Quantum Computing and Cybersecurity Law: Preparing for the Next Generation of Cyber Threats
Keywords:
quantum computing; post-quantum cryptography; cybersecurity law; harvest now decrypt later; NIST PQC standards; quantum-safe migration; cryptographic agility; quantum key distribution; international law; critical infrastructureAbstract
The advent of fault-tolerant quantum computing poses an existential threat to the cryptographic foundations upon which the security of digital communications, financial transactions, governmental systems, and critical infrastructure presently rests. Current public-key cryptographic algorithms — including RSA, elliptic curve cryptography, and Diffie-Hellman key exchange — are mathematically vulnerable to attacks by sufficiently powerful quantum computers running Shor's algorithm, and the widespread deployment of quantum-capable systems within the coming decade or two would render vast archives of encrypted data immediately legible to adversaries who have harvested and stored them. This prospect, known as 'harvest now, decrypt later', represents a present legal and regulatory challenge, not merely a future one. Yet the legal and regulatory frameworks governing cybersecurity have been conspicuously slow to respond to the quantum threat, and the scholarly literature on the legal dimensions of quantum computing remains underdeveloped relative to the technical and policy literature. This article addresses that gap, examining the quantum threat to cybersecurity law from multiple angles: the nature and timeline of the quantum risk; the adequacy of existing legal frameworks to incentivise and mandate the post-quantum cryptography transition.