Site navigation

NCSC Issues Quantum Security Roadmap For Businesses

Tom Quinn

,

quantum security
With quantum computing set to break traditional encryption, the NCSC is advising sensitive industries to begin transitioning to quantum-resistant security methods.

The UK’s National Cyber Security Centre (NCSC) has issued new guidance to help protect key industries against future quantum computing threats.

The newly published advice outlines a timeline for organisations to transition to quantum-resistant encryption methods over the next decade, arguing that current encryption standards will prove vulnerable to the power of quantum computers

By encouraging the adoption of post-quantum cryptography (PQC), the NCSC hopes to safeguard sensitive information in sectors such as banking and secure communications.

While today’s encryption methods rely on mathematical problems that current-generation computers struggle to solve, quantum computers have the potential to solve them much faster, making conventional encryption methods insecure.

The NCSC said that migrating to PQC will help organisations stay ahead of this threat by deploying quantum-resistant algorithms before would-be attackers have the chance to exploit weaknesses.

The guidance outlines three phases to support firms through the migration process. The first phase focuses on discovery and assessment, identifying services reliant on cryptography – such as cybersecurity, communications, and data processing – as well as exposed hardware, devices, and IoT applications.

This first phase, which the NCSC said should be completed over the next three years, ends with the creation of an initial plan for the migration of the highest-priority services.

Phase two, estimated to last from 2028 to 2031, involves switching services to platforms that offer PQC compatibility, replacing the most vulnerable components with PQC equivalents, and beginning to make minimal changes as the PQC ecosystem develops. 

The third phase is to complete migration to PQC of all systems, services and products, with 2035 as the target date for completion.

The NCSC has encouraged organisations to begin preparing for the transition now to allow for a smoother, more controlled migration that will reduce the risk of rushed implementations and related security gaps, warning that for some larger organisations, PQC will require intense planning and significant investment.

“Quantum computing is set to revolutionise technology, but it also poses significant risks to current encryption methods,” said Ollie Whitehouse, NCSC chief technical officer.

“Our new guidance on post-quantum cryptography provides a clear roadmap for organisations to safeguard their data against these future threats, helping to ensure that today’s confidential information remains secure in years to come. 

“As quantum technology advances, upgrading our collective security is not just important – it’s essential.”


Recommended reading


Last month, Europol issued its own warning to European financial services over the risks of future quantum threats, saying that quantum-safe cryptography must be prioritised as the risks posed by ‘store now, decrypt later’ (SNDL) attacks continue to grow.

According to the law enforcement agency’s Quantum Safe Financial Forum, estimates suggesting that quantum computers capable of such threats will emerge within the next ten to fifteen years, the time required to transition to more secure cryptographic methods could put financial firms at significant risk of quantum attack methods.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data