UNCLASSIFIED · CLEARED FOR WIDE DISTRIBUTION
DT-D-2026-018 280900K JUN 26 CHANNEL: CYBER UPDATED 170900K JUL 26 READ TIME 11 MIN

Quantum readiness for health boards and executives: what to do now, what can wait

BLUF: BOTTOM LINE UP FRONT

A future quantum computer, powerful enough that the Australian Signals Directorate (ASD) calls it a cryptographically relevant quantum computer, will be able to break the public-key encryption that secures almost everything we send and store, including healthcare information. Healthcare leaders should take note of the latest advice from the ASD to stop relying on today's public-key encryption by the end of 2030, with a refined transition plan in place by the end of 2026. For healthcare the threat is already live, because attackers can harvest your encrypted patient data now and decrypt it later, and a medical record stays sensitive for a lifetime. The good news is that most of the work right now is planning and procurement, not ripping out encryption. This dispatch sets out 1. what healthcare executive teams should deliver now, and 2. what healthcare boards should govern, plus what both should deliberately leave alone. Updated 17 July 2026 with the questions ASD now recommends you put to your vendors, and what a weak answer sounds like. Scroll to the end for a quick one-page test for your role to help you get started on preparing for quantum.

YEARS LATER THE QUANTUM THREAT, IN ONE IDEA Harvest now, decrypt later. Encrypted patient data stolen today, unlocked years later. A record stays sensitive for a lifetime.
Harvest now, decrypt later: data taken today, opened years on. A medical record stays sensitive for a lifetime.

Why this significantly impacts healthcare

Most cyber threats are a concern as soon as the breach occurs. A future of quantum-based attacks is different. Adversaries can harvest your data now, store it in its encrypted format, and unlock it once technology is more advanced.

For a bank, much of the harvested data ages out. A card number gets reissued, a password gets rotated. Healthcare does not work that way.

You can re-issue a credit card. You cannot re-issue a patient's medical history.

A person's diagnoses, genetic information, mental health records and immunisation history stay sensitive for their whole life, and sometimes their family's. ASD's own triage guidance singles out data with "long-lived confidentiality requirements" as the first thing to protect. In healthcare, that is most of what you hold.

A second trap is your equipment. Infusion pumps, imaging systems and other connected medical devices run for ten to fifteen years and cannot always be patched. Some of what you buy this year will still be running, on its original cryptography, when the deadline arrives. That makes today's procurement a quantum decision, whether you frame it that way or not.

A third trap is the one most boards have not checked: insurance. Harvest now, decrypt later breaks the usual pattern of a cyber claim. The data leaves tonight, but the breach you must notify, and the harm to patients, may not surface for years, possibly after the policy has lapsed or renewed. Cyber policies are often written on a "claims made" basis, so a loss that crystallises long after the theft can fall into a gap. Do not assume you are covered. Ask your broker and insurer in writing whether the policy responds to data taken now and exploited years later, and consider an independent legal review of the terms. This is a question for your advisers, but one the board should make sure has been asked.

What the executive team should do now

ASD frames the transition in five phases it calls LATICE: locate, assess, triage, implement, and communicate and educate. The early phases are where executive effort belongs this year.

1. Start the cryptographic inventory

You cannot protect what you cannot see. Commission a cryptographic bill of materials, or CBOM. This is not a list of your sensitive data; it is a list of the locks: which encryption methods each system, application, cloud service and device uses. You need it because the quantum fix means replacing specific vulnerable algorithms, so you first have to find them. Start simple, even just the critical security functions you depend on. Mapping your high-risk data is a separate exercise, and comes next.

2. Put post-quantum clauses in every contract and renewal

The highest-leverage, lowest-cost move available today. From now on, every procurement, renewal and new medical device should ask the vendor how and when they will deliver post-quantum cryptography aligned to the ASD Information Security Manual. You are not buying anything new. You are refusing to lock yourself into another decade of obsolete encryption. ASD has now published the questions to ask, and they are set out below.

3. Map your long-lived sensitive data

The data inventory, companion to the CBOM. Identify the data with the longest confidentiality life: patient records, genomic data, research, anything kept for decades. That is your harvest-now-decrypt-later target list. Overlay it on the CBOM to see which vulnerable locks sit in front of your most sensitive data. That overlap sets your priority order.

4. Set the end-2026 plan milestone

ASD suggests a refined transition plan by the end of this year. Make it a board-visible milestone with a named owner, a budget line and the inventory feeding into it. A plan is not the work done; it means you know your starting position and priority order.

5. Stand up the working group and report up

Quantum readiness touches the whole organisation, so it needs a small cross-functional group, not a single overworked security chief (the CISO, your most senior cyber security executive). Which executive is accountable will vary, but the group should bring together ICT, security, procurement, clinical engineering, risk, health information management (HIM), privacy and clinical leadership. One executive sponsors it and reports to the board against the 2026, 2028 and 2030 milestones. Treat it like your cyber incident response: owned at the executive table, not buried in the ICT backlog.

