Is Quantum Computing the Next Systemic Cyber Threat?

Is Quantum Computing the Next Systemic Cyber Threat?

Simon Glairy is a titan in the Insurtech space, currently navigating the turbulent waters of systemic risk and technological evolution. As a specialist in AI-driven risk assessment, he has watched the cyber landscape shift from simple phishing to sophisticated state-sponsored maneuvers that threaten the very fabric of digital trust. In our discussion, we explore the jarring disconnect between rising claim frequencies and falling premiums, the looming shadow of “Q-Day,” and how the “harvest now, decrypt later” strategy is already creating a silent backlog of future catastrophes. We also dive into the shifting role of underwriters who must now look beyond basic backups and multifactor authentication toward a more resilient future defined by cryptographic agility.

The recent data from the National Association of Insurance Commissioners shows a startling trend where US cyber claims have jumped nearly 40% to almost 50,000, yet direct written premiums have actually dipped by 7% to about $9.14 billion. How do you interpret this disconnect, and what does it suggest about the current stability of the cyber insurance market?

This divergence is a bit of a wake-up call for the industry because it suggests we are working in a hyper-competitive environment that might be underpricing the actual volatility of the risk. When you see claims volume hitting nearly 50,000 in a single year while the total premium pool shrinks to $9.14 billion, it tells you that insurers are fighting tooth and nail for market share even as the frequency of loss events accelerates. It feels like a race to the bottom in terms of pricing, which is dangerous when the underlying threats are not just staying steady but are becoming more expensive to remediate. We are seeing a “softening” market where capacity is high, but that 40% surge in claims serves as a cold reminder that the peace is fragile. If this trend continues, carriers will eventually have to reckon with the fact that they are collecting less money to cover a much larger and more active field of fire.

With ransomware appearing in 44% of breaches and a 34% increase in vulnerability exploitation, the digital perimeter seems more porous than ever. Could you walk us through the evolution of these threats and why traditional defenses like virtual private networks are becoming such high-stakes targets?

The shift we are seeing is a move away from the “spray and pray” phishing tactics of the past toward highly targeted exploitation of the tools we actually use to secure our networks. When attackers focus on zero-day vulnerabilities in perimeter devices and VPNs, they aren’t just knocking on the door; they are finding a flaw in the lock itself. The 34% jump in vulnerability exploitation is particularly concerning because it shows that threat actors are becoming much faster at weaponizing flaws before a patch can even be conceived. It creates a sense of constant siege for IT teams who thought they were safe behind their encrypted tunnels. Using a VPN is no longer a silver bullet if the gateway itself is the weakest link, leading to a landscape where 44% of breaches result in the devastating financial and operational paralysis of ransomware.

The concept of ‘Q-Day’ often feels like a plot from a science fiction novel, yet experts suggest a code-breaking quantum computer could be just a decade or two away. From a risk management perspective, how do we begin to quantify a threat that could theoretically shatter the very foundations of public-key systems like RSA?

Quantifying quantum risk is an exercise in preparing for a “zero-day” event that targets the entire world simultaneously rather than just one piece of software. The GAO has placed the arrival of a cryptographically relevant quantum computer somewhere between 10 and 20 years away, which might sound like a long time until you realize how deeply embedded RSA and elliptic-curve cryptography are in our global infrastructure. We are talking about the potential for absolute havoc where every digital signature, online transaction, and sensitive database becomes transparent. As underwriters, we have to stop looking at this as a distant abstraction and start viewing it as a systemic exposure that could trigger concentrated losses across every sector at once. It is a looming threat to the very idea of “confidentiality,” and our current risk models are only just beginning to grasp the scale of a world where traditional encryption is essentially useless.

One of the most chilling concepts mentioned in recent reports is the ‘harvest now, decrypt later’ strategy. What are the long-term implications for sectors like healthcare or government when data stolen today can be weaponized years down the line?

The “harvest now, decrypt later” phenomenon is perhaps the most insidious aspect of the quantum threat because it means the breach has already happened, even if the damage hasn’t been realized yet. Threat actors are currently vacuuming up encrypted medical records, financial histories, and government secrets with the full intention of sitting on that data for a decade or more until a quantum machine can unlock it. For a patient whose sensitive medical data is stolen today, the privacy violation is a “time bomb” that might explode in 2035, long after the original incident has been forgotten by the public. This creates a massive tail of liability for insurers and a permanent loss of security for individuals whose “long-lived” data must remain confidential for decades. We are essentially watching a silent robbery of the future, and it makes the need for post-quantum encryption a matter of immediate urgency rather than a future project.

Washington is clearly accelerating its response, with a June 2026 executive order setting strict deadlines for post-quantum cryptography by 2030 and 2031. How realistic are these timelines for federal agencies and critical infrastructure, and what does this mean for the private sector contractors caught in the middle?

The timelines set by the June 2026 executive order are incredibly aggressive, requiring federal high-value assets to transition their key establishment by the end of 2030 and digital signatures by 2031. For massive federal bureaucracies and aging critical infrastructure, this is going to be a monumental lift that feels like trying to change the engines on a plane while it’s mid-flight. It isn’t just about the government; federal contractors are being pulled into this vacuum with procurement rules that demand compliance by December 31, 2030. NIST finalized its first three post-quantum encryption standards in August 2024, but knowing the standard and actually implementing it across legacy systems are two very different things. Those who fail to pivot fast enough will find themselves uninsurable or, worse, legally barred from the very contracts that sustain their businesses.

As the threat landscape shifts toward these systemic quantum risks, how must the role of the cyber underwriter evolve beyond simply checking for multifactor authentication and standard backups?

The underwriter of the future has to move away from the basic “hygiene” checklist and start acting more like a forensic technologist who understands the guts of a company’s cryptographic architecture. We are going to start asking much harder questions, such as whether an organization maintains a detailed inventory of its cryptographic assets and which of its third-party vendors are still relying on vulnerable, legacy algorithms. The key term here is “crypto-agility”—the ability for a company to swap out an entire encryption method without having to tear down and rebuild their entire IT stack. If a business isn’t agile, they are a sitting duck for Q-Day, and insurers will likely start pricing that lack of flexibility into their premiums. It’s no longer enough to have a backup; you have to prove that your data will still be a secret ten years from now.

What is your forecast for the future of encryption and the industry’s ability to adapt to these looming systemic threats?

My forecast is a “glass-half-full” view where we see a high-stakes arms race between the destructive power of quantum computing and the innovative potential of quantum-proof encryption. While quantum machines will undoubtedly create the ability to cause mayhem on an unprecedented scale, I believe the same technological leap will provide us with new, more robust models of security that we can’t even fully imagine yet. We have seen this cycle before: every time a new technology emerges that threatens to break our systems, we eventually learn how to adapt and build something even stronger. The transition period will be incredibly messy and likely filled with “absolute havoc” for those who are slow to move, but I am confident that the industry will emerge with a more resilient, crypto-agile framework that can withstand the next century of threats.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later