LeadershipNot yet confirmed elsewhere1 publisher3 min readPublished
Harvest now, decrypt soon: post-quantum migration is a funded program, not a research topic
A Forbes Tech Council argument for urgency leans on benchmarks that were never factoring runs. The part of it that survives scrutiny is still enough to justify the spend.
The Board Room · Leadership desk
What happened
- Amentum's CTO for Intelligence and Cyber argues in a Forbes Tech Council post that quantum cyberattacks are now a CIO deadline rather than a research topic.
- His case starts with Google's 53-qubit Sycamore in 2019, credited with a 200-second calculation valued at 10,000 supercomputer-years.
- It then cites the 105-qubit Willow clearing a benchmark in under five minutes against an estimated 10 septillion classical years.
- China is reported to have committed more than $15 billion to quantum technology, including Hefei's Quantum Avenue and a national quantum information laboratory.
- NIST has finalised its first post-quantum standards, ML-KEM for key establishment and ML-DSA for digital signatures.
Why it matters
- decision The funding question changes from when RSA breaks to which traffic must stay secret past the migration, and the second one can be answered from retention schedules this quarter.
- cost Scope is every system holding an RSA or ECC key, so the bill is an estate-wide inventory and replacement program on the CIO's budget rather than a library upgrade.
- constraint With the standards published, vendors can no longer defer on the grounds that the algorithms are unsettled, and the remaining lag is contractual and integration work buyers must chase.
- contradiction The urgency rests on speedup figures from problems that were not key-breaking, so a board asking for the date at which current keys fail will not find it in this argument.
Begin with the part of the case that does not depend on a hardware forecast. Harvest now, decrypt later assumes an adversary copies ciphertext today, stores it, and waits for a machine that can run Shor's algorithm against the key that protected it [7]. Karisik's revision, harvest now decrypt soon, is a claim about the wait being shorter than most CIOs budgeted for [15]. The operative variable sits on the other side of that equation: how long a given flow of traffic has to stay secret. Anything with a ten-year confidentiality requirement leaving the building today under RSA or ECC is already committed [6]. That is a records-retention question, and it can be answered without knowing when a cryptographically relevant quantum computer arrives.
Now the hardware figures, which do less work than their size suggests. Sycamore in 2019 had 53 qubits and a calculation the piece values at 10,000 supercomputer-years [4]. Willow has 105 qubits and a benchmark valued at 10 septillion classical years [2]. Qubit count roughly doubled [8]. The claimed classical-equivalent time rose by a factor of about 10^21 [9]. Those two numbers describe different benchmark problems, and neither run was an attempt to factor a key; the article names no qubit count and no date at which RSA or ECC would actually fall [5]. The figure in that set that bears on cryptanalysis is the third one, a logical error rate twenty times below Sycamore's [12], because factoring needs error-corrected logical qubits held stable through a very long circuit rather than a headline peak count. The piece's own nod to below-threshold error correction points at exactly that [15].
So the defensible version of the argument is narrower than the "mathematical cliff" framing [10], and more useful. The state space grows exponentially with each qubit [11], Shor's algorithm turns that into an attack on both factoring and discrete logarithms [13], and a state reported to have committed more than $15 billion, with dedicated campuses at Hefei, is a plausible funder of a decade-long build [14]. None of that produces a date. NIST produces a date: with ML-KEM and ML-DSA finalised [1], the schedule for a migration program is set by asset inventory, vendor support and integration testing rather than by a standards committee. The delay has moved into procurement, where the CIO owns it.
Worth noting who is making the case. It comes from the CTO for Intelligence and Cyber at Amentum, writing as a Forbes Tech Council contributor [3], which is an interested party arguing for urgency. The interest does not make the argument wrong. It does mean the load-bearing items for a board paper are the two that can be checked independently: the standards are published, and the traffic you are sending this quarter has a retention life you already know.
What to watch
- Published hardware resource estimates for factoring RSA-2048, which would turn the migration schedule from rhetoric into an arguable number.
- Whether ML-KEM and ML-DSA start appearing as procurement and contract requirements rather than vendor roadmap items.
