Quantum Computing Risk
Quantum computing risk is the danger that future, sufficiently powerful quantum computers could break the encryption that protects sensitive data and communications today. Because much of modern security relies on cryptographic methods once considered secure for decades, a capable quantum computer could expose or compromise that protected data. This is a security and technology concern rather than an insurance coverage term, and whether related losses are insurable depends entirely on specific policy wording.
Quantum computing risk refers to the potential for a cryptographically relevant quantum computer (CRQC) to defeat modern cryptographic algorithms, undermining the confidentiality and integrity assumptions on which current data protection depends. The primary exposure is to public-key (asymmetric) cryptography, where a CRQC could break widely deployed encryption standards; symmetric ciphers and hashing algorithms are generally considered to face a smaller reduction in effective strength rather than outright collapse. A frequently cited concern is the compromise of sensitive data, including scenarios in which currently protected information is exposed once decryption becomes feasible. Some analyses have suggested that such capabilities could emerge relatively soon, but the timeline remains uncertain and is a subject of genuine debate. This entry describes a threat to security controls (cryptography), not an insurance coverage trigger, sublimit, or resilience metric; the extent to which resulting losses, whether first-party (such as data restoration) or third-party (such as privacy liability), are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction, and insurance does not reduce the underlying likelihood of cryptographic compromise.
Why it matters
Quantum computing risk matters because a large share of the world's sensitive data is protected by public-key cryptography that was long considered secure for decades. A sufficiently powerful, cryptographically relevant quantum computer could break these algorithms, and the primary consequence would be sensitive data being lost or compromised, an impact with wide-reaching effects across industries. For organizations that hold long-lived confidential information, the concern is not only future data but data protected today, because information intercepted now could be exposed once decryption becomes feasible.
The timeline for this threat is genuinely uncertain and a subject of active debate among researchers. Some analyses have suggested that quantum computers could crack widely used security keys before the decade is over, while others regard practical, cryptographically relevant machines as further off. This uncertainty is itself part of the risk: organizations must make decisions about cryptographic migration and data-protection strategy without a settled forecast of when the capability will arrive.
It is important to keep this concern in its proper category. Quantum computing risk is a threat to a security control, cryptography, not an insurance coverage trigger, sublimit, or resilience metric. Insurance does not reduce the likelihood that cryptography is broken; it can at most transfer some financial consequences, and only to the extent specific policy wording, endorsements, exclusions, and jurisdiction allow. Whether resulting losses, whether first-party such as data restoration or third-party such as privacy liability, are covered depends entirely on the policy in question and cannot be assumed.
Who it's relevant to
Inside Quantum Computing Risk
Common questions
Answers to the questions practitioners most commonly ask about Quantum Computing Risk.
