Your Company's Sensitive Data Could Already Be at Risk as Quantum Computing Advances

Picture this: Some threat actors may already be collecting encrypted corporate data with the expectation that future quantum capabilities could make it easier to access.
Those machines are closer than most people realize.
Last week, researchers at Google and a quantum computing startup called Oratomic published papers showing that quantum computers capable of breaking modern encryption could arrive significantly earlier than previously expected. The reports sent shockwaves through the cybersecurity community. A widely used internet security provider, which secures a significant fraction of the internet, announced it was accelerating its own deadline to prepare for quantum computers to 2029. Google had already moved its internal deadline to the same year, six years ahead of where most of the industry assumed the window would close.
Efforts to prepare enterprise data security for potential quantum-era threats are underway, though many organizations may still be early in their planning.
In some cases, data may be collected now with the possibility of future decryption attempts.
The attack that security professionals fear most does not require a quantum computer to exist yet. It only requires one to exist eventually.
The strategy is called harvest now, decrypt later. Foreign adversaries and the Federal Reserve have begun using this phrase in official communications. Merger negotiations. Drug compound formulas sent between pharmaceutical companies and manufacturers. Hospital patient records. Defense contractor communications. All of it is encrypted, and some of it could be stored by actors anticipating that current encryption methods may become less effective over time.
A patient record transmitted today will still be sensitive in four years. A trade secret negotiated this quarter will still be valuable when the machines arrive. The organizations that understand this are the ones treating quantum security as an urgent problem. The vast majority are still treating it as a 2030 problem.
It is not a 2030 problem.
The $3.3 trillion scenario
Citi has quantified what a successful quantum attack on the financial system would look like. A quantum computer breaking encryption on a top-five bank's access to the Fedwire payment system could expose every interbank message, payment authentication, and digital signature. The impact could extend beyond a single institution, particularly in interconnected systems where encryption plays an important role.
JPMorgan, HSBC, and the largest financial institutions have dedicated quantum security teams and multi-year migration roadmaps. They have the resources to figure it out. The organizations most exposed are the ones just below that tier: regional banks, community hospitals, mid-sized defense contractors, local governments. Most have not conducted a cryptographic inventory. They do not know what encryption they are running or where it lives in their systems. The migration needed to close that gap takes four to five years. For institutions that have not started, the math is already bad.
A new front in the race
The urgency sharpened last week when the Google and Oratomic papers landed. Researchers found that artificial intelligence was instrumental in developing algorithms that could reduce the size of quantum computers needed to break encryption by a factor of 100. One of the paper's authors described the results as "a real shock." Cloudflare's security researcher called for efforts to "speed up considerably."
Against that backdrop, a company called ZeroTier launched ZeroTier Quantum during RSAC, billing it as an early end-to-end networking platform designed with quantum-resistant security principles built for enterprise deployment. The platform uses NIST-standardized post-quantum cryptography embedded directly into the transport layer, meaning data is protected while it is moving across networks, not just when it is sitting still.
That distinction matters more than most security leaders currently appreciate.
“Most organizations are focused on protecting stored data,” said Andrew Gault, CEO of ZeroTier. “The bigger gap is data in motion. That’s where it’s most exposed, and that’s the problem ZeroTier Quantum is built to solve. Quantum embeds post-quantum cryptography directly into the transport layer, so the data is protected in transit without organizations having to rebuild the infrastructure they already run."
Gault came to this problem from an interesting direction. Before building ZeroTier Quantum, he co-founded 7percent Ventures. He has spent years inside the investment community watching qubit estimates compress faster than almost anyone expected.
“I invested in quantum technology because I saw how quickly it was advancing,” he said. “I know this shift is happening much faster than most people realize.”
Some organizations with higher exposure may be less familiar with the concept of Q-Day
The largest enterprises have started the conversation. The ones most exposed often have not.
NIST finalized post-quantum cryptography standards in 2024. In January, CISA ordered every federal agency to purchase only from vendors that are quantum-secure. Apple and Google are baking post-quantum protections into their consumer products. The government is moving. The question is whether the rest of enterprise America moves fast enough to matter.
For regional hospital networks, community banks, and mid-sized manufacturers, retrofitting quantum security into a legacy network is not a straightforward IT upgrade. It is a multi-year infrastructure project that most of their security teams are not equipped to manage, and most of their boards have never discussed.
The most common thing security leaders say when the topic comes up is that they will deal with it when it gets closer. That logic worked before harvest; now, decrypt later attacks existed. It does not work anymore. The data being stolen today could surface in four years. Organizations that begin preparing their networks now may be better positioned to maintain customer confidence as the landscape evolves.
Organizations that delay preparation could face difficult-to-detect security incidents involving legacy encrypted data, including information transmitted years earlier.
The machines are being built. The algorithms are improving faster than predicted. The companies that understand that are the ones still standing when it happens. The ones that do not will find out the hard way.
PanOxyl’s “Here For It All” Campaign Is Changing the Way Brands Talk About Acne
From Cornell to 300 Million Views: How Derrick Geng Built a New Kind of Comedy for Chinese Audiences