I'm sitting across from a major general, and the conversation keeps circling one point: with quantum supercomputing, the timeline is no longer the interesting question. The exposure is. He isn't asking me when a cryptographically relevant quantum computer arrives. He's asking what is already lost the day it does — and whether the networks under his responsibility were built on an assumption that has quietly expired.
That is the right question, and most operators are still asking the wrong one. Quantum supercomputing does not simply make computers faster. It changes the mathematics beneath the encryption that protects banking, defense communications, power grids, and health records. The security we treat as permanent is, in fact, dated — and the people who understand that first will set the terms for everyone who understands it late.
Why Quantum Breaks Today's Encryption
Almost every secure channel in production today rests on two families of hard math: RSA, which leans on the difficulty of factoring very large numbers, and elliptic-curve cryptography, which leans on the discrete-logarithm problem. Classical computers cannot solve either in any useful timeframe — factoring a 2048-bit RSA key would take conventional machines far longer than the age of the universe. That gap is the entire reason the modern internet, and modern command-and-control, can be trusted.
A sufficiently capable quantum computer running Shor's algorithm collapses that gap. Shor's algorithm turns factoring and discrete logarithms from effectively impossible into merely expensive — reducing the problem from exponential to polynomial time. The moment a machine with enough stable, error-corrected qubits exists, the padlock on RSA and elliptic-curve keys is not picked; it is dissolved. Symmetric encryption like AES-256 fares better and is weakened rather than broken, but the public-key handshakes that establish those symmetric keys in the first place are the exposed joint.
This is why the U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards in 2024, and why the NSA's CNSA 2.0 suite now sets timelines for national-security systems to migrate. These are not speculative exercises. Standards bodies do not move on this scale for problems they consider hypothetical.
Harvest Now, Decrypt Later: The Threat Already in Motion
What the general and I keep returning to is the phrase that should keep every operator honest: harvest now, decrypt later. An adversary does not need a working quantum computer today to do damage today. They only need to capture encrypted traffic now and store it until the decryption capability arrives.
That reframes the risk entirely. The clock is not counting down to a future breach — it is already running on data that has left the building. Every intercepted diplomatic cable, every exfiltrated dataset with a ten-year secrecy requirement, every set of long-lived credentials moving across a network is a liability accruing interest against a deadline no one on the defending side controls. If the information you are protecting must stay secret for a decade, and a cryptographically relevant quantum computer is plausibly within that decade, then for practical purposes that information is already at risk.
What Happens If This Power Lands in the Wrong Hands
Picture the capability held by an adversary rather than an ally. It does not look like the breaches we are trained to recognize. There is no ransom note, no defaced site, no single dramatic intrusion. It is silent, retroactive, and total: a decade of communications that everyone believed were secure, opened at once.
The consequences compound across every domain that trust touches. Command-and-control traffic becomes readable, which means intent and movement become predictable. Financial rails become forgeable, because the signatures that authorize transfers can be reproduced. Most corrosive of all, critical-infrastructure authentication fails — the cryptographic handshake that says this controller, this substation, this device is who it claims to be can no longer be believed. At that point the damage is not the theft of any one secret. It is the loss of confidence in the channel itself, and confidence is the thing that cannot be patched overnight.
This is the part the general understands instinctively and most boardrooms do not: the strategic value of breaking encryption is not reading one message. It is the ability to quietly invalidate an opponent's entire assumption of privacy, all at once, at a moment of the attacker's choosing.
Network Protection in a Post-Quantum World
Network protection has always been layered, and quantum does not change that principle — it changes which layers you can trust for how long. The immediate exposure is in key establishment and digital signatures, so that is where the work concentrates: the TLS handshakes, VPN tunnels, code-signing chains, and device-identity certificates that silently authenticate everything else.
The near-term answer is hybrid cryptography — running a classical algorithm and a post-quantum algorithm together so a channel stays secure as long as either holds. This is already shipping in major browsers and network stacks, and it buys the most valuable thing in a transition: time without a cliff. Alongside it, network segmentation and shortening the lifetime of secrets reduce how much any single future decryption event can unlock. A key that rotates weekly is a far smaller prize than one that guards a decade of traffic.
The Operator's Migration Path
The protection is not mysterious, and it exists now. The first move is an inventory: know what you encrypt, which algorithms you depend on, and — the question almost no one can answer on the spot — how long each category of data must remain secret. That secrecy horizon, measured against the plausible arrival of quantum capability, is what tells you which systems migrate first.
The second move is migration to NIST's post-quantum standards on a real schedule, sequenced by that inventory: longest-lived secrets and highest-value channels first. The third, and the one that separates the organizations that do this once from the ones that do it forever, is crypto-agility — building systems so that swapping a cryptographic algorithm is a configuration change, not a multi-year replatforming project. The next transition will come; agility is how you make it routine.
None of this requires exotic hardware or a research team. It requires treating cryptography as an asset with an expiration date rather than a permanent fixture — which is exactly the shift most operators have not yet made.
What I Tell Leaders Now
The operators treating this as a 2030 problem are the ones who will be breached with today's data — quietly, and retroactively, on a timeline they never got to see. The ones who move now decide the terms: what gets protected first, how much exposure they are willing to carry, and how fast they can adapt when the standards shift again.
That is what the conversation with the general keeps proving to me. This is not a story about a future machine. It is a story about the decisions being made — or not made — this quarter, on networks that are carrying tomorrow's secrets today. The math is already changing. The only variable left is who prepares before it finishes.