The majority of firms (70 per cent) are addressing these challenges by adopting post-quantum cryptographic (PQC) algorithms, which are seen as the most comprehensive approach to mitigating near-term risks
Rapid advances in quantum computing are pushing organisations to reassess their cybersecurity defences, with nearly two-thirds now identifying it as the most critical threat in the next three to five years, according to a new report by the Capgemini Research Institute.
Titled Future encrypted: Why post-quantum cryptography tops the new cybersecurity agenda, the report highlights growing fears around “harvest-now, decrypt-later” attacks — where data is stolen today to be decrypted once quantum computers become powerful enough. This threat, alongside tightening regulations, has prompted urgent discussions around post-quantum security preparedness.
The study found that 65 per cent of organisations are concerned about these emerging attack vectors. Among early adopters of quantum-safe technologies, one in six expect “Q-day” — the moment quantum computers can break current cryptographic algorithms — within five years, while around 60 per cent believe it will happen in a decade.
“Quantum readiness isn’t about predicting a date — it’s about managing irreversible risk,” said Marco Pereira, Global Head of Cybersecurity, Cloud Infrastructure Services at Capgemini. “Every encrypted asset today could become tomorrow’s breach if organisations delay adopting post-quantum protections. Transitioning early ensures business continuity, regulatory alignment, and long-term trust.”
Despite this growing awareness, the report notes a disparity between sectors. High-risk industries such as banking and defence are leading the transition to quantum-safe solutions, while consumer-facing sectors such as retail and consumer products are showing slower uptake.
The majority of firms (70 per cent) are addressing these challenges by adopting post-quantum cryptographic (PQC) algorithms, which are seen as the most comprehensive approach to mitigating near-term risks. Nearly half of early adopters are already assessing feasibility or piloting PQC initiatives. Regulatory pressure is proving to be a strong motivator, with 70 per cent of firms citing it as a key driver behind their quantum-safe strategies.
However, 30 per cent of organisations surveyed are yet to act on the quantum threat, often due to limited budget and staffing for cryptographic transition. The report warns that delaying action could leave them vulnerable to future data breaches and regulatory non-compliance.
The Capgemini Research Institute conducted the study in April and May 2025, surveying 1,000 companies with annual revenues exceeding USD 1 billion across 13 sectors and 13 countries, including markets in Asia-Pacific, Europe, and North America. Around 70 per cent of respondents were identified as early adopters of quantum-safe solutions. The survey findings were supplemented with interviews from 16 industry executives.

