Guest Post: Quantum Investment May Start With Post-Quantum Security

Courtney Olujobi
Hub Hub

Guest Post By Courtney Olujobi, Principal at Moon Pursuit Capital.

From an investment perspective, one of the first significant markets created by quantum computing may have very little to do with buying access to quantum computers themselves. It may come from the amount of capital businesses will need to spend protecting the financial systems, digital infrastructure and sensitive data that were built for a world in which today’s encryption was considered secure.

We do not know exactly when a quantum computer capable of breaking widely used public-key encryption will arrive, and estimates still vary considerably. Economically, what matters is that companies cannot wait for that moment to prepare. Spending on quantum resilience is already finding its way into regulation, procurement requirements and long-term technology planning, which means the commercial impact of quantum could start showing up in cybersecurity and infrastructure budgets well before quantum computing itself reaches broad commercial maturity.

The reason is simple. Encrypted data can be copied today and decrypted later. An adversary does not need a quantum computer to steal a bank’s archived records, a hospital’s patient files or a company’s deal documents. It only needs patience. So the relevant question for any business is not when the machine arrives. It is how long its data has to stay secret, and how long it will take to move that data onto new cryptography. If those two periods together run past the arrival date, the exposure has already started.

Introducing TQI 2.0Introducing TQI 2.0

That logic is now turning into deadlines. In June, the White House signed Executive Order 14412, which directs federal agencies to move their most sensitive systems to post quantum encryption by the end of 2030 and post quantum digital signatures by the end of 2031, and starts a rulemaking that would extend compliance to federal contractors. The NSA requires new national security system acquisitions to support quantum resistant algorithms from January 2027. In January, the G7 Cyber Expert Group, chaired jointly by the U.S. Treasury and the Bank of England, published a roadmap for the financial sector’s transition. It is explicitly nonbinding. I expect examiners, auditors and large counterparties to treat it as the benchmark anyway.

Private industry is moving faster than regulators. Google has set 2029 as its target for completing its own migration. When the companies that run the internet’s infrastructure pull their dates forward, everyone who depends on them inherits a shorter clock.

Spending will show up first where data has a long shelf life and where value depends on digital signatures. That puts financial services and fintech at the front of the line. Banks, payment processors, custodians and lending platforms hold records that must stay confidential for decades, and they authorize the movement of money with signatures. A forged signature is not a data breach. It is a theft.

Technology companies come next, because they sell the migration to everyone else. Cloud providers, certificate authorities, hardware security module makers and identity platforms have to upgrade their own stacks before their customers can.

The sequence matters for investors. The first dollars go to discovery, because many institutions have never fully mapped where cryptography lives inside their systems. The next go to certificate and key management, then to hardware. Some hardware can be patched. Some must be physically replaced. Then comes integration and testing, which is where large migrations tend to run over budget.

I think about technology in cycles that move from the core to the edge. This migration will travel the same path. The core, meaning the largest banks and cloud platforms, will move first because it has the budgets and the regulatory pressure. The edge is harder: smaller fintechs, embedded devices, supplier networks and decentralized digital asset networks, where an upgrade has to be coordinated across thousands of independent participants rather than mandated from the top. That long tail is where migration will take longest, and where demand for tools and services will last longest.

In the near term, most of this spending will not be new money. It will be reallocated from existing security and infrastructure budgets, competing with everything else a security team has to fund. Over time it becomes a refresh cycle: hardware, software and contracts replaced on a schedule set by regulators rather than by normal replacement timing. Refresh cycles with a fixed date are rare, and valuable to whoever supplies them.

There are three ways this goes wrong for investors, and each should be priced before capital goes in.

First, compliance spending is often a cliff, not an annuity. Y2K remediation created real revenue for real companies, and much of it disappeared once the date passed. A vendor whose growth comes from a one time migration should not be valued as if that revenue recurs.

Second, the largest platforms may absorb the market. If cloud providers, browsers and operating systems ship post quantum protection as a default at no extra cost, much of the value that looks available to standalone vendors gets captured by incumbents or given away. Some of those incumbents have said publicly that post quantum security should be a baseline, not a premium product.

Third, timelines slip. Budgets follow deadlines, and deadlines move. If hardware progress stalls, urgency could fade even though the risk to harvested data does not. The standards are also still expanding, so early implementations may need rework.

The companies that come through this well will not be the ones selling a single upgrade. They will be the ones that make cryptography replaceable, so the next change is a configuration update rather than a multiyear program. That capability, usually called crypto agility, is the part of this market I expect to outlast the deadlines.

For investors, the diligence question has changed. It is no longer when quantum computing arrives. It is whether a company has a credible plan to migrate its cryptography, what that plan will cost, and who gets paid to carry it out. The first quantum dividend will not come from a quantum computer. It will come from preparing for one.

For readers looking to go deeper into post-quantum cryptography and related security topics, TQI’s coverage of quantum-safe encryption and why migration has already started, why RSA and ECC are being replaced, and cryptographic inventory challenges in post-quantum transitions is worth checking out.

This article reflects the views and analysis of the author, Courtney Olujobi, Principal at Moon Pursuit Capital. The views expressed do not necessarily reflect those of The Quantum Insider or its editorial staff.

Keep track of everything going on in the Quantum Technology Market. In one place.

Share

Stay Ahead of Quantum

Get the latest research, company news, and market intelligence every week.

MENTIONED IN THE ARTICLE

More in Research

Related Articles