The Attack Is Already Underway
The White House has accelerated its deadline for federal agencies to migrate off quantum-vulnerable cryptography. If you read that as a future-facing technology policy story, you’ve missed the point. The Ars Technica report frames this as a race against an emerging threat. It isn’t. The threat is active. The urgency in the executive order exists precisely because adversaries — state actors, primarily — have been harvesting encrypted data for years, holding it until quantum capability matures enough to break the encryption retroactively.
This is the “harvest now, decrypt later” strategy. It requires no quantum computer today. It requires only storage, patience, and the reasonable expectation that quantum capability will arrive within the decade. Nation-state actors operate on exactly these timeframes. If your organisation handles data that retains sensitivity for ten or more years — health records, legal communications, financial instruments, defence contracts, intellectual property, classified government material — the collection phase of an attack against that data has almost certainly already happened.
What the Policy Response Is Actually Telling You
Governments don’t accelerate national security deadlines without cause. The compressed timeline in the US executive order is an implicit acknowledgement that the intelligence community believes the threat window is shorter than previously communicated publicly. Read it that way.
Australia is not an observer to this problem. Australian government agencies, financial institutions, and critical infrastructure operators sit within the same threat environment. AUKUS alignment, Five Eyes intelligence sharing, and Australia’s role in regional security make Australian data — government, defence-adjacent, and commercial — a legitimate collection target. The fact that Australia lacks an equivalent executive order with hard deadlines doesn’t mean the threat is more distant here. It means the governance response is less mature.
APRA’s CPS 234 requires regulated entities to maintain information security capability commensurate with the size and nature of threats to their information assets. Post-quantum cryptographic risk is not a hypothetical future threat for institutions managing data with long-term sensitivity. It is a present-tense material risk that belongs in risk registers now, not after a domestic regulatory mandate arrives.
The Inventory Problem
Most organisations have no clear picture of where cryptography is actually deployed across their environment. Not at the asset level, not at the data classification level, and not in terms of which data sets have long-term sensitivity that makes them attractive for harvest-now-decrypt-later collection.
This matters because the migration to post-quantum cryptography isn’t a single switch. It requires knowing what algorithms are in use, where, protecting what data, in what systems, with what dependencies. Cryptographic libraries are embedded in applications, infrastructure, third-party software, cloud services, and vendor products — much of it not visible without deliberate inventory work. Some of it will require vendor action, not internal remediation. Some of it will be in systems with long replacement cycles. None of it can be addressed without first understanding the landscape.
A cryptographic inventory is the foundational prerequisite for any remediation plan. It is also the work that takes longest and is least visible to boards, which is precisely why it gets deferred.
If your organisation hasn’t started a cryptographic inventory, you are not preparing for a future threat. You are behind a current one.
What Boards on Audit and Risk Committees Should Ask
The question isn’t whether post-quantum migration is on the IT roadmap. The question is whether your organisation has assessed which data assets are already exposed to retroactive decryption risk, and what the consequence of that exposure is.
Ask your CISO or CTO three things:
First: Do we have a cryptographic inventory? Not a plan to do one — an actual inventory of what encryption algorithms protect what data across which systems.
Second: Have we identified data with long-term sensitivity — data whose value or sensitivity persists for a decade or more — and assessed whether that data has been or could be collected by a sophisticated adversary?
Third: Are we tracking NIST’s post-quantum cryptography standards and the ASD’s guidance on migration, and do we have a board-level timeline for remediation that reflects realistic system replacement cycles?
If the answers are vague, the risk is real and unmanaged.
The Vendor and Consultant Problem
The cryptographic migration market will generate considerable noise over the next two to three years. Vendors will repackage existing products with “quantum-ready” labelling. Consultants will sell readiness assessments that produce reports rather than remediation. Boards should be sceptical of both.
The genuine work here is unglamorous: inventory, classification, prioritisation, vendor engagement, and staged migration across multi-year timescales. It doesn’t fit neatly into a product sale or a short engagement. Organisations that treat this as a procurement decision rather than a structured programme will produce theatre, not protection.
The Honest Position
The acceleration of the US deadline is a signal, not an isolated policy event. It reflects intelligence assessments that are not fully public. Australian organisations in financial services, critical infrastructure, and government-adjacent sectors should treat it as such.
The data that adversaries have already collected cannot be un-collected. The only question is whether, when quantum capability arrives, that data remains protected or becomes readable. The answer depends on decisions made now — specifically, whether cryptographic migration programmes are funded, scoped, and governed as material risk responses rather than deferred IT projects.
Start the inventory. Classify your sensitive data by longevity. Set a board-level timeline. The window for getting ahead of this is narrowing, and for some data, it has already closed.