As many as 96 percent of companies recorded at least one cybersecurity incident last year. According to the latest KPMG report, phishing continues to dominate the list of the biggest threats. Although awareness of cyber risks is growing and more companies are trying to protect their data, the scale of incidents remains alarming. This is particularly worrying in the context of the approaching quantum revolution, which is undermining the effectiveness of traditional security methods. Cybercriminals are aware of this, which is why they are increasingly simply stealing encrypted files in order to decrypt them in the future using quantum computers.
Quantum computers are developing very rapidly, and with them the risk to today’s cryptographic systems is growing. To stay ahead, organisations must already prioritise quantum-resistant cryptography, thereby ensuring long-term cyber resilience and trust in a post-quantum world.
Meanwhile, according to a Capgemini study, as many as 30 percent of surveyed organisations underestimate quantum threats, risking future data exposure and potential regulatory penalties. At the same time, more and more hacker groups are operating according to the principle of “harvest now, decrypt later.” This is a highly concerning trend, because all corporate data and assets are becoming targets of cyberattacks — even those that are effectively encrypted at the time of theft.
Confidential data stolen today, such as customer information, medical records and financial data, may in the future be used to exert pressure on an organisation. Capgemini research shows that this is a cause for concern for 65 percent of companies.
For example, in June 2025, international public attention focused on reports of a leak involving 16 billion stolen login credentials from 30 different databases, giving cybercriminals an unprecedented opportunity for identity theft and account takeover. The scale of this phenomenon highlights the enormous challenge organisations will have to face when encryption algorithms can be broken by quantum computers.
“The accelerating pace of technological development and the emerging quantum revolution have given hacker groups hope that information which is useless today may be worth keeping for later, so that it can be decoded using devices capable of doing so in seconds rather than over many, many years. As the number of ‘harvest now, decrypt later’ threats grows, quantum security has moved from being a technical issue to a management priority. Regulatory pressure, the evolving technology ecosystem and competitive advantage all favour those who prepare first for what the future will bring,” says Artur Kmiecik, Head of Cloud and Infrastructure at Capgemini Poland.
Capgemini’s study shows that quantum security is gaining importance in management plans, which is a very positive development, as 70 percent of organisations among so-called early adopters are already assessing or implementing appropriate protection measures. However, only 15 percent of these companies can be described as “quantum security leaders,” standing out for their maturity in both governance and the technical implementation of safeguards.
The quantum threat is not a matter of the distant future, but a current and urgent business challenge. However, most chief information security officers still underestimate the scale of the transformation required: from recompiling thousands of custom applications, to replacing cryptographic libraries, rotating keys, updating hardware security modules and reissuing certificates.
For sectors such as banking, this will require significant work and investment. And because soon everyone will be competing in the labour market for the limited number of specialists in quantum security, the time to take preventive action is quickly running out.
However, by planning a multi-year migration sufficiently early and allocating resources for this transformation, organisations can avoid regulatory penalties and costly hardware upgrades when a breakthrough in quantum technology finally arrives. Moreover, such migration also sends a clear signal to stakeholders that the organisation takes cybersecurity seriously.





