Quantum cybersecurity: innovation to protect critical data

Why quantum cybersecurity already matters?
Quantum cybersecurity has become a priority for businesses, public authorities and critical infrastructure operators. Although quantum computers capable of breaking today’s cryptographic systems are not yet in widespread use, their progress is already forcing organisations to prepare new protection strategies.
The risk is not only a future one. Attackers can capture encrypted data now and store it to decrypt it later, once quantum computing reaches greater capability. This scenario, known as “harvest now, decrypt later”, especially affects information with long-term value: financial data, medical records, government communications, intellectual property, strategic contracts and industrial systems.
For this reason, quantum cybersecurity is not merely a technological trend. It is also an opportunity to strengthen digital sovereignty, modernise infrastructure and protect the critical data that underpins the digital economy.
Quantum cybersecurity prepares businesses and critical infrastructure for the risks that quantum computing may pose to today’s encryption systems.
What is quantum cybersecurity?
Quantum cybersecurity brings together technologies, methodologies and strategies designed to protect information against threats arising from quantum computing. Its aim is to ensure that data, communications and digital identities remain secure in a post-quantum scenario.
Within this field, three major innovation lines stand out. The first is post-quantum cryptography, which develops algorithms resistant to attacks carried out by both classical and quantum computers. The second is Quantum Key Distribution, or QKD, which enables cryptographic keys to be generated and shared using the principles of quantum physics. The third is crypto-agility, meaning an organisation’s ability to change algorithms, certificates and protocols quickly as threats or standards evolve.
In addition, the transition towards quantum cybersecurity requires cryptographic inventories, pilot tests, integration with legacy systems, supplier management and long-term planning. Therefore, it is not just about replacing algorithms, but about transforming the governance of digital security.
Quantum cybersecurity and the protection of critical infrastructure
Quantum cybersecurity affects any organisation that relies on encryption to protect information. However, it is particularly relevant in sectors such as energy, healthcare, finance, telecommunications, defence, transport, research and public administration.
These sectors manage essential services and sensitive data. A security breach can compromise operational continuity, public trust, economic stability or national security. For this reason, the transition towards systems resistant to quantum computing must begin before the risk becomes immediate.
Organisations that act early will be able to identify their cryptographic dependencies, prioritise critical assets, test hybrid solutions and reduce the cost of future migrations. By contrast, those that delay this adaptation may face urgent, costly and difficult-to-audit processes.
A quantum cybersecurity strategy should include a cryptographic inventory, risk analysis, crypto-agility, post-quantum pilots and a migration roadmap.
Latest trends in quantum cybersecurity
The analysis of recent European projects shows that quantum cybersecurity is moving from research to real-world deployment. Projects funded over the last year are already working on cross-border networks, trusted nodes, optical ground stations, submarine fibre, satellite links and commercial solutions for secure communications.
Cross-border QKD networks
One of the clearest trends is the deployment of Quantum Key Distribution networks between European countries. These infrastructures make it possible to distribute cryptographic keys securely and reinforce institutional, financial, healthcare and industrial communications.
Projects such as 24-EU-DIG-SEEWQCI, 24-EU-DIG-QUAPITAL and 24-EU-DIG-QCIMED show how Europe is moving towards a pan-European quantum infrastructure connected to EuroQCI.
Hybrid infrastructure: terrestrial, satellite and submarine fibre
Quantum cybersecurity is also evolving towards hybrid models. New projects are not limited to terrestrial fibre-optic networks. They also test optical ground stations, satellite connections and submarine links.
This approach is essential to protect long-distance communications, connect strategic regions and create more resilient networks against physical, technological or geopolitical risks.
Protection of critical data and essential services
Recent projects focus on high-value sectors: governments, critical infrastructure operators, data centres, energy, healthcare, finance and public services. As a result, quantum cybersecurity is becoming established as a resilience tool for systems that cannot afford disruptions or information leaks.
Convergence between QKD and post-quantum cryptography
Another relevant trend is the combination of technologies. Some projects integrate QKD with post-quantum cryptography, quantum primitives, key management systems and orchestration tools. This convergence enables more robust and adaptable security architectures.
Commercial solutions against the “harvest now, decrypt later” risk
Innovation is also moving towards the market. Some companies are developing photonic encryption and optical communications protection solutions to prevent data captured today from being decrypted in the future. This line is particularly interesting for telecommunications, data centres and high-security business environments.
Success stories in quantum cybersecurity
NEXUS: QKD for a secure digital future
The NEXUS project is developing a new generation of Quantum Key Distribution solutions to protect government, financial and personal data against the risks of quantum computing.
Its technology is based on Measurement Device Independent Quantum Key Distribution, or MDI-QKD, an architecture that seeks to improve security, scalability and cost efficiency compared with traditional QKD systems. The project also directly addresses the “harvest now, decrypt later” risk.
