Somewhere between “AI will take your job” and “the metaverse will change everything,” quantum computing has been patiently waiting its turn as the tech industry’s favorite apocalypse. Unlike those other two, it has a legitimate claim to the title. It won’t replace your job or talk you into buying a hideous headset, but it could eventually make the encryption protecting your Cloud environment about as useful as a screen door on a submarine.
The operative word is eventually. Nobody is running RSA-2048 through a quantum computer in their garage this week. But “eventually” is doing a lot of quiet, expensive work in boardrooms right now, and CISOs and Cloud providers treating it as a someday problem are setting up for a very bad day whenever someday arrives. In the post-quantum world, Cloud pros need updated cryptography, crypto-agility, and a plan for future attacks.
The machine that isn’t here yet, except for the parts that are
IBM has put a date on its own version of someday: a roadmap for Quantum Starling, a large-scale, fault-tolerant quantum computer it plans to bring online by 2029 at a new IBM Quantum Data Center in Poughkeepsie, New York. IBM says Starling will be capable of running quantum circuits comprising 100 million quantum gates on 200 logical qubits, a sentence that means nothing to most of us and everything to the people who currently sleep soundly because breaking modern encryption requires computing power that doesn’t exist yet. IBM is backing its ambition with real money too, pledging more than $10 billion toward quantum computing over the next five years.
Whether Starling lands exactly on schedule is beside the point. A Forrester report bluntly titled “Quantum Security Isn’t Hype” put the timeline for commercially available quantum computers capable of cracking today’s asymmetric cryptography at somewhere between five and ten years out, and argued that organizations need to start preparing regardless of the exact date. As Forrester analyst Andras Cser told TechNewsWorld, the migration won’t be entirely in any one company’s control, since it depends on vendors upgrading their own technology first, which means the whole process could easily stretch across years even after the starting gun fires.
Harvest now, panic later
Here’s the part that should keep you up tonight, not in 2029. Cybercriminals and nation-states are already running “harvest now, decrypt later” operations: scooping up encrypted data today with the plan of cracking it open once a sufficiently powerful quantum computer exists. If your organization handles data that needs to stay confidential for years (health records, financial data, government secrets, that embarrassing internal Slack thread from 2022) it’s already a target, regardless of what year the machine actually shows up.
This should already be on the CloudFest community’s radar. Cloud infrastructure is exactly the kind of long-term memory system that makes harvest-now-decrypt-later attractive: backups, archives, and logs sitting in storage for years, encrypted with algorithms that were perfectly respectable when written and increasingly less so with every quantum headline since.
Crypto-agility: The buzzword that’s actually useful
The consistent advice across serious analyses of this issue, from Forrester and from Cloud Computing News‘s coverage of network readiness, is not “buy quantum-proof encryption tomorrow.” It’s crypto-agility: building systems that can swap cryptographic algorithms without a multi-year, budget-torching overhaul every time the standards shift. Quantum computing poses one of the biggest threats and most significant opportunities in Cloud security history, and organizations that lag will be caught off guard by how quickly it arrives.
That’s a fair summary, and it cuts both ways. The same quantum properties that threaten RSA and ECC also enable genuinely useful defensive tools, like quantum random number generation for stronger encryption keys and quantum-assisted threat detection that can chew through network data faster than classical systems. Quantum isn’t just a wrecking ball swinging toward your firewall. It’s also, potentially, a better lock.
What to actually do this week
Nobody needs a post-quantum rollout plan finalized by Friday. What CISOs and Cloud providers do need, starting now, is a real inventory: where encrypted data lives, what’s protecting it, who owns the keys, and how old that encryption really is. As IT-Harvest’s Richard Stiennon points out, most organizations doing this exercise discover they don’t fully know where their own “family jewels” are sitting, quantum threat or not. That’s a useful discovery on its own merits.
Post-quantum cryptography standards already exist; NIST finalized its first set in 2024. Major Cloud providers, browsers, and CDNs are already testing hybrid key exchanges that pair classical and quantum-resistant algorithms, hedging their bets in case any single approach proves less bulletproof than advertised. Providers who build crypto-agility now won’t need to panic-migrate everything the day a fault-tolerant quantum computer ships. Everyone else will be relearning the phrase “legacy system” under far more stressful circumstances.
Quantum will come, eventually. The organizations that treat “someday” as a planning horizon instead of a platitude will be the ones still standing when it does.
For more on how the cloud and hosting community is preparing for what comes next, see our coverage of cybersecurity and compliance at CloudFest 2026 and ethical hacker Ralph Echemendia’s take on building for resilience.
