Case Study: Should Your Organization Have a Quantum Program?
Executive Summary
A CTO is under pressure. Two competitors have announced quantum partnerships, the board has asked about quantum strategy, and a consultancy has proposed a $2M "quantum readiness" engagement.
The right answer for most organizations is a small, cheap, specific program — and emphatically not the $2M engagement. This case study builds the decision framework: what a quantum program should actually contain, what it costs, what triggers escalation, and how to tell a real opportunity from fear of missing out.
Skills applied
- Distinguishing quantum-threat exposure from quantum-opportunity exposure (§31.13).
- Sizing a proportionate program.
- Setting escalation triggers.
- Evaluating vendor and consultancy proposals.
Phase 1: Two entirely separate questions
The single most common analytical error is treating "quantum strategy" as one topic. It is two, with different timelines, different owners, and different urgency.
| Threat | Opportunity | |
|---|---|---|
| Question | Will quantum computers break our cryptography? | Will quantum computers solve our problems faster? |
| Applies to | Every organization | A small minority |
| Timeline | Acting now is required | 2035+ for most |
| Owner | Security / infrastructure | R&D |
| Cost | Moderate, unavoidable | Discretionary |
| Certainty | High — the algorithms exist and the standards are published | Low — no proven commercial advantage yet |
The threat side is not optional and not speculative. Harvest-now-decrypt-later means the clock started years ago (Chapter 30). The opportunity side is genuinely uncertain.
Conflating them produces the characteristic failure: an organization spends heavily exploring quantum chemistry it will never use while its RSA-wrapped backup keys sit unaddressed.
Phase 2: The threat assessment — everyone does this
Regardless of industry, run Mosca's inequality against your data:
| Data class | Lifetime | Migration | Sum | Act now? |
|---|---|---|---|---|
| Public marketing content | 0 | — | — | No |
| Session tokens | 1 day | 0.5 yr | 0.5 | No |
| Customer records | 7 yr | 2 yr | 9 | Probably |
| Medical / genomic | 50 yr | 2 yr | 52 | Yes |
| Firmware signing | 15 yr | 3 yr | 18 | Yes |
If any row exceeds a plausible $T_{\text{CRQC}}$, the threat program is mandatory. For most organizations at least one row does.
Cost: inventory plus migration planning, roughly 0.5–2 FTE for a year in a mid-sized organization, scaling with complexity. Not optional, and not a research project.
Phase 3: The opportunity assessment — most organizations stop here
Does your organization have a problem that is (a) quantum-amenable and (b) not already solved classically?
Run the filter from the earlier chapters:
| Problem type | Quantum prospect | Why |
|---|---|---|
| Simulating molecules / materials with strong correlation | Genuine | Classical baseline is exponential (Ch. 17) |
| Combinatorial optimization | Poor | Classical solvers exploit structure (Ch. 13, 20) |
| Machine learning on classical data | Poor | Data loading defeats it (Ch. 21) |
| Machine learning on quantum data | Genuine | No loading cost (Ch. 21) |
| Cryptanalysis (defensive understanding) | Relevant | But that is the threat side |
| Monte Carlo finance | Marginal | Quadratic at best, huge constants |
| Logistics / scheduling | Poor | OR-Tools solves it today |
Most organizations have nothing in the "genuine" rows. Banks, retailers, logistics firms, healthcare providers, and software companies overwhelmingly do not. Pharmaceutical, chemical, materials, and battery companies sometimes do.
If you have nothing in the genuine rows, the correct opportunity program is: monitor, and revisit in three years. That is a defensible position, not a failure of ambition.
Phase 4: The proportionate program
For an organization with threat exposure and no genuine opportunity:
| Activity | Effort | Annual cost |
|---|---|---|
| Cryptographic inventory (year 1) | 2 FTE | $300k |
| PQC migration planning and execution | 1 FTE ongoing | $160k |
| Monitoring: one person tracking the field at 10% time | 0.1 FTE | $20k |
| Cloud credits for occasional experimentation | — | $10k |
| Total | ~$490k year 1, ~$190k after |
Against the consultancy's $2M "quantum readiness" engagement — which typically delivers a landscape report, a use-case workshop, and a pilot on a problem the organization does not have.
For an organization with genuine opportunity exposure, add: 1–2 researchers with domain plus quantum knowledge, deeper cloud access, and an academic collaboration. Perhaps $600k/yr more. Still far below $2M, and directed at a specific technical question.
Phase 5: Escalation triggers
Rather than revisiting annually on instinct, define triggers in advance:
Escalate the threat program if: regulators mandate PQC timelines in your sector; a lattice cryptanalysis result weakens ML-KEM; your inventory finds exposure larger than expected.
Escalate the opportunity program if: a peer-reviewed result shows quantum advantage on a problem class you have; logical qubit counts exceed ~100 with algorithmic-grade error rates; a vendor demonstrates an application beating tuned classical baselines at equal wall-clock on published benchmarks.
De-escalate if: three years pass with no advantage demonstration in your domain and no change in the logical-qubit trajectory.
Written triggers convert a recurring judgement call into a monitoring task, which is both cheaper and less susceptible to whichever competitor announced something last week.
Phase 6: Reading the pressure
The CTO's three pressures, assessed:
"Competitors announced partnerships." Most such partnerships are exploratory access agreements generating press releases. Ask what the competitor actually receives — usually cloud credits and joint marketing. Announcing a partnership is cheap; the useful question is whether they have shipped anything.
"The board asked." They deserve a real answer, and the real answer is a one-page version of this analysis: here is our threat exposure and what we are doing about it; here is our opportunity exposure, which is minimal, and here are the triggers that would change that. That is a stronger board answer than a $2M program, because it demonstrates that the question was actually analyzed.
"The consultancy proposed $2M." Ask what the deliverable is and how it differs from what a well-informed employee could produce in a month. Ask them to name the specific problem in your organization with a quantum advantage argument, and to state the classical baseline. Firms that cannot answer are selling the topic, not a solution.
Discussion Questions
- Threat and opportunity have different timelines, owners, and certainties. Why does conflating them systematically misallocate effort?
- Most organizations have nothing in the "genuine opportunity" rows. Is that likely to change, and what would change it?
- Written escalation triggers replace annual judgement calls. What are the failure modes of that approach?
- Draft the one-page board answer for an organization you know.
Your Turn: Extensions
- Run the Mosca table for your organization's three longest-lived data classes.
- Apply the opportunity filter to your organization's computational workloads.
- Cost a proportionate program at your organization's scale.
- Evaluate a real vendor or consultancy proposal against the Phase 6 questions.
Key Takeaways
- Quantum threat and quantum opportunity are separate questions with different timelines, owners, and certainties; conflating them misallocates effort.
- Threat exposure applies to essentially every organization and requires action now, driven by data lifetime rather than quantum forecasts.
- Opportunity exposure is real for a minority — mainly chemistry, materials, and quantum-data problems — and absent for most.
- A proportionate program costs a few hundred thousand a year, not millions; large "readiness" engagements usually deliver landscape reports.
- Define written escalation triggers in advance so the decision is monitored rather than relitigated whenever a competitor issues a press release.