forumNordic

Global Visibility for Nordic Innovations

The Clock Is Ticking on Your Encryption, and Nobody Told IT – Explained in a White Paper from Finland’s VTT

Finnish research giant VTT has published a playbook on post-quantum cryptography, and the core message is uncomfortable: the encryption underpinning financial transactions, healthcare records and software updates is on a countdown, and most organisations haven’t noticed the clock is running.

The threat comes from Cryptographically Relevant Quantum Computers (CRQCs) — machines powerful enough to break the mathematical problems that today’s encryption relies on. NIST is targeting a phase-out of current cryptographic standards by the early 2030s, and VTT argues the window to prepare is already closing.

Two attack scenarios explain the urgency. In “harvest now, decrypt later,” attackers steal encrypted data today — personal records, financial data, IP — banking on the ability to unlock it once quantum computers mature. In “trust now, forge later,” future quantum capabilities could let attackers forge digital signatures, fake identities, and tamper with signed software and transactions, corroding the trust that underpins digital systems generally.

What makes the fix hard isn’t the cryptography itself — new quantum-resistant standards already exist and are deployment-ready. It’s that cryptography is buried everywhere: PKI, embedded devices, legacy software, and it’s usually poorly documented. Most organisations, VTT notes, don’t actually know where their own cryptography lives, which makes planning near-impossible. Previous cryptographic migrations took over a decade; this one is expected to be more complex still.

Regulation isn’t yet forcing the issue directly. Europe’s NIS2 and DORA frameworks raise the cybersecurity bar without mandating post-quantum specifics, though VTT expects that to change. The US is moving faster on critical infrastructure requirements, and the practical effect is a ripple: companies may find post-quantum readiness demanded not by law, but by customers, partners and procurement checklists — especially in finance, energy and infrastructure.

VTT’s playbook recommends three starting moves: understand how quantum risk actually applies to your organisation (including your vendors), build a cryptographic inventory to see what algorithms and protocols are actually in use, and begin a controlled transition toward “crypto-agile” architecture — systems built so cryptographic components can be swapped without disrupting operations.

The bigger point: this isn’t a project with an end date, since standards and threats will keep evolving. VTT’s advice is to stop trying to predict exactly when the quantum threat arrives and instead build the capability to be ready whenever it does.

Photo: VTT

© 2024 forumNordic. All rights reserved. Reproduction or distribution of this material is prohibited without prior written permission. For permissions: contact (at) forumnordic.com