By exploiting the properties of quantum mechanics, high-performance, fault-tolerant quantum computers offer the tantalizing prospect of solving certain classes of problems that remain intractable even for today’s most advanced computers.
In particular, they are expected to excel at combinatorial optimization, enabling the creation of ultra-efficient supply chains and optimal investment portfolios. The benchmark example of this is the “traveling salesperson problem,” where the challenge is to find the shortest possible route for sales calls across a set of geographically dispersed cities. With five cities to visit, the number of possible routes is just 24. But the complexity grows exponentially as more city stops are added, and by 20 the calculation needs to consider more than 6 quadrillion possible routes: impossible for a classical computer but (theoretically) quick and easy for a quantum computer.1
Aside from combinatorial optimization, quantum computers are also expected to dramatically speed up the solving of differential equations, thereby enhancing the modeling of complex systems ranging from chemical reactions to climate dynamics. And they promise to revolutionize linear algebra and so accelerate tasks such as the training of AI models and the detection of intricate fraud patterns.
But this disruptive technology also carries a big downside. Quantum computers are particularly adept at factorization – the decomposition of numbers into their factors. The issue with that: the public-key cryptography that underpins the security of much of today’s digital landscape (RSA) relies on the fact that conventional computers find factorization – especially of large primes – difficult, if not impossible.
Moreover, another widely used approach to public-key cryptography, known as elliptic-curve cryptography (ECC), relies on the difficulty of computing the so-called elliptic curve discrete logarithm problem. That is also at risk from the potential capabilities of quantum technology.
In short, quantum computers will effectively be able to break the encryption methods that protect current digital assets and communication systems across business, government, and personal domains.
Two threats stand out as the most pressing. One is the “harvest now, decrypt later” scenario: sensitive data that is secret now can be captured by malicious actors to be deciphered and exploited when quantum machines become operational.
Estimates of when that moment – often referred to as “Q-Day” – will arrive vary widely. Many experts expect the emergence of a cryptographically relevant quantum computer capable of breaking widely used public-key encryption in the timeframe of 2030 to 2040. In response, regulators and government agencies worldwide are urging organizations to undertake a complete migration of systems to implement post-quantum cryptography (PQC) by 2035.
The second major threat involves the long life cycle required by many security systems. An ID card, a driver’s license, or a passport, for example, must remain trustworthy for 10 years or more. So, building in quantum resistance before the emergence of powerful quantum computers is vital.



