Blog

Post-quantum cybersecurity and the quantum internet: understanding both

The word “quantum” is appearing more and more frequently in technology discussions. Quantum computers, post-quantum cryptography, quantum communications, the quantum internet, quantum key distribution, and quantum sensors are now part of a vocabulary that executives and technology leaders encounter regularly. Because these technologies share certain scientific foundations, it can be tempting to group them under a single transformation and to imagine that they will arrive at roughly the same time.

The reality is far more nuanced. Several transformations are advancing simultaneously, addressing different problems and reaching very different levels of maturity. Some remain largely experimental, while others already justify preparatory work within organizations. This distinction is particularly important when comparing the quantum internet with post-quantum cybersecurity.

The quantum internet aims to create new capabilities allowing distant quantum systems to interact and share certain resources specific to quantum physics. Post-quantum cybersecurity addresses a different problem: preparing today’s digital infrastructures to withstand certain capabilities that sufficiently powerful quantum computers might eventually possess.

For an organization, this difference is fundamental. It makes it possible to distinguish what needs to be understood and monitored for tomorrow from what may need to be prepared today.

To understand this distinction, we first have to come back to the quantum computer itself. A classical computer processes information using bits, whereas a quantum computer exploits quantum systems, notably qubits, in order to perform certain calculations according to different physical principles. Its value does not lie in the idea that it would automatically become faster for every computing task. The advantages being sought concern instead certain categories of problems for which the properties of quantum computing might eventually deliver particular capabilities.

That is precisely what interests the field of cybersecurity. Some cryptographic algorithms widely used today could become vulnerable to sufficiently powerful quantum computers. This prospect explains the development of post-quantum cryptography, whose objective is to provide cryptographic mechanisms designed to resist the categories of attacks that future quantum computers might enable.

One essential point deserves to be underlined: you do not need a quantum computer in order to use post-quantum cryptography. These new mechanisms are specifically intended to be integrated into classical IT infrastructures. Applications, servers, certificates, VPNs, APIs, network equipment, embedded systems, communications, and digital identities already use cryptography. The post-quantum transition therefore directly concerns the technology environment organizations operate today.

The quantum internet pursues a different objective. A quantum network seeks in particular to enable the distribution of quantum resources, including entanglement, between distant systems. In the longer term, these capabilities could contribute to the development of certain forms of distributed quantum computing, sensor networks, specialized communications, or other applications that directly exploit quantum properties. Current research on quantum memories, repeaters, and communications is gradually seeking to overcome the physical difficulties associated with distance and with the fragility of quantum states.

We therefore have two different trajectories. On one side, new quantum infrastructures are being developed in order to make possible capabilities that do not yet exist at scale. On the other, organizations must prepare classical infrastructures already in operation for an evolution of the cryptographic mechanisms that protect them. Confusing the two could lead to a misreading of priorities.

A company may thus have no operational need for a quantum network for many years and nevertheless have every interest in beginning now to understand its cryptographic exposure. The two relevant questions are different. The first is determining when certain quantum capabilities might become useful to the organization’s activities. The second asks how long it will take to inventory, prioritize, and evolve the cryptographic mechanisms already embedded in its systems. In a large organization with thousands of applications, devices, and technology dependencies, this second undertaking can represent a multi-year program.

The confidentiality lifespan of information adds another dimension to the problem. An attacker can theoretically intercept encrypted data today, store it, and wait for the emergence of capabilities that might eventually allow them to exploit a weakness in the cryptographic mechanism used. This strategy, generally referred to as Harvest Now, Decrypt Later, forces us to think about risk in terms of how long a piece of information must remain confidential.

Information whose value disappears after a few days obviously does not have the same profile as a trade secret, intellectual property, certain government or defense information, medical data, or other information that must remain confidential for many years. In these situations, the relevant timeline does not necessarily begin on the day a quantum computer capable of compromising certain mechanisms becomes available. It can begin far earlier, at the moment when sensitive information could be intercepted and stored.

For many organizations, however, the first difficulty of the post-quantum transition will be far more pragmatic: knowing where the cryptography is. Cryptographic mechanisms are embedded deep within certificates, applications, APIs, databases, mobile devices, network equipment, backups, cloud environments, industrial systems, vendor software, and products deployed at customer sites. Some technologies may have been in operation for many years, and their documentation does not always make it possible to identify quickly the mechanisms they depend on.

The cryptographic inventory then becomes a strategic capability. It makes it possible to determine which mechanisms are used, where they are located, which data they protect, which applications depend on them, and who actually has the ability to change them. That last question is particularly important because an organization does not necessarily control all the cryptography it depends on.