NEXUS also contributes to European technological sovereignty, as it strengthens domestic capabilities in secure communications and aligns with initiatives such as EuroQCI.
NEXUS applies MDI-QKD to protect sensitive data against quantum threats and the “harvest now, decrypt later” risk.
24-EU-DIG-SEEWQCI: quantum connection between South-East and Western Europe
The 24-EU-DIG-SEEWQCI project is building a secure and scalable infrastructure that connects the national quantum communication networks of Greece, Bulgaria, Cyprus and the Netherlands.
The initiative deploys a 1,100-kilometre terrestrial quantum network between Greece and Bulgaria, five optical ground stations and multiple cross-border links. It also combines terrestrial and satellite components, making it a leading example of hybrid infrastructure for quantum cybersecurity.
The project will validate secure communications in sectors such as energy, healthcare, finance and government services.
24-EU-DIG-QUAPITAL: secure communication between Vienna and Frankfurt
24-EU-DIG-QUAPITAL focuses on protecting highly sensitive data in the financial sector. Its aim is to establish a quantum-secure fibre-optic connection between Vienna and Frankfurt using entangled Quantum Key Distribution, or eQKD.
The project includes trusted nodes, penetration testing, IT security validation and interoperability with other European QKD infrastructures. Its strategic value lies in connecting two major economic centres and helping to shape future shared standards for secure quantum communications.
24-EU-DIG-QUAPITAL deploys eQKD between Vienna and Frankfurt to protect financial communications and strengthen European digital sovereignty.
24-EU-DIG-QCIMED: quantum connectivity in the Mediterranean
The 24-EU-DIG-QCIMED project connects Italy and Austria through QKD, deploys optical ground stations and tests a submarine fibre connection to Greece.
Its approach combines terrestrial quantum networks, long-distance connections, integration with existing classical networks and potential space links. It also works on protocols that combine QKD, post-quantum cryptography and quantum primitives.
For this reason, QCIMED represents a key trend: the quantum cybersecurity of the future will rely on hybrid architectures capable of protecting complex and distributed communications.
CyberRidge – Carmel: photonic encryption for the post-quantum era
CyberRidge – Carmel offers a different approach. Rather than focusing only on QKD, it develops a photonic encryption solution for high-speed optical communications.
Its technology aims to protect data against post-quantum attacks and the “harvest now, decrypt later” risk. The system is designed for fibre-optic networks in data communications and telecoms environments, with links of 80 to 100 kilometres and speeds above 100 Gbps.
Its features include optical key encoding, stealth transmission, metadata elimination and compatibility with existing networks. This case reflects how quantum cybersecurity is beginning to generate commercial solutions applicable to businesses and technology operators.
CyberRidge – Carmel develops photonic encryption to protect optical communications against post-quantum threats and future data harvesting.
Quantum cybersecurity and European funding
Quantum cybersecurity opens up relevant opportunities for R&D projects, technology deployment, solution validation, specialised training and international collaboration.
Programmes such as Horizon Europe, Digital Europe, CEF Digital and the EIC Accelerator are supporting both large public infrastructure projects and deep-tech solutions developed by innovative companies. This combination makes it possible to accelerate the creation of European quantum networks, strengthen technological autonomy and facilitate the market uptake of new protection solutions.
For start-ups, SMEs, technology centres, universities and large companies, this trend creates a clear opportunity. Projects may focus on post-quantum cryptography, QKD, secure communications, key management, integration with critical infrastructure, pilot validation or the development of specialised hardware and software.
How to prepare a quantum cybersecurity strategy
Organisations that want to move towards quantum cybersecurity should begin by identifying which information needs long-term protection. They should then build a cryptographic inventory covering algorithms, certificates, protocols, applications, devices and suppliers.
Based on this diagnosis, the organisation can prioritise critical assets, test post-quantum solutions, adopt hybrid approaches and improve crypto-agility. It should also train technical teams and update internal security policies.
The key is to act gradually, but early. Waiting until the threat becomes immediate may make the transition more expensive and increase the exposure of critical data.
Protecting today the data of the future
Quantum cybersecurity marks a new stage in the protection of strategic information. Its importance does not depend solely on when quantum computers capable of compromising current cryptography will arrive. The real challenge is to prepare systems, networks and organisations now to protect data that will remain valuable for years.
Recent European projects show that the transition is already under way. QKD networks, hybrid infrastructure, cross-border connections, photonic encryption and post-quantum solutions are beginning to transform digital security.
Ultimately, quantum cybersecurity is not just a response to an emerging threat. It is an opportunity to drive innovation, strengthen European digital sovereignty and protect the critical data that supports the economy, public services and trust in the digital environment.
