
Quantum-Safe Networking: Why Encryption Decisions Made Today Matter in 2035
Encrypted data captured today can be decrypted later. Why quantum-safe networking is a present-day decision for organisations holding long-lived sensitive data.
Encrypted data captured today can be decrypted later. Why quantum-safe networking is a present-day decision for organisations holding long-lived sensitive data.

Most security problems demand attention because something is happening now. This one demands attention because of what will be possible later, and because the window to act closes before the threat arrives.
The reasoning runs as follows. Encrypted traffic can be captured and stored by anyone with access to the path it travels. Stored ciphertext does not expire. When cryptographically relevant quantum computing becomes available, the mathematics protecting today's public-key encryption becomes solvable. Data captured this year and held becomes readable in the year that capability arrives.
The industry calls this harvest now, decrypt later. It means the exposure decision is being made today, by every organisation transmitting data whose sensitivity outlasts the current cryptographic era.
FortiOS 8.0 includes quantum-safe capabilities among its new features, alongside AI-driven security and next-generation SASE. That inclusion reflects a broader shift in how the networking industry treats the problem: as an architectural requirement rather than a research topic.
Which data is actually at risk
Not everything needs quantum-safe protection, and treating the problem as universal produces expense without proportionate benefit. The variable that matters is how long the data stays sensitive.
Long-lived sensitive data is the concern. Patient records, financial and legal archives, intellectual property, government and defence material, engineering designs, and long-term contracts all retain sensitivity for decades. Data of this kind captured today remains valuable when decryption becomes feasible.
Short-lived operational data is not. A session token, a routine transactional message, or a stock level from last Tuesday carries no value once the moment passes. Retroactive decryption gains an attacker nothing.
The assessment question is therefore straightforward: for each data flow, how long would this remain damaging if it became readable. Anything answering in decades belongs in the migration plan. Anything answering in hours or days does not.
Why the timeline forces action now
Three periods stack, and organisations frequently consider only the last of them.
The first is data lifetime — how long the information stays sensitive after transmission. The second is migration time — how long the organisation needs to move its systems to quantum-resistant algorithms across an entire estate, including legacy applications, embedded devices, and third-party integrations. The third is the period until cryptographically relevant quantum capability exists.
If data lifetime plus migration time exceeds the time remaining before that capability arrives, the organisation is already exposed. Not exposed in future tense. Exposed now, in the traffic it is transmitting this week.
The uncomfortable part is that migration time is measured in years for any organisation of scale. Cryptography sits inside applications, appliances, protocols, and vendor products, much of it undocumented and some of it hardcoded. Organisations that start when the capability arrives will finish long after it matters.
What migration involves
Cryptographic inventory comes first, and it is the step organisations most underestimate. The question is where cryptography is used across the estate, which algorithms and key lengths, in which protocols, and inside which applications and appliances. Most organisations cannot answer this today. The inventory typically surfaces embedded certificates nobody knew existed and legacy systems using algorithms that were deprecated years ago.
Data classification by sensitivity lifetime follows, mapping each data flow to how long it stays sensitive. This produces the priority order for everything after it.
Crypto-agility matters more than any specific algorithm choice. Systems that hardcode cryptographic primitives require replacement when standards evolve. Systems designed so that algorithms can be swapped survive the next transition without another migration programme. Building agility now is the durable investment, because this is unlikely to be the last cryptographic transition.
Network layer migration is the practical starting point for most organisations, because network infrastructure can adopt quantum-resistant key exchange without touching the applications above it. Hybrid approaches that combine classical and post-quantum algorithms provide protection without discarding proven cryptography, which is why the industry has converged on them for the transition period.
Third-party and supply chain review closes the loop. An organisation's own migration means less if its critical suppliers and integrations continue transmitting its data over classical encryption.
The regulatory dimension
Saudi organisations under national and sector cybersecurity frameworks should expect quantum readiness to appear in future control revisions. Frameworks track industry consensus with a lag, and the consensus has formed.
There is also an evidence dimension worth anticipating. An organisation asked to demonstrate that it has assessed quantum risk will need a cryptographic inventory and a documented migration position. That artefact takes months to produce and cannot be assembled during an assessment.
Frequently asked questions
Is this a real risk or vendor marketing? The threat model is straightforward and does not depend on predicting a date. Encrypted data can be captured and stored now. If it stays sensitive long enough, it becomes readable eventually. Organisations holding decades-sensitive data face a present exposure regardless of when the capability arrives.
When will quantum computers break current encryption? Estimates vary widely and no responsible answer treats any specific year as reliable. The planning approach does not require one: the calculation compares data lifetime plus migration time against an uncertain horizon, which is why long migration timelines create exposure independent of the exact date.
Where should an organisation start? Cryptographic inventory and data classification by sensitivity lifetime. Both are useful work regardless of quantum timelines, and neither requires any procurement decision.
Does quantum-safe protection require replacing everything? No. Network layer migration protects data in transit without application changes, and hybrid approaches allow a phased transition. Full estate migration is a multi-year programme, which is exactly why it should start before it becomes urgent.
How ITBuilders supports cryptographic transition
ITBuilders assesses cryptographic posture across enterprise estates, covering inventory, data sensitivity mapping, and phased migration planning at the network layer. Because the same team operates the underlying network infrastructure, migration planning reflects what the estate can absorb without disrupting the services running across it.
To discuss quantum readiness, contact ITBuilders at 920-020-750 or itbuilders.com.sa
Related services
Turn this insight into a practical next step.
Discuss your environment with our team and get a clear recommendation grounded in your operational reality.


