Blog

PQC Impacts: How Quantum Risk Exposure Varies by Sector

Post-quantum security exposure is not uniform. Compare quantum risk across defence, healthcare, finance, nuclear, transport and government estates.

How post-quantum risk exposure varies by sector

Post-quantum exposure is not uniform. It is determined by how long data must remain confidential, how long the underlying assets remain in service, and how attractive the organisation is to a well-resourced adversary. Defence, healthcare and nuclear carry the highest exposure; retail and general commercial IT carry the lowest.

What determines post-quantum security exposure

Six factors set the exposure level, and they combine rather than operate independently.

Data confidentiality lifetime is the primary driver. Data that must remain secret for thirty years and is transmitted today is already exposed to harvest now, decrypt later collection, because the traffic can be stored until a capable machine exists.

Asset service life sets the migration constraint. An estate refreshed every three years can migrate through normal procurement. An estate of controllers, sensors and safety systems with a twenty-five year design life cannot, and much of what is installed this year will still be operating after 2035.

Adversary interest determines whether harvesting is happening at all. Nation-state collection is targeted, and sectors of strategic or intelligence value are collected against systematically.

Authentication criticality determines the severity of a capability arriving. Where a forged signature grants physical control or safety-critical command authority, the consequence is immediate rather than retrospective.

Regulatory exposure sets the compliance deadline independently of the threat, through NCSC timelines, sector regulators and, for organisations operating internationally, US and EU mandates.

Estate complexity determines how long discovery takes, which is usually the largest single component of migration time.

Sector ranking for post-quantum security risk

Sector ranking for post-quantum security risk
Sector ranking for post-quantum security risk-2

The ranking should be read as a starting position for assessment, not a conclusion. An organisation in a lower-ranked sector holding one class of long-lived data inherits the exposure of that class regardless of its sector average.

Where the highest exposure sits

Defence and national security

Exposure is maximal on every driver. Classified material carries confidentiality requirements measured in decades or held indefinitely. Platforms, radios, cryptographic devices and embedded systems have service lives of twenty years or more, and many hold keys that cannot be rotated without physical access. Adversary collection against defence traffic is a working assumption rather than a risk.

Authentication carries equal weight to confidentiality here, because forged credentials in command, control or logistics systems produce operational consequences immediately. This is the sector where the CNSA 2.0 requirements for ML-KEM-1024 and ML-DSA-87 apply directly, and where hardware roots of trust must be identified first. See our work in PKI for defence.

Nuclear

The defining factor is asset life. Plant and safety-related systems are designed for forty to sixty years of operation, so equipment commissioned now will outlive every published migration deadline by decades. Change control is correspondingly heavy, with safety case implications for modifications to systems important to safety, which means migration must be planned into major outages years in advance rather than deployed through routine patching.

The dominant risk is authentication and integrity rather than confidentiality: the concern is forged commands, unauthorised firmware and compromised remote access, not the disclosure of historic data. See PKI for nuclear.

Healthcare

Healthcare has the longest routine data lifetimes outside national security. Under the UK Records Management Code of Practice, maternity records are retained for 25 years, children's records until the patient's 25th birthday, and cancer records for 30 years. Genomic data is effectively permanent and identifies relatives as well as the patient.

Any of that material transmitted today under RSA or elliptic curve protection is exposed to future decryption. Medical devices compound the problem, with service lives of ten to twenty years, constrained processing capability and firmware update paths that often require manufacturer involvement and revalidation. See PKI for healthcare.

Central government

Government holds citizen identity data, policy material subject to the twenty-year rule for public records, tax and benefits records, and diplomatic traffic. Confidentiality lifetimes are long and adversary interest is high.

The additional factor is identity infrastructure. Where government issues credentials that citizens or officials use to authenticate, the credential issuance chain is itself a target, and the consequences of forged government-issued identity extend well beyond the issuing department. See PKI for central government.

Financial services

Exposure is split. Most transactional data has a short useful life, but long-dated products do not: mortgages run to 40 years, pensions and life policies longer, and the associated customer data carries the same lifetime.

Payment authentication is the more urgent concern. EMV, payment HSMs and card issuance depend on cryptographic key hierarchies with long-lived roots, and a forged payment credential has immediate financial consequence. The G7 Cyber Expert Group has set a 2035 target for post-quantum transition in the financial sector, and DORA imposes resilience testing obligations that increasingly encompass cryptographic dependency. See PKI for financial services.

