Post-quantum cryptography is already a business risk for APAC

The question is no longer whether organizations across Asia-Pacific will need to prepare for post-quantum cryptography, but whether they will do it on their own terms or under external pressure.

Khai Peng Loh
5 Min Read
Image courtesy of HPE.

Most organizations may believe they still have time to think about the implications of quantum computing. In reality, the bigger risk is not predicting when a cryptographically relevant quantum computer will arrive, but ensuring there is enough time to prepare for it.

Post-quantum cryptography (PQC) requires organizations to take stock of where and how cryptography is used across their environments, assess dependencies and vulnerabilities, and progressively modernize systems without compromising business continuity. Because cryptography is foundational to secure communications, software integrity, device identity, and regulatory compliance, quantum readiness is increasingly becoming a strategic resilience priority rather than a future cybersecurity consideration.

In fact, the numbers back up the urgency. According to IDC, 20% of Asia’s top 2,000 enterprises will engage cybersecurity professional services firms to conduct quantum risk assessments by 2028. This is indeed a sign that most enterprises don’t yet have this capability in-house.

Why the time to prepare is now

- Advertisement -
Ad imageAd image

Three factors explain the urgency for organizations:

  • First, harvest-now/decrypt-later risk means adversaries can capture encrypted data today and decrypt it once quantum capability matures, putting long-lived information at risk before “Q-Day” arrives, an increasingly important consideration for the region’s financial services, government, healthcare and telecom sectors, which manage data with long retention requirements.
  • Second, regional frameworks now exist to plan against it, with Singapore launching Southeast Asia’s first National Quantum-Safe Network Plus in 2023 and having already started rolling out Cyber Security Agency of Singapore (CSA) quantum security guidelines from 2025. Similarly, CyberSecurity Malaysia the country’s national cybersecurity agency, has developed a Post-Quantum Cryptography Migration Framework and technical implementation guide, giving organizations a structured pathway to quantum-safe cryptography.
  • Third, migration will take years, since cryptography is embedded throughout enterprise environments, from certificates and code signing to device identity, networking, and third-party systems, and multinational Asia-Pacific (APAC) operations must coordinate this work across jurisdictions with different timelines. In practice, core migration can take 24 to 36 months, and broader infrastructure transition 24 to 48 months or more, often longer still for APAC organizations managing data sovereignty and cross-border requirements.

PQC readiness is an infrastructure transformation challenge, not a single security upgrade, and organizations that skip the groundwork pay for it later.

Laying the foundation for quantum readiness

That groundwork rests on three practical steps:

  • For business leaders, the issue is timing. PQC migration will take longer than many organizations expect because cryptography is deeply distributed and often poorly inventoried. Getting ahead of the transition starts with visibility, building a complete inventory of where cryptography is used across infrastructure, applications, certificates, code signing, device identity, and third-party services. From there, prioritize systems with long confidentiality horizons alongside the hardest-to-change areas, including hardware-rooted identity, secure boot, firmware signing, and internal public key infrastructure (PKI), the certificates and cryptographic keys that verify digital identities and secure communications.
  • Establish governance early, pushing vendor discussions toward standards alignment, migration roadmaps, and long-term support, and building PQC requirements into procurement for long-lived infrastructure. A vendor’s “PQC-ready” claim isn’t enough on its own, since production readiness requires interoperability, validation, and operational support as guidance continues to evolve.
  • Build crypto-agility, the ability to introduce, test, and replace cryptographic algorithms without redesigning the environment each time standards or threat models change, with infrastructure refresh cycles aligned to PQC requirements so new investments reduce migration debt rather than add to it.

The executive takeaway

The question is no longer whether organizations across Asia-Pacific will need to prepare for post-quantum cryptography, but whether they will do it on their own terms or under external pressure. Those that start now can make measured, standard-aligned decisions, protect the data that matters most, modernize the trust anchors that are hardest to change, and avoid costly last-minute remediation. That means taking practical steps today to understand their exposure, prioritize risk, and build crypto-agility across the stack of technology.

The goal is not simply to prepare for the quantum era, but to do so with a clear, practical path forward.

Follow:
Khai Peng Loh is Vice President and Managing Director - Singapore and Southeast Asia at HPE