Nearly two-thirds of organisations consider quantum computing as the most critical threat they face over the next five years, according to fresh research from Capgemini.
With the rapid progression of quantum computing threatening to render current encryption algorithms obsolete, the global tech services firm’s latest report, Why Post-Quantum Cryptography Tops the New Cybersecurity Agenda, shows that quantum safety has shifted from a technical concern to a C-suite priority.
Polling 1,000 executives from enterprise firms around the world, Capgemini found that two-thirds (65%) of organisations are now concerned about ‘harvest-now, decrypt-later’ quantum attacks.
These assaults see hackers target encrypted data, but then store it to wait for a hypothetical future date when quantum computers will become powerful enough to break current cryptographic algorithms.
While current quantum computers cannot break widely used encryption yet, according to Capgemini, six in ten early adopters of quantum-safe technologies predict that this ‘Q-day’ will arrive within a decade.
Although most organisations (70%) are already working on or planning to use quantum-safe solutions, those in consumer-focused sectors like consumer products (48%) and retail (51%) are showing less urgency.
That compares to 76% of telecom firms, 86% of banking institutions and, unsurprisingly, 90% of defence-focused organisations protecting their systems against emerging quantum threats.
Seven in ten of these early adopters agreed that transitioning to post-quantum cryptography (PQC) is the best available solution to address near-term quantum risks, though interestingly, the same number (70%) also believe that PQC is essential to providing a competitive edge.
According to the report, Vodafone is one prominent example of this, having already trialled quantum-safe tech to protect smartphone browsing by applying PQC standards to current encryption algorithms, putting it ahead of competitors.
That has led around half of early adopters to run PQC pilots, often in partnership with cloud providers and specialist vendors, but few have a clear roadmap for enterprise-wide transition.
Uncertainty about the timeline for quantum threats is stymying plans (58%), as is a lack of training (63%), insufficient information on best practices (58%), and budget constraints (59%).
Recommended reading
- NCSC Issues Quantum Security Roadmap For Businesses
- Firms Unprepared for Quantum Computing’s Rapid Rise
- Financial Services Under Quantum Threat, Warns Europol
Tellingly, concerns about compliance with existing standards (49%) are also holding firms back, even as regulators are encouraging the transition to quantum-safety and begin to introduce laws covering PQC.
With 70% of firms citing ‘regulatory mandates’ as a top factor in their urgency to adopt post-quantum security, governments may have to step in to help guide firms towards PQC before it is too late.
“Quantum readiness isn’t about predicting a date, it’s about managing irreversible risk,” said Marco Pereira, global head of cybersecurity, cloud infrastructure services at Capgemini.
“Every encrypted asset today could become tomorrow’s breach if organisations delay adopting post-quantum protections. Transitioning early ensures business continuity, regulatory alignment, and long-term trust.
“The organisations that recognise this fact early will best insulate themselves against future cyber-attacks.”





