G7 tells businesses to prepare for quantum cybersecurity threats
G7 urges governments and organizations to start transitioning to quantum-resistant encryption to guard against future quantum computers breaking current standards like AES.
Virtually every industry today relies on encryption to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else use some form of encryption, most likely AES (Advanced Encryption Standard). Decrypting protected data without the encryption key is considered almost impossible because the computational effort required is too large. However, quantum computers work on a fundamentally different principle, and once they are mature enough, they are believed to be able to crack today’s encryption standards.
The G7 warning states that to protect themselves from the threat posed by cryptographically relevant quantum computers (CRQCs), organizations should begin planning their PQC (post-quantum cryptography) transition now and aim to complete it within timelines set by their national cybersecurity authorities. It also notes that organizations delaying the transition may lose competitive advantage or be excluded from contracting opportunities, including public procurement.
The G7 advises governments and organizations to identify critical systems and prioritize them, adopt a phased and risk-based strategy, start their transition early, inventory their cryptographic assets, map dependencies, and develop a transition plan. To limit costs, the group recommends purchasing products that integrate PQC and replacing systems with quantum-safe ones as part of standard renewal schedules. Starting early could result in lower migration costs overall, and proper planning would help organizations prevent insecure implementations and avoid increased exposure to conventional cyber threats.