A board-level reframing for boards, CISOs, CIOs, CROs, and audit leaders — why quantum readiness is a problem of judgment, not cryptography.
A board chair once asked me a question so plain it cut through a month of beautiful work.
“If the standard changed tomorrow, would we change how we run the business?”
There was a pause. Everyone became fascinated by their pen.
We had the maps, policies, control library, and careful words. Yet the question exposed the bruise. We had built a response to regulation, not a system for judgment.
That is how I now think about quantum risk.
Not as a beast waiting in a physics lab. Not as a crypto seminar with better sandwiches.
Most organisations will file quantum under “cyber,” give it to a technical team, open a post-quantum cryptography workstream, and feel calmer by Thursday.
I understand the instinct. But it hides the real question.
Can your organisation take a moving standard, long-life data risk, messy suppliers, and a fragile technology estate, then turn all of that into clear choices?
That is not a crypto question. That is a Decision Layer question.
Technical labels make leaders outsource judgment. Someone says “ML-KEM” or “RSA,” and half the room quietly exits its own responsibility.
Boards do not need to become cryptographers. They need to know what is exposed, who decides, what gets funded, and how the reasoning will stand up later.
That takes Risk Taxonomy, Decision Architecture, and Decision Infrastructure.
Quantum risk is often described as if it were one thing.
It isn’t.
There is today’s clock: crypto inventory gaps, weak key management, forgotten certificates, old protocols, and systems nobody wants to touch because they still work. Mostly.
Then there is tomorrow’s clock: data stolen now and decrypted later, when quantum capability can break today’s public-key protections.
If you collapse those two clocks into one “future risk,” you make a clean-looking error.
The first clock already creates audit trouble. You do not need a quantum computer to suffer from poor cryptographic hygiene. A departed system owner and a hopeful spreadsheet will do.
The second clock asks a harder question: how long must this data remain secret?
That is where taxonomy matters. Not clerical tidiness. Board sense-making.
A decent taxonomy should split quantum into clear risk types: harvest-now-decrypt-later exposure, inventory weakness, migration risk, supplier crypto dependency, and standards-change exposure.
Each one asks for a different decision. Treat them as one blob, and the organisation negotiates fog.
Inventory work matters. It is dull in the way plumbing is dull until the kitchen floods.
But inventory without decision architecture creates another heavy spreadsheet looking for a home.
Suppose the crypto inventory returns with 800 systems, five high-risk suppliers, and limited budget. Who decides what moves first?
Not who coordinates. Who decides?
That one word saves months.
Decision Architecture defines the authority chain and the threshold for action. It tells the organisation when data longevity, customer impact, regulation, or supplier dependency forces movement.
It also prevents the classic committee waltz. Without architecture, every discussion starts again. With architecture, the room knows the choice: migrate, defer, accept risk, replace a supplier, or fund a control gap.
Quantum governance should not ask, “Which algorithm do we like?” first. It should ask, “What decisions must we make again and again as standards, suppliers, and threat assumptions move?”
That is the adult version of readiness.
Many governance systems remember activity but not reasoning.
They can show the meeting happened. Lovely. But ask why a decision was made, what assumptions mattered, who accepted the risk, and when the decision expires. Suddenly the room sends calendar invites.
Quantum migration will run for years. People will move roles. Vendors will change their stories. Standards will shift. Regulators will ask questions after everyone forgets the mood of the original meeting.
Decision Infrastructure gives the institution a memory: decision log, evidence map, dependency map, rhythm, and proof pack. Nothing glamorous. Which is usually how useful things behave.
For quantum, this matters because the organisation may need to defend a 2026 migration choice in 2029. The answer cannot be, “Dave had a rationale, but Dave now runs a vineyard in Portugal.”
Good for Dave. Bad for audit.
The Decision Layer gives the logic. The six control families give the machinery.
Governance owns the decision. Risk decides what matters first. Technical controls prove the estate can move. Third-party controls expose what sits outside your walls but inside your blast radius. Incident and recovery controls prepare for discovery. Assurance tests whether any of this works.
The weight will not sit evenly. Families one, two, and four will carry much of the pain: authority, materiality, and suppliers. That is where technical plans meet organisational reality.
This is where boards should lean in. Not to pick algorithms. Please don’t. To ask sharper questions.
If those answers do not fit on one clear page, the issue is not lack of information. It is structure.
Quantum will tempt organisations into theatre. New programme. New dashboard. New acronym soup. Everyone looks busy. The board gets comfort. The risk gets older.
A better organisation does something less dramatic and more useful.
It names the risk cleanly. It builds the authority to decide. It records the reasoning while memory is fresh. Then it runs the work through control families.
It is glamorous governance with its sleeves rolled up.
It shifts the question from, “When will quantum arrive?” to “Can we make the next hard decision before the future makes it for us?”