Quantum on the Board's Radar: Are the Board and CEO Looking at the Same Map?
Does quantum belong on the board's radar today? For some companies, the answer may already be, “yes”. For others, its immediate relevance remains limited, but with post-quantum security standards advancing, technology providers preparing for migration, and potential commercial applications continuing to develop, it is becoming harder to dismiss the question. There is value in asking whether the board and management understand its potential relevance to the company in the same way.
In a previous article, I introduced the Quantum Relevance Map, which places a company in one of four quadrants: Monitor, Protect, Explore, or Protect + Explore based on two axes: potential security exposure and potential business opportunity. You can use this tool to start the conversation. Before discussing the map as a group, ask the CEO and each director to place the company on it independently and record their answers, and then compare them.
Start With Where You Are
Suppose the CEO places the company in Monitor, while several directors place it in Protect. The results show they see the company's exposure differently. Perhaps directors are focused on the longevity of sensitive data that management has discounted. Perhaps management understands technology dependencies or vendor migration plans that management has more insight into than the board. Perhaps they are making different assumptions about customers, regulation, acquisition exposure, or how quickly which standards will affect the company's ecosystem.
The disagreement or divergence is itself informative, as it identifies something worth considering.
Agreement Can Hide More Than Disagreement
There is a more subtle possibility. Suppose the CEO and every director independently place the company in Monitor. That looks like alignment, so consider a possibility. Before discussing their answers, they were asked a follow-on question: What would have to become true for you to move the company to Protect?
· The CEO says a major customer would need to introduce a post-quantum security requirement.
· One director says discovering that the company holds sensitive information with a 15-year confidentiality life would be enough.
· Another says a critical technology vendor would need to announce a migration timeline.
· One other points to a change in regulatory or insurance expectations.
Everyone agrees about where the company sits today, but they do not necessarily agree about what would make today's answer wrong tomorrow. That may be the more consequential form of divergence.
Compare More Than the Box
The exercise becomes more useful if the CEO and directors answer four questions independently before the discussion begins:
1. Where are we today?
Place the company on the map.
2. What evidence puts us there?
What do we know about long-lived data, cryptographic dependencies, customers, vendors, regulation, transactions, and potential business applications that support that placement?
3. What would cause us to move?
What specific change would make the current position no longer appropriate?
4. What would we do differently if that happened?
Would ownership change? Would the issue come to the board? Would vendor conversations change? Would investment be required? Would diligence expand? Would the company begin exploring a commercial opportunity?
The sequence is simple: Position → Evidence → Trigger → Response
Agreement on the first does not necessarily mean alignment on the remainder. That’s the point I want to make: the organization not only needs to recognize where it is today; it needs to recognize when today's answer is no longer the right one.
Not Every Difference Needs to Be Resolved
Boards sometimes treat alignment as synonymous with agreement, and it isn't.
If a director believes a customer requirement should trigger movement to Protect while management believes a vendor migration announcement should come first, the objective is not to garner consensus and reach a shared view. A useful outcome is to determine whether the difference was surfaced, understood, and translated into a governance mechanism.
Perhaps both conditions should be monitored. Perhaps one belongs with management while the other warrants board visibility. Perhaps additional information is needed.
Good governance does not eliminate different perspectives. It makes them visible enough to improve the organization's ability to recognize change.
On the Radar Does Not Mean Running the Response
Putting quantum on the board's radar does not mean making it a standing agenda item, creating a quantum committee, or asking directors to monitor technical developments themselves.
Management still owns management. The board's questions sit at a different level:
· Do we understand why management has placed the company where it has?
· Is someone accountable for monitoring the conditions that could change that assessment?
· Do we know what would cause greater attention or escalation?
· Would the board hear about it when it should?
· Does the organization have the capacity to respond if the answer changes?
For a company in Monitor, periodic visibility may be sufficient. A company in Protect may require greater attention to data exposure, vendor dependencies, migration planning, or customer requirements. A company moving toward Explore may begin asking questions about strategy, competitive position, partnerships, capabilities, and capital allocation.
The level of oversight should follow the company's actual condition, not the prominence of quantum in the headlines.
Movement Does Not Always Mean Progress
As tempting as it is with a quad chart, the map is not a maturity model; there is no winning quadrant. A company might move from Monitor to Protect because a customer changes its requirements. It might move from Monitor to Explore because a commercially credible use case emerges. It could move toward Protect + Explore as both become relevant.
Movement can also go in the other direction, although the two axes behave differently. Opportunity can recede. An exploratory use case may prove economically unattractive, or a technology pathway may develop more slowly than expected.
Security exposure is less easily reversed. Long-lived sensitive data that already exists does not become less exposed simply because quantum develops more slowly. But the company's burden may change; for example, if a critical vendor assumes responsibility for a migration the company previously expected to manage itself.
The objective is twofold: have a position that reflects the company's condition and know when that condition changes.
The Larger Governance Test
Boards cannot become expert in every emerging technology, geopolitical development, regulatory shift, or new form of enterprise risk. What they can ask is whether the organization has a mechanism for recognizing when something previously peripheral becomes material.
· Who notices the signal?
· Who determines what it means?
· Who owns the response?
· What causes escalation?
· When does the board need to know?
Quantum is a useful test because uncertainty remains high, timelines are debated, and relevance varies significantly by company. That makes it tempting either to overreact or to wait.
A board and CEO can both be in the same quadrant and still be looking at very different maps.
Governance alignment isn't simply agreement about today's answer. It is sufficient shared understanding of why that answer is right, what would cause it to change, and what the organization would do next.
Quantum is one test of that capability, and it won't be the last.