
One of your organisation’s biggest operational resilience incidents may have already happened. You just won’t know it for another ten years.
That is not a prediction about quantum computers. It is a statement about data.
Imagine that last year, an attacker quietly copied a large volume of your organisation’s encrypted information — customer files, transaction records, board papers. No ransom demand. No disruption. Because the data remained encrypted, no notification was triggered, and the incident was closed as low-impact.
For a decade, nothing happens. Then advances in quantum computing render that encryption obsolete, and information that appeared secure all along becomes readable.
So when did the resilience failure occur? Not on the day the data became readable — by then, nothing could be done. It occurred on the day the information was harvested, which was the organisation’s last chance to prevent the outcome.
This strategy — harvest now, decrypt later — makes quantum computing the first major business continuity threat whose impact occurs years after the incident itself. Every continuity framework in use today assumes the opposite sequence: event, disruption, response, recovery. Quantum reverses it. And there is no recovery from retroactive decryption.
A new dimension of risk: time
Conventional risk assessment weighs likelihood and impact, usually over the coming year. Quantum risk introduces a third dimension most enterprise risk frameworks have never considered explicitly: the lifetime of the information itself.
We call this Time Horizon Risk — the risk that the confidentiality lifetime of information exceeds the effective lifetime of the cryptography protecting it.
Its practical power lies in what it does not require. A board does not need to predict when quantum computers will arrive — a number nobody knows — to act rationally. It needs to know two things that are entirely knowable facts about its own organisation: how long its information must stay confidential, and how long a cryptographic migration would take. When those two numbers are large, uncertainty about the third is an argument for starting, not for waiting.
Consider a retail bank. A thirty-year mortgage originated this year carries confidentiality obligations running to the 2050s. If those records were harvested today and became readable in the mid-2030s, the bank would be notifying customers of a breach that happened more than a decade earlier — with twenty years of the obligation still to run.
And the exposure scales with concentration. A telecommunications operator does not merely hold its own secrets — it transports an economy’s worth of everyone else’s, and harvesting a satellite downlink requires an antenna, not an intrusion.
The dependency nobody maps
Operational resilience methodology asks firms to map their critical business services and everything those services depend on. Mature firms map data centres, cloud providers, telecommunications, payment infrastructure, key personnel.
Almost no one maps cryptography.
Yet encryption, digital signatures and public key infrastructure sit beneath virtually every service in those maps — onboarding, payments, remote access, software updates, electronic contracts. And cryptographic compromise fails differently from every other dependency: nothing stops. Services keep running comfortably within their impact tolerances while the confidentiality and authenticity they depend on has already been undermined. Availability metrics are silent on the question that matters.
Regulators are converging on the same conclusion
This is no longer a theoretical debate, because the regulatory traditions that shape Gulf supervision have both moved.
Europe has set the clock. The EU’s coordinated post-quantum roadmap, published in June 2025, classifies any use case as high-risk if a compromise of confidentiality ten or more years from now would still cause significant damage — and requires high-risk cases to be migrated by the end of 2030, with everything else following by 2035. Under that logic, long-lived data is high-risk today. For financial institutions, DORA’s technical standards already require monitoring of cryptographic threats, explicitly including quantum.
The United States has set the sunset. NIST finalised the first post-quantum standards in August 2024 and will phase today’s vulnerable algorithms out of its standards by 2035, with joint federal guidance framing the task in organisational terms: inventory your cryptography, prioritise by data longevity, engage your supply chain.
The financial stability community has joined them. The Bank for International Settlements has called quantum decryption one of the most significant cybersecurity threats facing the financial system and launched Project Leap to begin quantum-proofing it — and central banks take their cues from the BIS.
What this means in Qatar and the GCC
No GCC regulator has yet issued a binding post-quantum mandate — and any credible adviser should say so plainly. But the building blocks are visibly being laid at all three layers of the region’s regulatory architecture: central banks (QCB, SAMA, CBUAE) drawing on the BIS agenda; national cybersecurity agencies signalling quantum-safe guidelines and directing entities toward cryptographic inventories; and the financial centres (QFCRA, DFSA, FSRA), whose operational resilience regimes — including the QFCRA’s, effective October 2026 — mandate exactly the dependency-mapping methodology through which quantum readiness should be delivered.
Both traditions on which GCC frameworks are built now point at the same requirement. Only the timing is uncertain — and for groups operating across several Gulf jurisdictions, requirements will almost certainly arrive from multiple supervisors, on different schedules. Firms that build readiness once, on a sound resilience foundation, will answer every regulator from the same evidence base. Firms that wait will respond several times, reactively, at greater cost.
Where to start — and why it costs less than you think
Quantum readiness does not begin with buying anything. It begins with three assessments that extend work most well-governed firms have already done:
A data longevity assessment — adding a time dimension to your existing data classification. How long must each category of information remain confidential? Anything clearing the ten-year threshold is, by the EU’s own definition, high-risk now.
Cryptographic dependency mapping — extending the critical-service dependency maps your resilience programme already maintains to include the cryptographic trust each service relies on.
Crypto-agility in third-party risk — asking suppliers for post-quantum migration roadmaps, because your readiness can be no better than that of your critical vendors.
In the maturity model set out in our Boardroom Paper, these steps take an organisation from Unaware to Prioritised — the point at which it can demonstrate governed readiness to any supervisor, counterparty or acquirer. Reaching that point requires no new technology at all. Only governance.
The clock is not the quantum computer’s. It is your data’s.
Nobody knows when cryptographically relevant quantum computers will arrive, and this article will not pretend otherwise. But that uncertainty is precisely why the resilience framing matters: the relevant date is not the machine’s arrival — it is the moment your long-lived data was first exposed to harvesting. For most organisations, that moment has passed. What remains within your control is how much of what you hold tomorrow is still protectable.
Quantum resilience is not a technology refresh to schedule for the 2030s. It is a governance discipline whose first steps belong in this year’s plan.
Download LAMAH Boardroom Paper No. 1. This article is based on Quantum Resilience: Why Boards Must Govern Time, Not Just Technology — the first in the LAMAH Boardroom Papers series — which sets out Time Horizon Risk in full, the regulatory evidence base, the LAMAH Quantum Resilience Model and its five-level maturity assessment, the seven questions every board should ask, and a note on where quantum key distribution fits alongside post-quantum cryptography. Download the paper
The Quantum Readiness Briefing. For Boards and executive teams that want to go deeper, we deliver a focused briefing covering Time Horizon Risk, the regulatory direction of travel, and what quantum readiness means for your organisation — from the first classification exercise to a governed migration roadmap. If this is a conversation your Board should be having, get in touch to explore whether a briefing or a readiness assessment is the right starting point.
About LAMAH Intelligent Solutions
LAMAH Intelligent Solutions is a Qatar-based management consulting and enterprise IT firm. LAMAH operates across three lines of business—Consulting, Outsourcing, and Managed Services—and serves three core domains: Digital Transformation, IT GRC, and Corporate Integrated Risk Management. We advise on what to change and deliver how to do it—seamlessly combining business consulting with enterprise technology execution.
This article forms part of LAMAH Intelligent Solutions’ ongoing research on operational resilience, cybersecurity, digital resilience, and integrated risk management in an increasingly complex global environment.
Disclaimer
The views and information expressed in this article are provided for general informational and educational purposes only and do not constitute professional, legal, financial, regulatory, or investment advice. LAMAH Intelligent Solutions and the author(s) make no representations or warranties as to the accuracy, completeness, or suitability of the information contained herein and accept no liability for any loss or damage arising from reliance on it. Readers are advised to seek independent professional advice before making any decisions based on this content.


