top of page

Quantum Is No Longer a Cyber Risk. It's a Fiduciary Duty.

  • Writer: Brian Couzens
    Brian Couzens
  • Jul 19
  • 1 min read

Buried in a legal update this week was a signal that should concern every Board.


Lawyers are now being trained on post-quantum cryptography, quantum evidence, AI-quantum convergence and Q-Day.


Think about that.


The legal profession is preparing for the consequences.


Is your Board?


Now imagine the cross-examination.


"When did you become aware that quantum computing would eventually render your cryptography obsolete?"


"You knew your regulators had already issued migration guidance?"


"You knew about Harvest Now, Decrypt Later?"


"You knew some of your data needed protecting well beyond the arrival of a cryptographically relevant quantum computer?"


"So why did you continue deploying quantum-vulnerable cryptography?"


"Why didn't you begin deprecating legacy cryptographic dependencies when you knew the risk was foreseeable?"


"Where is the Board paper?"


"Where is the risk assessment?"


"Where is the documented challenge?"


"Where is the migration strategy?"


"Where is the independent assurance?"


If those questions cannot be answered, don't expect "we were waiting" to be an adequate defence.


A known, foreseeable and material risk that is ignored is no longer simply a technology issue.


It becomes a governance issue.


It becomes a Board issue.


It becomes a fiduciary issue.


At some point, the question won't be whether quantum computing arrived.


The question will be why you failed to act when you already knew it was coming.



Quantum Trust & PQC Assurance Services | Sitg-Consulting

 
 
 

Comments


bottom of page