As quantum computing advances, Asia Pacific’s cybersecurity challenge is no longer just replacing RSA and ECC. It is finding where cryptography already sits, strengthening digital identity, and building infrastructure that can adapt before quantum attacks become practical.
- The first problem is visibility
- The urgency is institutional
- Cryptographic agility is the strategic answer
- Identity may be the real battlefield
- Digital sovereignty enters the equation
- The infrastructure must be ready for machines as well as people
- A regional effort will require common standards
- Preparing now without waiting for the future
The quantum era is arriving from two directions at once.
Governments and technology companies across Asia Pacific are pouring investment into quantum computing, communications and related technologies. At the same time, those advances threaten the cryptography that protects the region’s fast-growing digital economy.
For enterprises, quantum readiness is less about guessing when quantum computers arrive and more about understanding the cryptographic infrastructure they already depend on.
The first problem is visibility
Sujatha S. Iyer, Head of AI Security at Zoho ManageEngine, believes organisations are approaching quantum risk from the wrong starting point. She argues that most organisations mistake quantum risk for a future cryptography problem, when the first barrier is operational visibility.
Before moving to post-quantum standards, enterprises need to know where encryption is used across their environments — a level of visibility many still lack.”
The problem is particularly severe in large hybrid environments, where infrastructure has accumulated over years of cloud adoption, application modernisation, mergers and technology refreshes. In large hybrid environments, Iyer notes, RSA and ECC are buried across applications, VPNs, APIs, certificates, databases, endpoints and third-party integrations.
“Years of cloud adoption, mergers, modernisation and refreshes have often outpaced documentation, leaving organisations unsure which systems are exposed or hardest to migrate,” suggests Iyer.
That makes cryptographic discovery a foundational task. Before organisations can migrate to post-quantum cryptography (PQC), they need to know where vulnerable algorithms, keys, certificates and dependencies reside.

Amaanie Hakim, Vice President of Innovation and IP at IDEMIA Secure Transactions, sees the same problem across Asia Pacific. Hakim says APAC organisations are moving in the right direction, but most remain at an early-to-mid stage of post-quantum readiness. In banking, government and telecommunications, the issue is not awareness alone; it is the complexity of cryptography embedded across identity systems, cloud, mobile services, networks and connected devices.
That matters in Southeast Asia, where digital transformation is uneven. Singapore has mature infrastructure, while Indonesia, Malaysia, Thailand, Vietnam and the Philippines are rapidly expanding cloud adoption, digital payments, e-government and connected services.
A regional quantum strategy therefore cannot simply assume that every country or enterprise is starting from the same technological baseline.”
The urgency is institutional
Singapore offers perhaps the clearest example of how the issue is moving from research into operational cybersecurity.
Its National Quantum-Safe Network Testbed is designed to trial commercial-grade quantum-safe technologies, including both QKD and PQC, with public and private organisations. It also evaluates performance, security and interoperability and contributes to standards and deployment guidance. More recently, Singapore’s Cyber Security Agency released a Quantum-Safe Migration Handbook and Quantum Readiness Index on 16 July 2026, framing migration as a complex, multi-year effort and urging critical infrastructure operators and government agencies to begin now.
Singapore’s government has also said it will use NIST standards as a baseline, while treating QKD as complementary technology for more specialised, high-assurance applications. It is deploying two nationwide quantum-safe networks through NQSN+, intended to reduce technical and financial barriers for businesses adopting quantum-safe solutions.
Amaanie Hakim argues that the urgency is becoming more concrete across the region. She says the biggest gap remains visibility: many organisations still lack a clear inventory of where cryptography is deployed, making it difficult to assess exposure or prioritise migration.
Execution is the next challenge.
Post-quantum security cannot sit with security teams alone; it requires infrastructure, procurement, cloud, device management and vendor ecosystems to move together.”
With some experts warning that quantum computers capable of threatening current cryptography could emerge as soon as 2030, the transition window is already narrowing.
India’s national Quantum Safe Ecosystem roadmap, for example, sets phased milestones from 2027, with critical infrastructure expected to complete post-quantum adoption by 2029 and broader enterprises by 2033. For large infrastructures that take years to migrate, waiting until the threat is immediate may be too late.
Cryptographic agility is the strategic answer
The second major challenge is what happens after an organisation discovers its cryptographic dependencies. Simply identifying vulnerable algorithms is not enough. Enterprises need infrastructure capable of replacing them without rebuilding entire systems.
Iyer says organisations should prioritise cryptographic discovery, asset inventory and crypto-agile architecture, so security teams can find vulnerable algorithms and update them without rebuilding entire systems. That flexibility will matter as post-quantum standards continue to evolve.
Cryptographic agility, she adds, will become a defining requirement of enterprise security architecture because no single migration effort can permanently solve a problem whose standards and deployment guidance are still changing.
The implication is significant.
Organisations should not design a “quantum-safe” architecture that assumes today’s PQC standards will remain unchanged forever. They need architectures capable of changing as standards, implementation practices and threat intelligence evolve.”
Many legacy systems were built with fixed cryptographic implementations that are hard to change. In a post-quantum environment, that turns every major algorithm transition into a slow, costly and disruptive exercise. Enterprises instead need infrastructure that lets security teams rotate algorithms, certificates and key-management policies with minimal friction. That principle has particular relevance to Southeast Asia’s fast-growing cloud and digital services sectors.
A bank modernising its mobile platform today, for example, should not have to rebuild that platform when a cryptographic standard changes tomorrow. A telecommunications provider deploying millions of connected devices cannot realistically replace every device simply because its cryptographic implementation becomes outdated. Agility therefore becomes a form of future-proofing.
