Quantum computing is moving from research into real-world applications. Although this technology may turn out to have a substantive impact on legal work, the immediate concern is the potential for quantum computers to break the encryption on which law firms rely to protect their communications and data. Though a cryptographically relevant quantum computer (CRQC) is not yet available, CRQCs will likely be able to undermine encryption methods currently used to protect confidential client information, communications, systems, and digital identities.
Although CRQCs are not here yet, the risk is. Stolen encrypted data may be safe from decryption today, but threat actors can stash it away with the intention of decrypting it as soon as sufficiently powerful quantum technology becomes available. Governments and banking regulators are already setting expectations for those who hold their data; quantum readiness may soon be a key market differentiator for law firms, if not an outright requirement.
This session, presented by Katharine Freding, Director of Information Governance, Crowell & Moring LLP, will begin with a practical introduction to quantum computing: what it is and how it differs from classical computing. We will then review what is meant by post-quantum cryptography and give an updated timeline for the possibility of a cryptographically relevant quantum computer. From there, we will explore the wider operational, governance and compliance implications, including:
• The impact on encryption and the protection of confidential and regulated information
• Dependencies on technology providers, cloud platforms, and the wider supply chain
• Understanding where information resides, how long it needs to remain protected, and that ‘the data breach’ may already have happened
• The role of information classification and defensible disposition in reducing threat exposure
• Client, contractual, regulatory, insurance and professional obligations – and who will be requesting