Nir Ben-David

Who Owns Quantum Readiness?

Ask an organization who owns cybersecurity, cloud infrastructure, data privacy, or regulatory compliance, and chances are you will get a specific answer quickly.

Ask who owns quantum readiness, and the answer is often much less clear.

That ambiguity matters.

Preparing for the Quantum Era is frequently treated as a cybersecurity problem. That makes sense at first. Much of the immediate concern revolves around cryptography: the algorithms protecting sensitive information, communications, identities, transactions, and digital infrastructure.

But replacing vulnerable cryptography across a complex organization goes beyond security. It touches technology, data, hardware, procurement, vendors, budgets, compliance, business operations, and long-term risk.

Which creates a surprisingly difficult question: Who is actually responsible for making sure the organization is ready?

The problem crosses the org chart

In my previous articles, I described quantum readiness through three clocks: the Data Clock, the Migration Clock, and the Quantum Clock. But no single department naturally owns all three.

The Data Clock measures how long information created today needs to remain protected. The CISO may understand the security exposure, but may not know how long every category of business information needs to remain confidential. Business leaders, legal teams, data owners, and compliance functions may have important parts of that answer.

The Migration Clock measures how long an organization may need to discover its cryptographic dependencies, prioritize them, test alternatives, coordinate with vendors, replace or upgrade systems, validate the changes, and deploy them safely. The CIO may understand the technology estate, but may not control every embedded system, third-party platform, hardware dependency, or supplier timeline.

The Quantum Clock represents the uncertain horizon before cryptographically relevant quantum computers could threaten today’s public-key cryptography. The CTO may understand architecture and technical transformation, but may not be positioned to determine how much uncertainty the organization should accept when planning for that horizon.

Procurement may manage relationships with critical technology vendors, but may not know which suppliers represent the largest cryptographic bottlenecks. Legal and compliance teams may understand retention requirements and obligations, but may not know how difficult a cryptographic migration will be.

Each function sees part of the problem.

Someone has to see the whole.

When an organization brings those clocks together, a practical deadline begins to emerge. If the information it needs to protect must remain secure longer than the time available after accounting for migration, preparation cannot wait for quantum computers to arrive.

Ownership is not the same as execution

It is tempting to solve this by assigning quantum readiness to the CISO.

In some organizations, that may be exactly the right answer. In others, the CIO, CTO, Chief Risk Officer, or another senior executive may be better positioned.

The more important distinction is between accountability and execution.

One executive should be accountable for quantum readiness. No single function can execute it alone.

So how should an organization choose that person?

The answer should have less to do with title than with fit.

The right owner needs enough authority to bring different functions to the table and turn decisions into action.

They need enough reach across the organization to understand how decisions in security, technology, procurement, compliance, and the business affect one another.

They need the ability to translate technical risk into business priorities that executives can understand, fund, and act upon.

And they need continuity. Quantum readiness is unlikely to be a single technology project with a clear beginning and end. It may involve decisions about systems being purchased today, information that must remain protected for decades, and vendors whose own migration timelines are outside the organization’s direct control.

Authority. Reach. Translation. Continuity.

Those qualities matter more than having “quantum” in a job title.

The person does not need to be the organization’s leading quantum expert. They need to be able to make quantum readiness an organizational responsibility rather than a technical issue waiting for someone else to solve.

Once that owner is identified, the next task is to build the team around them.

That means bringing together security, IT, architecture, data owners, procurement, legal and compliance, risk management, and the relevant business units.

This does not require creating another large organizational bureaucracy or appointing a “Chief Quantum Officer.”

For many organizations, the first governance step can be much simpler: name an accountable executive, establish a cross-functional working group, define the information and systems that matter most, and begin measuring the problem.

The objective is not to create a quantum department. It is to make sure quantum readiness does not fall into the gaps between existing departments.

From awareness to accountability

For the past several years, much of the quantum-security conversation has focused on awareness: explaining the threat, discussing post-quantum cryptography, and debating when powerful quantum computers might arrive.

Awareness was necessary.

But awareness without ownership eventually becomes another risk everyone recognizes and nobody is accountable for reducing.

Organizations do not need perfect forecasts before they begin. They need someone responsible for asking the right questions, assembling the right people, and turning uncertainty into a plan.

Discovery tells an organization what it has. Ownership determines whether anyone acts on what it finds.

The Three Clocks can structure that conversation. But someone still has to own it.

Because a risk that belongs to everyone has an uncomfortable tendency to belong to no one.

Next: What Should You Migrate First? — Why quantum readiness is not about replacing everything at once, but knowing what matters most.

About the Author
Nir Ben-David is a Brigadier General (Res.), entrepreneur, former senior military commander, and strategic advisor specializing in national security, quantum technologies, cybersecurity, and digital trust. He is the Founder & CEO of Qombat and an angel investor for the hardware-anchored post-quantum technology company, EigenQ. He writes about the intersection of emerging technologies, public policy, and global security.
Related Topics
Related Posts
Sign in or Register
Please use the following structure: example@domain.com
Or Continue with
By registering you agree to the terms and conditions
Register to continue
Or Continue with
Log in to continue
Sign in or Register
Or Continue with
check your email
Check your email
We sent an email to you at .
It has a link that will sign you in.