Identity may be the real battlefield
The quantum threat also changes the conversation around identity.

Encryption is only one layer of digital security. Organisations must also ensure that the people, devices, applications and machines connecting to their infrastructure are genuinely who or what they claim to be. Iyer argues that sophisticated attackers are already exploiting this weakness.
Iyer notes that attackers often do not need to break encryption directly. They compromise identities, abuse privileged access or exploit unmanaged devices — risks that become sharper as quantum research, AI systems and critical infrastructure grow more valuable. That risk becomes even more significant as quantum research facilities, AI systems and critical digital infrastructure become more valuable targets.
In quantum-enabled environments, organisations may be protecting sensitive research data, proprietary models and critical infrastructure workloads, so identity management must move beyond static authentication.
For enterprises, that means continuous verification, adaptive access policies and behavioural analysis must increasingly become part of the security architecture. Privileged accounts are another concern; privileged access also needs more attention. Persistent privileged accounts remain a major attack surface, making least-privilege access, session monitoring, credential rotation and just-in-time privilege elevation increasingly important.
The problem extends to devices. Endpoints now sit near the centre of enterprise operations, and a single compromised endpoint can open a path into much broader infrastructure if monitoring and policy enforcement are inconsistent.
Digital sovereignty enters the equation
Quantum-safe infrastructure is also becoming part of a larger debate around digital sovereignty. For governments building national digital identity platforms, sovereign clouds and critical infrastructure, dependence on cryptographic technologies that cannot evolve could become a strategic vulnerability.
Hakim says quantum-resilient identity and authentication systems are becoming central to digital sovereignty because sovereignty depends on trust, control and long-term resilience. Governments investing in national digital identity, sovereign cloud or critical services need security foundations that can evolve with the threat.
“That is especially relevant in APAC, where countries are investing in trusted digital ecosystems and strategic technologies. Quantum-safe infrastructure helps governments retain long-term control over the systems protecting citizen data, authentication and critical services,” says Hakim.
The infrastructure must be ready for machines as well as people
The future digital environment will contain vastly more machine identities than human identities. Cloud workloads, APIs, IoT devices, connected vehicles and industrial systems will continuously authenticate with one another. Each interaction potentially involves certificates, keys and cryptographic protocols.
Hakim warns that as organisations move into hybrid and distributed computing environments, trust must extend across cloud, edge, devices, users, workloads and, eventually, quantum-enabled systems. This makes certificate lifecycle management and secure provisioning central to quantum readiness.
That creates pressure around certificate lifecycle management, machine identities, workload authentication, secure provisioning and key management at scale.
Approaches such as crypto-agility, hardware-backed trust and secure elements can help organisations move toward quantum-safe models without disrupting operations.”
For Singapore’s highly connected economy, Malaysia’s expanding digital infrastructure and Indonesia’s enormous digital ecosystem, the ability to manage machine identities at scale will be critical.
A regional effort will require common standards
Southeast Asia’s diversity is simultaneously an opportunity and an obstacle. Different countries operate under different regulatory systems, levels of digital maturity and technology infrastructures. Yet financial transactions, cloud workloads, telecommunications and supply chains routinely cross borders.
Hakim argues that interoperability standards and regulatory coordination are essential. “Without common frameworks and migration guidance, APAC organisations risk building fragmented security architectures that are hard to scale or secure across borders.”
The region has a foundation on which to build. Research into Southeast Asia’s quantum ecosystem notes that Singapore, Thailand and the Philippines have already launched quantum strategies or roadmaps, while other countries are exploring deeper regional cooperation. The challenge now is converting national initiatives into interoperable regional capabilities.
Preparing now without waiting for the future
For enterprises, the practical response is not to wait for certainty about when quantum computers can break today’s encryption. It is to start with the infrastructure they already control. Iyer argues that quantum readiness can be folded into existing transformation programmes.
Many of the foundations needed for post-quantum readiness already overlap with investments in cloud modernisation, identity governance, automation and infrastructure visibility. Quantum preparedness does not have to become a separate, standalone security programme.
The next step is to identify data that must remain confidential for many years. The “harvest now, decrypt later” risk is most relevant to data that must remain confidential for years, such as financial records, healthcare information, intellectual property, government communications and critical infrastructure data. Those datasets should be identified early and protected first.
The result should be a phased migration rather than a panic-driven replacement exercise. A phased, risk-based approach is usually the most practical path. Not every system needs immediate remediation; what matters is knowing where the highest-value data sits, which systems are most exposed and which legacy technologies could slow migration later.
Hakim’s conclusion is direct:
Organisations should first build visibility into how cryptography is used, then prioritise exposed systems and long-lived data before moving toward crypto-agility, vendor coordination and gradual migration.”
Quantum readiness, she says, should be part of every organisation’s digital resilience strategy, not a future side project.
For Southeast Asia, the quantum transition is therefore already underway – even if the quantum computers capable of breaking today’s encryption have not yet arrived. Singapore’s testbeds, Malaysia’s migration planning and quantum sandbox, Indonesia’s national-resilience focus and the Philippines’ emerging roadmap show a region moving from awareness to preparation.
The ultimate competitive advantage may not belong to the country that builds the first powerful quantum computer. It may belong to the organisations that ensure their digital infrastructure can survive it.
Iyer’s broader lesson is that organisations with strong visibility across identities, endpoints, encrypted assets and infrastructure dependencies will be better positioned to adapt as post-quantum standards mature — and those capabilities improve resilience no matter how quickly quantum computing advances.
For APAC’s digital economies, that is perhaps the most important message of all: quantum readiness is not a future security project. It is becoming a measure of how resilient today’s digital transformation really is.


