Organisations today are navigating a constant wave of change, whether it is Agentic AI or the continued evolution of digital commerce. The reality is that new technology creates opportunities as well as new risk parameters that require organisations to balance the security challenges of today with the emerging threats of tomorrow.
One emerging technology that deserves greater attention is quantum computing.
While a quantum computer capable of breaking modern encryption does not yet exist, its potential impact on digital commerce means organisations should be considering it now. How do we prepare for a future that may arrive sooner than expected?
Why Quantum Matters
Quantum computing has the potential to solve certain problems far faster than traditional computers, which has significant ramifications across medicine, science and technology. Yet this very breakthrough also represents a fundamental challenge for cybersecurity.
In digital commerce, encryption is fundamental to maintaining trust. It helps protect cardholder data, secure transactions and support the systems that keep money moving around the world.
The concept of "Q-Day" refers to the point at which a quantum computer becomes powerful enough to break widely used cryptographic standards. According to the Global Risk Institute's Quantum Threat Timeline Report, there is a 50 per cent chance that quantum computers capable of breaking today’s public-key cryptography could emerge within the next decade¹.
While we don’t know when this moment will be, we do know that we need to be preparing for it now.
Harvest Now, Decrypt Later
One reason that quantum readiness is critical is due to the practice of "Harvest Now, Decrypt Later".
This refers to the practice of collecting encrypted data today with the intention of decrypting it in the future, once quantum capabilities mature. For organisations that store sensitive information over long periods, understanding this risk is becoming increasingly important.
More broadly, it challenges a common assumption in cybersecurity - that risk is largely contained to the period immediately following an incident.
In Australia, recent data breaches have highlighted that the impact of a cyber incident is not always fully understood at the time it occurs. Organisations typically focus on what data was exposed and the immediate implications for customers and operations.
Quantum computing introduces a new dimension to that challenge, requiring organisations to think not just about the risks of today's breach, but future scenarios where data may already have been compromised.
The challenge is that cryptography is deeply embedded across complex technology environments. In payments, encryption underpins everything from card credentials and authentication systems to tokenisation and transaction processing. Maintaining trust in digital commerce depends on these protections continuing to evolve alongside emerging threats.
Modernising these systems cannot happen overnight. It requires planning, coordination and long-term investment across a highly interconnected ecosystem.
What Readiness Looks Like
For many organisations, quantum preparedness is still in its early stages. Research from CSIRO suggests a significant proportion of Australian organisations are yet to move beyond awareness of the issue².
For many organisations, quantum readiness begins with visibility rather than new technology. Establishing a cryptographic inventory, mapping critical third-party dependencies and understanding the longevity and sensitivity of protected data can help identify where future exposure may exist. Starting this work now will make the transition to post-quantum cryptography more manageable as standards continue to evolve.
Importantly, organisations are not starting from scratch. The US National Institute of Standards and Technology (NIST) has already published its first post-quantum cryptography standards, providing internationally recognised benchmarks that organisations can use to inform transition planning and technology roadmaps.
The payments industry is arguably better placed than many sectors to prepare for this transition because collaboration, security standards and technology modernisation are already deeply embedded in how the ecosystem operates.
Across the payments ecosystem, banks, payment networks, merchants, technology providers and industry bodies are working together to better understand quantum-related risks and prepare for the transition to future cryptographic standards.
Initiatives such as AusPayNet's AES Migration Program are helping strengthen the foundations for long-term resilience, while organisations continue to assess where quantum considerations should be incorporated into existing security roadmaps.
For Visa, this means working closely with clients, partners and industry stakeholders to assess emerging quantum-related risks, support ongoing cryptographic modernisation efforts and help ensure the payments ecosystem is ready for future standards as they emerge.
Looking Ahead
Quantum computing remains an emerging technology, and there is still uncertainty around when its most significant impacts will arrive. What is becoming increasingly clear, however, is that the organisations best positioned for the future will be those that start preparing before the threat fully materialises.
The transition to a post-quantum world will not happen overnight. By beginning the journey now, organisations can strengthen resilience, protect customer trust and ensure they are ready for the next era of digital commerce.

