Enterprise customers are increasingly asking not only how quantum computers could create new business opportunities, but also how soon they need to protect themselves from them, according to executives on IonQ’s second-quarter earnings call.
The comments suggest that quantum cybersecurity is becoming a more immediate commercial concern for corporations, particularly in finance and other data-intensive industries, as the timeline for practical quantum computers continues to compress. While governments have spent years urging organizations to prepare for post-quantum cryptography, IonQ executives said those conversations are now becoming commonplace in corporate boardrooms and customer meetings.
“So we’ve had a number of calls, Niccolo (de Masi) meet CEOs all the time. Our sales team does. I joined many of those. And in each one, security now enters into the discussion,” Chief Operating Officer and Chief Financial Officer Inder Singh said during the company’s question-and-answer session.
He added: “A year ago, it was about computing. Now it’s about computing. How do I, of course, create more revenue? How can I use your solutions to do things that classical can’t do? But equally, how can you protect me from the inevitable? And if the inevitable is 2 years away, 3 years away, it doesn’t really matter. It’s not 20 years away. So it’s pretty broad-based.”
The remarks came as IonQ reported record quarterly revenue and highlighted growing demand across its quantum computing, networking and security businesses. While much of the earnings call focused on the company’s roadmap toward larger fault-tolerant quantum computers and its recent acquisition of semiconductor manufacturer SkyWater Technology, executives repeatedly returned to cybersecurity as an emerging growth area.
Security Moves with Computing
Singh said customers increasingly view quantum computing and quantum security as related purchasing decisions rather than separate technology initiatives.
The team is seeing high demand for both quantum computing and quantum security, which, on the business side, is a significant cross-selling opportunity.
The discussion appears to reflect increasing concern surrounding so-called Q-Day—the point at which a fault-tolerant quantum computer could break widely used public-key encryption systems such as RSA and elliptic curve cryptography. Although experts continue to debate when such machines will become practical, governments have warned organizations to begin migrating vulnerable systems because replacing cryptographic infrastructure can take years.
According to Singh, customers are no longer debating whether they should prepare, but when.
“Financial services is definitely waking up to the cold hard reality that at some point, RSA-2048 and other encryption protocols such as ECC-256 may all be broken,” Singh said. “And the debate is around, is it in 2 years, 3 years, less or more? I think you’ve heard from many companies now that, that is getting very, very close.”
Beyond Post-Quantum Cryptography
IonQ is positioning itself as a provider of what executives described as a “defense-in-depth” approach to quantum cybersecurity rather than relying solely on post-quantum cryptography (PQC).
Chief Executive Officer Niccolo de Masi said the company’s strategy combines PQC with quantum key distribution (QKD), quantum networking and other technologies intended to secure communications in a future quantum computing environment. He also announced a new QKD product designed to operate over existing municipal fiber networks.
That strategy differs somewhat from the current mainstream approach to quantum security. Governments including the United States have largely centered their migration efforts on standardized post-quantum cryptographic algorithms developed through the National Institute of Standards and Technology (NIST). QKD, which uses the properties of quantum mechanics to detect eavesdropping during key exchange, is generally viewed as a specialized solution for particularly sensitive communications rather than a replacement for public-key cryptography across the internet.
IonQ executives argued that organizations with the most valuable data will ultimately require multiple layers of protection.
We’ve always believed that the code-making, code-breaking race will be a continual one,” de Masi said. “And it will happen at the software level, of course, because you need PQC everywhere, and that race between code makers and code breakers has been going for at least back to Julius Caesar. It’s probably a 10,000-year-old process, but at least a 2,000-year-old process, and it will keep going.”
Singh also outlined a new service opportunity to help organizations identify where their networks remain vulnerable to future quantum attacks.
He said IonQ is developing tools that can scan enterprise networks for quantum-related security risks, identify vulnerable systems and continuously monitor those environments as organizations migrate toward quantum-safe technologies.
Some of those conversations, he said, now begin with chief executive officers rather than only information technology departments.
“They want to know, am I vulnerable? If I’m vulnerable, where?” Singh said. “So we can provide that map on day 1 for them, help them understand where the worst vulnerabilities are and protect those now. Whether they choose to use PQC or QKD or another flavor, we intend to be the one-stop shop for all of those.”
He added that future regulatory requirements could eventually require organizations to demonstrate that they have protected their networks against quantum-enabled attacks, although no such mandates currently exist.



