Thales researchers explain why the defence against the quantum threat starts now

  • Cybersecurity
  • Data security
  • Cybersecurity services

© 123Ref

  • Type Insight
  • Published

When will quantum computers (QCs) break today’s cryptographic systems – and how should enterprises prepare for this historic moment? Two leading Thales researchers share their insights into the quantum threat.

All over the world, enterprises are thinking about “Quantum Day” (Q Day) – the date when powerful quantum computers break the public-key cryptography that protects today’s computer systems. Many organisations are already assessing the impact of future quantum threats and beginning their migration planning.

So, when will Q Day arrive? While experts do not agree on a precise timeline, there is broad consensus on one point: organisations should start preparing now. Migrating to post-quantum and hybrid cryptographic solutions will take years, and waiting for certainty before acting could leave critical systems exposed when quantum capabilities eventually mature. Google believes it could be as early as 2029.

Truthfully, nobody knows the answer. For now, the quantum threat is still hypothetical. So why is there such widespread concern?

There are a number of reasons. First, quantum computers already exist. Google, IBM, Amazon, Rigetti, Microsoft and others have developed working prototypes. Though these products are unstable and limited in application, they illustrate that the tech is feasible.

The second big motivator is the challenge of ‘Harvest Now, Decrypt Later’. While cyber attackers cannot access Quantum Computers today, they can gather encrypted data with the intention of decrypting it when the tech becomes available. This data might include healthcare records, financial transactions, government communications, intellectual property and more. As a result, many organisations are already taking the threat seriously and assessing how to protect data that must remain secure for years or even decades.

These concerns explain why tech firms are already launching ‘quantum safe’ products. Take Thales’ quantum-resistant smartcard – MultiApp 5.2 Premium PQC. This innovative product is the result of ten years of research by Thales into the quantum threat. It features new digital signature algorithms standardised by the American National Institute of Standards and Technology (NIST). Last year, it became the first quantum-resistant smartcard in Europe to receive high-level security certification.

Yet, from an end-user perspective, nothing changes. Account holders can continue to use their cards as usual.

And there was another major breakthrough in 2026 when Thales announced that its Imperva cyber security platform had been updated to support both classical elliptic curve cryptography and a quantum-safe Key Encapsulation Mechanism. With this upgrade, the platform now protects customers from classical and quantum attacks regardless of which threat model materialises first.

It’s clear that governments, regulators, standards bodies and tech companies are now working together to coordinate their defences against the quantum threat.

To understand the topic better, we spoke to two post-quantum cryptography researchers. Frédéric Urvoy de Portzamparc, Cybersecurity Services Offer Manager at Thales, and Jacques Patarin, Head of the Advanced Cryptography team at Thales.

As cryptographers can you explain the significance of Quantum Day?

Patarin: It’s when quantum computers will be able to break our current day public key standard cryptographic algorithms. If and when this occurs, it will have a tremendous impact on cryptography. Basically, all the security on the internet, and in banks and so on, could be broken quite easily. Most people would say it’s about 10 years away. But there is no consensus. Some scientists believe it will be sooner – some much later.

Google, IBM and others have built quantum computers. But they are not yet capable of breaking public key encryption. Why not?

Patarin: It’s hard to keep these computers stable. The main challenge is spontaneous decoherence that occurs during the computation. It's very difficult to keep the qubits in a combined state. Another big problem is how to combine a given qubit with a lot of other qubits. A lot of research has been done in this area. For example, scientists have developed two kinds of qubits: one for computation and one for correcting errors. But this task is very difficult – much more than just increasing the number of qubits. And this is why it's so difficult to evaluate when Q Day will occur.

Why should organisations invest in post-quantum cryptography today, given the uncertainty around Quantum Day?

Urvoy de Portzamparc: We can see this in terms of viruses and vaccines. If we think a virus could potentially kill everybody on Earth and we already have a vaccine, should we use it? Clearly, yes! You shouldn’t just wait until the disease starts spreading. So even if you are skeptical about the danger, it is very important to introduce post quantum cryptography now.

Also, if you combine existing algorithms for classical computers with those that combat quantum threats, you achieve much better resistance to existing attacks. You can resist side channel attacks, bugs in the programme, or attacks with artificial intelligence. All these threats exist now and they are very serious.

How seriously should organisations take Harvest Now, Decrypt Later? Is the threat real?

Urvoy de Portzamparc: It’s hard to be sure. However, there are anecdotes about it within the cryptographic community. We now have vast data centres in the desert with servers storing terabytes and terabytes of data. The rumours say there are secret rooms in these buildings where communications are being wiretapped. 

I don’t know if these rumours are true, but is it worth the risk to ignore the threat? When the data is gone, it’s gone forever. And while some sensitive data loses its value over time, not all of it does. Something very embarrassing could remain very embarrassing after five or ten years. 

Even if Quantum Day does arrive, will criminals really be able to access quantum computers themselves? 

Patarin: The danger might not come from criminals at first. It’s more likely to come from rogue states. The challenge is to build a quantum computer that is both efficient and stable. As soon as this problem is solved, it’s possible that a criminal organisation could access a quantum computer, and then things could move very fast. 

If we assume the Quantum threat is real, which use cases and applications will be targeted first?

Urvoy de Portzamparc: I think the most obvious example is the VPN because it is a widespread technology adopted by a variety of organisations to secure communication over the internet. Cryptocurrency is another target. Ethereum and Bitcoin both use the ECDSA elliptic curve digital signature algorithm. That could be easily broken by a quantum computer. 

