At Gateway Network Governance Body (GNGB)’s September STN Cyber Forum, experts explored the emerging risks quantum computing poses to today’s cryptographic systems and, importantly, what organisations can be doing now to prepare. GNGB welcomed Professor Nalini Joshi AO, Payne-Scott Professor in Mathematics at the University of Sydney; Dr Colin Soutar, Deloitte’s US and Global Leader for Quantum Cyber Readiness; and Andrew Joyner, Specialist Director at Deloitte Australia. The discussion looked at the quantum threat, what it means for the Superannuation Transaction Network (STN), and the practical steps organisations can take as the transition to post-quantum cryptography (PQC) gets underway.
One message came through clearly: waiting until quantum computers arrive will be too late. Sensitive data with a long shelf life may already be being collected for decryption later, and the digital signatures that underpin trust between systems will need replacing well before then. For a highly interconnected ecosystem like the STN, that will require coordination across the network.
Why quantum computing changes the equation
Much of the security underpinning today’s digital environment relies on public key, or asymmetric, cryptography. These methods protect information by relying on mathematical problems that are extremely difficult for conventional computers to solve. Professor Joshi explained how a sufficiently powerful quantum computer could change this. Algorithms such as Shor’s algorithm could enable quantum computers to solve some of the mathematical problems underpinning widely used public key cryptography far more efficiently than classical computers. The good news is that replacement algorithms already exist. NIST finalised its first post-quantum cryptography standards (FIPS 203, 204 and 205) in 2024.
Exactly when a cryptographically relevant quantum computer will arrive is still uncertain. But, as the panel discussed, the transition to new cryptographic standards will itself take years, particularly across complex and interconnected systems. Waiting for certainty could therefore mean waiting too long.
The risk starts before quantum computers arrive
The forum also explored “harvest now, decrypt later”, the risk that encrypted information could be captured today and stored with the intention of decrypting it in the future when sufficiently powerful quantum technology becomes available. This is particularly relevant for information that remains sensitive for long periods. Within superannuation, personal and financial information can retain its value for decades, so organisations need to consider not only whether data is protected today, but how long that protection needs to last. For the STN, the issue goes beyond confidentiality. Public key cryptography also underpins authentication, digital signatures and the trust between systems that enables transactions to take place.
Mr Joyner highlighted that RSA is the algorithm currently specified within the STN standard and plays a central role in authentication and integrity for STN messaging. In the longer term, this is a dependency the ecosystem will need to address collectively.
Start with what matters most
A key practical takeaway from the forum was the need for organisations to understand where cryptography is being used across environments. Cryptography can sit throughout the technology stack – in applications, firewalls, certificates, code signing, protocols and third-party products. Developing a cryptographic inventory gives organisations a clearer picture of where vulnerable algorithms are being used and where migration will eventually be required. That doesn’t necessarily mean attempting to map everything at once. The panel recommended taking a risk-based approach and starting with critical business processes, systems and sensitive data. Understanding where that data is stored, how it is transmitted and what protects it. From there, the picture can become more detailed over time.
Australian Signals Directorate (ASD)’s guidance provides some clear milestones for this work. It recommends organisations have a refined plan for their transition to PQC by the end of 2026, commence the transition by the end of 2028 – starting with critical systems and data – and complete the transition by the end of 2030. Australian Prudential Regulation Authority (APRA) has also highlighted the need for regulated entities to make timely progress against ASD’s milestones, prioritising their most critical information assets and operations.
Read ASD’s guidance on planning for post-quantum cryptography
Talk to your vendors now
A large part of the transition will also depend on third-party technology providers. Cryptography is embedded in many of the applications, infrastructure and services organisations already use, so understanding vendor readiness will be an important part of planning. The panel encouraged organisations to start asking questions now. Where is cryptography used within vendor products? What are their plans for transitioning to PQC? When will updated capabilities become available?
ASD has also published practical guidance on the questions organisations should be asking third-party vendors about their readiness for PQC, including their cryptographic dependencies, transition plans and ability to support cryptographic agility as standards and recommendations evolve. These considerations should also feature in procurement requirements for new systems and services. The earlier they begin, the more visibility organisations will have over dependencies that may affect their own transition timelines.
ASD: Post-quantum questions to ask your vendors
For the STN, this is a collective challenge
The interconnected nature of the STN adds another layer to the transition. Gateways and other participants need to be able to communicate securely with one another, meaning migration cannot happen entirely at an individual organisation’s pace. As Mr Joyner noted during the session, a participant that starts late has the potential to become a constraint on others. Coordination, interoperability and testing will therefore be important parts of the work ahead.
GNGB has a role to play in helping coordinate this activity across the ecosystem, providing technical guidance around standards, working with the Australian Taxation Office (ATO) on deployment considerations and facilitating testing between network participants.
The role of standards and frameworks
Standards and frameworks will also have an important role to play in helping organisations navigate what is a complex, multi-year transition. During the forum, Dr Soutar discussed Deloitte’s Cryptographic Resilience Community Profile, published in 2025, structured around the NIST Cybersecurity Framework (CSF) 2.0. The profile is designed to help organisations approach quantum readiness as part of their broader cybersecurity risk management, rather than as a standalone technical exercise.
Using an established framework also creates a common language for organisations to assess where they are, identify priorities and develop a roadmap for improving cryptographic resilience. This becomes particularly important across interconnected ecosystems, where organisations, vendors and other participants need to move in a coordinated way. As Dr Colin noted during the discussion, there is a growing need for more prescriptive guidance that can help organisations work together. The intention is for the Cryptographic Resilience Community Profile to contribute to that broader, standardised approach.
Read Deloitte’s Cryptographic Resilience Community Profile
Building cryptographic resilience and agility
The discussion also made clear that preparing for PQC shouldn’t be approached as a single technology project with a defined end point. Cryptography has been relatively stable for many years. As the technology and threat environment evolves, that may change, and organisations may need to update cryptographic algorithms more regularly in future. This is where cryptographic resilience and cryptographic agility become important: Cryptographic resilience is having the visibility, governance and processes to manage cryptography as an ongoing risk. Cryptographic agility is the ability to change algorithms and protocols quickly, without disrupting operations, as standards and ASD recommendations evolve.
For the STN and the broader superannuation ecosystem, that means thinking about cryptographic management as an ongoing capability rather than simply a one-off migration exercise.
Key takeaways
There is still uncertainty around exactly when quantum computing will pose a practical threat to current cryptographic systems. What is clearer is that preparing for the transition will take time. For organisations, the work can start now: understand where cryptography is being used, focus first on critical systems and long-lived sensitive data, speak to vendors about their plans, and use established standards and frameworks to help structure a roadmap for building cryptographic resilience and agility.