New Zealand government agencies are being urged to invest in post-quantum computing (PQC) solutions before 2030, as the arrival of a fully error-corrected quantum computer threatens to unravel current encryption methods. This push follows recognition of a growing practice described as “harvest now, decrypt later,” or HNDL, where encrypted data is collected for future decryption.
“Anything you send now might not be secure in five years,” warns Professor David Hutchinson of Otago University, who advises the OECD on quantum computing. Virtually all current security protocols, from internet communications to banking PINs, rely on factorization of prime numbers, a system vulnerable to future quantum attacks.
HNDL Attacks and the Threat to Current Encryption
This tactic, recognized internationally and recently detailed in a US Federal Reserve paper, involves collecting data now with the intention of exploiting quantum computing power to unlock it when available. Hutchinson said that current internet security protocols, banking systems, and information kept safe within government largely depend on a security protocol based on the factorization of prime numbers, which is used whenever we share information, whether through the internet or when entering a PIN at a bank machine. The OECD highlighted HNDL attacks last year as justification for immediate action, noting that transitioning to quantum-resistant cryptography could take up to 20 years given the scale of systems involved.
Treasury reports from last year reveal concerns that agencies are not adequately prioritizing cyber security investment and preparedness for emerging threats. The GCISO reported to Treasury that investment proposals demonstrate agencies are not dedicating enough time and resources to address cyber security challenges, adapt to emerging technologies, and prepare for future threats. Despite awareness of the impending threat, Hutchinson notes that “people know what’s coming,” but the NCSC remains tight-lipped about specific agency investments, citing budget sensitivity and the potential to increase cyber security risk through disclosure.
Agencies will need to invest in PQC [post-quantum computing] solutions before the first fully error-corrected quantum computer is expected to come online in 2030.
NIST Post-Quantum Algorithms Guide Agency Investment by 2030
The NCSC is now actively widening the list of approved algorithms to incorporate post-quantum options developed by international standards bodies, with the US National Institute of Standards and Technology (NIST) currently offering three viable algorithms. The NCSC explained that aligning New Zealand with international standards ensures agencies can give suppliers clear technical specifications, signaling a move towards standardized procurement of quantum-resistant systems.
This standardization aims to clarify requirements for suppliers and facilitate a smoother transition to PQC. The GCISO and Government Digital Delivery Agency are integrating quantum considerations into the New Zealand Information Security Manual (NZISM), the nation’s core cyber security guidance.
So anything you send now, maybe in five years’ time might not be secure anymore.
Professor David Hutchinson of Otago University
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.




