22 Jul 2026

IM BLOG: Beyond the Dial Tone: Navigating the ASD’s 2030 Cryptography Rules in an Unstable Network Era

Quantum computing is coming. Is your organisation's long-term information protected against tomorrow's cryptographic threats?

Blog  Linda Shave  Beyond the Dial Tone Navigating the ASD’s 2030 Cryptography Rulesimage.png

For information management professionals, cryptography is more than a technical control, it is a governance obligation. When managing records with long retention requirements, such as health data, corporate intellectual property, legal records, or government archives, the challenge is not simply protecting information today, but ensuring that protection remains effective for decades to come.

The Australian Signals Directorate (ASD) has made its expectations increasingly clear. Organisations should be progressing beyond awareness and planning toward a structured post-quantum cryptography (PQC) transition. Current ASD guidance identifies key milestones, including the development of a refined PQC transition plan by the end of 2026 and the phased replacement of traditional asymmetric cryptography ahead of 2030.

For information managers, this means understanding where vulnerable cryptographic dependencies exist across the information estate. Legacy asymmetric algorithms such as RSA and elliptic curve cryptography (ECC) continue to underpin authentication, encryption, digital signatures, archives, and long-term records management systems. Identifying these dependencies now is essential for protecting information whose value and sensitivity may extend far beyond the lifespan of current cryptographic standards.

ASD has also highlighted the risk of 'Harvest Now, Decrypt Later' (HNDL) attacks, in which adversaries collect encrypted data today with the expectation that future quantum computing capabilities may allow it to be decrypted. This threat is particularly relevant for information assets with long retention periods, where confidentiality requirements may persist for decades.

Recent telecommunications disruptions, including the nationwide Telstra outage attributed to a software defect affecting network time synchronisation, serve as a reminder that resilience is not solely a cybersecurity issue. While the incident was not a cyberattack and there is no evidence that it exposed customer data, it demonstrated the extent to which governments, businesses, and citizens depend on communications infrastructure operating as intended.

This broader question of resilience aligns with concerns regularly raised by national security policymakers, including Shadow Minister for Defence James Paterson, regarding the security and robustness of Australia's critical infrastructure. His warnings have generally focused on the strategic risks posed by vulnerable infrastructure, foreign interference, and the potential targeting of essential services by hostile actors.

For information managers, the key lesson is not that a telecommunications outage creates a security breach, but that operational failures can expose assumptions about trust, availability, and continuity. If a software defect can disrupt services at national scale, organisations must also consider how future cyber incidents, supply-chain compromises, or quantum-enabled threats could affect the confidentiality and integrity of information entrusted to their care.

In that context, post-quantum cryptography is not simply an IT modernisation exercise. It is a long-term governance response to an evolving threat landscape. The objective is not merely to protect data while networks are functioning normally, but to ensure that sensitive information remains secure even as technologies, infrastructure, and threat actors change over time.

For organisations responsible for long-lived information assets, quantum readiness is rapidly becoming a foundational element of resilience. The question is no longer whether the transition should begin, but whether it will be completed before today's encrypted information becomes tomorrow's exposed archive.

Meet your blog author:

Linda Shave.png 1

 

Linda Shave, Life FRIM, CXRIM

Linda is a recognised Australian thought leader, researcher and author specializing in information management, digital modernisation and governance. Acknowledged as an "architect of change," she has extensively researched and written on the impacts of emerging technologies like Artificial Intelligence (AI), quantum computing and robotics, particularly within the government sector.