Post-quantum cryptography needs collective action, G7 finds

Understand this faster with AI
Several recent advances are forcing the G7 Cybersecurity Working Group to re-evaluate the timeline for quantum computing’s threat to digital security, shifting the focus from a distant possibility to an immediate risk. The group asserts that transitioning to post-quantum cryptography (PQC) is no longer a future consideration, but a necessary upgrade to safeguard organizations against both conventional cyberattacks and the emerging quantum threat. “Transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition,” the G7 group states, emphasizing the need for coordinated planning between public and private sectors to address these growing vulnerabilities. This call for collective action underscores the urgency of preparing for cryptographically relevant quantum computers and protecting long-term data confidentiality. G7 Highlights Growing Threat of Cryptographically Relevant Quantum Computers The group’s analysis points to several recent advances as catalysts for this revised perception, prompting a re-evaluation of preparedness strategies across both public and private sectors. These computers, powerful enough to break current public-key cryptography, are defined as cryptographically relevant quantum computers (CRQCs) capable of solving complex factorization and discrete logarithm problems used in vulnerable systems. This dual-purpose functionality positions PQC as a proactive security measure, rather than a reactive response to an impending technological shift. The G7 report emphasizes that PQC is a new field of cryptography designed to resist both classical and quantum cryptographic attacks, offering a comprehensive solution for evolving security needs. The group identifies five priority areas for PQC migration, building on initiatives already advanced by G7 countries to encourage proactive measures and inspire global adoption of these critical security protocols. The G7 Cybersecurity Working Group asserts that organizations must proactively address the quantum threat to maintain data security, rather than waiting for confirmed availability of cryptographically relevant quantum computers (CRQCs). This shift in perspective acknowledges that a reactive approach leaves systems vulnerable for an unacceptable period, given the lengthy timelines associated with transitioning to post-quantum cryptography (PQC). The group emphasizes that PQC is a present necessity for protecting confidential data, authentication mechanisms, and critical assets from both conventional and emerging quantum-based cyberattacks. Governments and organizations should prioritize PQC transition efforts by first identifying systems holding the most critical data, according to the group’s recent call to action. Acting before confirmed CRQC availability is important for effective quantum risk management; a phased, risk-based strategy is recommended to guide the process. Early adoption of PQC requires a comprehensive assessment of cryptographic assets, mapping dependencies, and developing a detailed transition plan, the group advises. This proactive stance acknowledges the complexity of migrating to new cryptographic standards and the need for long-term planning. “Store Now, Decrypt Later” Risks Demand Immediate PQC Planning The potential for adversaries to stockpile encrypted data for future decryption, a tactic known as “store now, decrypt later”, demands immediate action from organizations prioritizing long-term data protection, according to the G7 Cybersecurity Working Group. This risk exists even before the advent of cryptographically relevant quantum computers (CRQCs), as malicious actors can currently intercept and archive encrypted communications. The group highlights that this approach is particularly relevant for safeguarding governmental data, sensitive personal information, and proprietary business secrets requiring extended confidentiality. Vulnerabilities extending beyond a single organization represent a significant escalation of risk; compromised authentication mechanisms can enable rapid lateral movement within networks, exposing multiple entities and sectors. To mitigate these cascading effects, the G7 asserts that organizations should initiate PQC transition planning immediately, aiming for completion within timelines established by national cybersecurity authorities. Delaying this transition may not only increase quantum-related risks but also result in lost competitive advantages or exclusion from future contracting opportunities, including public procurement processes. The group emphasizes that a successful shift to post-quantum cryptography is not achievable through isolated efforts.
National Strategies Key to Scalable PQC Adoption & Awareness Successfully scaling PQC requires not only hardware and software solutions but also deliberate encouragement for organizations to implement them within existing security frameworks. These strategies should integrate with broader digital privacy and security initiatives already underway, ensuring a cohesive approach to evolving cyber threats. A significant barrier to widespread PQC implementation remains a lack of awareness among many organizations, with competing security concerns often taking precedence, the group found. Addressing this requires proactive campaigns that highlight PQC’s benefits and the economic risks mitigated by its adoption, framing the issue as more than simply a cryptographic challenge. Technical guidance and upskilling initiatives are also important to empower organizations to navigate the transition effectively, aligning with existing cyber risk management strategies. Organizations can utilize recommendations from the G7 Cybersecurity Working Group statement on preparing for a Post-quantum Cryptography Migration, but should also consult national guidelines and cybersecurity agencies for additional, locally relevant information. Research and development efforts should continue to focus on innovation and the creation of practical PQC solutions, furthering the field beyond theoretical advancements. “A successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk,” the group stated, emphasizing the need to reframe the conversation around quantum security. Source: https://oos.cloudgouv-eu-west-1.outscale.com/sitesconformes-prd-osc-cgw1-s3-cybergouvfr/sf-cyber/documents/G7_preparing_for_the_qost_quantum_era_a_call_to_action.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=4KPMC6G57D6727LM7P5K%2F20260906%2Fcloudgouv-eu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20260906T202330Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=bc851aca26c1102db6f5339bc907c639908dacbd6b04fcbd949f62b06b1d498b More like thisQuantum CryptographyANSSI leads G7 push for quantum-resistant encryptionQuantum SecurityBanco Sabadell Adopts Quantum Safe CryptographyQuantum CryptographyDigiCert’s New Edition Simplifies Post-Quantum Cryptography PlanningQuantum Computing Business NewsPost-Quantum Crypto: Alliance Transition GuideStay currentSee today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals. Tags:
Tags
Source Information
Discussion
0 professional contributions
Sign in to join this professional discussion.
Be the first to add a constructive contribution.
