Stay Up to Date
Subscribe to our newsletter
Insurers hold two versions of the same quantum risk. Their own claims and policyholder archives are encrypted with methods a future quantum computer could break, and they underwrite clients carrying identical exposure. Neither side is currently modeled, and the cyber insurance market has largely classified this as a future problem.
Quantum risk is not a forecast about attacks. It is a statement about the shelf life of encrypted data. Most sensitive information today is protected by public-key cryptography, principally RSA and elliptic-curve algorithms, whose security rests on mathematical problems that classical computers cannot solve quickly. A sufficiently powerful quantum computer solves them efficiently.
That machine does not exist yet. The threat does, because of a technique called harvest now, decrypt later: an adversary copies encrypted data today and stores it until decryption becomes possible. The breach happens now. The disclosure happens later. Nothing in a current security monitoring stack registers the first event, because from the outside it looks like ordinary encrypted traffic.
This matters more to insurers than to almost any other sector, for one reason that has nothing to do with technology. A claims file contains health records, settlement history, payment details, and identity data that stays sensitive for decades. Underwriting repositories hold client trade secrets and infrastructure assessments.
Insurance is a business built on retaining sensitive records for very long periods, which is precisely the data profile that harvest now, decrypt later is designed to exploit.
The standards to address it already exist.
The National Institute of Standards and Technology finalized its first three quantum-resistant encryption standards in August 2024: FIPS 203, FIPS 204, and FIPS 205. Migration to them is the work. It is measured in years, not quarters, because cryptography is embedded in nearly every system an insurer runs.
Cyber incidents ranked as the top global business risk for the fifth consecutive year in the Allianz Risk Barometer 2026, cited by 42% of the more than 3,300 risk management professionals surveyed, a ten-point margin over the next closest concern. That ranking measures known and detected incidents. It does not measure the incidents sitting undetected in encrypted archives, waiting on a decryption capability that does not exist yet.
This is the asymmetry insurers have not fully priced. A claims file contains health records, settlement history, payment details, and identity data with a useful life measured in years, not months. Underwriting repositories hold trade secrets and infrastructure assessments for the same clients that insurers are advising to inventory their own cryptographic exposure. A harvest now, decrypt later attack against an insurer's own systems is a breach that has already occurred and will not be provable, or reportable, until the day the stolen material is decrypted. That day could fall well outside the retention and reserving assumptions built into current models.
The insurer is not only the party assessing this exposure for clients. It is one of the parties holding the most durable versions of it.
Financial regulators are already treating quantum-resistant migration as a present-tense governance requirement, while actuarial models still treat quantum decryption as a discrete, distant, probabilistic event, and that gap is the practical risk.
The Swiss Financial Market Supervisory Authority published Guidance 05/2026 on July 9, 2026, following a survey of 60 banks, insurers, asset managers, and financial market infrastructures conducted between November 2025 and January 2026.

FINMA's guidance binds Swiss institutions. US insurers have no equivalent quantum-specific supervisory expectation, and the NAIC has not issued one. That changes when a carrier will be asked about this, not whether the exposure exists.

Federal deadlines set the timetable their government-adjacent policyholders and technology vendors will migrate on, which determines when a carrier's own third-party exposure actually starts to shrink.
A DigiCert survey of 1,001 IT and security decision-makers published in July 2026 found a wide gap between belief and deployment:

That distance between recognizing the threat and having done anything about it is what an underwriter is actually pricing when they assess a client's cryptographic posture.
The clearest attempt to translate this into actuarial terms is now three years old. A 2023 Moody's RMS analysis estimated a one to six percent probability of a quantum computer breaking RSA-2048 within five years, and translated that into a 16- to 100-year return period for modeling purposes.
No comparable public reframing has followed. A return-period model built on 2023 assumptions is being asked to price a 2026 regulatory environment it was not designed to reflect.
Closing this exposure means running two separate workstreams, and most carriers are currently running neither, or are running one and mistaking it for both.
A cryptographic inventory of the insurer's own systems, reaching past TLS certificates into:
This is the same discovery exercise FINMA now requires of the institutions insurers cover. There is no credible basis for exempting the insurer itself from it.
Underwriting questions calibrated to score a policyholder's actual cryptographic exposure and the credibility of its migration plan, rather than treating a clean annual control questionnaire as sufficient evidence of readiness. Four questions do most of the work:
A firm can pass every control test on file and still have no accurate view of where its cryptography lives.
Across cryptographic assessments run for financial-sector clients, the most common failure mode is not missing encryption. It is an inventory that stops at TLS certificates and never reaches the hardware security modules, backup tooling, and vendor-embedded keys carrying the data with the longest shelf life. That is exactly the data an insurer should be least willing to leave unexamined, and it is the data most likely to sit outside whatever inventory already exists.
Insurers who wait for certainty on quantum computing's arrival date will spend the next several renewal cycles pricing a risk they are simultaneously accumulating inside their own infrastructure. The sequence that holds up is to audit the carrier's own exposure first, then apply the same discovery question to every account on the book.

A fixed-fee Quantum Threat Assessment produces a board-ready snapshot of cryptographic exposure across an organization's infrastructure, without committing to a full migration program before the inventory is complete.

About Horizen Labs Quantum Security Team
Horizen Labs delivers expert-led quantum security consulting, helping organizations assess and address cryptographic exposure before regulatory and threat timelines force the issue.
Quantum Risk Check

A quantum risk score across three dimensions: cryptographic exposure, harvest risk, and signature Integrity, plus regulatory flags and recommended next steps.
Check NowYour board needs to understand quantum risk. Here's the briefing that gets it on the agenda.

Plain language. Current regulatory deadlines. Five actions they can approve today.
Download Now for FreeBLOG

Seven governments and CISA just called quantum risk present-tense, and not just a defense problem. Here's the timeline compressing into 2027, and what to map first.

Horizen Labs is migrating the Horizen protocol to quantum-resistant cryptography. Part 1 maps where the real exposure sits: the public-key and signature surfaces, not the hash primitives. It lays out a pull-based roadmap pegged to Ethereum's and the Superchain's post-quantum milestones, targeting end-2029.

Running a CBOM scanner before a Quantum Threat Assessment is the most common and expensive mistake in quantum-security migration. Without a prioritized threat model, scan results are either unmanageable or incomplete. Here's why the assessment has to come first, and what the right sequence looks like.