
By: O’Rane Gray, CEO of CompConn
The digital world is on the cusp of a technological shift so profound that it will fundamentally alter how we protect information. This shift is quantum computing—a multi-billion-dollar global race to build machines exponentially more powerful than anything in existence today.
While quantum computing promises to solve complex human challenges in minutes rather than millennia, it simultaneously introduces unprecedented risks. As Jamaica aggressively modernises its digital landscape—with Technology Minister Dr Andrew Wheatley recently outlining a brand-new national cybersecurity legislative framework for 2026—our island must look beyond immediate cyber threats like ransomware and urgently plan for the quantum era.

The Quantum Race: A Multi-Billion Dollar Global Effort
Quantum computing is no longer confined to theoretical physics textbooks. According to McKinsey & Company’s 2026 Quantum Technology Monitor, over 300 global companies are actively adopting the technology, and investment in quantum tech start-ups reached a staggering $12.6 billion in 2025—a 6.3-fold increase from the previous year [1]. Tech titans like IBM, Google, and Microsoft, alongside specialised firms like Rigetti and D-Wave, are pouring billions into development.
McKinsey estimates that quantum computing could create up to $2.7 trillion of economic value worldwide by 2035 as it enhances current industry use cases and unlocks new ones [1]. However, this immense computing power poses a direct threat to the foundation of modern internet security.

The Looming Threat of “Q-Day”
The core concern centres around a concept known as “Q-Day”—the day a quantum computer becomes powerful enough to break the encryption that currently protects all of our digital data.
Historically, experts believed Q-Day was decades away. However, recent breakthroughs have dramatically accelerated this timeline. In 2024, Google demonstrated a major leap in quantum error correction, proving that building large-scale quantum computers is an engineering challenge, not just a theoretical one. Subsequent research in early 2026 has shown that the number of quantum components needed to break standard encryption has dropped from millions to just thousands [2].
Consequently, leading tech companies and cybersecurity firms have updated their threat models. Google recently announced it is targeting 2029 to be fully secure against quantum attacks, warning that the threat may arrive much sooner than previously thought [3]. Similarly, a March 2026 report by Forrester Research characterised Q-Day as a plausible risk by 2030 [4]. A survey by DigiCert revealed that while 87% of organisations are pursuing post-quantum security initiatives, only 7% have actually deployed these solutions at scale, highlighting a massive readiness gap globally [5].
The “Harvest Now, Decrypt Later” Danger
Why should Jamaican citizens and businesses care about technology that is still largely confined to advanced laboratories? The answer lies in a strategy currently being utilised by hostile state actors and cybercriminals: “Harvest Now, Decrypt Later” (HNDL).
Bad actors are actively stealing heavily encrypted government records, banking transactions, and citizens’ personal data right now. They cannot read it today, so they store it. When a politically or commercially viable quantum computer becomes available—potentially within the next five years—they will use it to instantly crack today’s standard encryption.
Any organisation dealing with data that must remain confidential for the next 10 to 15 years—such as medical records, land titles, and national defence data—is already vulnerable to this threat. The encryption protecting Jamaica’s digital infrastructure today has an expiration date.
What the Jamaican Government and Businesses Need to Do
With Jamaica’s National Cybersecurity Strategy undergoing a massive reset for the 2026–2030 cycle, our policymakers have a narrow window to weave “quantum-hardening” into our legal and digital infrastructure. To mitigate these looming risks, the Jamaican government and businesses should urgently pursue a three-pronged approach:
1. Conduct a National Cryptographic Audit
Before we can secure our infrastructure, we need to know exactly what we are protecting. The Ministry of Science, Technology, and Special Projects should audit all government systems to catalog where encryption is used and identify which data reservoirs are most vulnerable to HNDL tactics.
2. Mandate Post-Quantum Cryptography (PQC)
The waiting period for new encryption standards is over. In August 2024, the US National Institute of Standards and Technology (NIST) finalized the first three Post-Quantum Cryptography (PQC) standards designed to withstand attacks from both classical and quantum computers [6]. Furthermore, the US Quantum Computing Cybersecurity Preparedness Act now requires federal agencies to migrate their systems to these new standards [7].
Jamaica’s upcoming Cybersecurity Standards Framework must follow these international precedents, mandating that critical infrastructure (banking, utilities, telecommunications, and national registries) systematically transition to PQC before Q-Day arrives.
3. Foster “Crypto-Agility” and Local Tech Talent
We must design our future state applications to be “crypto-agile,” meaning their encryption protocols can be upgraded easily without overhauling the entire software infrastructure. Simultaneously, through local universities, we must invest in localized training programs focusing on quantum security risk management to upskill our workforce and ensure we are not left behind in this new digital era.

The Bottom Line
Quantum computing promises to change the world, but it will also change the rules of survival in cyberspace. Jamaica cannot afford to treat this as a futuristic “first-world” problem. If we do not begin securing our data against the quantum threats of tomorrow, the digital economy we are building today will be resting on a foundation of sand.
References
[1] McKinsey & Company. (2026). McKinsey Quantum Technology Monitor 2026: A commercial tipping point. https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/mckinsey-quantum-technology-monitor-2026-a-commercial-tipping-point
[2] The Quantum Insider. (2026). Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline. https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/
[3] Google. (2026). Quantum frontiers may be closer than they appear. https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/
[4] Cloud Security Alliance. (2026). Q-Day Clock: Enterprise Post-Quantum Migration Imperative. https://labs.cloudsecurityalliance.org/research/strategic-post-quantum-cryptography-migration-enterprise-roa/
[5] DigiCert. (2026). Post-Quantum Encryption Gap: Enterprises Plan but Only 7% Have Deployed. https://www.techtimes.com/articles/321458/20260724/post-quantum-encryption-gap-enterprises-plan-only-7-have-deployed.htm
[6] National Institute of Standards and Technology (NIST). (2024). NIST Releases First 3 Finalized Post-Quantum Encryption Standards. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
[7] Congress.gov. Quantum Computing Cybersecurity Preparedness Act. https://www.congress.gov/bill/117th-congress/house-bill/7535
Comments