What to ask your vendors

On 16 July 2026 ASD published Post-quantum questions to ask your vendors, a vendor-neutral question set for procurement, contract renewals and vendor assurance. It closes the gap in the advice above. It tells you what "ask the vendor about post-quantum" actually sounds like in a contract conversation.

This lands harder in health than in most sectors. ASD singles out environments where cryptography is embedded, difficult to update and tied to long asset lifecycles: operational technology, Internet of Things, building management systems, and physical access and security systems. Read that as your infusion pumps, your imaging fleet, nurse call, theatre systems, badge readers and the building itself. In vendor-managed and cloud services, ASD makes the point plainly: the vendor controls the cryptography, not you. Their readiness becomes your readiness.

ASD is explicit that you are not expected to ask every question of every vendor. Apply them according to the risk of the product, how much of the cryptography the vendor controls, how sensitive and long-lived the data is, and how far along your own transition is. The questions below are the subset that bite hardest in healthcare. The full set is in the ASD publication.

Locate: what cryptography is actually in there

The middle two decide whether a device is a patch or a purchase. A vendor who cannot update the firmware signing chain is telling you that device is a hardware replacement, and that belongs in the capital plan, not the security backlog.

Assess: whose data, and for how long

The data lifetime question is harvest now, decrypt later translated into procurement language. A vendor whose product assumes data ages out in seven years has not designed for a record that stays sensitive for eighty.

Triage: will it be ready in time

Hybrid modes are a bridge, not a destination. ASD does not prohibit them, but a quantum computer renders the traditional half obsolete, so a vendor treating hybrid as the finish line has stopped halfway.

Implement: is it real yet, and what does it cost

The licensing question is the sharp one, and it is the question nobody thinks to ask. ASD lists the treatment of post-quantum cryptography as an optional or premium function among the warning signs in vendor responses. If meeting a national deadline turns out to be an upsell, you have just found a cost your 2028 budget does not carry.

Communicate: what happens after the sale

What a weak answer sounds like

ASD names seven patterns worth a second look: limited visibility of cryptographic use; reliance on general assurances; unclear or deferred transition timelines; use of proprietary or opaque cryptography; treatment of post-quantum cryptography as an optional or premium function; over-reliance on compensating controls; and a lack of governance or ownership.

None of these is automatically disqualifying, and ASD is careful to say so. The more useful signal is whether a vendor will engage transparently, name its constraints and show progress. A vendor who says "we do not know yet, here is who owns it and when we will tell you" is in better shape than one who answers "we are quantum-safe." The first has a governance problem you can track. The second has a marketing department.

What the board should require

The board does not run the transition. Its job is to make sure the transition is real, resourced and on a deadline, the same governance discipline it already applies to clinical risk. These things belong on the board's agenda:

What should wait

Just as important is knowing where not to spend. Moving too early can cost more than moving on time, and the "quantum-safe" pitches in your inbox are selling tomorrow's product at today's premium.

The work that pays off in 2026 is knowing what you have and controlling what you buy. The cryptography swap comes later, through your vendors.

The board's one-page test

Six YES or NO questions for the board's next meeting. These are governance questions: they ask whether the work is owned, funded and on track, not how it is done.

DT-CHK-06 · BOARD · UNCLASSIFIEDYES / NO
Q1Is one named executive accountable for quantum readiness, with a budget line?Y  N
Q2Will we have a refined ASD-aligned transition plan by the end of 2026?Y  N
Q3Is it our policy that no major system or device is bought without a vendor post-quantum roadmap?Y  N
Q4Are we shown evidence of real progress against the 2026, 2028 and 2030 milestones, not just told it is on track?Y  N
Q5Do we know which long-lived sensitive data is most exposed to harvest-now-decrypt-later?Y  N
Q6Have we confirmed in writing that our cyber policy responds to a breach exfiltrated now but exploited years later?Y  N
Any answer that isn't a clear "yes" is an action item. Assign it an owner and a deadline before the meeting ends.

The executive team's one-page test

The companion checklist for the people delivering the work. These are delivery questions: they ask whether the early phases are actually moving.

DT-CHK-07 · EXECUTIVE · UNCLASSIFIEDYES / NO
Q1Have we started a cryptographic bill of materials, even a basic list of critical functions?Y  N
Q2Have we mapped our longest-lived sensitive data and set a priority order for transition?Y  N
Q3Are post-quantum clauses now standard in our procurement and renewal templates?Y  N
Q4Is there a cross-functional working group spanning ICT, security, procurement, clinical engineering, risk, HIM, privacy and clinical leadership?Y  N
Q5Are we holding the line against rushing ahead of standardised, ASD-approved implementations?Y  N
Q6Have we commissioned a review of our cyber insurance, including independent legal advice, on cover for a breach exfiltrated now but exploited later?Y  N
Any answer that isn't a clear "yes" is an action item with an owner and a date. Report the gaps up, do not absorb them.

