Skip to main content

From awareness to execution:

Quantum Security Transition

Although quantum computers capable of breaking today’s encryption are not yet an operational reality, the risk already exists. Data collected today through 'harvest now, decrypt later' attacks could be decrypted tomorrow, once sufficient quantum computing power is available. The question is therefore no longer 'when', but 'will we be ready in time?'

Talk to an expert

Challenges

The weaknesses of current encryption and the computing power of quantum computers are a concern

Many encryption methods rely on factoring large prime numbers

Quantum computers are particularly powerful at solving this type of problem. Once enough stable qubits are available, classical methods such as RSA will no longer be effective – new, quantum-safe methods are already on the market.

Harvest now, decrypt later

Encrypted data intercepted and stored today can be decrypted once sufficient quantum computing power becomes available. For data with a long confidentiality lifespan, the risk is already real today.

When will quantum computing become relevant?

Two indicators show how quickly the field is evolving, and why preparation should start today rather than waiting for the first practical threat to appear.

Qubit growth is one of the most important properties of quantum computers

A single additional qubit doubles computing power. Tracking publicly communicated roadmaps from major manufacturers also shows an exponential increase in the number of qubits deployed.

Patent filings as an early indicator

The number of patent filings in quantum computing is also growing exponentially. Patents are typically seen as leading indicators – practical implementation follows with a delay, but it does follow.

A clear wake-up call from FINMA

Five action areas from Supervisory Notice 05/2026

In early July 2026, FINMA published a supervisory notice on quantum computing. Although formally addressed to FINMA-regulated banks and insurers, its content is relevant to any organisation handling sensitive data.

FINMA Guidance 05/2026 (PDF)

1. Crypto-agility

The ability of IT systems to swap out encryption algorithms quickly and flexibly.

2. Inventories and risk

Encryption methods and data classification, particularly how long information needs to remain confidential.

3. Process analysis

Which processes require which types of encryption, why, and how crypto-agile are they today?

4. Data analysis

Which data is critical, why, and what does that mean specifically in a quantum context?

5. Dependencies

Dependencies on external service providers and their own crypto-agility.

SPIE ICS supports you

From strategy to execution

The transition to post-quantum cryptography is a transformation programme requiring time, method and a cross-functional approach.

Risk analysis

Where and how is cryptography used today, and where do 'harvest now, decrypt later' risks arise?

Cryptographic inventory

Mapping certificates, protocols, signatures, keys, applications, code libraries, and vendor dependencies.

Contextualisation and prioritisation

Distinguishing and prioritising confidentiality, key exchange, digital signatures, and long-term proof.

PQC roadmap

A realistic, prioritised migration plan to avoid being caught off guard by the pace set by regulators.

Cryptographic governance

Embedding crypto-agility into architectures, contracts, IT processes, and future projects.

Team support

Supporting technical and business teams, including hybrid approaches where appropriate.

Events & webinars

Explore the topic in greater depth with our experts

Take part in our events and webinars to gain a better understanding of FINMA's expectations, speak to our experts, and identify the next steps in your quantum transition.

Our Solution

A transformation of this scale cannot be managed manually

Cryptography is the most widely used security measure in enterprises, yet it is also one of the least managed. It has accumulated silently over the years, becoming embedded across infrastructure, applications, protocols, and third-party services. Often, there is no owner or continuous view of how it aligns with policy. This is why we combine advisory work with our own technology, which keeps the entire cryptographic estate visible on an ongoing basis, from discovery to remediation.

Four elements. One loop.

1. Discovery: see what cryptography is in use and exactly where it is located: on-premises, in the cloud, in code or on the network.

2. Correlation and Contextualisation: Connect your findings to the assets, applications, and business context they affect.

3. Policy and triage: Measure against your own cryptography policy and prioritise what actually matters.

4. Remediation: Turn 'what is wrong' into a concrete plan that fixes it, with visible impact per action.

Maturity on the path to PQC

Each stage is a strict subset of the previous one – an organisation cannot be 'PQC-capable' without first being 'cryptographically clean'. This generic four-stage path is not tied to any specific customer's current numbers.

Your next step

Now is the right time to start the transition

Waiting for standards, vendors or regulators to set the pace risks leaving insufficient time for a clean migration.

Discuss your current situation with our experts or find out more about our approach during a demonstration.

Your information
Join our Newsletter
Privacy policy 
Talk to an expert