Quantum computing and post-quantum encryption: what to do now
Throughout 2026, quantum computing was on everyone’s lips again. The advances announced this year don’t mean that tomorrow someone will decrypt your emails, but they do confirm a trend that security specialists have been warning about for some time: the mathematics that today protect much of our digital information—passwords, transactions, records—have an expiration date. Sooner or later, a sufficiently powerful quantum computer could break the encryption methods we use every day.
Here it’s worth toning down the movie drama. That moment hasn’t arrived yet, and it’s probably years away. What matters for a Mexican company isn’t to panic, but to understand a very concrete risk and act with a cool head. Because there’s a part of the problem that already reaches us today, even though quantum computers aren’t ready yet. Let’s break it down.
The risk that already exists: “harvest now, decrypt later”
The most real danger isn’t in the future, it’s in the present. It’s known as harvest now, decrypt later. The idea is simple and a little uncomfortable. Someone with resources can intercept and store encrypted information right now—even if they can’t read it—betting that in a few years they’ll have the technology to open it.
This makes time a decisive factor. The data that doesn’t age well is what should worry you: medical records, contracts, tax information, intellectual property, your customers’ personal data. Everything that will still be sensitive five or ten years from now is precisely what’s worth protecting with more care today.
It’s not about locking everything down tomorrow, but about knowing which of your information will still matter a decade from now.
What post-quantum encryption is
The good news is that the answer already exists and doesn’t require any quantum computer to work. It’s called post-quantum cryptography: new encryption methods designed to resist both today’s computers and the quantum computers of the future. They run on the same hardware you already have; what changes is the mathematical “lock” underneath.
International standards bodies have already published the first recommended algorithms, and the major technology providers have begun incorporating them into browsers, messaging, and cloud services. In other words, this is no longer laboratory theory: it’s a transition that has already started and that, over the coming years, will make its way into the tools your company uses every day.
What this means for a Mexican small business
Here’s the reassuring part: a small business doesn’t have to become an expert in cryptography. Most of this transition will happen “under the hood,” in the platforms and services you already use. Your job isn’t to reinvent encryption, but to stay organized and make decisions with reliable information.
What is worth doing starting now:
- Know what data you have and which of it matters long-term. You can’t protect what you don’t know you have. A simple inventory of your sensitive information is the first step.
- Prefer providers that take security seriously. Ask your platforms and whoever develops your software what plans they have for this transition. A good answer is a sign of a serious partner.
- Keep your systems up to date. Much of the update will arrive as part of the normal updates to your tools; postponing them means falling behind without realizing it.
- Design systems that can evolve. When we develop custom software, it’s worth building it so that the encryption method can be changed tomorrow without rebuilding everything. That’s called cryptographic agility.
Where to start without alarmism
You don’t need a big project or a corporate budget. You need to start with something concrete and manageable:
- Make an inventory of sensitive data. Identify which information would still be delicate five or ten years from now. That’s your priority.
- Review how that information travels and is stored. Is it encrypted? Who has access? Which providers is it stored with? An honest assessment is worth more than any rushed purchase.
- Talk to your key providers. Ask them for their roadmap regarding post-quantum cryptography. Don’t expect everything to be solved; look for a plan to exist.
- Think ahead in your new developments. If you’re going to build or renew a system, put it in writing that it must allow its encryption to be updated without rebuilding it. You keep your data, processes, and history, and gain peace of mind.
Security isn’t about fear, but about anticipation. Quantum computing is just beginning its story, and the companies that put their data in order today will be the ones that arrive best prepared. If you want to know which of your information will still matter a decade from now, at Normandia Web we can help you make that assessment and take the first step calmly. Let’s talk.
Ready to put it to work in your company?
Tell us what’s costing you time, money or control. We’ll help you figure out where to start.
Start your consultation →