Some of these mechanisms may be embedded in commercial software, SaaS services, physical equipment, or cloud providers’ infrastructures. Post-quantum preparation then also becomes a technology supply chain issue. You have to understand which suppliers have a transition strategy, which products can be upgraded, which systems will eventually have to be replaced, and which dependencies could slow the migration. A cryptographic decision can thus become simultaneously an architecture, governance, procurement, and digital sovereignty decision.

This is why crypto-agility represents a far more durable capability than simply knowing which algorithm to adopt next. Standards will continue to evolve after the post-quantum transition. New vulnerabilities will be discovered, some methods will be improved, and others will eventually be replaced. A crypto-agile organization therefore seeks to know the mechanisms it uses, understand their dependencies, quickly measure its exposure when a problem arises, and progressively replace the components concerned without having to rebuild its entire infrastructure.

Post-quantum preparation thus becomes an opportunity to solve a deeper problem: the difficulty many organizations have in evolving technology mechanisms that have become invisible because they have worked for so long. A living inventory, a map of dependencies, and architectures designed to allow the progressive replacement of certain components deliver value that will outlast the first generation of post-quantum standards.

Another distinction is necessary when we talk about quantum cryptography. While certain quantum infrastructures may eventually make it possible to develop new communication or cryptographic distribution mechanisms, that does not make post-quantum cryptography unnecessary. Classical digital infrastructures will continue to represent an immense share of the global computing environment. Billions of devices, applications, servers, and systems will have to continue communicating without necessarily having a specialized quantum infrastructure.

Post-quantum mechanisms can be progressively integrated into these classical environments, whereas certain forms of quantum communication require physical infrastructures and specialized equipment. The costs, use cases, and deployment conditions are therefore different. In some particularly sensitive environments, several approaches could eventually coexist. The relevant choice will then depend on the architecture, the level of risk, the maturity of the technologies, and the organization’s real needs.

This distinction is a reminder of an important principle: the word “quantum” should never replace risk analysis. Growing interest in these technologies will inevitably lead to the appearance of new commercial solutions whose maturity, relevance, and value will vary considerably. An organization must be able to understand which technology is actually being used, what problem it solves, which standards it complies with, what evidence supports its performance, what dependencies it introduces, and how it will be able to evolve.

This capacity for discernment itself becomes a component of Hypersecurity. An organization does not need to adopt every emerging technology in order to be well prepared. It must be able to understand its environment, its risks, and new technological possibilities well enough to recognize the moment when an evolution becomes relevant. In the post-quantum field, that means in particular connecting cryptography to information assets, suppliers, architectures, sovereignty, and the real sensitivity lifespan of data.

Governance is ultimately the starting point that makes it possible to turn a complex scientific subject into a concrete organizational program. Executives do not need to become quantum physicists or cryptographers. They must, however, be able to determine who is accountable for post-quantum risk, whether the organization has sufficient visibility into its cryptographic mechanisms, which information requires long-term confidentiality, which suppliers are critical, and whether current architectures will allow the technologies concerned to be replaced progressively.

These questions can be asked today without speculating on the arrival date of a cryptographically relevant quantum computer. They make it possible to move from an abstract discussion about the future of quantum technology to a structured approach to risk management, architecture, and technological preparation.

The quantum internet and post-quantum cybersecurity belong to the same scientific universe, but they represent neither the same technology, nor the same problem, nor the same timeline for organizations. The first seeks to create new capabilities allowing quantum systems to interact. The second aims to evolve the mechanisms that protect classical digital infrastructures against certain future capabilities of quantum computing.

This distinction makes it possible to avoid two opposite mistakes: investing prematurely in technologies the organization does not yet need, and waiting too long before undertaking transformations that could take several years. Technology monitoring remains appropriate for several emerging quantum applications, while cryptographic inventory, dependency analysis, assessment of how long data remains sensitive, and the development of crypto-agility can already be part of a structured risk management approach.

At Quantum Beyond, our experts work alongside IT, cybersecurity, and governance teams to turn this preparation into a realistic trajectory. Post-quantum readiness assessment, Crypto Asset Discovery, Crypto Dependency Mapping, Harvest Now, Decrypt Later exposure analysis, crypto-agility assessment, and migration prioritization make it possible to progressively establish what must be understood, monitored, prepared, or transformed. Internal teams remain essential to this work since they hold the knowledge of their systems, their data, and their constraints; our expertise complements that knowledge with a specialized, cross-cutting view of the transition.

This approach also matches the logic of Hypersecurity: preparing the organization to continue protecting its systems while the technologies, the risks, and the protection mechanisms themselves evolve. The relevant question is therefore not simply when “quantum” will arrive. Several quantum transformations are already advancing, each at its own pace. Maturity consists in knowing which ones to watch for tomorrow, which ones to prepare for today, and how to preserve the ability to evolve when their moment comes.