Quantum security is becoming a matter of digital sovereignty

Who can we still trust online?

Quantum computers: The end of encryption as we know it

Quantum computers still sound like a thing of the future. They conjure up images of laboratories, white coats and machines that look as though someone has crossed a chandelier with a fridge. Yet their influence has long since reached the present day. For as soon as powerful quantum computers become available, the very foundations of digital security will come under pressure. 

A classical computer operates using bits. A bit has two states: 0 or 1. A quantum computer, on the other hand, works with qubits. These can represent multiple states simultaneously and, thanks to quantum mechanical effects, massively speed up certain tasks. This does not automatically make quantum computers better general-purpose machines. However, when it comes to specific mathematical problems, they could significantly outperform classical supercomputers. This is precisely where the problem for cryptography begins. 

Key facts at a glance

  • Quantum computers pose a particular threat to digital chains of trust – such as certificates, digital signatures and secure connections.
  • The risk is already present today: encrypted data can be stored and decrypted at a later date.
  • Post-quantum readiness is not simply a matter of updating systems; it affects systems, processes, suppliers and data holdings.
  • Organisations should establish transparency now and identify their cryptography, security requirements and dependencies.
  • Those who act early can migrate in a controlled manner, rather than simply reacting to new risks later on.

The real danger lies in our chains of trust

Many of today’s encryption methods are based on mathematical problems that classical computers are practically unable to solve. These include, for example, the factorisation of large numbers into prime factors or the calculation of discrete logarithms. Methods such as RSA, Diffie–Hellman and elliptic curves are based on this assumption. 

A sufficiently powerful quantum computer could attack these schemes using Shor’s algorithm. This would put not just individual passwords at risk, but the entire mechanism of digital trust relationships: certificates, digital signatures, key exchange, software updates, machine identities, VPN connections, email security, administrative procedures and critical infrastructure. 

Symmetric ciphers such as AES-256 do not automatically lose their protective effect due to quantum computers. Above all, it is the security margin that changes. The greater danger lies with asymmetric methods. It is precisely these methods that currently secure identities, certificates, signatures and digital relationships between systems. In other words: quantum computers pose less of a threat to individual encrypted files than to the trust upon which digital processes are built. 

‘Harvest now, decrypt later’ is the underestimated risk

The threat does not begin only on the day a quantum computer actually cracks RSA or elliptic curve cryptography. Attackers can already intercept, store and later decrypt sensitive data today. This principle is described as ‘harvest now, decrypt later’. 

This is particularly critical for data with a long retention period: health data, tax data, administrative records, research data, defence information, contractual documents, trade secrets or identity data. What appears to be adequately protected today may become readable tomorrow. 

As the Federal Office for Information Security (BSI) warns, organisations must therefore assess at an early stage which cryptographic methods they use and which data must remain protected in the long term. The Fraunhofer Institute also does not view this challenge as a purely technological issue, but rather as a structural task for IT architectures, processes and organisations. 

Post-quantum readiness begins with an uncomfortable stock-take

Post-quantum cryptography is often discussed as if it were a future software update. This is precisely where the dangerous oversimplification lies. The transition to quantum-secure methods affects established system landscapes, legacy business processes, certificate chains, interfaces, suppliers, hardware, embedded systems, cloud services and regulatory requirements. 

Post-quantum readiness begins with uncomfortable questions: 

  • Where do we use cryptography? 

  • Which data must remain confidential for ten, twenty or thirty years? 

  • Which systems can actually be updated? 

  • Which suppliers must support the new methods? 

  • Which business processes rely on old certificates? 

  • Which machine identities, interfaces and signature processes are documented?  

  • What risks arise if individual parts of the chain do not comply? 

This makes post-quantum cryptography a management task. It belongs on the roadmap of CIOs, CISOs, senior management and operators of critical infrastructure. Anyone who waits until standards have been implemented across the board will be too late in many system landscapes. 

Security requires a data strategy

This presents organisations with a twofold challenge. They must understand their own cryptographic infrastructure, and they must know which data requires what level of protection. Without proper data classification, any cryptographic strategy remains incomplete. 

Shaping digitalisation responsibly means considering technical modernisation, data strategy, governance and security architecture as an integrated whole. Particularly in the public sector, in regulated industries and amongst KRITIS operators, it is not enough simply to replace individual processes. What is crucial is having as comprehensive an overview as possible of data flows, protection classes, business processes, interdependencies and responsibilities. 

Europe’s opportunity: trust architectures rather than a race for scale

Europe does not necessarily have to win the race for the largest quantum hardware to become more digitally sovereign. The greater opportunity lies in building quantum-secure trust architectures: for public administration, KRITIS, industry, healthcare, mobility, energy supply and digital infrastructures. 

Those who redefine security shape sovereignty. This is particularly true for Europe. After all, digital sovereignty does not arise solely from proprietary platforms or European cloud services. It arises from manageable dependencies, robust standards, transparent security architectures and the ability to further develop critical systems in a timely manner. 

Post-quantum cryptography can therefore become a competitive advantage for Europe. This requires that policymakers, public administration and industry do not treat it as a niche topic for cryptography experts. It belongs in strategic programmes for resilience, the digitalisation of public administration, the protection of KRITIS systems and industrial competitiveness. 

Conclusion: Take stock now, then migrate

Quantum computers will not destroy digital security overnight. However, every organisation should know which cryptographic methods it uses, which data must remain protected in the long term, and which systems need to be prepared for migration. 

Start with a cryptographic and data inventory. Prioritise data requiring special protection and critical chains of trust. Review suppliers, certificates, interfaces and specialist procedures. Use this to develop a roadmap for post-quantum readiness. 

After all, those who establish transparency today will be able to migrate in a controlled manner tomorrow. Those who wait until quantum computers become practically relevant will be left merely reacting. And in IT security, reaction is rarely the best solution. 

Please feel free to get in touch with us.

We help you to turn questions about the future into concrete areas for action.

Robert Stricker
Abteilungsleiter Security Consulting