Then there is the SIM card. The mobile industry uses classical cryptography to protect keys that are stored in secure elements. Criminals might tap mobile traffic with a plan to decrypt it in the coming years. This is a challenge for the entire ecosystem. Of course, Thales is deeply involved in all the standardisation committees, such as GSMA and 3GPP, that are working to protect mobile phone users from this threat.

What is ‘crypto agility’, and why is it so important for enterprises?

Patarin: Crypto-agility describes the capacity of an organisation to change the cryptographic functions of a system during its lifetime. This is a significant challenge. An organisation must align its people, processes and technology if it wants to evolve its cryptography management practices successfully.

One approach is hybridisation – using two algorithms for extra security. I think this is very important. If one of the algorithms crashes, you can rely on the second one. This is something I tried to promote in France for many years, before there was any quantum risk. Now, as the quantum threat has grown, the banks have become much more open to it.

And anyway, it will be mandatory by the law to have two algorithms in a few years. It will be similar to the situation in France a few years ago when all banking cards had to contain a microprocessor. It stopped being a philosophical question for enterprises and became a legal one. And it worked very well.

Overall, how do you think enterprises view the quantum threat today?

Urvoy de Portzamparc: The honest answer is that many of them just don't care about cryptography. Mostly, the tech works. We are lucky enough to have security systems that are powerful and trusted. They don’t have to think about it. But they should.

Patarin: It’s so important for enterprises to prepare because unexpected events can change things very fast. For example, 20 years ago the module used in smart card RSA cryptography was quite small. But banks were not worried because only a small number of mathematicians knew how to factor these numbers. 

Then something new appeared: the internet. One day, someone used the internet to ask mathematicians to factorise one of these smart card numbers. Suddenly, he was able to break the French banking system. So, the fact that everything is OK now does not mean that it will be OK in the near future.

Many companies are now talking about post-quantum security. What differentiates Thales in this field?

Patarin: Thales has been involved in advanced cryptography for decades. We contributed to the foundations of post-quantum cryptography long before it became a strategic concern for industry. Our teams actively contribute to international standardisation efforts, and we combine scientific excellence with practical deployment experience. 

Research is essential, but what matters most is turning innovation into trusted solutions that can protect critical infrastructures, identities, communications and sensitive data at scale. 

Urvoy de Portzamparc: What makes Thales unique is the combination of research, consulting expertise and trusted security technologies. We can help customers understand the quantum threat, assess their exposure, build a pragmatic migration roadmap and deploy quantum-ready solutions. This is quite rare. Few organisations can support customers across the entire journey – from awareness and governance to operational deployment – with the breadth of expertise that’s available within Thales.

What practical advice would you give executives that want to prepare for the quantum threat today?

Urvoy de Portzamparc: The first step is to understand your environment. Don’t replace all existing cryptography. Instead, ask which applications rely on cryptographic mechanisms? Which systems protect sensitive data that must remain confidential for many years? Which assets have long lifecycles and cannot be easily upgraded? Once you have that visibility in your organisation, you can then prioritise actions and build a roadmap aligned with business risks and operational realities. 

Patarin: I would add that the focus should be on crypto-agility. In other words, designing security systems to adapt. Crypto-agility allows organisations to transition smoothly as standards, technologies, and regulations evolve. Ultimately, preparing for post-quantum cryptography is not just about deploying new algorithms – it is about building long-term resilience into security architectures.

So, the message is clear: quantum readiness starts long before quantum computers become a practical threat?

Patarin: Absolutely. The organisations that prepare today will be the ones that remain in control tomorrow. Post-quantum security is about anticipation, not reaction. 

Urvoy de Portzamparc: This is key. With the right strategy, organisations can transform a complex technological challenge into a structured and manageable program. They can use this program to strengthen security, support compliance and protect long-term business value. 

Are you hopeful about the PQC future?  

Patarin:  Yes, I am. From a research point of view, this is extremely exciting. For the ecosystem, I believe the reality of quantum computing will, in the long run, deliver a much more efficient and secure and strong cryptography. – and it will lead us to a much safer digital world.

Which algorithms are at risk from quantum computing?

The greatest quantum threat is to public-key cryptography. Vulnerable algorithms include RSA, Elliptic Curve Cryptography (ECC) and Diffie-Hellman. If these were broken, attackers could potentially decrypt confidential communications, impersonate users, forge digital signatures, compromise software updates and more. ‘Symmetric’ encryption algorithms such as AES and secure hashing functions are considered to be less affected by quantum computing.

What are the new Post-Quantum Cryptography (PQC) algorithms?

Work on new standards is on-going. The US-based National Institute of Standards and Technology (NIST) released three PQC standards in 2024. The formal name for these algorithms is the Federal Information Processing Standard (FIPS) 203, 204 and 205 (also known as ML-KEM, ML-DSA and SLH-DSA) They are based on a family of math problems called structured lattices. The algorithms are designed for two main tasks: general encryption and digital signatures. 

In 2025, NIST selected a backup algorithm for post-quantum encryption called HQC, which will serve as a backup for ML-KEM.

More standards are coming. Thales is active in multiple PQC consortia across North America and Europe. These include the Post-Quantum Cryptography Alliance, PKI Consortium, and the CFDIR

Quantum-Readiness Working Group, NIST’s National Cybersecurity Center of Excellence (NCCoE)’s Migration to PQC Project and more.

Receive the latest Cyber and Digital insights straight to your mailbox