The threat does not always arrive with a ransom note or a locked screen.

Sometimes, an attacker simply takes your encrypted data and stores it.

They cannot necessarily read it today. But if quantum computing eventually becomes capable of breaking some of the encryption protecting that data, information stolen now could potentially be decrypted in the future.

This is known as “harvest now, decrypt later” (HNDL), and it is becoming an increasingly important consideration for organisations thinking about their long-term cybersecurity.

For businesses in Oxfordshire and the wider Thames Valley, it is also a conversation worth having locally, given the region’s strong connection to quantum research and technology.

The short version, without the jargon

Modern encryption protects huge amounts of information, from emails and customer records to intellectual property and confidential business communications.

Some of the mathematical problems behind today’s widely used public-key cryptography could potentially be solved much more efficiently by sufficiently capable quantum computers.

That capability does not exist at scale today.

But HNDL does not require attackers to decrypt information immediately.

The idea is simple: steal encrypted data today and wait for the technology to catch up.

For information that needs to remain confidential for many years, that creates a very different risk calculation.

Think intellectual property, sensitive contracts, personal information, research data or commercially valuable communications.

Why businesses should start thinking about it now

Quantum-safe migration is not something most organisations can complete overnight.

Businesses first need to understand where encryption is being used, which systems depend on vulnerable algorithms, what their suppliers are doing and which information has the longest confidentiality requirements.

For SMEs, this creates an opportunity.

Starting early means there is time to understand the problem, prioritise critical systems and work with technology providers rather than being forced into rushed changes later.

The goal is not to panic about quantum computers.

The goal is to avoid being unprepared for them.

Oxfordshire has a particular reason to pay attention

This conversation is especially relevant in Oxfordshire.

Oxford has a significant research and innovation ecosystem around quantum technologies, meaning the subject is not simply something happening in distant laboratories.

For businesses in the region, that creates an opportunity to engage with local expertise and understand how quantum developments could affect cybersecurity, technology and data protection.

It also reinforces an important point: organisations do not need to wait until quantum computing becomes mainstream before considering its implications.

What should a business do now?

You do not need a quantum physics degree to take the first steps.

1. Map your encryption

Find out where encryption is being used across your organisation.

Look at applications, cloud services, VPNs, certificates, databases, communications and other systems handling sensitive information.

You cannot protect what you cannot identify.

2. Identify your long-term sensitive data

Not every piece of information has the same value.

Ask:

“If someone obtained this data today, would it still be sensitive in 10, 15 or 20 years?”

If the answer is yes, it deserves greater attention.

3. Ask your suppliers about their plans

Your cybersecurity strategy depends partly on the technology providers you use.

Ask vendors and cloud providers whether they have a roadmap for post-quantum cryptography and how they intend to support migration.

4. Start thinking about crypto-agility

One of the most practical concepts to understand is crypto-agility: the ability to replace cryptographic algorithms and protocols without having to rebuild an entire technology environment.

You may not need to replace everything today.

But you should understand how easily your systems could adapt tomorrow.

5. Put it on the technology roadmap

Quantum security should not simply sit in a risk register that gets reviewed once a year.

Start conversations between cybersecurity, IT, procurement and leadership.

The earlier the organisation understands its dependencies, the more options it has.

Not a reason to panic. A reason to plan.

This is not about suggesting that every Oxfordshire business needs to become a quantum security expert immediately.

It is about recognising that cybersecurity risks can have very long timelines.

The organisations best positioned for the transition will be those that understand their data, know where their cryptography sits and have started conversations with their technology providers before migration becomes urgent.

And for a cybersecurity community based in the Thames Valley, this is exactly the kind of conversation worth having early.

Quantum computing may still be developing. Your data is already here.

If you are a security leader, technology professional, business owner or simply interested in where cybersecurity is heading, connect with the OxCyber community and be part of the conversation.