Governments and businesses are being encouraged to work together on quantum-safe technologies, national strategies and cybersecurity requirements.
The G7 Cyber Security Working Group and the US Cybersecurity and Infrastructure Security Agency have urged governments and organisations to begin preparing for the risks posed by quantum computing. Their new call to action warns that advances in quantum technology could eventually undermine widely used public-key encryption and put sensitive information and digital infrastructure at risk.
The guidance stresses that organisations should not wait until powerful quantum computers become available. Attackers can already collect encrypted information with the intention of decrypting it in the future, while sufficiently powerful quantum computers could also threaten authentication systems, potentially allowing trusted identities to be impersonated and creating wider supply-chain risks.
The G7 identifies five priorities for the transition to post-quantum cryptography: increasing awareness, developing national strategies, supporting research and development, strengthening public-private cooperation, and incorporating quantum-safe measures into cybersecurity requirements and procurement. Organisations are also encouraged to catalogue their cryptographic assets, map dependencies and adopt phased, risk-based migration plans.
The working group says early preparation can help organisations manage migration costs and avoid insecure implementations, while delayed action could affect future contracting opportunities. It argues that governments, industry and academia must work together to build the expertise, technologies and policies needed for a secure transition to post-quantum cryptography.
Why does it matter?
The shift to post-quantum cryptography is not simply about replacing one set of algorithms with another; it is about protecting the digital infrastructure on which modern economies increasingly depend. If encryption and authentication underpin everything from government records to commercial transactions, weaknesses in those foundations can have consequences that extend far beyond individual organisations. Cybersecurity planning increasingly requires decisions to be made years ahead of the technologies and threats they are designed to address.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
