Quantum Risk Calculator

Is your firm ready for a quantum-based cyber attack? Use the quantum calculator to find out.

Quantum Risk Calculator

Quantum computers offer exciting possibilities for revolutionary advancements, but they also pose a significant threat to information security. Cryptographic methods that are secure against today’s computers will become vulnerable to quantum attacks. Consequently, organizations need to transition to “quantum-safe” cryptographic variants well before quantum computers become a reality.

The BITS Quantum Risk Calculator assesses the quantum computing threats to your organization, helping you understand when and how to take action to stay secure in a world with quantum computers.

  • Confidential data must remain secure for extended periods, often due to regulatory requirements or internal policies for data retention and privacy.
  • Often called change management (or change control), this is the time for technology teams to make change all necessary cryptography to quantum-safe variants. Industry transition timelines are typically 5-10 years for 90% of systems and then another 5-10 years for the remaining 10%.
  • This is a question that inspires debate even among experts in the field. If you are unsure, National Security Memorandum 10 proposes 2035 as a target date.
    For definitions, please refer to the glossary below. If you’re unsure, you likely use asymmetric cryptography—any secure, public-facing website relies on it.
  • This field is hidden when viewing the form
    Estimated arrival – current year
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
    How long until a large-scale (cryptographically relevant) quantum computer? – How many years will it take to upgrade your infrastructure? – Current Year
  • This field is hidden when viewing the form
    How long until a large-scale (cryptographically relevant) quantum computer? – How many years from now must your data remain confidential?
  • This field is hidden when viewing the form
    How long until a large-scale (cryptographically relevant) quantum computer? – How many years will it take to upgrade your infrastructure?:9
  • This field is hidden when viewing the form
    How long until a large-scale (cryptographically relevant) quantum computer? – How many years from now must your data remain confidential? – {How many years will it take to upgrade your infrastructure?
  • This field is hidden when viewing the form
    ( {How long until a large-scale (cryptographically relevant) quantum computer?:10} – {How many years will it take to upgrade your infrastructure?:9} ) – {How many years from now must your data remain confidential?:8}
  • This field is hidden when viewing the form
    ( {How long until a large-scale (cryptographically relevant) quantum computer?:10} – {How many years from now must your data remain confidential?:8}) – {Year:14}
  • This field is hidden when viewing the form
    Current Year + How many years from now must your data remain confidential? + How many years will it take to upgrade your infrastructure?
  • This field is hidden when viewing the form
    How many years from now must your data remain confidential? + How many years will it take to upgrade your infrastructure?
  • This field is hidden when viewing the form
    How many years from now must your data be secure? + How many years would it take to retool your infrastructure?
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
    Action required by the following date: Current Year + (Z-(X+Y))-1


Glossary

  • Cryptographically relevant quantum computer: A quantum computer powerful enough to break critical types of cryptography currently in use.
  • Asymmetric cryptography: Also known as “public-key” cryptography, it does not require shared secrets and includes digital signatures and public key encryption. Connecting to secure webpages via SSL/TLS, using banking apps, downloading software updates, and using credit card chips all rely on asymmetric cryptography.

    Example algorithms include RSA, elliptic curve cryptography (ECDSA, ECDH, EdDSA), and finite field cryptography (DSA).
  • Symmetric cryptography: This is encryption where both parties share a secret key (such as AES and 3DES). While asymmetric cryptography is used to securely exchange keys and establish connections (like in SSL/TLS protocols), symmetric cryptography is typically employed for the actual data encryption due to its efficiency. Most secure internet communications rely on a combination of both—using asymmetric cryptography for key exchange and authentication, and symmetric cryptography for encrypting the data transmitted.
  • Hash functions: Indispensable cryptographic tools used for authenticity, integrity, and randomness. Applications include authenticator apps and secure password storage. Examples include SHA-2 and SHA-3.
  • Quantum-safe cryptography: Also called “post-quantum” cryptography, it is based on new mathematical problems that should be hard to break for both quantum computers and today’s computers.

Acknowledgements

BITS would like to thank Dr. Michele Mosca and the Institute for Quantum Computing for developing foundational concepts that form the basis for this calculator.

BITS also acknowledges the National Institute of Standards and Technology (NIST) for leading the search for quantum-resistant cryptographic algorithms and for their innovative approaches to quantum cryptography.

Disclaimer: BPI is not responsible for any misuse of this calculator. It is intended for planning purposes only, and your organization should conduct a full internal risk assessment.