Enterprise security leaders are split on how urgently to prepare for post-quantum cryptography (PQC) as quantum computing remains an uncertain but potentially disruptive threat to widely used public-key algorithms such as RSA. Some CIOs and CISOs characterize quantum as a low near-term priority due to unclear timelines, while others argue preparation is unavoidable and should begin now as a business risk decision rather than a purely technical one.
In healthcare specifically, a PwC survey of 381 global healthcare executives (May–July 2025) found organizations are cutting cybersecurity budgets under financial pressure even as threats intensify, with data protection the top spending driver but only 35% reporting data risk controls across the full data lifecycle (vs. 44% cross-industry). Healthcare leaders cited cloud-related threats, quantum computing risks, and attacks on connected products as areas of lowest preparedness; in pharma/life sciences, more than half reported they have not started quantum-resistant measures, and only 7% plan to allocate budget toward quantum readiness in 2026—highlighting a gap between acknowledged quantum risk and funded mitigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
DigiCert’s 2026 quantum-readiness report found that while most organizations recognize quantum-related cryptographic risk and many are planning or testing post-quantum adoption, fewer than 7% have deployed quantum-safe or hybrid certificates at scale. The report also said 84% believe some of their data is exposed to harvest-now-decrypt-later risk and 50% expect current encryption standards to be broken within five years.
Coinbase established an advisory board to assess quantum-computing risks to crypto systems and help guide mitigation strategy. The move reflects growing concern within the digital-asset industry that quantum threats require active planning rather than being treated as purely theoretical.
Google announced Android 17 support for the NIST-aligned ML-DSA post-quantum digital signature algorithm. It also said it plans to migrate Play Store and developer app-signing systems to quantum-resistant standards as part of its accelerated 2029 post-quantum timeline.
Google announced it is targeting 2029 for its own readiness for 'Q Day' and called on the broader industry to replace or augment RSA and elliptic-curve cryptography with post-quantum cryptography. The company framed the move as an effort to increase urgency as estimates for the resources needed to break current public-key systems continue to fall.
Researchers from INRIA Rennes presented a EUROCRYPT 2026 paper describing a new quantum algorithm for the elliptic curve discrete logarithm problem that significantly reduces logical-qubit requirements versus prior work. The paper estimated breaking P-256 would require 1,193 logical qubits instead of 2,124, reinforcing urgency around post-quantum migration and harvest-now-decrypt-later exposure.
PwC reported that global healthcare organizations are reducing cybersecurity budgets under financial pressure while facing intensifying threats. The survey found weak preparedness for cloud threats, quantum risks, and connected-product attacks, with healthcare lagging in end-to-end data risk controls.
Government, finance, and defense organizations are described as early adopters starting post-quantum planning, including asset discovery, threat modeling, prioritization of long-lived sensitive data, and efforts to build crypto agility. Experts warn that migrations can take 5–10 years, making delay risky even before cryptographically relevant quantum computers arrive.
NIST issued post-quantum cryptography guidance and timelines that began pressuring organizations, especially government entities, to plan migrations away from vulnerable public-key algorithms. The references cite this as a key forcing function for enterprise quantum-readiness efforts.
In 2025, some commercial VPN providers, including NordVPN, ExpressVPN, and Mullvad, began deploying post-quantum encryption for VPN traffic. The rollout remained limited, with support largely confined to WireGuard or Lightway while many providers and OpenVPN users still lacked protection against harvest-now-decrypt-later risks.
NIST finalized its first three post-quantum cryptography standards in August 2024, marking a major standardization milestone for migration efforts. In March 2025, it selected HQC as a backup standard, further expanding the approved post-quantum toolkit.
Ethereum is described as having started preparing for post-quantum cryptography in 2018, with foundation-led work including dedicated teams, devnets, and hard-fork roadmap milestones. The effort is contrasted with Bitcoin's lack of a coherent, broadly supported migration roadmap.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
enterprisetimes.co.uk
Open sourcescworld.com
Open sourcewords.filippo.io
Open sourceruby-doc.org
Open sourcesdxcentral.com
Open sourcebankinfosecurity.com
Open sourcewebflow.sysdig.com
Open sourcenvlpubs.nist.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.