03.09.2026 - 13:00

Quantum-safe now: Why critical infrastructure cannot afford to wait

Quantum security is no longer a challenge for the distant future. Anna Beata Kalisz Hedegaard, CEO of Quantum Security Defense, explains why governments, defence organisations and critical infrastructure operators need to act now — and how quantum-safe architectures, post-quantum cryptography and a clear migration strategy can strengthen resilience and technological sovereignty.

Quantum security is often discussed as a future challenge, but many organisations are already making decisions today that will affect their long-term security. Where do you currently see the greatest urgency for governments, defence organisations and critical infrastructure operators?

Anna: If you are defending government intelligence, defense telemetry, health records, or critical infrastructure blueprints that must remain secret for 10, 20, or 50 years, your systems are already compromised if they rely on legacy public-key encryption.

Adversaries are actively executing Harvest Now, Decrypt Later (HNDL) campaigns today, hoovering up encrypted traffic from backbone fiber, satellite feeds, and cloud pipelines to decrypt retroactively once scalable quantum hardware arrives. Furthermore, embedded operational technologies (OT) in defense, energy grids, and space assets possess 15-to-20-year deployment lifecycles. If an organization commissions a satellite, a naval vessel, or a power distribution network today without crypto-agility and quantum-resistant primitives built into its firmware, that asset will be vulnerable in the field for most of its operational life.

QSECDEF works at the intersection of quantum technologies, cybersecurity and defence. What are the most common misconceptions you encounter when organisations start thinking about quantum security?

Anna: Because I primarily speak with top-tier defense strategists and cryptographic experts, the misconception is rarely about the physics or the reality of Harvest Now, Decrypt Later campaigns. The awareness is absolutely there. The new 2026 DigiCert Quantum Readiness Outlook (July 23, 2026 ) presented that 87% of organizations report they are planning, testing, or implementing post-quantum cryptography (PQC) initiatives. But only 7% report that more than half of their digital certificates currently use quantum-safe or hybrid cryptography. The survey identified that the top barrier to deployment is legacy system complexity, cited by 26% of respondents, then comes performance impact and budget constraints (each 19%). Interestingly skills gaps were right after where 10% surveyed mentioned it as an issue. Upskilling is exactly what we offer at QSECDEF and we do observe increase in interest of our services for whole organizations.

The most dangerous misconception today is strategic, and it happens at the budget allocation level. Right now, boards and defense ministries are heavily skewing their budgets toward Artificial Intelligence as an immediate competitive imperative, while treating quantum as a "tomorrow" problem that can wait. But, the  imminent convergence of quantum computing and generative AI fundamentally destabilizes our current cyber-defense paradigms.

Pouring billions into AI while neglecting cryptographic bedrock is building a fortress on sand. A powerful quantum computer will inevitably break the standard public-key encryption systems currently used to protect secure web traffic, digital signatures, and critical data flows. Concurrently, generative AI drastically alters the economic model of cyber-offensives. Frontier AI models now possess the coding capabilities to autonomously discover and exploit software vulnerabilities at a scale and speed that surpasses skilled human experts. We are already seeing this, Anthropic's Claude Mythos Preview model has identified thousands of zero-day vulnerabilities across major operating systems and web browsers.

By lowering the cost of attack generation and automating sophisticated vulnerability discovery, AI renders traditional human-centric governance and behavioral defenses increasingly inadequate. The sheer volume of these attacks by diverse and distributed actors guarantees that system breaches will become a statistical inevitability governed by the law of large numbers. 

Some attacks will be successful, that means our cryptography needs to make sure that data is useless for attackers to exploit and that architecture of networks can minimize impact. This is all recommended now by national security agencies around the world, and PQC migration despite lacking WOW effect that AI has cannot be postponed anymore.

Post-quantum cryptography and quantum key distribution are often mentioned in the same conversation, but they solve different problems. How should decision-makers understand the relationship between PQC, QKD and broader quantum-safe architectures?

Anna: The most dangerous mistake a decision-maker can make is treating PQC and QKD as competing solutions in a zero-sum budget war. They are not rivals; they are fundamentally different, highly complementary layers of a defense-in-depth strategy. 

You deploy PQC to secure scalable, everyday data-in-transit across your broader network and distributed endpoints. Because it is mathematical and software-driven, it provides the agility needed for widespread enterprise deployment.

However, for critical operations like defense intelligence pipelines, central bank transfers, and sovereign satellite links you anchor your security with QKD. QKD relies on the unbreakable laws of physics rather than computational complexity, guaranteeing that any attempt to intercept the encryption key is instantly detectable.

This hybrid necessity is exactly why major telecommunications providers are now preparing to offer QKD links as a premium, commercially available service to secure critical infrastructure. Nokia’s defense-in-depth quantum-safe architecture is a prime example of this model in action, layering algorithmic PQC for broad network scalability with physics-based QKD for point-to-point backbone security. You do not choose between math and physics; you stack them.

In defence and security, technological sovereignty is becoming increasingly important. What role can quantum technologies play in strengthening resilience, secure communications and strategic autonomy in Europe?

Anna: Strategic autonomy means operational survival. Europe should strive for the freedom to act independently without being blinded, jammed, or intercepted, and without waiting on or relying on technology, components, or expertise from foreign territories that could be cut off overnight by political upheaval, export restrictions, or disaster emergencies. Quantum technologies deliver that autonomy by providing significant enhancement of existing capabilities or capabilities classical systems cannot replicate.

