Europol and US Watchdog Urge Organisations to Prepare for the Quantum Threat to Encryption
Europol and the US Government Accountability Office (GAO) have each published reports this week calling on organisations to accelerate their move to post-quantum cryptography (PQC). The concern is the arrival of cryptographically relevant quantum computers, sometimes called "Q-day", which could crack the encryption that most government and corporate cybersecurity depends on. Experts disagree on when that will happen, but Google predicted in March that it could be as soon as 2029.
The GAO said it has made 89 recommendations to 23 agencies, including building inventories of vulnerable cryptography and identifying funding for the transition. It found that none of the 24 agencies named in its report have fully addressed all three core areas it identified. It attributed this partly to a lack of cryptography expertise, a lack of processes for inventories and funding, and a lack of plans to guide PQC testing.
Europol published two reports on 7 October. The first looks at how encrypted communications and stored files could be exposed to "harvest now, decrypt later" attacks, where data is collected today and unlocked once quantum computers are capable. Europol said an organisation's exposure depends on the protocols, configurations and key management practices it uses. The second report examines the quantum risk to cryptocurrency wallets, concluding that cryptocurrencies will not collapse because of quantum computing but need proactive defence and a phased move to quantum-resistant cryptography.