
This article originally appeared in our July 30th edition of the Diligent Minute Newsletter. For more insights like these, delivered straight to your inbox, subscribe here.
For a long time, quantum computing felt like one of those topics boards could safely file under “watch this space.” It was interesting, potentially transformative and worth understanding at a high level, but still far enough away that most directors could focus on more immediate demands.
That assumption is getting harder to defend.
In a recent conversation on the Corporate Director Podcast, quantum expert Aaron Kemp described a timeline that appears to be compressing, particularly on the cybersecurity side. Quantum computing may still be years away from broad commercial use, but the governance implications are arriving much sooner.
Kemp pointed to the growing “harvest now, decrypt later” threat. Sensitive data can be intercepted and stored today, then decoded later when quantum capabilities improve. For organizations with long-life data such as intellectual property, regulated personal information, health records and strategic communications, that should get attention now. A document or dataset does not have to be compromised today to become a serious problem tomorrow.
That creates a difficult oversight challenge for directors given quantum’s uncertain timing, complex technical dependencies and significant operational consequences. Kemp noted that many large organizations could need a decade or more to complete a full migration to post-quantum cryptography. If that is even directionally true, waiting for certainty would leave many companies behind before the real urgency becomes obvious.
As Dr. Kemp notes, this is also much bigger than a technology refresh. Directors should be asking management where vulnerable encryption exists across the organization, whether a cryptographic baseline has been completed, what the migration roadmap looks like and how exposed key vendors and third parties may be. They should also understand the likely cost, staffing and infrastructure implications. For some companies, the hardest part may not be the cryptography itself, but the aging systems and technical debt underneath it.
What stayed with me after the interview was how clearly this issue reflects a broader reality in governance. The pace of technological change is moving faster than the old rhythm of oversight. When a planning horizon shifts from 2035 to something closer to 2029, annual reviews and quarterly updates can start to feel thin. Boards need a more continuous view of emerging risks, especially the ones that can accelerate quickly.
Of course, directors already have full agendas. AI, geopolitics, cyber risk, succession and regulation are all competing for time and attention. Quantum may sound like one more problem to add to the pile. But it connects directly to several issues boards are already discussing, especially cyber resilience, data governance and long-term technology strategy.
Boards do not need deep expertise in quantum physics. They do need enough fluency to ask good questions early, push for a credible roadmap and revisit the issue regularly. On this topic, delay carries its own cost. The boards that start now will have more room to respond thoughtfully and help guide management in pacing investments and managing the transition on the company’s own terms.