Author

Richard Crump, journalist

Quantum computing is beginning to move beyond experimental research, with practical, if narrow, uses emerging and commercial applications drawing nearer.

According to Quantum Global Intelligence, quantum computing vendors are projecting tangible business benefits by 2030 and accelerating their expected timelines to commercial scale over the next five to seven years.

‘Quantum computing warrants strategic attention today’

‘We’re no longer debating whether quantum computing is possible,’ says Scott Likens, chief AI engineer at PwC US. ‘The focus has shifted to the engineering challenges required to make it practical and scalable.’

Likens says that ‘meaningful’ progress in hardware performance, error correction and cloud access means that quantum computing ‘warrants strategic attention today’ for many businesses.

Global race

Around the world, governments and businesses are racing to establish leadership in what many see as the next strategic technology after AI. The US, UK, EU, China, Japan and Canada all have major national programmes, while Gulf states including Saudi Arabia, Qatar and the UAE are investing heavily through partnerships with global technology businesses.

‘There are numerous countries and localities investing in quantum technologies,’ says Scott Buchholz, CTO for public sector at Deloitte US. ‘The localities that are able to sustain investment and focus over the long term are more likely to see benefits over those who have intermittent or one-time pushes.’

Transformational

Quantum computers could prove transformative for solving highly complex optimisation and simulation problems. Buchholz points to two major trends in the market: quantum-inspired techniques that run on today’s hardware are already generating ROI and value, while credible vendor roadmaps are projecting commercially relevant quantum computers in 2028 and 2029.

‘The earliest benefits are likely to emerge in industries that rely on solving highly complex optimisation and simulation problems,’ Likens says. ‘Quantum computing could eventually help improve areas such as supply chain optimisation, drug discovery, materials science, energy efficiency, and cybersecurity.’

‘The economics point to cloud-based services’

For finance professionals, the opportunities extend well beyond faster calculations to areas such as scenario analysis, forecasting and capital allocation, particularly when combined with AI and advanced analytics.

‘The impact is likely to be felt first through improved insights, risk management and strategic decision support rather than core accounting processes,’ Likens says.

Buchholz believes organisations are already seeing benefits from quantum-inspired techniques. ‘They can accelerate and improve calculations for areas like derivative pricing and value at risk. We also know they can materially improve fraud detection in payment processing.’

In the cloud

For most organisations, however, access to quantum computing is unlikely to come through ownership of specialised hardware. Instead, it will increasingly be delivered through quantum computing as a service (QCaaS).

Cloud-based access lowers barriers to experimentation. Professor Julien Chaisse at the City University of Hong Kong says this will become the usual route through which banks, insurers, asset managers and market firms obtain quantum capacity. ‘The economics point in that direction. Quantum hardware is costly to build and operate. Access is scarce. Performance depends on frequent calibration. It also requires specialist staff and a tightly controlled computing environment.’

‘How do you control something you cannot directly audit?’

Relying on external providers to perform complex calculations will also create new governance challenges. Dyuti Pandya, an analyst at the European Centre for International Political Economy, says: ‘QCaaS creates a specific legal and regulatory problem. How do you demonstrate control, accountability and operational resilience over something you cannot directly audit, reproduce or exit from easily?’

Q-Day catastrophe

A further concern is the cybersecurity threat posed by quantum computing. The point at which quantum computers become powerful enough to breach encryption standards is fast approaching.

No one knows precisely when that moment – often referred to as ‘Q-Day’ – will arrive, but some experts now believe it could emerge as early as 2029, while others place it further into the 2030s, says Vikrant Rai, an advisory leader in Grant Thornton’s cyber and risk practice.

‘Leaders should be assessing encryption dependencies’

‘No-one can predict the exact timing of Q-Day with certainty because the technology continues to advance rapidly,’ he says. ‘What is clear is that organisations should begin preparing now. We are actively working with clients to assess quantum-related risks and build resilient controls, rather than waiting until the threat becomes imminent.’

The concern is heightened by the growing threat of ‘harvest now, decrypt later’ attacks, in which criminals steal encrypted data today with the expectation of decrypting it once sufficiently powerful quantum computers become available.

Mobilise now

Experts agree that organisations should prepare now to understand where they may already be exposed.

‘The most immediate concern is the long-term impact quantum computing could have on current encryption standards,’ Likens says. ‘Leaders should be assessing encryption dependencies, building crypto-agility and aligning with emerging post-quantum cryptography standards.’

‘Internal audit is uniquely positioned to connect the dots’

Internal audit has a critical role to play in ‘connecting the dots and ensuring the risks are being addressed from a futuristic standpoint’, Rai says. ‘As an independent third-line function, internal audit is uniquely positioned to assess whether organisations are implementing effective and resilient controls. Because internal audit has visibility across business functions, technology environments and governance processes, it can help organisations identify gaps, assess readiness and drive greater accountability for risk.’

One of the first steps is to develop an inventory of sensitive data, encryption use cases and cryptographic dependencies, and to understand which cryptographic standards protect it.

‘At this stage, the focus is largely on governance,’ says Alex Hinkebein, a senior manager at Grant Thornton Advisers LLC. ‘Organisations need to understand their data inventory, identify where sensitive information resides, evaluate the controls protecting that data, and establish accountability for managing cryptographic risk.’

Advertisement