CFOtech Ireland - Technology news for CFOs & financial decision-makers
Ireland
Beyond Q-Day: Why Crypto-Agility Will Decide Who's Ready

Beyond Q-Day: Why Crypto-Agility Will Decide Who's Ready

Thu, 8th Oct 2026 (Today)
Daniel Kwong
DANIEL KWONG Field CISO, North Asia Fortinet

Quantum computers are poised to fundamentally reshape the cybersecurity landscape. One day soon, they will possess the computational power required to break the classical public-key Infrastructure (PKI) that underpins modern digital infrastructure - protecting everything from the global financial sector to energy grids, healthcare systems, and critical public services. While the exact arrival of this watershed moment - known as "Q-Day" - remains a subject of debate, regulators worldwide agree that the threat is both imminent and severe. Governing bodies across the G7, the European Union, and China are moving swiftly to establish post-quantum frameworks. For organizations operating within Hong Kong, a premier global financial capital, the challenge is uniquely complex: institutions must navigate this shifting and stringent regulatory landscape across multiple international jurisdictions simultaneously.

The Local Reality and the Global Pace

The scale of the task ahead is underlined by recent regulatory assessments. The Hong Kong Monetary Authority's (HKMA) inaugural Quantum Preparedness Index, launched in late July 2026, places Hong Kong's financial sector at an early stage of readiness, scoring an average of 2.3 out of 10. While the HKMA views its 2030 target of 10 as ambitious, it is an essential benchmark for systemic stability. Industry data shows that for banks with transition plans already in place, the average implementation time spans approximately 5.6 years. This tight runway is further accelerated by market leaders; global technology pioneers like Google and Cloudflare have set 2029 as their internal post-quantum migration targets, underscoring how quickly serious actors are modernizing their defenses.

The Immediate Danger: Harvest Now, Decrypt Later

The true urgency of quantum readiness extends far beyond the arrival of Q-Day itself. Enterprises face a clear and present danger today through the "Harvest Now, Decrypt Later" (HNDL) tactic. Malicious actors - ranging from advanced persistent threat groups to nation-state adversaries - are actively intercepting and hoarding encrypted data flows. They are building massive stockpiles of long-lived, sensitive information, waiting for the day quantum capabilities unlock secrets that are securely locked today. Waiting for Q-Day to begin migration means your organization's most critical data has already been compromised.

Building Crypto-Agility: What to Do Now

To counter these evolving threats, organizations must transition toward crypto-agility - the capacity to rapidly adapt and upgrade cryptographic systems without disrupting underlying infrastructure or business operations. A structured approach involves six core pillars:

  • Inventory: Begin with a comprehensive Cryptographic Bill of Materials (CBOM) to map and categorize cryptographic assets, prioritizing the longest-lived and highest-value data first.
  • Infrastructure Readiness: Ensure that data-at-rest encryption is fully AES-256 capable to raise the baseline security of stored information against brute-force and classical threats.
  • HSM & PKI Management: Audit and upgrade Hardware Security Modules (HSMs) to ensure they are fully ready to support Post-Quantum Cryptography (PQC) key generation, secure storage, and hybrid certificate lifecycles alongside legacy algorithms.
  • PQC-Ready Tunnels for VPN: Implement quantum-resistant IPsec tunneling mechanisms to secure site-to-site connectivity against active interception and future decryption attempts.
  • Application Connectivity via TLS-PQC: Modernize application-layer security by deploying hybrid Transport Layer Security (TLS) implementations that incorporate NIST-standardized PQC algorithms, safeguarding web traffic and API communications.
  • Deployment: Implement lattices-based mathematics PQC using hybrid cryptography designed to withstand both classical and mathematical quantum attacks. Moreover, enterprise can leverage Quantum Key Distribution (QKD) to introduce an additional layer of protection, utilizing quantum mechanics rather than mathematical complexity alone to secure key exchanges. 

Quantum Resilience as a Data Security Architecture

At Fortinet, we view quantum resilience not as a solitary product upgrade, but as a holistic data security architecture. Securing modern networks requires protecting sensitive data across its lifecycle - whether it is stored in databases, actively processed by applications, or transmitted across distributed cloud environments. Each operational state presents unique exposure profiles that demand targeted cryptographic controls. However, upgrading encryption algorithms through PQC and QKD only secures the transmission channels and storage boundaries; it does not replace foundational security controls. Identity verification, granular access management, network segmentation, and zero-trust policies remain vital components of the overarching architecture, ensuring that protection is enforced consistently across users, data centers, and SaaS applications.

Conclusion

The scale and immediacy of the post-quantum challenge mean that quantum readiness is fundamentally a board-level resilience issue, not merely a cryptographic update task. In an era of profound technological transition, agility - not prediction - will ultimately determine an organization's success.