Case Study: Should Your Organization Have a Quantum Program?

Executive Summary

A CTO is under pressure. Two competitors have announced quantum partnerships, the board has asked about quantum strategy, and a consultancy has proposed a $2M "quantum readiness" engagement.

The right answer for most organizations is a small, cheap, specific program — and emphatically not the $2M engagement. This case study builds the decision framework: what a quantum program should actually contain, what it costs, what triggers escalation, and how to tell a real opportunity from fear of missing out.

Skills applied

  • Distinguishing quantum-threat exposure from quantum-opportunity exposure (§31.13).
  • Sizing a proportionate program.
  • Setting escalation triggers.
  • Evaluating vendor and consultancy proposals.

Phase 1: Two entirely separate questions

The single most common analytical error is treating "quantum strategy" as one topic. It is two, with different timelines, different owners, and different urgency.

Threat Opportunity
Question Will quantum computers break our cryptography? Will quantum computers solve our problems faster?
Applies to Every organization A small minority
Timeline Acting now is required 2035+ for most
Owner Security / infrastructure R&D
Cost Moderate, unavoidable Discretionary
Certainty High — the algorithms exist and the standards are published Low — no proven commercial advantage yet

The threat side is not optional and not speculative. Harvest-now-decrypt-later means the clock started years ago (Chapter 30). The opportunity side is genuinely uncertain.

Conflating them produces the characteristic failure: an organization spends heavily exploring quantum chemistry it will never use while its RSA-wrapped backup keys sit unaddressed.

Phase 2: The threat assessment — everyone does this

Regardless of industry, run Mosca's inequality against your data:

Data class Lifetime Migration Sum Act now?
Public marketing content 0 No
Session tokens 1 day 0.5 yr 0.5 No
Customer records 7 yr 2 yr 9 Probably
Medical / genomic 50 yr 2 yr 52 Yes
Firmware signing 15 yr 3 yr 18 Yes

If any row exceeds a plausible $T_{\text{CRQC}}$, the threat program is mandatory. For most organizations at least one row does.

Cost: inventory plus migration planning, roughly 0.5–2 FTE for a year in a mid-sized organization, scaling with complexity. Not optional, and not a research project.

Phase 3: The opportunity assessment — most organizations stop here

Does your organization have a problem that is (a) quantum-amenable and (b) not already solved classically?

Run the filter from the earlier chapters:

Problem type Quantum prospect Why
Simulating molecules / materials with strong correlation Genuine Classical baseline is exponential (Ch. 17)
Combinatorial optimization Poor Classical solvers exploit structure (Ch. 13, 20)
Machine learning on classical data Poor Data loading defeats it (Ch. 21)
Machine learning on quantum data Genuine No loading cost (Ch. 21)
Cryptanalysis (defensive understanding) Relevant But that is the threat side
Monte Carlo finance Marginal Quadratic at best, huge constants
Logistics / scheduling Poor OR-Tools solves it today

Most organizations have nothing in the "genuine" rows. Banks, retailers, logistics firms, healthcare providers, and software companies overwhelmingly do not. Pharmaceutical, chemical, materials, and battery companies sometimes do.

If you have nothing in the genuine rows, the correct opportunity program is: monitor, and revisit in three years. That is a defensible position, not a failure of ambition.

Phase 4: The proportionate program

For an organization with threat exposure and no genuine opportunity:

Activity Effort Annual cost
Cryptographic inventory (year 1) 2 FTE $300k
PQC migration planning and execution 1 FTE ongoing $160k
Monitoring: one person tracking the field at 10% time 0.1 FTE $20k
Cloud credits for occasional experimentation $10k
Total ~$490k year 1, ~$190k after

Against the consultancy's $2M "quantum readiness" engagement — which typically delivers a landscape report, a use-case workshop, and a pilot on a problem the organization does not have.

For an organization with genuine opportunity exposure, add: 1–2 researchers with domain plus quantum knowledge, deeper cloud access, and an academic collaboration. Perhaps $600k/yr more. Still far below $2M, and directed at a specific technical question.

Phase 5: Escalation triggers

Rather than revisiting annually on instinct, define triggers in advance:

Escalate the threat program if: regulators mandate PQC timelines in your sector; a lattice cryptanalysis result weakens ML-KEM; your inventory finds exposure larger than expected.

Escalate the opportunity program if: a peer-reviewed result shows quantum advantage on a problem class you have; logical qubit counts exceed ~100 with algorithmic-grade error rates; a vendor demonstrates an application beating tuned classical baselines at equal wall-clock on published benchmarks.

De-escalate if: three years pass with no advantage demonstration in your domain and no change in the logical-qubit trajectory.

Written triggers convert a recurring judgement call into a monitoring task, which is both cheaper and less susceptible to whichever competitor announced something last week.

Phase 6: Reading the pressure

The CTO's three pressures, assessed:

"Competitors announced partnerships." Most such partnerships are exploratory access agreements generating press releases. Ask what the competitor actually receives — usually cloud credits and joint marketing. Announcing a partnership is cheap; the useful question is whether they have shipped anything.

"The board asked." They deserve a real answer, and the real answer is a one-page version of this analysis: here is our threat exposure and what we are doing about it; here is our opportunity exposure, which is minimal, and here are the triggers that would change that. That is a stronger board answer than a $2M program, because it demonstrates that the question was actually analyzed.

"The consultancy proposed $2M." Ask what the deliverable is and how it differs from what a well-informed employee could produce in a month. Ask them to name the specific problem in your organization with a quantum advantage argument, and to state the classical baseline. Firms that cannot answer are selling the topic, not a solution.

Discussion Questions

  1. Threat and opportunity have different timelines, owners, and certainties. Why does conflating them systematically misallocate effort?
  2. Most organizations have nothing in the "genuine opportunity" rows. Is that likely to change, and what would change it?
  3. Written escalation triggers replace annual judgement calls. What are the failure modes of that approach?
  4. Draft the one-page board answer for an organization you know.

Your Turn: Extensions

  • Run the Mosca table for your organization's three longest-lived data classes.
  • Apply the opportunity filter to your organization's computational workloads.
  • Cost a proportionate program at your organization's scale.
  • Evaluate a real vendor or consultancy proposal against the Phase 6 questions.

Key Takeaways

  • Quantum threat and quantum opportunity are separate questions with different timelines, owners, and certainties; conflating them misallocates effort.
  • Threat exposure applies to essentially every organization and requires action now, driven by data lifetime rather than quantum forecasts.
  • Opportunity exposure is real for a minority — mainly chemistry, materials, and quantum-data problems — and absent for most.
  • A proportionate program costs a few hundred thousand a year, not millions; large "readiness" engagements usually deliver landscape reports.
  • Define written escalation triggers in advance so the decision is monitored rather than relitigated whenever a competitor issues a press release.