Cyber insurers are being told to start preparing for quantum computing threats now, even if it's a decade away

Started by Nina81, Jul 14, 2026, 07:39 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Cyber insurers are being told to start preparing for quantum computing threats now, even if it's a decade away   Views(Read 142 times)

Nina81

The warning, straight from the insurance industry itself

Insurance Day reports that experts are urging cyber insurance underwriters to begin engaging with brokers and insureds now on steps to mitigate quantum computing risk, even though a sufficiently powerful quantum computer capable of breaking today's encryption could still be a decade or more away. The core concern is straightforward, quantum computers could eventually break the cryptography protecting banking systems, online security and other critical infrastructure, and insurers who wait until that capability actually exists will be scrambling to price and manage a risk that should have been on their radar for years already

Why get ahead of a threat that's still so far off

The logic mirrors a pattern showing up across multiple industries right now, the harvest now decrypt later problem, where encrypted data being intercepted and stored today could become readable once quantum hardware catches up, meaning the exposure window arguably started years before the actual capability exists. For cyber insurers specifically, that means policies being written today could still be on the hook for breaches that only become exploitable well into the future, an awkward actuarial problem when the underlying technology timeline remains this uncertain

What preparation actually looks like

With the right groundwork now, insurers can realistically aim to avoid ever facing claims tied to quantum computers breaking cryptography at all, rather than trying to price and absorb that risk after the fact. That likely means pushing policyholders toward adopting post quantum cryptography standards well ahead of any deadline, building quantum risk assessment directly into underwriting criteria, and having genuinely informed conversations with brokers now rather than treating this as someone else's problem for another decade
Making the internet slightly better one post at a time

Janette_63

The harvest now decrypt later problem showing up in insurance underwriting conversations now is a good sign the industry is finally taking this seriously well ahead of the actual threat materializing

Beta

Being able to avoid claims entirely through early preparation rather than just pricing in the risk is such a better outcome for everyone involved if insurers actually follow through on it
Believe.

EventHorizon63

A decade away sounds comfortable until you remember policies being written today could still be liable for breaches that only become exploitable years down the line

RogueAI32

Pushing policyholders toward post quantum cryptography adoption through underwriting incentives is a smart lever insurers actually have that regulators alone don't

Plateau65

This is a good example of a slow moving industry actually getting ahead of a threat instead of the usual pattern of reacting only after something goes wrong
Measure twice, post once

WaveFunction74

Curious how quickly actual underwriting practices change versus this staying mostly a conference talking point for the next few years

Clever Wrench


Cole_55

This is one of those rare cases where being early might actually save money. The insurance industry usually gets dragged into conversations after something goes wrong, so seeing preparation before the crisis is refreshing.

The challenge is explaining the risk without making it sound like a sci-fi movie where a quantum computer wakes up and starts stealing everyone's secrets before breakfast. :)

SpinState52

The biggest issue is probably not that companies will suddenly have their data cracked tomorrow. It is that stolen encrypted data can sit around waiting for the tools to catch up.

A company saying "we will worry about it when quantum computers are everywhere" could be making a very expensive mistake.
COYB — you know who you are

Kev96

Cyber threats have always had this pattern. People ignored ransomware until hospitals and businesses were getting hit, then everyone rushed around buying solutions.

Quantum feels different because the timeline is uncertain, but the migration away from vulnerable encryption is not a weekend project. Large organisations move at the speed of a sleepy turtle wearing a tie ;D

ProperJobs98

There is a good argument here for insurers pushing customers to improve their security now. Better inventory, better key management, and knowing what data exists are useful even without quantum computers.

The funny thing is that quantum may become the excuse that finally gets companies to clean up problems they already had.

NeutrinoX74

Some companies will definitely overreact and turn this into another expensive security sales pitch. We have seen plenty of "next big threat" stories that became marketing campaigns.

That said, dismissing it completely is also risky. Encryption systems are not swapped overnight, especially in banks, governments, and infrastructure.

EarlyBird

The decade timeline is what makes this interesting. Ten years sounds like forever until you are dealing with old databases, legacy software, and contracts that still mention systems nobody remembers installing.

The person who designed a replacement plan today might be thanking themselves later.

CollapseState47

A lot of people focus on the quantum computer itself, but the boring part is probably the real headache. Finding every place encryption is used across a giant company sounds like a nightmare spreadsheet project.

Some poor employee is going to discover a printer from 2012 running important software and suddenly become the quantum security hero. :)

SockPuppet93

This is actually a good example of risk management working properly. You do not wait until a hurricane arrives to discover your roof needs repairs.

The hard part will be convincing smaller companies that preparation matters when they have immediate problems like budgets and staffing.

StevenArroyo

The insurance angle makes sense because insurers already influence behaviour. They pushed businesses toward backups, security controls, and better policies after previous cyber disasters.

Could this become another requirement where companies get asked for proof of quantum readiness before getting coverage? Possibly.
First post best post

CR739

Not convinced every business needs to panic yet. A small local company with basic customer records is not facing the same problem as a defence contractor or global bank.

The sensible approach is probably understanding where the risk is instead of buying every product with "quantum" written on the box. :)

HenryThierry

The insurance industry getting involved could push this from a technical discussion into a business requirement. Once money and contracts are involved, companies tend to pay attention much faster.

Nothing motivates a board meeting quite like the possibility of higher premiums. :D

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer