Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By John Prisco, CEO of Safe Quantum Inc. and Toshiba Consultant
As we look toward 2025, the cybersecurity industry is evolving at an unprecedented rate, largely driven by advancements in quantum computing. For years, our defense again cyber threats revolved around routine tasks like updating software – often referred to as “Patch Tuesday”. This process was solely to make sure systems were up to date and was often considered the gold standard of a routine cyber security sweep to spot any potential threats or vulnerabilities. But the era of Quantum is pivoting priorities, and it demands a paradigm shift. Cryptographically Relevant Quantum Computers (CRQCs) promise to overturn the traditional rules of encryption and data security.
While we won’t see fully operational CRQCs for another 5 years or so, these quantum computers will possess methods, such as those based on Diffie-Hellman public key cryptography, essentially rendering most of today’s security measures useless. To keep organization’s data and sensitive information safe, we must first shift to quantum safe methods.
Fostering a Quantum-Safe Future
To build quantum-resistant security measures, organizations must adopt a hybrid defense strategy that leverages the strengths of both Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD).
You may be asking, why is a hybrid approach necessary? PQC, which has recently been standardized by the National Institute of Standards and Technology (NIST), is a critical step forward, offering encryption methods designed to withstand advanced quantum attacks. However, PQC alone does not provide information-theoretic security also known as the gold standard of encryption, which can still leave the door open to system vulnerabilities. That’s why QKD is a necessary co-pilot.
Even with unlimited computational power or infinite time, an advanced hacker cannot decrypt QKD-protected data streams without setting off alarm bells. By combining QKD with PQC, companies can create a hybrid approach that fortifies its defenses, similar to wearing both a seatbelt and having an airbag in your car. Foregoing this combination will inevitably leave the company’s data vulnerable to cyber security attacks and create a recipe for disaster.
The Quantum Threat Is No Longer a Theoretical Concept
In the coming year, we will likely see quantum computer development largely focused on error correction, which is a crucial step on the path to CRQCs. This progress spotlights the limited time we have to prepare for the quantum threat. Organizations, governments, and industries need to act now to deploy quantum safe communications. Failure to do so could open the floodgates to unprecedented cyberattacks, jeopardizing sensitive data and critical infrastructure worldwide. Transitioning to quantum-safe methods involves both technological and cultural shifts. Government agencies will have to prioritize investments in quantum technology and foster collaboration between private and public sectors.
Additionally, organizations must thoroughly audit their current encryption systems and begin integrating PQC algorithms and QKD into their cybersecurity frameworks. Public awareness campaigns can also play a role in highlighting the importance of quantum security, encouraging widespread adoption.
By 2030, we can anticipate the momentum behind quantum advancements will demand organizations and company leaders to make system wide changes. A proactive approach combined with prioritizing innovation and transparency will help organizations stand out from their competition. The tools to secure a quantum-safe future are within our grasp. The question remains whether organizations will act swiftly and strategically enough to stay a step ahead of the “quantum threat.”
##
ABOUT THE AUTHOR
Toshiba Consultant and Security CEO/ Founder of Safe Quantum Inc., working with data-driven companies to define, develop and deploy quantum-safe technologies.






