You’ve probably seen “quantum computing” mentioned in tech news alongside words like “unbreakable encryption” and “internet-ending threat.” Most of it is written for engineers. This article isn’t. This is the plain-English version — what’s actually going on, and what it means for you and your business.
We write about this in more technical depth over on Mono Training’s Insights. This is the short version for the rest of us.
What is Post-Quantum Cryptography?
Every time you check your bank balance, send an email, or shop online, your data is protected by encryption — mathematical locks that scramble information so only the right person can unscramble it. The most common lock, called RSA, works because there’s one thing regular computers are genuinely terrible at: taking a giant number and figuring out which two prime numbers were multiplied together to make it. Try it by hand with a huge number and you’ll be there until the heat death of the universe. That difficulty is the whole security guarantee.
Photo by Growtika on Unsplash
Quantum computers are a different kind of machine, built on genuinely different physics. They’re not “faster” computers in the way a new phone is faster than an old one — they can explore huge numbers of possibilities at once in a way normal computers structurally can’t. And it turns out that exact “unpickable” lock — factoring — is one of the very few problems a quantum computer would be spectacularly good at cracking.
Here’s the catch: nobody has built one powerful enough yet. Current machines have a few thousand of the specialised components (called qubits) needed; experts think it’ll take somewhere in the hundreds of thousands to over a million before today’s encryption is genuinely at risk. Estimates for when that happens range from the early 2030s to considerably later, and that range keeps narrowing as the underlying science improves.
Post-Quantum Cryptography (PQC) is the new generation of locks, already finalised by the US National Institute of Standards and Technology (NIST) in 2024, designed to resist both regular and quantum computers.
The good news: the new locks already exist, and the biggest tech companies have quietly started fitting them. Chrome, Cloudflare, Signal, and Apple’s iMessage are already using them behind the scenes. You don’t need to do anything to benefit from that part.
What individuals need to know
For most people, this isn’t an emergency — it’s a slow-moving weather front, not a storm that’s landed. You don’t need to change your passwords tomorrow or panic about your online banking. The tech giants running the infrastructure you use every day are already handling the heavy lifting.
There is one idea worth understanding, because it changes how “not urgent yet” should feel: harvest now, decrypt later. Some data being sent today — under today’s encryption — is already being intercepted and stored by patient adversaries, on the bet that they’ll be able to unlock it once quantum computers catch up. If it’s something with a short shelf life (a meme, a takeaway order), nobody cares. If it’s something meant to stay private for decades — medical records, legal documents, ID scans, anything genuinely sensitive — that’s the category where “later” is a real risk sitting quietly in the background right now.
The practical takeaway for individuals: keep doing the fundamentals well — strong, unique passwords, multi-factor authentication, and genuine caution about what sensitive documents you send and where you store them, since those habits protect you regardless of what’s cracking encryption or when. Beyond that, this is one to watch, not one to act on urgently today.
What businesses need to know
For a business — even a small one — “wait and see” isn’t a strategy for much longer, because the fix isn’t a software update. It’s a multi-year programme.
Three things worth knowing now:
- The standards are finalised, and the deadline is real. Australia’s cyber security agency (the ASD) has set a target of 2030 for organisations to move away from vulnerable encryption on systems holding long-term sensitive data. That sounds distant. It isn’t, once you account for how long the actual work takes.
- The first job is finding out what you’ve got. Most organisations don’t have a clear picture of everywhere encryption is quietly doing its job — websites, VPNs, internal systems, vendor software. Building that list (a “cryptographic inventory”) is consistently the step that takes longer than expected, and it’s the step nothing else can start without.
- Your vendors carry part of your risk. If a supplier can’t answer “what’s your post-quantum plan?” with something specific, that’s worth flagging now, not discovering later.
None of this needs to happen overnight, and none of it needs deep technical expertise to start — it needs someone accountable for asking the right questions and keeping the programme moving. That’s exactly the gap this kind of awareness training exists to close.
This is a condensed version of Mono’s four-part deep dive into post-quantum cryptography — the mechanics, the standards, and a full operational roadmap for organisations. Read the full series →
