Security/ quantum computing · encryption · g7 · cybersecurity

G7 tells businesses to start migrating to quantum-safe encryption

The G7 wants organizations to inventory their encryption and start migrating now, before quantum computers can break public-key systems like RSA.

The G7 wants every business on the planet to start planning for a future where today's encryption no longer holds.

The G7 issued guidance urging governments and organizations to begin transitioning to post-quantum cryptography (PQC) now, rather than waiting for a cryptographically relevant quantum computer (CRQC) to show up. The advice: inventory your cryptographic assets, prioritize critical systems, map dependencies, and build a phased, risk-based migration plan. To limit costs, the guidance suggests buying products that already support PQC and swapping in quantum-safe systems as part of normal renewal cycles, rather than a costly rip-and-replace. The G7 also warns that laggards risk more than a future breach: they could lose contracts, including government procurement, once buyers start requiring quantum-safe systems.

Here's the nuance the warning glosses over. The real risk isn't AES, the algorithm protecting your bank transfers, which survives quantum attacks reasonably well with a longer key. The actual casualty is public-key cryptography, RSA and ECC, the systems that set up those encrypted connections in the first place. A sufficiently powerful quantum computer could break that outright using Shor's algorithm, while only weakening AES. Businesses chasing 'quantum-safe AES' are solving the wrong problem while the handshake protecting their data stays exposed.

No one knows exactly when a cryptographically relevant quantum computer will exist, but harvest-now-decrypt-later attacks mean data intercepted today could be unlocked years from now. That's what makes the G7's timeline pressure less hypothetical and more actuarial.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →