Quantum threat timeline raises cyber insurance questions for NZ brokers
Current policy wordings may not account for encrypted data stolen today and decrypted years from now
Quantum threat timeline raises cyber insurance questions for NZ brokers
CYBER
By Roxanne Libatique
10 Oct 2026

A global cyber security firm has warned New Zealand organisations to prepare for quantum computing threats that could render current encryption obsolete by 2030, raising questions about whether cyber insurance policies are equipped for the fallout.

Fortinet senior executives visited New Zealand last week to brief organisations across health, finance, energy, and utilities on the combined risks of AI and quantum computing, as reported by Radio New Zealand (RNZ).

For brokers, the compressed timeline puts a new category of long-tail exposure on the agenda.

How harvest now, decrypt later creates coverage uncertainty

The core concern is a strategy known as Harvest Now, Decrypt Later (HNDL). Cyber criminals are collecting encrypted data now with the intention of decrypting it once quantum computing reaches sufficient capability.

Filippo Cassini, senior vice president and global chief technical officer at Fortinet, told RNZ that bad actors were already preparing for what the industry calls Q-Day.

This creates a problem for cyber insurance. Data harvested in 2026 could become a fully realised breach in 2030 or later. Does the policy in force at the time of data theft respond, or the one active when decryption occurs? Brokers advising commercial clients will need to consider how current wordings address that gap.

Duncan Morrison, cyber practice leader at Aon New Zealand in Auckland, has previously noted the importance of boards understanding their financial exposure from cyber events. “Without that financial lens, cyber risk can be underestimated or deprioritised,” Morrison said, as previously reported by Insurance Business. The quantum dimension adds a new layer to that calculus.

Wei Ling Neo, vice president of product management at Fortinet, said investment had shortened the quantum timeline. “(It) has been shortened by a lot of investments into quantum computing, which has brought the timeline much closer to 29 and 2030, for when we will have a viable quantum computer that will be able to decrypt the current algorithms that we use,” Neo said.

Read next: Falling cyber alerts may not mean lower risk at renewal

NZ government is already moving on quantum readiness

New Zealand’s government has signalled that quantum readiness is a priority. The Cyber Security Action Plan 2026-2027, published by the Department of the Prime Minister and Cabinet (DPMC), includes a specific action led by the National Cyber Security Centre (NCSC) to “enable New Zealand to process and manage quantum-resistant cryptographic material.”

The Government Chief Information Security Officer (GCISO) has also reported to Treasury that agencies’ investment proposals do not dedicate enough time and resources to cyber security or emerging threats, according to Quantum Zeitgeist.

The New Zealand Information Security Manual (NZISM), updated in November 2025, now includes a section on post-quantum cryptography. It recommends that agencies inventory sensitive datasets needing long-term protection, identify systems reliant on public key cryptography, and develop transition plans. The Government Communications Security Bureau (GCSB) noted it may deprecate current cryptographic standards within the next two to three years.

While the NZISM guidance applies to government agencies, it offers a framework that brokers can reference when talking to private sector clients about their own preparedness, similar to how recent NCSC supplier-oversight guidance has shaped cyber insurance conversations.

Broader preparedness remains low

A 2025 poll of more than 2,600 professionals by ISACA found that 55% had taken no preparatory action on quantum computing threats. Only 5% had a defined strategy, and 37% had never discussed the topic within their organisation, as reported by IT Brief New Zealand.

Respondents from Oceania showed concern at least 10 percentage points above the global average.

Jamie Norton, ISACA board director, said: “Too many Australian and New Zealand organisations remain in reactive mode.”

Cyber threats are already escalating in NZ

The quantum risk arrives on top of a worsening threat environment. The Cyber Threat Report 2025 recorded 331 incidents of potential national significance in the 2024/25 year. Criminal or financially motivated actors accounted for 137 of those, up from 65 the previous year. Direct financial losses reported to the NCSC reached $26.9 million, up from $21.6 million.

The report also found that 53% of small and medium enterprises experienced a cyber threat in the first half of 2025, up from 36% in 2024.

A separate NCSC quarterly report for Q1 2026 recorded three C2 (highly significant) incidents, the first at that severity level since the 2021/22 financial year, according to OpenGov Asia.

The NZ cyber insurance market has softened even as threat levels have risen, with Aon classifying conditions as soft in Q1 2026.

Read next: NZ cyber threat rises as insurance market moves the other way

What should brokers be asking clients?

Neo said many organisations remain focused on AI without assessing their broader exposure. “The timeline is getting shorter and shorter for them to be ready, to protect against quantum threat,” she said.

Cassini noted that upgrades would be costly but necessary. “I think they should be looking at how safe and upgradable it is. It’s a little bit of extra money, but I think it’s worth it,” he said.

Under the Privacy Act 2020, New Zealand organisations must take reasonable steps to protect personal information. As quantum threats become more widely documented, what qualifies as “reasonable” may shift to include cryptographic readiness. The Cyber Security Action Plan also flags that the Ministry of Justice is advising on incentives to protect personal information, including a potential civil pecuniary penalty regime under the Privacy Act.

Research firm CyberCube noted in January 2026 that insurers are beginning to explore indicators of cryptographic readiness, though discussions remain focused on education and scenario analysis rather than pricing changes, as reported by Help Net Security.

For brokers, client conversations about cyber cover should now include questions about data retention policies, encryption standards, and whether systems can be upgraded to post-quantum cryptography before the 2030 window closes.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB NZ.