Forget AI – quantum computing could be cyber's next systemic threat

Q-Day may be years away, but cyber exposure is already building

Forget AI – quantum computing could be cyber's next systemic threat

Cyber

By Gia Snape

The cyber insurance industry is still learning how to price and manage artificial intelligence, but another technological risk may already be moving from science fiction toward the underwriting agenda: quantum computing.

The potential threat would arrive in a market already managing rising claim frequency. The National Association of Insurance Commissioners reported that the number of US cyber claims climbed almost 40% in 2024 to nearly 50,000, even as direct written premium fell 7% to about $9.14 billion.

Meanwhile, Verizon's 2025 breach study found ransomware in 44% of breaches and a 34% increase in vulnerability exploitation as an initial-access route, with attackers focusing heavily on zero-days in perimeter devices and virtual private networks.

Washington moves to set the timeline

The primary concern around quantum risk is that a cryptographically relevant quantum computer could break public-key systems such as RSA and elliptic-curve cryptography, which protect online transactions, digital signatures and sensitive data. Today's machines remain rudimentary and error-prone, but the US Government Accountability Office said experts place the arrival of a code-breaking quantum computer roughly 10 to 20 years away.

The risk may already be unfolding, as threat actors can steal encrypted information today and hold it until quantum technology is capable of unlocking it, a strategy known as "harvest now, decrypt later." This is potentially worrying with regard to medical, financial, government and commercial information that must remain confidential for years or decades. The GAO warned in 2025 that the US still lacked a fully coordinated national plan covering both federal agencies and critical infrastructure.

Washington has since accelerated its response. A June 2026 executive order requires federal high-value assets and high-impact systems to use post-quantum cryptography for key establishment by the end of 2030 and for digital signatures by the end of 2031. It also directs regulators to propose procurement rules requiring covered federal contractors to comply with post-quantum federal standards by December 31, 2030.

The National Institute of Standards and Technology finalized its first three post-quantum encryption standards in August 2024 and urged organizations to begin transitioning immediately.

What underwriters should be asking

The issue for carriers is less about predicting the exact date of so-called "Q-Day" (i.e, the point at which quantum computing could defeat widely used encryption) than identifying where long-lived encrypted data, legacy systems and technology dependencies could produce concentrated losses.

A successful break-in commonly used cryptography could affect financial institutions, healthcare systems, cloud providers, software supply chains and critical infrastructure at the same time.

Quantum risk could therefore widen the role of cyber underwriters beyond familiar controls such as multifactor authentication, backups and endpoint detection. Insurers may increasingly ask whether organizations maintain an inventory of cryptographic assets, know which vendors rely on vulnerable algorithms and have a plan for "crypto-agility" — the ability to replace encryption methods without rebuilding entire systems.

Bob Parisi, head of cyber solutions for North America at Munich Re, described Q-Day as a live risk rather than a distant abstraction. “We may get to a point where, if you have enough quantum computing power, you can get through any kind of encryption,” he said. “It's like a zero-day vulnerability."

Parisi remains cautiously optimistic that the same technology creating the threat could help produce its solution. He also compared the uncertainty with earlier technological turning points, from Y2K and cloud migration to the Internet of Things and AI.

"My glass-half-full view is that, to the extent quantum computing creates a Q-Day when all current forms of encryption are breakable, I'm hoping quantum computing will also create a new type of encryption that is quantum-proof," he told Insurance Business in an interview earlier this year. "When current encryption models get broken, we're going to need a new model.

"Each level (of technology development) has created new complexity and a new ability to cause absolute havoc and mayhem. But we've learned how to adapt to it."

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!