Published Leadership3 min read
The quantum program died in nine months. The clock it was funded to beat did not.
A risk executive's account of a shelved quantum program argues the mistake was structural: quantum is an input to the six control families you already run, scored heavy, medium or light, not a seventh box with a logo on...
Context for builders, not their beat.See today for builders

What happened
- Maman Ibrahim, described as a cyber and digital risk executive who helps boards, CROs, CIOs and CISOs turn risk work into decisions, delivery and proof, wrote the Forbes Technology Council piece 'Quantum Risk Doesn't Need A Program - It Needs Six Scores'.
- A quantum program launched last spring was effectively dead within nine months. It had a name, a budget line and a logo on the deck, and produced one tool evaluation and nothing else.
- The standards had not settled, so the committee shelved the program.
- Programs start, spend and stop; quantum is a risk class, and risk classes do not wait for a budget cycle.
- An organisation's architecture already has six control families: governance, risk, operational, third-party, incident and assurance. Every regulation belongs somewhere within those six, and so does quantum risk, which is a new input to that structure rather than a reason to create another.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
A quantum program launched last spring had a name, a budget line and a logo on the deck, and within nine months it was effectively dead, having produced one tool evaluation and nothing else [2]. It was shelved because the standards had not settled, according to cyber and digital risk executive Maman Ibrahim, writing for Forbes [1][3]: one deliverable per nine months of funded attention [23], on a risk whose second clock does not stop when a committee does [7].
Ibrahim's argument is structural rather than technical. The architecture already carries six control families, governance, risk, operational, third-party, incident and assurance, and every regulation on the desk already lands in one of them, as does quantum [5]. A named program is a seventh box, and programs start, spend and stop, while a risk class does not wait for a budget cycle [4]. Two timelines run through all six families: the one you control, finding where cryptography lives and making it changeable [6], and the one you do not, in which harvested encrypted data becomes decryptable once a cryptographically relevant quantum computer exists, with no evidence of the copying ever reaching you [7].
The instrument proposed is a score, not a charter. Each family gets one word: heavy where the gap is significant or depends on decisions outside your authority, medium where you know what needs to happen and have not done it, light where you could produce the answer this week with evidence [8]. Run it with the people who own architecture, vendor management, the data taxonomy, the incident playbook and decision approval [9].
The tests are cheap and unflattering. Governance reads light on a single page stating that you are not migrating X until Y because Z, with an owner and a review date, and heavy when nothing is in writing and "we are watching the standards" is the policy; minutes alone do not count [10]. Risk asks which systems hold data whose confidentiality must outlive 2035 and which cross networks you do not control, and that answer either arrives in minutes or has not been operationalised [11]. The fix is one inventory field, a confidentiality horizon of under three years, three to 10, or more than 10, with the longest horizons crossing networks you do not control forming the priority list [12]. Note the overlap: from 2026, 2035 sits nine years out, so the test bites inside the middle bucket, not only at the long tail [25]. Operational asks you to pick one high-value system and measure what swapping its algorithm actually costs in teams, dependencies and coordination [13]. Third-party asks which contracts let you require a change rather than request one, given that your cryptography also sits in vendor products, supplier build pipelines and cloud key management [14]. As Ibrahim puts it, you can instruct your own engineers, and suppliers can only be asked [15]. Incident asks who decides, the morning a working quantum machine is announced, whether that is an incident or the news, and whether you can re-key at scale without taking a service offline [16].
Forbes ran the opportunity case the same day, and it points the same direction on funding [24]. Scott Buchholz, CTO of Deloitte Consulting's Government and Public Services practice, writes that he has seen quantum initiatives parked in innovation departments with little accountability for ROI, which he treats as the exception rather than the model [17][20]. His prescription is small: a couple of data scientists or engineers already on staff, a Ph.D.-level specialist or part-time adviser, budget for training, sandboxes and a few priority use cases, and a stop rule when a method does not beat the current one [21][22].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Maman Ibrahim, described as a cyber and digital risk executive who helps boards, CROs, CIOs and CISOs turn risk work into decisions, delivery and proof, wrote the Forbes Technology Council piece 'Quantum Risk Doesn't Need A Program - It Needs Six Scores'.
- [2]
A quantum program launched last spring was effectively dead within nine months. It had a name, a budget line and a logo on the deck, and produced one tool evaluation and nothing else.
- [3]
The standards had not settled, so the committee shelved the program.
- [4]
Programs start, spend and stop; quantum is a risk class, and risk classes do not wait for a budget cycle.
- [5]
An organisation's architecture already has six control families: governance, risk, operational, third-party, incident and assurance. Every regulation belongs somewhere within those six, and so does quantum risk, which is a new input to that structure rather than a reason to create another.
- [6]
The first timeline is the organisation's own: find where cryptography lives, then make it changeable. That pace is controlled and measurable by the organisation.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- forbes.comMaman Ibrahim, Forbes Councils MemberAug 13Quantum Risk Doesn't Need A Program—It Needs Six Scores
- forbes.comScott Buchholz, Forbes Councils MemberAug 13How Leaders Can Pursue A Strategic Path To Quantum Computing
Additional citations
- Maman Ibrahim, Forbes
- Scott Buchholz, Forbes



