This piece is by Richard Geyman, Technical Director, Intersys; and James Day, Lead Engineer, Intersys
There is a long-standing joke in technology that quantum computing is always five years away. But while Quantum computers cannot yet break the public-key cryptography that underpins insurance, banking and digital commerce, the threat of Q-Day is certainly looming. That is precisely why the market must act now. The exposure begins before the machine arrives, and the migration will take years.
Q-Day is the point at which a cryptographically relevant quantum computer can defeat widely used public-key cryptography. RSA, elliptic-curve cryptography and Diffie-Hellman key exchange protect web sessions, virtual private networks, identity systems, software updates, secure email and the public key infrastructure beneath them. Shor’s algorithm makes the mathematical problems behind those schemes tractable on a sufficiently large, fault-tolerant quantum computer.
The machines available today are nowhere near that task. But the insurance market does not need a precise arrival date to recognise a foreseeable risk.
The date is uncertain. The direction is not
The last two months have provided further evidence of progress. In July, IBM and the University of Chicago demonstrated a quantum computation with significantly fewer errors, while in August IBM announced advances that could enable larger and more powerful quantum systems.
Those are important milestones, not proof that RSA will be broken in 2029. Quantum advantage does not equal cryptographic capability. Shor’s algorithm still demands formidable scale, error correction and circuit depth. Vendor roadmaps are ambitions, not actuarial certainties. The prudent conclusion is that the probability is moving while remediation remains limited by the slowest systems in the estate.
Google and Microsoft both made the same distinction clear when they set a 2029 timetable for their own post-quantum cryptography migration in March and June respectively. These are not predictions of Q-Day. They are statements about how long serious technology operators believe the change will take.
The scale of the transition is particularly significant given Microsoft’s widespread use across email, workplace productivity, identity and cloud infrastructure. Progress will not be uniform across the technology landscape, however. Some Linux distributions already support post-quantum algorithms, illustrating that elements of the migration are already technically possible, even if widespread implementation remains some way off
The risk has already started

The most immediate exposure is the concept of harvest now, decrypt later. An adversary can capture encrypted traffic or steal encrypted archives today, retain the material and decrypt it when capability becomes available. The value of the attack therefore depends less on when Q-Day falls than on how long the underlying data remains sensitive.
Insurance data is unusually durable. Claims files contain health information, legal strategy, settlement history, payment details and identity data. Underwriting repositories contain trade secrets, security assessments and details of critical infrastructure. Bordereaux and delegated authority systems aggregate information across many insureds. A five-year-old marketing list may be stale. A five-year-old medical record, engineering drawing or sanctions investigation may still be acutely valuable.
DigiCert’s survey of 1,001 IT and cyber security decision-makers, published on 23 July, exposes the implementation gap. Eighty-seven per cent said their organisations were planning, testing or implementing post-quantum cryptography, yet only 7 per cent had deployed quantum-safe or hybrid cryptography across most digital certificates. Eighty-four per cent believed at least some encrypted data was already exposed to harvest now, decrypt later, while 39 per cent expected a full transition to take three to five years.
The first quantum attacker will not look like ransomware-as-a-service
Early cryptanalytic capability is likely to be scarce and extraordinarily expensive. It will sit first with nation states and organisations able to spend millions, perhaps tens of millions, on hardware, specialist talent and target selection. That matters. Q-Day will not instantly make every small business equally attractive, and insurers should resist undifferentiated catastrophe narratives.
The exposure will be asymmetric. Defence, financial infrastructure, pharmaceuticals, energy, telecommunications, government suppliers and businesses with valuable intellectual property are more plausible early targets.
Smaller firms whose data loses value quickly may face much lower direct risk. But they can still be caught through shared cloud platforms, identity providers, managed service providers, software supply chains and payment systems. A scarce attack capability does not prevent systemic loss when a single dependency serves thousands of policyholders.
The second-order threat is authenticity. A quantum attacker able to forge digital signatures could impersonate services, sign malicious code, undermine certificate authorities or corrupt trusted software updates. Confidentiality losses may emerge slowly as stolen archives are decrypted. A failure of digital trust could move much faster.
The ultimate systemic risk?

Quantum risk will not stay inside a cyber policy. Depending on wording, facts and governing law, the same event could touch privacy breach, network interruption, cybercrime, technology errors and omissions, professional indemnity, directors’ and officers’ liability, and regulatory investigation costs. Questions of trigger and aggregation will be difficult.
Was the relevant occurrence the covert collection of ciphertext, the later decryption, the publication of data, or a service failure caused by forged credentials? Which policy period responds? How are multiple victims of one compromised technology provider aggregated? The market should examine these questions before claims force the answers.
The underwriting danger is false comfort from a clean annual control questionnaire. A firm can patch promptly, use multi-factor authentication and still have no reliable view of where cryptography sits in its estate. Certificates are only one part of the problem. Keys may be embedded in appliances, firmware, application libraries, backup tools, operational technology and products expected to remain in service for a decade. The weakest migration dependency may belong to a vendor several tiers down the chain.
What the market should ask now
Insurers do not need to demand an immediate wholesale switch to post-quantum algorithms. Mature, interoperable implementations are still arriving, and a rushed migration can create fresh security and availability failures. Underwriters should instead look for evidence that the insured understands the problem and has put a governed transition in motion.
● Has the organisation completed, or at least commissioned, a cryptographic discovery exercise covering TLS, VPNs, private PKI, code signing, email, backups, cloud services, operational technology and embedded devices?
● Has it classified information by sensitivity and useful life, including data that would still matter to an adversary in five or ten years?
● Can it identify critical vendors, their supported standards, product roadmaps, upgrade paths and any hardware that cannot be updated?
● Does its architecture provide crypto-agility, so algorithms and keys can be changed without replacing entire applications or creating an uncontrolled outage?
● Is there a funded, owned and tested migration roadmap, with high-priority confidentiality protections first, clear rollback arrangements and regular board-level review?
The UK National Cyber Security Centre provides a sensible outer framework: discovery and an initial plan by 2028, the highest-priority migration work by 2031, and completion by 2035. For insurers, these should become underwriting reference points, not dates to revisit the subject. Google’s 2029 programme and the three-to-five-year migration estimate in DigiCert’s research show why discovery that starts in 2028 may already be late for complex estates.
Price the preparedness, not the prediction
There is no merit in pretending we know the exact date of Q-Day. There is equally little merit in using uncertainty as permission to do nothing. Insurance exists to make decisions under uncertainty. Here, the market can observe the value and longevity of data, the concentration of shared suppliers, the age of hardware, the quality of cryptographic inventory and the credibility of a migration plan. Those are underwriteable facts today.
The sensible near-term action for most organisations is practical: ask software, cloud, security and managed service providers for their post-quantum roadmaps; identify information that needs long-term confidentiality; build a cryptographic inventory; and make crypto-agility a requirement for new projects. Insurers and brokers should ask the same questions, reward demonstrable progress and map aggregation across the providers on which their books depend.
Waiting for a quantum computer to break encryption before acting would be like buying flood defences after the water reaches the underwriting floor. Q-Day may still be years away. The deadline for orderly preparation is not.

Be the first to comment