Threats, opportunities and the need for post-quantum cryptography

December 2024 AI & Data Analytics, Infrastructure

The first quantum computer was created almost three decades ago, in 1998. Yet the topic still seems to illicit images of ‘Back to the Future’ for most. While its applications are still unknown to many, this advanced field combines computer science, physics, and mathematics to deliver solutions the world has been trying to find for aeons – and those it does not yet know it needs.


Carrie Peter

Rivalling classical computers and coming out on top, quantum computing uses quantum mechanics to find fast and complete answers to complex problems. According to Carrie Peter, Managing Director at Impression Signatures and Advocacy Committee Vice-Chair at the Cloud Signature Consortium, “Although it sounds futuristic, quantum computing is advancing at a rapid rate – certainly faster than expected. Today, many countries already possess their own quantum computers, with quantum computing even being available as a SaaS solution.”

As is the case with most technological developments, however, the opportunities offered by quantum computing are equalled by the threats this advanced computer science introduces. “The evolution of quantum computing puts the security of any data available in the digital space in jeopardy,” warns Peter.

IBM recently published an article about quantum computing, noting that “quantum technology will soon be able to solve complex problems that supercomputers cannot solve, or cannot solve fast enough.” What if the problem it is trying to solve, is breaking through security firewalls or encryptions?

“This poses a massive threat to encryption as a quantum computer could decrypt traditional encryption in a fraction of the time. While this surely will not halt the evolution of the quantum computer, it does mean that security must be bolstered,” adds Peter. Thankfully, global standards and security bodies have been hard at work developing and testing a new set of post-quantum encryption algorithms, with the first three standards are being released on 13 August 2024.

As published by the National Institute of Standards and Technology (NIST), these new standards include the Federal Information Processing Standard (FIPS) 203, intended as the primary standard for general encryption; FIPS 204, intended as the primary standard for protecting digital signatures; and FIPS 205, also designed for digital signatures and employing the Sphincs+ algorithm.

Prepare for the risks of quantum computing

In parallel, as standards and security measures are fortified against the threats of quantum computing, it is essential that organisations begin paying attention to post-quantum cryptography (PQC). “Somewhat short-sightedly, many business leaders are countering the argument for PQC with the misguided belief that we are ‘years’ away from commercially available quantum computers,” says Peter. “The reality is that these computers are already being miniaturised and will likely come to market much sooner than expected.”

Additionally, putting PQC measures in place now will protect data from nefarious strategies such as Store-Now Decrypt-Later (SNDL). “This cyber threat entails storing large amounts of encrypted data now, in an effort to decode and use it later, once quantum computers become more widely available.”

In a recent blog entry, HP put it like this, “A sufficiently powerful quantum computer will break the cryptography we rely on in our digital lives. An attacker can intercept and store encrypted data today, and when quantum computers become feasible, the attacker could decrypt the stored data.”

Lastly, Peter motivated that companies need to start thinking about PQC now, because some devices (such as cars) that are being produced today will most certainly be on the road when quantum computing is proliferated. “In 2023, the US government already put out a mandate that companies must transition onto PQC as soon as possible. Now, with the release of the new standards, it is critical to take the need to transition onto PQC seriously.”

Of course, with many global standards being incorporated into these algorithms, any standards-based organisation or solution (such as digital signature providers) will be forced to adopt and comply with PQC. This means for users of these solutions, the switch to the more secure standard will be seamless.

However, it is important for companies to note that encryption is only as good as the authentication they apply while using encryption. “For organisations to guarantee that they are, in fact, secure, they must ensure appropriate access management, authentication, and zero trust within their organisations.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Integrating the industry
News & Events Infrastructure
With private security, neighbourhood watches, CCTV, drones, control rooms and community safety networks expanding across the country, the next frontier may not be more technology, but connecting what already exists.

Read more...
AI assistants learn bad workplace habits
AI & Data Analytics Security Services & Risk Management
An employee under pressure at a logistics firm finds a productivity-boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
SA does not have an AI problem, it has a data problem
AI & Data Analytics Asset Management
Organisations are investing in generative AI, predictive analytics and intelligent automation, driven by the promise of increased productivity, faster decision-making and competitive advantage. Yet many businesses discover AI is not delivering the results expected.

Read more...
Shadow AI: The next evolution of Shadow IT
AI & Data Analytics Security Services & Risk Management
Today, as AI gains traction in all aspects of life and business, African organisations face a new challenge, known as ‘Shadow AI’, where employees at all levels make use of AI without considering the potential impact.

Read more...
The growing AI confidence gap
AI & Data Analytics
The rapid evolution of artificial intelligence has ushered in a new era of possibilities for enterprise IT, yet it has also exposed significant vulnerabilities and a widening confidence gap among leaders.

Read more...
Protect More with SecuVue
Secutel Technologies Surveillance AI & Data Analytics
Whether you are responsible for electronic key management, securing safes and containers, transport operations or high-value equipment, every asset represents an investment that deserves intelligent protection.

Read more...
Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...
From hype to practical value
Genetec AI & Data Analytics
Artificial intelligence is drawing more attention across the physical security industry. In the 2026 Genetec State of Physical Security report, AI ranked alongside access control and video surveillance as a key priority for the year ahead.

Read more...
African cities need intelligence, not smart infrastructure
AI & Data Analytics Government and Parastatal (Industry) IoT & Automation
Too many smart city conversations still begin with the visible symbols of progress: cameras, sensors, apps, dashboards, connected streetlights, smart meters, and control rooms. While useful, none of them on their own makes a city intelligent.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.