IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Post-quantum cryptography: are we sleepwalking into the next Y2K moment?

Post-quantum cryptography: are we sleepwalking into the next Y2K moment?

Tue, 21st Jul 2026 (Yesterday)
David Land
DAVID LAND VP for Asia Pacific and Japan Gigamon

For many organisations, post-quantum cryptography (PQC) still feels like a distant problem. Even something to worry about in the next decade, not the next budget cycle.

That mindset should sound familiar.

In the late 1990s, the looming Y2K bug was (at least at first) widely dismissed as overblown. Systems continued to run, deadlines slipped, and many assumed the issue would resolve itself. It didn't. What followed was one of the largest coordinated remediation efforts in IT history, a race against time to identify, fix, and validate systems before a hard, immovable deadline. While systems were still complex back in those days, and audits had to consider everything from mainframes running a pool of MS-Dos based endpoints right down to the computers running a CEO's car to work each day, they bear little resemblance to the modern world, where nearly every component of our public and private lives are governed by technology.

Today PQC presents a similar inflection point. It is time to evaluate every fine detail of organisational risk, and gauge where the company stands. The difference is that this time, the clock is less visible, and the risks are infinitely greater.

The invisible threat already underway

Unlike Y2K, post-quantum risk isn't tied to a single date rollover. It is already unfolding.

The concept of "harvest now, decrypt later" means attackers are collecting encrypted data today with the expectation that future quantum computers will be able to break it. Sensitive intellectual property, financial data, and government communications are all potential targets.

This is not theoretical. The cryptographic algorithms that underpin modern digital trust such as RSA, Diffie-Hellman, and elliptic curve cryptography are expected to become vulnerable in a post-quantum world. 

Plus, critically, data has a shelf life. If information needs to remain confidential for 5, 10 or 20 years, then the risk is immediate rather than deferred.

Why PQC is harder than Y2K

The Y2K challenge was, at its core, a code remediation problem. PQC is far more complex.

Cryptography is deeply embedded across modern environments, from applications and APIs to IoT devices, operational technology, and third-party services. In many cases, organisations don't have a complete inventory of where cryptography is being used, let alone how.

Transitioning to PQC requires organisations to:

  • Identify every system using classical cryptography 
  • Understand the sensitivity and lifespan of the data it protects 
  • Prioritise and execute a phased migration 
  • Continuously monitor for legacy cryptographic use 

This is not a one-off upgrade. It is a multi-year transformation that spans infrastructure, software supply chains, and vendor ecosystems.

The 2030 deadline is closer than it looks

Government guidance is starting to sharpen timelines.

In Australia, the ASD has flagged that several widely used cryptographic algorithms will no longer be approved beyond 2030. 

Globally, similar deadlines are emerging, with phased transitions expected through to 2035.

At first glance, that may seem like ample time. But history tells us otherwise.

Large-scale cryptographic migrations are notoriously slow. Dependencies are complex, testing cycles are long, and legacy systems often cannot be easily upgraded. Just as with Y2K, organisations that delay will find themselves compressing years of work into months, with far higher risk and cost.

You can't fix what you can't see

If there is one lesson from both Y2K and today's cyber landscape, it is this; visibility is everything.

More than 90 percent of internet traffic is now encrypted, and attackers are increasingly using encryption to evade detection. 

At the same time, many organisations lack visibility into how cryptography is actually being used across their environments, particularly in hybrid cloud, unmanaged devices, and shadow IT.

This creates a critical blind spot.

Before organisations can transition to PQC, they must first answer a fundamental question: Where is cryptography in use, and what data is it protecting?

Network-derived telemetry offers a scalable way to address this challenge. By analysing traffic flows and metadata, organisations can discover cryptographic usage across both managed and unmanaged assets without relying solely on agents or manual inventories.

This "outside-in" visibility is essential for identifying risk, prioritising remediation, and ensuring that PQC adoption doesn't introduce new gaps.

Avoiding a repeat of history

The Y2K effort ultimately succeeded, but only because organisations mobilised early, invested heavily, and treated the problem as a business-critical priority.

PQC demands the same mindset.

The transition will not happen overnight. It will require coordination across security, infrastructure, development and compliance teams, as well as close alignment with vendors and partners.

Most importantly, it requires a shift in perspective.

Post-quantum cryptography is not just a future security upgrade. It is a present-day data risk issue, a visibility challenge, and a governance priority.

The organisations that act now by building inventory, improving visibility, and developing transition plans, will be best positioned to navigate the shift.

Those that wait may find themselves in a familiar position - facing a known problem, against a fixed deadline, with far less time than they expected.