Cybersecurity is a major and unavoidable challenge in the digital age, where protecting data and communications is essential. Quantum computers, whose underlying concepts were introduced in the 1980s, promise unprecedented computing power, capable of solving complex problems much faster than classical computers. However, this technological advancement also represents a potential threat to the cryptographic systems currently in use. Let us explore the challenges quantum computing poses to cybersecurity and the solutions being considered to ensure data security in the future.
What Is a Quantum Computer?
Definition and Fundamental Principles
A quantum computer relies on principles derived from quantum physics:
-
Qubits: Unlike classical bits, which can take a value of either 0 or 1, qubits exploit superposition, allowing them to exist in multiple states simultaneously.
-
Superposition: This property enables a qubit to participate in multiple computational possibilities simultaneously, potentially increasing processing capabilities for certain types of problems.
-
Quantum entanglement: Two entangled qubits can exhibit correlated states regardless of the distance separating them, opening up potential applications in secure communications.
Differences Between a Classical Computer and a Quantum Computer
A classical computer processes information using bits, with performance largely determined by its hardware and architecture. A quantum computer, by contrast, uses quantum phenomena such as superposition and entanglement to process certain types of problems in fundamentally different ways.
This does not mean that quantum computers are faster than classical computers for every task. Rather, they have the potential to solve specific problems significantly more efficiently than classical systems.
Advantages and Limitations of Quantum Computing
Quantum computing is attracting growing interest in areas such as molecular simulation, optimization, and artificial intelligence. However, the technology still faces major challenges.
Qubits are extremely sensitive to their environment, and even minor disturbances can cause computational errors. Quantum systems also often require highly controlled conditions, including extremely low temperatures close to absolute zero, making them difficult and expensive to operate.
Another major challenge is scaling the number of qubits. Building sufficiently powerful and reliable quantum computers requires not only more qubits, but also high-quality qubits with low error rates and effective error-correction mechanisms. Current systems remain far from the scale that would be required for large-scale fault-tolerant quantum computing.
The Impact of Quantum Computers on Cybersecurity
The Ability of Quantum Computers to Break Current Cryptosystems
Modern cryptographic systems rely on mathematical problems that are deliberately difficult to solve, thereby protecting communications and data.
RSA encryption, for example, relies on the computational difficulty of factoring very large integers. For a classical computer, factoring sufficiently large numbers can be computationally infeasible.
Similarly, cryptosystems based on elliptic curves rely on another difficult mathematical problem: the discrete logarithm problem.
The discrete logarithm problem involves determining an unknown exponent from a known base and result. If a number b is raised to an unknown power k to obtain x (x = b^k), the discrete logarithm problem consists of determining k when only b and x are known.
For very large numbers, this problem is extremely difficult to solve within a reasonable timeframe using classical computers. This computational difficulty currently protects systems such as Diffie-Hellman and ElGamal, which are widely used for secure key exchange and communications.
However, sufficiently powerful quantum computers could fundamentally change this situation. Using Shor’s algorithm, quantum computers could efficiently solve problems such as integer factorization and discrete logarithms that are considered computationally infeasible for classical computers.
As a result, cryptographic schemes based on factorization and discrete logarithms could become vulnerable and potentially obsolete for security applications.
A Technology That Is Still Immature
Despite their potential, quantum computers are still far from being operational at large scale.
Their operation is hindered by the instability of qubits, which can lose their quantum coherence when exposed to environmental disturbances, leading to computational errors. To mitigate these effects, quantum systems must operate in highly controlled environments, which currently limits their deployment.
Error correction represents another major challenge. Unlike classical bits, qubits require sophisticated mechanisms to detect and correct errors while preserving the quantum information.
In addition, most current quantum computers do not yet have enough high-quality qubits to solve large-scale practical problems. Their development and manufacturing remain costly, and algorithms capable of fully exploiting their potential are still being developed.
Vulnerabilities of Classical Algorithms to Quantum Attacks
Current cryptographic algorithms present a structural vulnerability: many rely on mathematical problems that are difficult for classical computers but could become tractable for sufficiently powerful quantum computers.
This risk is not purely theoretical. The concept commonly referred to as “harvest now, decrypt later” involves intercepting, storing, and archiving encrypted data today, with the expectation that it could be decrypted in the future once sufficiently powerful quantum computers become available.
Countries such as China and the United States are frequently mentioned in international analyses in relation to their capabilities for large-scale intelligence collection. For example, various U.S. intelligence assessments have reported concerns regarding the collection of large volumes of encrypted diplomatic and industrial communications, potentially allowing such information to be exploited in the future as technological capabilities evolve.
This strategy is particularly concerning for communications and information that must remain confidential over long periods, including medical data, industrial secrets, strategic research, military information, and diplomatic communications.
A communication that is securely encrypted today could potentially become readable in the future if the underlying cryptographic systems are not replaced in time.
The situation is even more critical in sectors such as defense, energy, and telecommunications, where sensitive information may be retained for several decades. Once quantum computers reach the required level of maturity, some archived encrypted data could potentially be decrypted retrospectively, compromising information that was previously considered protected.
As a result, once sufficiently powerful quantum computers become available, many widely deployed public-key cryptographic systems could become vulnerable. Communications protected using RSA, Diffie-Hellman, or elliptic-curve cryptography could potentially be compromised, threatening the confidentiality and integrity of sensitive information.