The quantum threat sounds like a problem for physicists. The readiness for it is ordinary discipline split across two levels: the board governs and funds the plan, the executive team builds the inventory and controls what gets bought. The patients whose records you hold are trusting you to keep them private for the rest of their lives. The clock on that promise has already started.

If you want help building the inventory, writing the procurement clauses, or briefing your board, book a call with me directly.

Book a call
Dave Kempson
Dave Kempson FAIDH · FACHSM · CHCIO · Principal, Digital Tactics

Executive advisor and coach who has taken the 2am incident call. Former CIO and CDO of billion-dollar health systems in Australia and the United States, with 30 years of military leadership. Advises health executives and boards across Australia on cyber readiness, including post-quantum transition planning and the procurement decisions that lock it in.

FAQ

Quantum readiness, in brief

What is quantum readiness for a healthcare organisation?

Preparing your cryptography for the day a quantum computer can break today's public-key encryption. For health organisations it is mostly planning: inventory where you use cryptography, identify long-lived sensitive data, and put post-quantum requirements into procurement. ASD recommends a refined plan by the end of 2026 and a completed transition by the end of 2030.

What is a harvest-now-decrypt-later attack?

An attacker steals encrypted data today and stores it until a quantum computer can decrypt it later. No quantum computer is needed now, only access to your encrypted traffic, files or backups. Healthcare is acutely exposed because medical records stay sensitive for decades.

What is the ASD post-quantum deadline?

The ASD Information Security Manual recommends ceasing traditional asymmetric cryptography (RSA, Diffie-Hellman, ECDH and ECDSA) by the end of 2030: a refined plan by end of 2026, critical systems underway by end of 2028, transition complete by end of 2030.

Will Australia adopt the NIST post-quantum standards?

Effectively yes, through its own rulebook. ASD has written the NIST-standardised algorithms into the ISM as ASD-approved (controls ISM-1990 to ISM-1995 add ML-KEM and ML-DSA), so you comply with the ISM, not NIST directly. By 2030 the ISM requires the stronger settings ML-KEM-1024 and ML-DSA-87.

Should we buy quantum key distribution or quantum-safe products now?

Not yet. QKD uses physics rather than maths to share a key, but it needs specialised hardware, cannot prove who is on the other end, and does nothing for data already harvested, so ASD does not support it. Avoid products marketed as quantum-safe before vendors ship validated, ASD-approved algorithms. Spend on inventory, planning and procurement clauses instead.

What should we ask vendors about post-quantum readiness?

ASD published a vendor question set on 16 July 2026, covering cryptographic inventory, risk, transition timing, implementation and ongoing communication. You are not expected to ask every vendor every question; apply them by product risk, how much cryptography the vendor controls, and how long your data stays sensitive. In health the sharpest four are: is any cryptography hardcoded, fixed or hardware bound; what data lifetime does the product assume; which components need hardware replacement rather than a patch; and is post-quantum cryptography included in base licensing.

Who is responsible, the board or the executive team?

Both. The board governs: it requires an ASD-aligned plan, funds it, names an accountable executive, and reviews progress. The executive team delivers through a cross-functional group spanning ICT, security, procurement, clinical engineering, risk, health information management (HIM), privacy and clinical leadership. Readiness fails when each level assumes the other owns it.

Does cyber insurance cover a harvest-now-decrypt-later breach?

Do not assume so. The data is exfiltrated now, but the notifiable breach may not surface for years, possibly after the policy has lapsed. Cyber policies are often claims-made, so a late loss can fall into a coverage gap. Ask your insurer in writing, and consider an independent legal review of the terms.

References
  1. Australian Signals Directorate, Quantum technologies (guidance hub), cyber.gov.au.
  2. Australian Signals Directorate, Planning for post-quantum cryptography, last updated 22 September 2025.
  3. Australian Signals Directorate, Post-quantum questions to ask your vendors, 16 July 2026 (PDF).
  4. ASD Information Security Manual, Guidelines for cryptography, cyber.gov.au/ism.
  5. NIST, First three finalised post-quantum encryption standards (FIPS 203, 204, 205), August 2024.
  6. Office of the Australian Information Commissioner, Notifiable Data Breaches scheme (notification obligations for health information).

Join the distribution list

An occasional brief, no more than once a month, for senior leaders in health, government and defence: field-tested frameworks, the thinking behind my client work, and first access to new tools and dispatches. No selling, no noise.

NO MORE THAN ONE EMAIL A MONTH. UNSUBSCRIBE IN ONE CLICK.