Risks of quantum computers
In October 2025, Singapore released a draft guide on how organizations can implement “quantum-resistant solutions” to overcome the risks posed by quantum computers (e.g., data loss, cryptocurrency theft, etc.). Thus, “Q-day” marks the beginning for the spread of quantum computers (in the next 5-10 years), which will capable of cracking cryptographic methods of28 network data encryption (up to 100
Из выпуска мониторинга No. 10 (22), October 2025 · выпуск целиком, PDF · на сайте Института Гайдара

The Singapore experience
In October 2025, Singapore released a draft guide on how organizations can implement “quantum-resistant solutions” to overcome the risks posed by quantum computers (e.g., data loss, cryptocurrency theft, etc.). Thus, “Q-day” marks the beginning for the spread of quantum computers (in the next 5-10 years), which will capable of cracking cryptographic methods of1 network data encryption (up to 100 million2 times faster than classical computers ), less vulnerable encryption (such as blockchain networks), and critical infrastructure (banks, government systems).
Quantum threats pose a risk of leaking both personal data and commercial and state data, including the risk of “collect now, decrypt3 later” . System failures are also the risk (if access to dispatch control systems for industrial and engineering facilities, housing and utilities is intercepted). As a result, compromised access elements (such as digital signatures) lead to the risk of financial manipulation (e.g., cryptocurrency theft or in transactions) or data alteration. To prevent threats, organizations can implement “quantum-resistant solutions.” The following is required:
1. Assess the risks of quantum threats,4 considering business priorities and the affected data (classify the most vulnerable5 data) .
2. Organize a corporate management system, develop a plan for implementing new encryption standards.
3. Change data encryption algorithms to the resistant of quantum computers attacks (e.g., according to standards - FIPS 203, 204,6 205 ), conduct regular testing.
4. Train employees.
5. Assess quantum security risks when interacting with suppliers (third parties).
To assess the deployment of such systems by organizations, Singapore has developed a self-assessment checklist – the Quantum Readiness Index (QRI). For example, how much valuable data being processed could be affected? Is an inventory of all cryptographic assets for encrypting information in the system being conducted? There are four QRI assessment levels in total: where 0 means that the process has not been launched, the organization has not started post-quantum migration, and 3 means that the organization is implementing quantum-resistant solutions and has launched a continuous monitoring process.
Russia’s experience
The Technical Committee for Standardization (TC26) is working on developing standards for post-quantum cryptography. The latest standard was published on September 17, 2025, and defines a system of concepts in the field of cryptographic information7 protection.
It is reasonable to expect that regulators around the world (including Russia) will become more active in introducing requirements for their organizations to transition to post-quantum cryptography (e.g., these are the deadlines by which national organizations must fully implement quantum-resistant encryption standards). The US and UK have set a deadline of 2035 for organizations to complete the phased transition, while Australia has set a8 deadline of 2030. It is also worth expecting Russia to adopt a full-fledged post-quantum cryptography standard.
- Short-term securities used by banks to borrow money from each other at a fixed rate. 23An investment company that manages various types of funds and assets for private and institutional investors. ↑
- https://www.businesswire.com/news/home/20251016818364/en/BlackRock-Introduces-40-Act-2a7-Money-Market-Fund-in-GENIUS-aligned-Form ↑
- A US law that regulates the issuance of stablecoins and determines the assets in ↑
- https://www.citigroup.com/global/insights/money-tokens-and-games ↑
- https://web-assets.bcg.com/1e/a2/5b5f2b7e42dfad2cb3113a291222/on-chain-asset-tokenization.pdf ↑
- Technical network methods used to make data inaccessible to third-party users (e.g., online transactions, messages). ↑
- https://www.proskauer.com/blog/blockchain-and-quantum-computing ↑
- “Collect now, decrypt later” is a method in which attackers obtain data in encrypted form now with the intention of decrypting it in the future when a quantum computer 34,35 becomes available. The most vulnerable data will be valuable data with a long storage period, as decrypting it in the future could yield significant benefits, such as personal financial data and medical records. ↑
- Organizations can use established standards to analyze business impact, plan for business continuity, and quantify risks (e.g., ISO/TS 22317 (business impact analysis), ISO 22301 (business continuity management systems), NIST SP 800-34 (emergency planning). ↑
- For example, such data: publicly available or confidential secret data. ↑
- Three international post-quantum cryptography standards from the US National Institute of Standards and Technology that offer encryption algorithms resistant to quantum computer attacks. ↑
- Level 1 - The organization has begun studying the quantum threat and has started work on implementation. ↑
- Level 2 - The organization is taking an organization-wide approach to implementing quantum-resistant solutions. ↑
From the monitoring issue No. 10 (22), October 2025. Download the full issue (PDF) · issue page at the Gaidar Institute