Leading with Proof: IonQ’s Blueprint for Quantum-Safe Enterprise Security

Table of contents
IonQ Staff
,
August 24, 2026

At a glance:

IonQ has devised a quantum-safe security solution leveraging the strengths of both quantum key distribution (QKD) and post-quantum cryptography (PQC).

This hybrid approach is now running live in IonQ’s own network, protecting the company’s mission-critical data between locations in Geneva, Switzerland, and Seoul, South Korea.

IonQ is showing organizations how they can act now to accelerate their own quantum-safe security migrations, and mitigate the risk of “Harvest Now, Decrypt Later” attacks.

The solution directly addresses recent proclamations by governments worldwide urging more rapid migration to quantum-safe security.

The hybrid solution is just one aspect of IonQ’s broader roadmap to help organizations worldwide reduce their exposure to threats that could cause revenue loss and weaken operational stability.

Leading with Proof: IonQ’s Blueprint for Quantum-Safe Enterprise Security

Hybrid QKD+PQC Approach Adds a New Layer of Protection as Q-Day Nears

A Pragmatic Enterprise Defense Solution

Proving by Using

Mitigating the HNDL Risk

The Roadmap to a More Secure Enterprise

Hybrid QKD+PQC Approach Adds a New Layer of Protection as Q-Day Nears

IonQ today has a multi-layered approach ready to help corporate and government organizations prepare for the imminent cybersecurity threat posed by near-term quantum computers. This global, hybrid quantum-safe security initiative, leveraging both quantum key distribution (QKD) and post-quantum cryptography (PQC) technologies, is deployed now on a portion of IonQ’s network between Switzerland and South Korea, and is protecting IonQ’s own valuable assets.

Our intent in highlighting our own deployment is to show government leaders and corporate executives everywhere the action they can–and must–take right now to reduce susceptibility to quantum attacks and their consequences–huge financial losses, damage to critical infrastructure and operations, and great harm to brand reputation and organizational stability.

We have been living for decades with the knowledge that a sufficiently powerful quantum computer could one day crack public-key cryptography algorithms like Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC). In 1994, Peter Shor developed Shor’s Algorithm, which could be run on a quantum computer to efficiently factorize large numbers. Since factoring is the mathematical problem underlying both RSA and ECC, this means a quantum computer of the right size could break both schemes. No such quantum machine existed back then, but the knowledge that one eventually would exist led to that line on the horizon being called “Q-Day.”

More than 30 years later, there is new urgency about Q-Day, in large part because quantum computing capabilities are advancing more quickly than ever. IonQ’s early benchmarking of a quantum computer’s ability to run advanced algorithms, and our achievement of Algorithmic Qubit goals ahead of schedule are just two proof points of this acceleration. Error mitigation and correction capabilities also have evolved quickly, enabling quantum computers to more efficiently translate physical qubits into logical qubits that could achieve algorithm runs with greater efficiency and accuracy.

These achievements compressed the Q-Day timeline. It was once thought that millions of qubits would be required to crack RSA and ECC, but recent research suggests the necessary number could be much smaller. Last March, Google Quantum AI and its research partners published a landmark whitepaper claiming 256-bit ECC could be broken with as few as 1,200 logical qubits drawn from a quantum machine capable of 500,000 physical qubits. This research drove Google to urge migration to PQC by 2029. Other research has suggested that fewer than 100,000 qubits could be required to factor a 2,048-bit RSA integer. Yet another paper, from researchers at Caltech and Oratomic, claimed Shor’s Algorithm could be run with as few as 10,000 qubits.

But, here’s the most urgent reality check about Q-Day: By the time quantum computers can run Shor’s Algorithm, it will be too late for corporations and governments to begin adopting quantum-safe security. Migrating to this new layer of protection can take an organization several years, including laborious and time-consuming enterprise-wide asset inventories, vendor selection processes, and testing and validation phases. To put it simply, organizations can’t wait any longer to start down this road.

Hackers certainly aren’t waiting. The world has come to a queasy understanding that they could be stealing encrypted data right now, and planning to use a quantum computer later to break the locks–a practice commonly known as “Harvest Now, Decrypt Later” (HNDL).

IonQ’s proactive effort to strengthen IT security practices reflects this reality, and also arrives as nations around the world are coming to terms with the quantum threat. For example, in the US, a new mandate recently pulled forward the deadlines for federal government agencies to adopt PQC-standard public keys and quantum-safe digital signatures. Meanwhile, in Europe, the European Commission recently said all member states should start transitioning to PQC by the end of this year. The governments of the US and Japan also recently agreed to “collaborate to accelerate” PQC adoption in their respective countries.

All of the above make the quantum threat a present and practical corporate risk management and governance priority for government agencies, corporate boards and C-level officers worldwide.

A Pragmatic Enterprise Defense Solution

This encroaching reality and new sense of urgency set the stage for IonQ’s new hybrid protection architecture that encompasses both QKD and PQC in a single infrastructure solution to help protect widely distributed corporate and government locations.

This infrastructure is operational now in its inaugural deployment across two continents, securing four IonQ sites between Geneva, Switzerland, and Seoul, South Korea. In this new hybrid approach, QKD protects local fiber links connecting IonQ sites in Geneva, providing information-theoretic security for high-priority internal communications, while an additional layer of PQC secures software-defined VPN endpoints between Geneva and IonQ’s South Korea headquarters.

This deployment is not a standalone project, but the first step in a broader global program that has been undertaken by IonQ to provide a blueprint for executing a systematic, scalable, and repeatable strategy for implementing quantum-safe security.

 

A closer look at QKD and PQC:

Related blogs

No items found.
min
min

Download PDF