Cybersecurity Governance for the AI and Quantum Age
Last month I had the privilege of chairing the AI session at the Governance Institute of Australia’s Governance and Risk Management Forum in Brisbane. The conversation in that room was telling. Directors and executives across sectors are increasingly aware that AI is changing the cyber threat their organisations face, but far fewer have thought about a second, less visible risk now building in the background: quantum computing, and what it means for data their organisation holds today.
That gap is what prompted this two-part series.
I have spent more than 25 years working across board governance deep tech in several sectors. In that time, I have watched plenty of ‘next big threats’ come and go. What is different this time is that two significant risks are arriving together, and boards need a clear-eyed, non-technical understanding of both to ask the right questions of their management teams.
This series is written for directors, not technologists. Part one explains what has changed and why it matters. Part two sets out practical steps boards should expect to see management taking in response.
Two Risks, Arriving Together
Until recently, cybersecurity at board level meant understanding ransomware, phishing, and data breaches, and making sure management had a credible plan to prevent and respond to them. That is still essential. But two new developments mean the conversation has grown.
The first is artificial intelligence. AI is making familiar attacks more effective. Criminals can now use AI to write phishing emails that read as though a trusted colleague wrote them, and to create deepfake audio or video convincing enough to impersonate a CEO or CFO authorising a payment. Attacks are also moving faster: the time between a hacker breaking in and stealing data has fallen sharply in the past year, in some cases to little more than an hour. That leaves far less time for an organisation to notice and respond before damage is done.
The second is quantum computing. This sounds like a problem for the distant future, and in one sense it is, as a computer powerful enough to break today’s encryption algorithms does not yet exist. But here are the part directors need to understand: the risk to your organisation’s data may already have started, even though the technology that exploits it has not arrived yet.
‘Harvest Now, Decrypt Later’ Explained
Imagine someone today steals a locked box of your organisation’s most sensitive information including contracts, health records, strategic plans, customer data however, they cannot yet open the lock. Rather than walking away, they keep the box. They are betting that within five to ten years, a new kind of computer will exist that can pick that lock easily. At that point, everything inside becomes readable.
That is precisely the strategy intelligence agencies and sophisticated criminal groups are pursuing right now. It is known in the cyber security sector as ‘harvest now, decrypt later’ and it means that data your organisation considers safely encrypted today could become exposed in the 2030s, simply because someone collected and stored it years in advance.
This matters most for organisations holding data that needs to stay confidential for a long time: health records, legal files, strategic and merger documents, intellectual property, and government or citizen data. If your organisation holds that kind of information, the clock may already be running.
Australia Is Behind on This
Recent research found that only 5% of Australian organisations have a clear plan to deal with this emerging quantum risk, and around half are not even aware that the federal government’s security agency has set a 2030 deadline for organisations to have moved away from the encryption methods that quantum computers will eventually be able to break.
This is not primarily a technical problem for IT to solve quietly in the background. It is a governance problem, because it involves long-term risk to information the organisation is responsible for protecting, and because addressing it properly requires decisions about priorities, budget, and timing that sit squarely with the board.
Questions Worth Asking at Your Next Board Meeting
Directors do not need to become technical experts in either AI or quantum computing. What boards do need is enough understanding to ask good questions and recognise a credible answer when they hear one.
1. For AI: Do we know where AI is being used across our organisation, including by our suppliers? How would we detect a sophisticated, AI-generated scam targeting our finance team? Are we confident our incident response plan accounts for how fast these attacks now move?
2. For quantum risk: Has anyone assessed which of our systems and data would be exposed if encryption methods in use today were eventually broken? Do we have a plan, and a timeframe, for moving to safer alternatives? Has anyone benchmarked us against the government’s 2030 expectations?
If management cannot answer these clearly, that is itself a useful and important finding for the board.
The throughline across both AI and quantum risk is the same: the pace of change has outstripped many organisations’ governance processes. Boards that wait for these risks to become urgent and obvious will find themselves making decisions under pressure, at greater cost, and with less room to manoeuvre.
Where This Leaves Boards
Boards that start asking the right questions now, even informally, put themselves and their organisations in a far stronger position. Part two of this series sets out what good practice looks like in response, and the practical steps organisations are taking to get ahead of both risks.
If your board would value an independent perspective on where you currently stand on either of these fronts, I would be glad to have that conversation.
About: Gary Morgan is a director, board advisor and principal consultant at MPT Innovation Group, specialising in governance, technology strategy, and organisational transformation for private and not-for-profit organisations. He is a Fellow and Member of the Queensland State Council of the Governance Institute of Australia, and an Adjunct Fellow and Member of the Griffith University Industry Advisory Board for the ICT School. Gary publishes regularly on board governance, AI, technology, and cybersecurity.
Acknowledgment: This article represents the author’s independent views and incorporates AI-assisted research and drafting.
References and Sources:
Australian Signals Directorate. (2025). Cyber Security Priorities for Boards 2025-26
Australian Signals Directorate. (2025). Planning for Post-Quantum Cryptography
CSIRO. (2025). How are Australian organisations navigating the quantum frontier?
Palo Alto Networks. (2026). Global Incident Response Report
UNSW. (2026). Is quantum computing the next big cybersecurity risk?