The economic consequences of data breaches are already significant. In 2024, the average cost of a data breach was estimated at $4.88 million globally, while the estimated average cost in France was approximately €3.8 million. These costs vary depending on the nature of the data involved, the time required to detect and contain the breach, regulatory penalties, and the resulting impact on productivity and reputation.
Research into Quantum-Resistant Cryptography
To anticipate these threats, post-quantum cryptography (PQC) is already being actively developed. Its goal is to design cryptographic algorithms capable of resisting attacks from future quantum computers.
Among the most promising approaches are systems based on complex mathematical structures, including lattice-based cryptography, which relies on mathematical problems believed to remain difficult even for quantum computers.
Other approaches include code-based cryptography and advanced error-correcting structures. Research has also explored approaches based on isogenies, which involve mathematical transformations associated with elliptic curves.
International institutions such as the National Institute of Standards and Technology (NIST) are already working on the standardization of new cryptographic systems in order to facilitate the transition toward a new generation of digital security.
Possible Solutions and Adaptations
Development of Quantum Cryptography
Alongside post-quantum cryptography, another approach relies directly on the laws of quantum mechanics: quantum cryptography, and more specifically Quantum Key Distribution (QKD).
In this model, encryption keys are exchanged using quantum states. An attempt to intercept or measure these states can disturb them, potentially allowing the communicating parties to detect the interception.
Once the key has been securely established, it can then be used with conventional encryption mechanisms to protect communications.
Unlike classical approaches that rely primarily on the computational difficulty of mathematical problems, QKD derives its security properties from the principles of quantum physics and is therefore designed to remain secure against certain attacks enabled by quantum computing.
Security Protocols Based on Quantum Entanglement
Quantum entanglement opens up interesting possibilities for secure communications.
Through quantum entanglement, it may be possible to develop highly secure communication networks in which certain forms of interference or eavesdropping can be detected.
Two entangled particles form a quantum system with correlated properties. Any attempt to measure or manipulate the system can affect the quantum states involved.
An easy analogy is to imagine two magical dice that, wherever they are located, always produce correlated results when measured.
International Efforts to Anticipate These Threats
Around the world, governments, research institutions, and private companies are increasing their efforts to prepare for the post-quantum era.
They are investing in the development of quantum-resistant algorithms, experimenting with highly secure quantum communications, and raising awareness among strategic stakeholders about emerging risks.
For example, university laboratories have demonstrated significant advances in quantum teleportation. In 2014, a team from the University of Geneva led by Professor Nicolas Gisin demonstrated the teleportation of the quantum state of a photon over a distance of 25 kilometers.
Quantum teleportation relies on quantum entanglement, which allows two particles to share correlated quantum information over a distance. From a security perspective, this technology is significant because it demonstrates the ability to transfer quantum states without physically transmitting the quantum state itself through the communication channel.
However, quantum teleportation does not mean that information can be transmitted instantaneously or without classical communication. Rather, it demonstrates the possibility of transferring quantum states using entanglement combined with classical communication.
These experiments are important because they demonstrate not only the ability to transfer quantum states, but also the potential foundations for future secure quantum networks capable of distributing cryptographic keys and quantum information.
These efforts reflect a broader international objective: anticipating the threat posed by sufficiently powerful quantum computers capable of breaking widely used cryptographic systems and developing secure infrastructures before that threat becomes operational.
Conclusion
The rise of quantum computing represents a major turning point for global cybersecurity.
While these technologies offer unprecedented computing capabilities, they could also challenge some of the cryptographic foundations currently used to protect data, electronic communications, and information systems.
The risks are not necessarily immediate, but they must be anticipated because sufficiently powerful quantum computers could eventually compromise cryptographic systems that are widely used today.
The transition toward security protocols capable of resisting quantum attacks is therefore becoming a strategic priority.
Post-quantum cryptography, which is already undergoing standardization, and quantum cryptography, including technologies such as QKD, represent complementary approaches that may contribute to building a robust and sustainable digital security ecosystem.
From a GRC (Governance, Risk and Compliance) perspective, the arrival of quantum computing requires organizations to rethink their strategic approach:
-
Governance: Executive management should integrate quantum risks into cybersecurity roadmaps, define clear responsibilities, and support the investments required to transition toward quantum-resistant security standards. This is no longer simply a technical issue, but a broader organizational resilience challenge.
-
Risk Management: The “harvest now, decrypt later” threat requires organizations to reassess the sensitivity period of their data. Any information with long-term strategic value — including healthcare data, defense information, R&D, intellectual property, trade secrets, and financial information — should be considered potentially exposed to future quantum threats. Maintaining an up-to-date inventory of critical assets and developing a cryptographic migration plan are therefore essential.
-
Compliance: Regulatory and standards organizations such as NIST and ANSSI are moving toward explicit requirements and recommendations regarding post-quantum cryptography. Anticipating these developments can help organizations reduce future compliance risks and align their security strategies with emerging international standards. Failure to prepare could eventually result in costly remediation requirements and potentially regulatory consequences.
In summary, the quantum era should not be viewed solely as a technological evolution, but as a structural transformation of cybersecurity and organizational governance.
Although quantum computing remains at an early stage, rapid technological progress suggests that some of the current challenges may be overcome over the coming decades.
This means that classical cryptography will remain useful for some time, but a decade can pass quickly, and sensitive data stolen today could potentially be decrypted tomorrow.
It is therefore essential to anticipate quantum threats now and begin transitioning toward security mechanisms designed for the coming era.
Organizations that begin preparing for cryptographic migration today will be better positioned to strengthen their long-term resilience, compliance, and ability to protect their strategic assets in the post-quantum era.