Transport

Transport data is mostly short-lived, so confidentiality exposure is low. The risk is authentication across very long-lived assets. Rail signalling, ETCS trackside equipment, airside systems, roadside units and vehicle-to-everything communications rely on certificates and device identity, on assets with service lives of twenty-five to forty years.

Two features make this difficult. Certificate outages already cause service disruption, so the estate is sensitive to lifecycle failure before any quantum consideration. And multi-vendor supply chains mean device trust depends on suppliers whose upgrade paths the operator does not control. See PKI for transport.

What lower exposure does not mean

A lower sector ranking indicates a smaller confidentiality problem, not an absence of obligation.

Authentication risk is close to universal. Every organisation depends on TLS certificates, code signing, software update verification and administrative access, all of which fail if signatures can be forged, regardless of how long the data matters.

Supply chain position also transfers exposure. An organisation supplying defence, healthcare or critical infrastructure will face post-quantum readiness requirements through contract and procurement well before any regulator addresses its own sector. The US Executive Order signed in June 2026 extended requirements to federal contractors on that basis, and UK procurement is likely to follow the same pattern.

Finally, the discovery work is identical in every sector. The inventory that supports migration also supports audit, incident response and outage prevention, and it takes comparable effort whether the exposure is high or moderate.

How to assess post-quantum security in your own sector

Sector ranking is a prior, not an answer. The assessment that produces an answer is specific to the estate, and it follows the same method regardless of sector.

Establish the confidentiality lifetime of each data class from regulation and contract, rather than from retention policy. Establish the service life of the assets protecting each class, since that sets the earliest feasible migration point. Identify the authentication dependencies whose compromise would have immediate operational consequence, and treat those separately from confidentiality exposure. Then compare the sum of data lifetime and migration time against a range of capability arrival dates, as set out in the three timelines used in quantum risk assessment.

Organisations consistently find that exposure is concentrated. A small number of data classes and a small number of long-lived signing keys account for most of the risk, and identifying them early is what makes the programme affordable.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.

We establish sector-specific exposure through our PKI health check and cryptographic bill of materials services, then prioritise migration against the constraints that actually bind in each environment: safety case processes in nuclear, device revalidation in healthcare, multi-vendor supply chains in transport, and accreditation requirements in defence.

For the underlying algorithm detail, see our comparison of the NIST post-quantum algorithms.

Frequently asked questions

Which sector faces the highest post-quantum risk?

Defence and nuclear, for different reasons. Defence combines decades-long data confidentiality requirements with sustained adversary collection and long-lived embedded systems. Nuclear combines forty to sixty year asset lives with heavy change control and authentication risk in safety-related systems, meaning migration must be planned into outage cycles years ahead.

Does post-quantum risk apply to organisations that hold no sensitive data?

Yes, through authentication. Forged signatures allow impersonation of services, compromise of software update mechanisms and abuse of administrative access, none of which depend on the value of stored data. Every organisation relying on TLS, code signing or certificate-based access has this exposure.

How does data retention policy relate to quantum risk?

Retention policy states how long data is kept. Quantum risk depends on how long it must remain confidential, which is often much longer and set by regulation or contract. Records that have been deleted may still have been captured in transit, so deletion does not remove harvest now, decrypt later exposure.

Are small organisations affected?

Directly, less so. Most small organisations will receive post-quantum protection through platform and service provider upgrades, as the NCSC anticipates. The exception is where they supply regulated or critical sectors, in which case readiness requirements arrive through procurement and contract rather than regulation.

Does operational technology need migrating before IT?

Not necessarily first, but it needs planning first. OT assets have the longest lead times, the heaviest change control and the least capable hardware, so decisions about them constrain the whole programme. Identifying which OT assets can never be migrated in place is an early priority, since those require replacement rather than upgrade.

How do we justify prioritising one sector risk over another internally?

Use the exposure calculation rather than the sector label. Ranking data classes by confidentiality lifetime plus migration time, against a range of capability dates, produces a defensible order that can be recorded on the risk register and evidenced to auditors and regulators.
Author
Unsung Ltd
October 2, 2026
-