Despite acknowledging the severity of the threat, CISOs continue to be slow to respond to warnings that existing systems need to be upgraded to address the risks posed by the impending advent of quantum computers. Quantum computers threaten the security of existing public-key cryptography systems.
See also: MITRE publishes Post-Quantum Cryptography roadmap

Government agencies such as the US National Institute of Standards and Technology and the UK National Cybersecurity Centre (NCSC) are advising the adoption of post-quantum era (PQC) encryption before the 2030 deadline, in time for the expected obsolescence of vulnerable cryptographic algorithms.
However, five years ahead of that deadline, PwC's Global Digital Trust Insights report paints a picture of a general lack of preparation for implementing resilient encryption in the quantum era.
The majority of independent experts interviewed by CSO say the findings of the PwC report reflect a real gap between industry awareness and operational readiness for PQC. Jason Soroko, senior partner at Sectigo, tells CSO that sectors of the economy that are already cryptographically mature are moving forward with PQC projects, leaving other sectors even further behind.
See also: Ocelot: Amazon Web Services' (AWS) quantum computing chip

Financial services and professional services are ahead, but manufacturing, oil and gas, mining and healthcare lag significantly behind, in some cases with PQC adoption as low as 2%, according to cybersecurity vendor Forescout. Chris Hickman, CSO at digital identity management company Keyfactor, says most organizations are waiting “either to sense the risk more immediately or for others to make the first move.”
Barriers to widespread adoption range from a lack of skilled personnel, limited time and competing priorities, and slow adoption of existing standards. Encryption supports the security of everything from healthcare records to government data and e-commerce transactions. But only 8.5% of SSH servers currently support quantum-era secure encryption.
The main barriers to widespread adoption of PQC include cost, uncertainty of standards, and organizational inertia. This latter issue is important given that preparing for the quantum threat requires an approach phase for cryptographic agility. Delays in PQC adoption not only leave organizations vulnerable to future quantum threats but also amplify vulnerabilities already targeted by attackers. Uncertainty, complexity, and difficulties in mapping cryptographic assets also slow PQC deployments.
See also: Robust security protocols for quantum computers

Analysts predict that quantum computers capable of breaking current encryption are anywhere from five to 20 years away. The PwC report should serve as a wake-up call. Organizations that address PQC as a strategic security initiative now will be able to reduce risk and build resilience; those that wait risk being exposed to both current and future threats.