Operationally, this starts with unjammable navigation. Quantum Positioning, Navigation, and Timing (PNT) decouples defense platforms and autonomous systems from realying only on vulnerable satellite constellations, guaranteeing precision navigation in electronically contested environments. In communications, initiatives like EuroQCI and the IRIS² constellation provide physics-backed secure command and control, ensuring military and diplomatic telemetry cannot be covertly intercepted or spoofed. Furthermore, quantum gravimetry and magnetometry deliver an asymmetric advantage, allowing us to detect deep-sea submarines or subterranean assets without active emissions.

Equally critical is economic resilience. Sovereign post-quantum cryptography protects our energy grids, telecommunications, and financial rails from systemic collapse. At the same time, investing in domestic quantum computing ensures Europe does not outsource future breakthroughs in advanced materials, semiconductors, and bio-defense to foreign hyperscalers. If we don't own and adopt technology fast domestically, strategic autonomy remains an illusion.

Quantum technologies are not only relevant for defence organisations, but also for operators of critical infrastructure and highly regulated industries. Which sectors should be preparing now — and what risks do they face if they wait too long?

Anna: For critical infrastructure, the risk of waiting is not a standard data breach; it is physical disruption. While we have already mentioned "Harvest Now, Decrypt Later," an even more destructive threat emerges once quantum computers become available: "Trust Now, Forge Later." When quantum computers break public-key cryptography, they don't just expose secrets they break digital signatures, leading to a total collapse of authentication and integrity.

If energy and industrial operators run legacy control systems that cannot support quantum-safe signatures, an adversary can remotely forge authentication commands to trip breakers, alter chemical levels, or physically shut down power grids without detection. In finance, if the cryptographic signatures validating interbank settlements and clearing houses fail, the trust underpinning the entire transaction ledger evaporates, threatening immediate systemic market stability. Ultimately, every layer of digital identity industrial, hardware, software, and human is on the line.

An attack on foundational cryptography is not an incident you recover from over a weekend; it can take an organization out of operation for months rather than days. For a commercial enterprise, that duration of operational paralysis could lead in extreme situations directly to bankruptcy. For critical infrastructure if power, banking rails, or hospitals are knocked offline it can cascade into city-level or nationwide crises.

It is a mistake to assume you can solve this with an emergency budget once the threat arrives. Waiting simply guarantees that an organization will be forced into a chaotic, exponentially more expensive emergency hardware replacement under active cryptanalytic attack, rather than executing a controlled, budgeted engineering migration today. 

Also, when the threat matures, every utility, bank, and telecom provider on the planet will be chasing the exact same certified hardware, secure chips, and scarce cryptographic engineers leaving latecomers trapped in an impossible supply-chain bottleneck while their operational systems remain actively exposed.

Many organisations know that quantum technologies will affect cybersecurity, but struggle to define a practical roadmap. What would a realistic first step towards quantum readiness look like?

Anna: The most effective first step is adopting a proven standard like the ETSI framework for PQC migration (ETSI TR 103 619). However, before touching the infrastructure, the immediate priority must be organizational and educational.

Organizations must start by designating a cross-departmental operations team directed by a dedicated Migration Lead. This team carries a dual mandate: upward executive alignment and horizontal technical enablement. Boards and management need continuous strategic intelligence to justify capital allocation which is why at Quantum Security Defense (QSECDEF), we deliver tailored executive briefings and trend updates to C-suites and defense leadership to bridge that gap.

Simultaneously, you must upskill technical engineering and operational teams to execute the strategy and build internal crypto-agility. To solve this, our training platform at qsecdef.com equips both business decision-makers and technical specialists with practical insights and roadmaps. In fact, the concluding session of our summer QSECDEF Business Bootcamp was an end-to-end operational walkthrough of the entire ETSI migration standard, which is now available on-demand with official certification on the platform. Until this governance and human capital foundation is established, any technical migration will stall.

Your session at Quantum Effects 2026 will focus on defending critical infrastructure from cyber attacks. Which developments or risks do you believe decision-makers in industry, defence and critical infrastructure should understand most urgently?

Anna: At Quantum Effects 2026, my core message is that we are dealing with the "system of systems" vulnerability. Our energy grids, telecommunications networks, financial rails, and defense logistics are completely interdependent. A cryptographic failure in a tier-three telecom vendor does not stay contained; it cascades directly into military supply chains and civilian power grids.

Take the commercial banking sector as a prime example. A modern bank does not operate in isolation; its digital supply chain is incredibly complex, relying on hundreds of third-party APIs, cloud computing environments, and specialized fintech vendors. If a single, widely used software vendor or payment gateway fails to migrate to quantum-safe cryptography, that single point of failure cascades instantly. It can compromise the transaction integrity and settlement rails of multiple tier-one banks simultaneously. A cryptographic failure in a tier-three vendor does not stay contained it ripples through the entire economy.

Because of this intense interconnectivity, implementing Post-Quantum Cryptography cannot be treated as a localized IT project. It must be integrated into a Quantum-Safe Zero Trust architecture. We have to assume the perimeter is already breached and design networks that continuously authenticate every single device, vendor connection, and data flow using quantum-resistant primitives, removing any implicit trust from the system.

Furthermore, decision-makers must urgently understand the shifting legal and regulatory reality. In Europe, with frameworks like NIS2, DORA, and the Cyber Resilience Act now actively enforced, ignoring systemic cryptographic vulnerabilities in your supply chain is no longer just a technical oversight it is a direct legal liability. Board members and executives can now be held personally accountable for failing to mitigate known, foreseeable cyber risks. 

The quantum threat is no longer theoretical; it is quantifiable, it is here, and the regulatory grace period for preparing our critical infrastructure has officially expired. Our mission at QSECDEF is to bring that message to every room that needs to hear it.

zurück zur Übersicht