- Whether the next processor generation repeats Willow's order-of-magnitude gain in logical error rate or stalls short of it.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence38
- Adoption36
- Hype gap+42
- Incentives78
- Confidence48
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
NIST has finalized its first official standards for post-quantum cryptography, including the lattice-based algorithms ML-KEM for key establishment and ML-DSA for digital signatures.
- [2]
Google's Willow processor, equipped with 105 qubits, solved a benchmark problem in under five minutes that a leading classical supercomputer would take an estimated 10 septillion years to complete.
- [3]
The argument is made by Adi Karisik, Vice President and Chief Technology Officer, Intelligence & Cyber, at Amentum, in a Forbes Tech Council post on forbes.com headlined 'Quantum Cyberattacks Are Now A CIO Deadline, Not A Research Topic'.
- [4]
In 2019 Google's 53-qubit Sycamore processor achieved 'quantum supremacy', completing a highly specific, abstract calculation in roughly 200 seconds that would have taken a supercomputer an estimated 10,000 years.
- [5]
The two cited demonstrations are different benchmark problems, neither described as a factoring run, and the piece states no qubit count, error rate or date at which RSA or ECC keys would fall.
- [6]
RSA and ECC secure national security, banking, healthcare, cloud databases, VPNs and digital signatures, and depend on the near impossibility for classical computers of factoring very large primes or solving discrete logarithms within a human lifetime.
- [7]
Intelligence agencies have warned for years about 'harvest now, decrypt later': foreign adversaries intercept and store large volumes of encrypted data without breaking it, waiting for fault-tolerant quantum systems to mature.
- [8]
Qubit count roughly doubled between the two cited Google processors, from 53 on Sycamore to 105 on Willow (a factor of about 1.98).
- [9]
The claimed classical-equivalent runtime cited for the two demonstrations rose from 10,000 years (10^4) to 10 septillion years (10^25), a factor of roughly 10^21, while qubit count only doubled.
- [10]
The piece states that the enterprise cybersecurity playbook faces an 'impending mathematical cliff' and that the quantum threat to public-key cryptography is transitioning from a theoretical future to an immediate risk.
- [11]
Unlike classical computers, where added processing elements increase capacity incrementally, each additional qubit expands the number of possible computational states exponentially.
- [12]
Willow's logical error rate is 20 times lower than Sycamore's.
- [13]
Quantum computers running Shor's algorithm bypass that mathematical barrier, and the author says quantum architectures are rapidly approaching the scale needed to factor RSA and ECC public keys in a matter of minutes.
- [14]
Public policy data cited in the piece indicates China has made quantum technology a strategic priority with an estimated commitment surpassing $15 billion, including infrastructure hubs such as Hefei's 'Quantum Avenue' and the National Laboratory for Quantum Information Sciences.
- [15]
The author says below-threshold error correction and advanced chips are compressing timelines, reframes the risk as 'harvest now, decrypt soon', and says proprietary IP and strategic roadmaps transmitted over public networks today are vulnerable to exposure in the near, predictable future.
Sources
1 independent publisher whose own reporting we read for this story.
- forbes.comQuantum Cyberattacks Are Now A CIO Deadline, Not A Research Topic
1 article · August 21, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Harvest Now, Decrypt Later ThreatFollow
- Security Compliance MandatesFollow
- Quantum Computing HardwareFollow
- CIO Risk And Program PlanningFollow
- Post-Quantum CryptographyFollow
Entities
- Adi KarisikFollow
- AmentumFollow
- Forbes Tech CouncilFollow
- GoogleFollow
- SycamoreFollow
- WillowFollow
- National Institute of Standards and TechnologyFollow
- ML-KEM (Kyber)Follow
- ML-DSAFollow
- Elliptic Curve CryptographyFollow
- Shor's AlgorithmFollow
- CNSA 2.0Follow
- National Security AgencyFollow
- ANSSIFollow
- Executive Orders 14412/14413Follow
- Quantum Key DistributionFollow
- National Laboratory for Quantum Information SciencesFollow
- RSAFollow