quantum cryptography roadmaps — prioritise vendors who have committed to PQC support timelines aligned to the NIST standards framework.
- Communicate the quantum threat to the board in business terms: the risk is the permanent loss of confidentiality for data that is already held by adversaries — frame the investment case around the sensitivity and longevity of the data at risk.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
Harvest now, decrypt later is a threat strategy where adversaries capture and store encrypted data today, intending to decrypt it once quantum computing matures — typically within five to fifteen years. Nation states are already conducting systematic campaigns to harvest high-value encrypted data from government, financial, defence, and enterprise targets.
Estimates vary, but most security analysts and intelligence agencies place the risk window at five to fifteen years for quantum computers capable of breaking RSA and ECC encryption at scale. The NCSC and NIST have both initiated post-quantum migration guidance programmes, signalling that preparation must begin now — not when quantum capability arrives.
Post-quantum cryptography (PQC) uses algorithms resistant to both classical and quantum attacks. NIST finalised its first PQC standards in August 2024 — CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for digital signatures. The UK’s NCSC has endorsed migration to NIST PQC standards as the appropriate path for UK organisations.
For large organisations, a complete quantum-safe migration — replacing all RSA, ECC and Diffie-Hellman dependencies with post-quantum algorithms — typically takes three to seven years. Planning should begin now: a phased roadmap starting with cryptographic inventory and prioritised migration of highest-risk systems is the recommended approach.
