Cybersecurity Governance for the AI and Quantum Age
Part one of this series looked at why AI and quantum computing have created a new, combined cyber risk that boards need to understand, even without a technical background. Part two is about what to do with that understanding. What should a board reasonably expect to see from its management team, and how does an organisation move from awareness to genuine preparedness?
Good Reporting Should Now Cover More Ground
For years, board cybersecurity reporting in Australia has centred on a well-established baseline of protective measures recommended by the government’s cybersecurity agency. That foundation still matters and should not be abandoned. But a good report to the board now needs to cover additional ground.
A solid report should give the board a clear picture in four areas: the organisation’s overall security posture and any significant incidents or near misses; how AI is being used both as a risk and as a defensive tool, including where the organisation depends on external AI providers; where the organisation stands on preparing for the quantum risk described in part one, including whether a plan exists and what it covers; and a small number of meaningful measures the board can track over time, rather than a long list of technical statistics that obscure the overall picture.
The goal is not more paperwork. It is a report a director without a technical background can read, understand, and use to ask informed questions.
What a Sensible Quantum Transition Looks Like
Preparing for the quantum risk does not mean overhauling every system overnight. The approach recommended by Australia’s cybersecurity agency, and one I encourage clients to follow, breaks the work into manageable stages.
The first stage is simply finding out where the organisation currently relies on the encryption methods that will eventually become vulnerable. Most organisations have never done this exercise and are often surprised by what they find. The second stage is judging which of those systems matter most, based on how sensitive the data is and how long it needs to stay protected. Older customer records or one-off transactions may matter far less than long-term health, legal, or strategic data. The third stage is making a realistic plan for upgrading the highest-priority systems first, rather than attempting everything at once. The final stage is keeping that plan under review as the technology and the threat continue to evolve.
The government’s expectation is that organisations have a clear plan in place by the end of this year, begin acting on it within the next two years, and have completed the transition by 2030. That sounds like a long runway, but organisations that have done this kind of work before knowing that the early stages, simply finding out what you have, often take longer than expected.
The Business Case… This Is Also an Opportunity, Not Just a Cost
It is easy to frame all this purely as risk management, but there is a genuine upside worth boards understanding. Organisations that can demonstrate they have a credible plan in place are increasingly viewed more favourably by government agencies, larger corporate partners, and international clients who operate under stricter overseas requirements. Being able to say with confidence “we have assessed this risk and have a plan” is becoming a meaningful point of difference in tender processes and partnership discussions, not just a compliance checkbox.
Organisations that treat this as an opportunity to demonstrate strong governance, rather than a burden to be managed reluctantly, are likely to find it pays dividends well beyond cybersecurity itself.
However, none of this happens without resourcing, and boards should expect a sensible budget conversation alongside any plan. This includes the cost of the initial assessment work, any new tools or expertise required, updated insurance arrangements that reflect AI and quantum-related risks, and the cost of upgrading systems over time.
The good news is that organisations which fold this work into upgrades and system replacements they were already planning, rather than treating it as a brand-new standalone project, tend to spend considerably less and disrupt their operations far less. This is a strong argument for starting the assessment now, even if major spending decisions are still some way off.
Bringing It Together
The combination of AI and quantum risk has changed what good cybersecurity governance looks like. Boards no longer need to be technical experts, but they do need to ask sharper questions, expect clearer reporting from management, and understand that the data their organisation holds today carries risks that may not fully materialise for years.
Recent surveys suggest most Australian organisations are yet to seriously engage with the quantum dimension of this risk, even though the deadline for having a plan in place is fast approaching. Boards that get ahead of this now are not just protecting their organisation. They are positioning it as a more attractive, better-governed partner for the years ahead.
If your board is looking for an independent, plain-English assessment of where you currently stand on either AI governance or quantum readiness, I would welcome the opportunity to help.
About: Gary Morgan is a director, board advisor and principal consultant at MPT Innovation Group, specialising in governance, technology strategy, and organisational transformation for private and not-for-profit organisations. He is a Fellow and Member of the Queensland State Council of the Governance Institute of Australia, and an Adjunct Fellow and Member of the Griffith University Industry Advisory Board for the ICT School. Gary publishes regularly on board governance, AI, technology, and cybersecurity.
Acknowledgment: This article represents the author’s independent views and incorporates AI-assisted research and drafting.
References and Sources:
Australian Signals Directorate. (2023). Essential Eight
Australian Signals Directorate. (2025). Planning for Post-Quantum Cryptography
Australian Signals Directorate. (2025). Cyber Security Priorities for Boards 2025-26
CSIRO. (2025). How are Australian organisations navigating the quantum frontier?
Governance Institute of Australia. (2025). Effective Cyber Risk Management: A best practice governance guide
