This week second issue on 2025 Predictions focuses on the impact of quantum computing on cryptography and why I think this will matter next year, even though quantum computers are 10 years or so away from us.
Today’s digital economy depends on cryptography. Every email sent, financial transaction processed, or digital signature verified relies on cryptographic algorithms to ensure security. These systems, such as RSA and ECC, are designed to protect data based on mathematical problems so complex that classical computers would require millions of years to solve them.
Yet, quantum computing will make these systems obsolete. Let’s see not just why, but why I think this will be a topic in 2025.
Focus On: Quantum Computing
To understand the power of quantum computing, we can look back at the famous experiment of Schrödinger’s Cat. Imagine a cat placed inside a sealed box. Alongside the cat is a radioactive atom, a Geiger counter, a vial of poison, and a mechanism to release the poison if the Geiger counter detects radiation. Since the radioactive atom has an equal probability of decaying or not decaying within a given time frame, until the box is opened, quantum mechanics tells us that the atom is in a superposition—a state where it has both decayed and not decayed. As a result, the cat is also in a superposition: it is both alive and dead simultaneously. Only when an observer looks inside the box does the system “collapse” into one definite state—alive or dead.
Just as Schrödinger’s cat can exist in multiple states at once, quantum bits (qubits) can hold multiple states simultaneously. Unlike classical bits, which can only be a 0 or a 1, qubits can represent 0, 1, and any combination of 0 and 1 at the same time.
Now let’s imagine we need to solve a maze. A classical computer explores one path at a time, sequentially or through simultaneous threads in limited numbers. A quantum computer, leveraging superposition, explores all possible paths simultaneously, drastically reducing computation time.
For cryptography, this means quantum algorithms like Shor’s Algorithm can factorise large numbers or compute discrete logarithms—the basis of RSA and ECC—millions of times faster than classical computers, rendering these systems insecure.
Why this will matter in 2025
The quantum revolution is years away indeed, but a more immediate threat is among us: harvest now, decrypt later.
Several bad actors, both state-sponsored and individual operators, are collecting encrypted data today, storing it with the intention of decrypting it in the quantum future. For example, sensitive financial, healthcare, or government data stolen in 2025 could be decrypted by 2030+, exposing information assumed secure for decades.
This means we cannot wait until quantum computing emerges as a new technology, we need to protect data that will know will remain sensitive post 2030 today so that, even if stolen, they would not be decrypted with the use of quantum technologies.
This is referred as postquantum cryptography (PQC)—algorithms designed to resist both classical and quantum attacks.
PQC leverages mathematical problems that remain computationally difficult for quantum computers to solve. Unlike current algorithms, which quantum computers exploit, PQC relies on alternative methods, which I asked ChaGPT to simplify for me:
Lattice-Based Cryptography
Imagine a giant 3D grid of points, like an endless lattice fence. The goal is to find your way from one point to another, but there’s a twist: you can only move in specific patterns, and the grid is so vast and complex that even describing the “shortest path” is a near-impossible task.
For quantum computers, solving this kind of problem is incredibly challenging. That’s why lattice-based cryptography uses these grids as the foundation for its encryption. It’s like hiding a treasure in a maze so complex that even the most advanced quantum computer would get lost trying to find it.
Hash-Based Cryptography
Think of a hash function as a magical stamp. You put a document under it, press the stamp, and it generates a unique pattern of letters and numbers—a “fingerprint” for the document. Even the smallest change in the document creates a completely different fingerprint.
Quantum computers are great at solving many types of puzzles, but hash functions don’t rely on puzzles—they rely on the fact that it’s nearly impossible to reverse-engineer the stamp to recreate the original document. This makes hash-based cryptography a reliable shield against quantum attacks.
Multivariate Cryptography
Imagine trying to solve a jigsaw puzzle, but instead of one puzzle, you’re given hundreds of interconnected puzzles, each with pieces that can fit in multiple ways. To make it harder, the rules for how the pieces fit together change constantly.
Multivariate cryptography works on a similar principle. It uses mathematical equations that are like these overlapping puzzles—super complex and constantly changing. Quantum computers struggle to solve these kinds of problems because there’s no straightforward path to figure out the solution.
To this extent, algorithms like CRYSTALS-Kyber (encryption) and CRYSTALS-Dilithium (digital signatures), currently undergoing standardisation by NIST, represent the latest of quantum-safe techniques. However, these are not a drop-in solutions. Larger key sizes, much longer processing times, and changes to existing systems are huge challenges.
What to do now?
I believe in 2025 we will hear more conversations on this topic, probably along these lines:
1. Adopt Crypto-Agility
Build systems that can quickly adapt to new cryptographic standards. Crypto-agility ensures seamless upgrades as algorithms evolve, while at the same time achieving acceptable processing times.
2. Prioritise High-Value Data
Focus first on securing long-term sensitive data—financial records, trade secrets, and health records—against the harvest now, decrypt later risk. There is no need in securing data with a short lifespan, as it will be worthless in 2030. Anything created today still envisioned to be sensitive in 2030 should be guarded and protected carefully.
3. Raise Awareness and Train Teams
Equip not only IT and cybersecurity teams but the business and functional teams too with knowledge of quantum-safe algorithms, testing procedures, and best practices for managing their unique performance characteristics.
4. Develop a Phased Roadmap
Transitioning to PQC is a multi-year effort. Starting with critical assets in 2025 and gradually extending protections across all systems by the end of the decade.
Follow me
That’s all for this week. To keep up with the latest in generative AI and its relevance to your digital transformation programs, follow me on LinkedIn or subscribe to this newsletter.
Disclaimer: The views and opinions expressed in Chronicles of Change and on my social media accounts are my own and do not necessarily reflect the official policy or position of S&P Global.