
Imagine waking up on June 6, 1944. Thousands of Allied soldiers are about to land on the beaches of Normandy, and the world is about to change forever.
The invasion itself would take hours. But the preparation had taken years.
The most important work had happened long before the boats reached the shore. Alan Turing and his team had already broken the German Enigma code. By the time D-Day arrived, the decisive move had already been made in a quiet room, months earlier, by people the soldiers on the beach would never meet.
Nearly a century later, the world is preparing for another kind of D-Day. There is no beach, no fleet, and no date on the calendar. But the logic is the same. The most important work has to happen long before the day itself.
Q-Day is the moment a sufficiently powerful quantum computer could break the encryption that protects almost every piece of digital information in the world. Bank transfers. Medical records. State secrets. The invisible locks that hold up the digital economy would, in a matter of hours, no longer hold.
Why is quantum such a threat? Think of the encryption that protects almost everything on the internet as a bucket of mixed paint. Combining two specific colors to make a new shade is easy. But if you were handed the final color and asked to find the exact two shades that made it, you would be stuck for a lifetime. That asymmetry is what protects your bank account, your medical records, and every digital signature you rely on. A classical computer, no matter how powerful, cannot efficiently reverse the mixture. But a quantum computer, running the right recipe, can detect a hidden rhythm inside that mixture. And once the rhythm is found, so are the original colors. What would take a classical computer millions of years, a powerful enough quantum computer could do in hours.
We do not know when Q-Day will arrive. What we do know is that it is coming faster than we expected.
Only a few years ago, credible estimates placed Q-Day in the mid-2030s to early 2040s. In 2019, Google Quantum AI estimated that breaking a common encryption key would require around 20 million noisy physical qubits. In May 2025, they revised that estimate down to fewer than one million. In roughly five years, the requirement dropped by a factor of twenty.
The distinction matters. A “physical qubit” is the actual hardware qubit. Because they are error-prone, hundreds or thousands of them must be combined into a single reliable “logical qubit” that the algorithm can trust. When we talk about millions of qubits, we are almost always talking about the physical ones. And that is exactly the number that just shrank.
The leap did not come solely from faster hardware. It came from smarter algorithms and better error correction. In other words, from human ingenuity moving faster than most people expected.
But the more urgent threat is quieter, and it is already here. It has a name: Harvest Now, Decrypt Later. Adversaries are collecting encrypted data today, storing it, and waiting for the day quantum machines can unlock it. Financial records, medical histories, and state secrets sent across the internet right now are, in effect, already compromised. Not because the code is broken yet, but because someone is already keeping the box until the key exists.
This is why governments are not waiting, and the timelines keep getting shorter. In June 2026, the United States accelerated its federal deadline by five years, ordering agencies to transition their most sensitive systems to post-quantum encryption by 2030 for key exchange and 2031 for digital signatures. The United Kingdom is on a similar clock, and major technology companies like Google, Microsoft, and Cloudflare have set even more aggressive internal targets of 2029. Closer to home, Thailand’s National Cyber Security Agency has issued a “Quantum-Ready 2030” roadmap, and the Thai SEC has already warned financial institutions to begin preparing. What is striking is not any single country’s plan. It is that governments and companies that rarely move in unison are converging on the same window, and moving that window forward.
At SCBX, this is a question we take seriously. As one of Thailand’s largest financial groups, the trust we hold is written in the encryption that protects every transaction, every account, and every piece of customer data we handle. Quantum readiness is not a distant IT project. It is a core responsibility. It begins with the most fundamental step of all: an inventory assessment of our digital assets, so we know exactly where encryption lives across our systems and what needs to be migrated first. From there, we are actively upgrading legacy encryption, adopting hybrid post-quantum cryptography for our digital banking applications, and building the quantum-safe foundations that regional financial infrastructure will need long before quantum hardware arrives. Because in a world of Harvest Now, Decrypt Later, the work of protecting tomorrow’s data has to start today.
Back to Normandy. The reason D-Day is remembered as a turning point is not the courage on the beach, though that was real. It is that the invisible work had already been done. The codes had been broken. The plans had been laid. The preparation was already history by the time the boats landed.
Q-Day will be the same kind of moment. When it arrives, the outcome will not be decided by what happens that day. It will be decided by what we did in the years before.
The countdown has already begun.



