G7 sounds alarm on quantum cyber threats
The risk of 'harvest now, decrypt later' attacks is a leading concern for security agencies
The G7 Cybersecurity Working Group has issued a joint advisory urging organizations to get moving on post-quantum cryptography (PQC).
The advisory specifically highlights the risk that quantum computing poses to public-key cryptography, stressing that it's a near-term threat that needs addressing across all sectors, not just critical infrastructure.
"Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures," it said.
The big threat from cryptographically relevant quantum computers (CRQCs) is that they will be able to carry out 'harvest now, decrypt later' attacks.
This involves collecting and storing encrypted data protected by public-key cryptography that threat actors will be able to decrypt at a later date.
"Malicious cyber actors with access to CRQCs will also be able to target authentication mechanisms that help provide assurance and help protect the integrity of data between communicating parties and the integrity of devices," the advisory said.
"This capability could allow malicious cyber actors to impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data, therefore undermining confidence in secure communications or contractual agreements."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Quantum preparations
Organizations should adopt a phased and risk-based strategy, prioritizing the most sensitive data and assets. This means carrying out an inventory of their cryptographic assets, mapping their dependencies, and developing a transition plan.
To keep costs down, they should acquire products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule - this, the advisory noted, could result in lower migration costs overall.
Worryingly, the report said the quantum threat remains off the radar for many organizations and as such is under-resourced, with other security concerns taking precedence.
"Yet a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk," the report warns.
Raising awareness of the stakes involved will be critical, according to the working group. National strategies aimed at transitioning to PQC should aim to attain an adequate supply of PQC hardware and software products, and encourage users to adopt them.
Research and development efforts also need to be ramped up, with more cooperation between government, industry, and academia, and the introduction of specific requirements within the framework of public procurement.
"Tackling the risks that the impending quantum computing era poses to current cryptographic systems, and ultimately organizations in which they are embedded, requires a coordinated global effort to transition to PQC," the report concluded.
"To strengthen collective resilience and safeguard confidential data, supply chains, and critical systems, public and private organizations must jointly act now. The transition to PQC is the key foundation to help build a secure and resilient digital future."
Still a long way to go
The advice from the working group might not resonate with enterprises, however. A study by Juniper Research earlier this year found that only 27% of global businesses are set to be using PQC by 2030.
Those figures come despite recent predictions from Google that computers capable of breaking existing encryption could be here within just three years.
"The most important part of the G7’s message is the recognition that quantum can no longer be treated as a distant technology problem. Organizations are being told to start their PQC transition now, but transition and protection are not the same thing," said Simon Pamplin, CTO at Certes.
"The real challenge will be legacy infrastructure. Replacing cryptography embedded across decades of applications, supply chains and interconnected systems is not something organisations can achieve overnight.
"Security therefore needs to be abstracted away from individual applications and infrastructure and attached directly to the data, allowing the cryptography protecting it to change without repeatedly rebuilding the systems underneath."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
An AI kill switch ‘only solves half the problem’ with securityNews Efforts to protect national security are welcomed, but bolstering sovereignty is also required
-
¿Quieres liderar el mercado tecnológico actual? Conviértete en un partner del futuro e impulsa una verdadera transformación digital para los clientes.Para impulsar realmente la transformación digital, los proveedores de tecnología deben evolucionar hasta convertirse en partners orientados a resultados mediante la coordinación de cimientos sólidos de infraestructura en la nube y seguridad
-
Why quantum-ready data protection belongs in the channel portfolioIndustry Insights Quantum-ready, data-centric protection is the channel’s next major differentiator
-
Enterprises aren't moving fast enough on post-quantum cryptography preparations – ‘harvest now, decrypt later’ attacks mean it could cost themNews Organizations need to move faster on post-quantum cryptography preparations, according to new research, as concerns over 'harvest now, decrypt later' attacks rise.
-
A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’News NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration
-
Enterprises are preparing for a post-quantum world – experts worry it could be too late for manyNews More than 100 million firms are expected to embrace post-quantum algorithms by 2035, but that's just a drop in the ocean
-
Google just revised its ‘Q-Day’ timeline: Quantum computers could break existing encryption techniques within three years – and enterprises are nowhere near readyNews Google has warned that “Q-Day”, the point where a quantum computer is powerful enough to crack current encryption techniques, could come as soon as 2029.
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
Nearly half of enterprises aren't prepared for quantum cybersecurity threatsNews Most businesses haven't even started transitioning to post-quantum cryptography, research shows
-
Get started on post-quantum encryption, organizations warnedNews The UK's national cybersecurity agency is urging companies to begin preparing themselves for quantum threats by 2035.