Quantum computing risk insurance

Category: Emerging risks · Reviewed by Matt Bartlett, Director · Founder · Last reviewed 2026-06-10

Quantum computing risk insurance is an emerging line of cyber and professional indemnity cover that addresses the prospective ability of large-scale fault-tolerant quantum computers to break the public-key cryptography presently used to protect data, communications and financial systems.

The principal underwriting concern is the so-called “harvest now, decrypt later” attack: adversaries copy encrypted data today with the intention of decrypting it once a cryptographically relevant quantum computer (CRQC) becomes available. The UK National Cyber Security Centre’s (NCSC) post-quantum cryptography migration guidance and the United States National Institute of Standards and Technology (NIST) Federal Information Processing Standards FIPS 203, FIPS 204 and FIPS 205, published in August 2024, set out the migration framework against which insurers are now assessing exposure.

Definition

Quantum computing risk insurance is not a single product but a developing constellation of underwriting responses to a foreseeable but unrealised peril, including:

It overlaps with, but is distinct from, mainstream cyber insurance and cyber liability cover.

Legal and regulatory basis

There is no UK statute specific to quantum cryptography risk. The relevant framework is drawn from:

How it works in practice

Insurer responses currently fall into four categories:

  1. Exclusionary language — cyber wordings increasingly contemplate exclusion or sub-limit for losses arising from cryptanalysis of historic data using future quantum capability.
  2. Migration warranties — affirmative requirements that insureds maintain a documented PQC migration plan consistent with NCSC or NIST guidance.
  3. Affirmative cyber extension — limited capacity offered by Lloyd’s syndicates and specialty markets for breach-response costs and regulatory liability arising from decryption events.
  4. Silent risk reviews — insurers conducting portfolio-wide reviews of long-tail liability and BI exposures (analogous to “silent cyber” remediation following Lloyd’s market bulletin Y5258).

Common variations and subsequent developments

Example

A UK fintech holds five years of customer transaction data encrypted under RSA-2048. In 2026 its cyber insurer requires, at renewal, a warranty that the firm will commence migration to ML-KEM (FIPS 203) for new data in transit within 12 months and complete migration of stored data within 36 months. The policy excludes loss arising from decryption of historical data exfiltrated prior to migration, save for a sub-limited GBP 1 million breach-response extension. The firm engages its CISO and external cryptographer to deliver the migration plan and records progress against NCSC’s discovery and planning phases.

See also

References


This entry is part of the Apex Insurance Wiki. Last reviewed by Matt Bartlett on 2026-06-10. Next review: 2026-12-10.

Apex Insurance Brokers Limited. Authorised and regulated by the Financial Conduct Authority, FRN 724952. Registered in England and Wales, Companies House 07014570. This entry provides general information about UK insurance concepts and is not regulated advice. Consult your insurance broker on your specific position.

Talk to a specialist broker

Apex Insurance Brokers serves UK professional services firms and commercial businesses. Call 0117 325 0027, email hello@apexinsurancebrokers.co.uk, or request a quotation.

Get a quote
Our service promise. We acknowledge every quote request the same working day. For straightforward risks, indicative terms typically follow within five working days. Complex risks — higher-risk buildings, cladding, mid-term proposals requiring fresh underwriting — may take longer; we’ll send you a progress note by the end of the fifth working day in those cases.
★ 4.0 on Trustpilot (verified)|Listed on the ARB PI broker list|FCA FRN 724952