Home / Solutions / Quantum computing

Quantum computing

This service is mostly about cryptography rather than about quantum computers. The realistic quantum question for an Australian business today is not what one could compute for you, but what one will eventually be able to decrypt.

For almost every organisation, quantum computing has no near-term application. The machines that exist are small and noisy, and conventional hardware outperforms them on essentially every commercially relevant problem. Anyone selling quantum optimisation for your logistics today is selling a research collaboration described as a product. We would rather say that plainly than build a practice on it.

What is genuinely urgent runs the other way. A sufficiently capable quantum computer would break RSA and elliptic curve cryptography, which is most of what protects data in transit today. That machine does not exist yet, but the risk is already live, because encrypted traffic captured now can be stored and decrypted later — the reason the approach is called harvest now, decrypt later. Anything you transmit today that must stay confidential into the 2030s is already exposed.

The remedy is standardised and available. NIST published the first post-quantum standards in August 2024 — ML-KEM for key establishment, ML-DSA and SLH-DSA for signatures — and Australian government guidance is moving on a comparable horizon, with the end of this decade the working assumption for systems handling sensitive information. The work itself is not exotic: a cryptographic inventory, a dependency and vendor review, and a staged migration. It is the same discipline as any other managed change. Starting now costs a project. Starting late costs an incident.

What is included

Cryptographic inventory

Where cryptography is actually used across your systems — protocols, key sizes, certificate chains, libraries and hardware — which is almost always broader than anyone expects.

Exposure assessment

Which data has a confidentiality lifetime long enough to be at risk from harvest now, decrypt later, and therefore has to move first.

Vendor and dependency review

The post-quantum roadmaps of the platforms and suppliers you depend on, since a good deal of the migration is theirs to deliver rather than yours.

Migration plan

A staged, prioritised plan to the published standards, with crypto-agility built in so that the next transition is a configuration change rather than another project.

Use-case assessment

An honest evaluation of whether any quantum computing application is relevant to you. Usually the answer is no, and it is delivered with the reasoning rather than as an assertion.

How it is delivered

  • Inventory before plan. A migration plan written without knowing where the cryptography actually sits will miss the embedded and vendor-supplied cases, which are the ones that take longest.
  • Prioritised by data confidentiality lifetime, so the information that must survive longest moves first.
  • Targets the published NIST standards rather than proprietary schemes, and builds in crypto-agility so algorithms can be changed again later.
  • Where the honest finding is that you have no quantum use case and a modest cryptographic exposure, that is the finding, and the engagement is small.

What you receive

  • Cryptographic inventory across systems, vendors and dependencies
  • Exposure assessment ranked by data confidentiality lifetime
  • Staged post-quantum migration plan with sequencing and effort estimates
  • Vendor readiness summary, with the questions to put to each supplier
  • Written assessment of quantum computing applicability to your business

What is not included

Stated plainly, because unstated exclusions are where disputes begin.

  • Access to quantum hardware, quantum compute time, or quantum software development. We do not operate quantum machines and do not resell access to them
  • Quantum algorithm research
  • Any prediction of when a cryptographically relevant quantum computer will exist. Nobody can supply that honestly, and a plan that depends on the date is a bad plan
  • Implementation of the migration itself, which is delivered under cyber security or managed IT once the plan is agreed
  • Certification or accreditation against any government cryptographic standard

Common questions

Is this not years away?

The machine is. The exposure is not. Traffic captured today can be decrypted whenever the capability arrives, so any data that must stay confidential into the 2030s is already at risk. That is the whole argument for starting now, and it is the only part of the quantum story with a clear commercial case today.

Can you run our optimisation problem on a quantum computer?

Almost certainly not usefully. Conventional hardware outperforms current machines on commercially relevant problems. If you want that tested rather than asserted, we will assess your specific case and report what we find, which so far has always been that classical methods win.

Do we need this if our systems are all cloud services?

Less of it, but not none. Much of the migration belongs to your providers, which is exactly why the vendor review exists — you need their timelines and the gaps those leave you with. Anything you encrypt yourself, and every long-lived certificate and signing key, remains yours to handle.