Some of the most sensitive data moving across GCC networks today may already be sitting in an attacker’s archive, encrypted, unreadable and waiting for a machine that does not yet exist. Security specialists call the tactic “harvest now, decrypt later”, and it turns quantum computing from a distant research problem into a present exposure for any organisation holding records that must stay confidential for 10 to 20 years, from patient histories and trade secrets to national security intelligence.
That exposure is the market Help AG, the cybersecurity arm of e&, has moved into with Quantum 360, a portfolio of post-quantum services unveiled in September. It packages cryptographic discovery, migration planning and quantum-safe implementation into one engagement aimed at government entities, critical infrastructure operators and regulated enterprises. Christopher Zinn, Manager of AI, DevSecOps and Cloud Security at Help AG, said the decision to pair technology with services was deliberate.
“From a post-quantum perspective, this is both products and service. I think that really matters because anyone can sell a product, anyone can buy a product, but it’s around how do we actually enable the customer to get the real value from that,” he said.
Regulation has given the offer its urgency. The UAE Cybersecurity Council’s National Encryption Policy calls on government entities to establish approved transition plans for moving from traditional encryption to post-quantum cryptography, and the Dubai Electronic Security Center has published its own Post-Quantum Cryptography Guideline to prepare the emirate’s digital infrastructure.
The first job is finding keys most organisations have never counted
The date that concentrates minds across the industry is Q-Day, the point at which quantum computers become powerful enough to break the public-key encryption that protects banking, government services and most enterprise communications. Zinn said that prospect is already changing what regulated organisations are asked to know about themselves.
“It’s becoming mandated, specifically for highly regulated industry, to understand what their crypto assets look like. The reason for this is Q-Day is approaching,” he said.
Knowing what those assets look like is harder than it sounds. Encryption sits inside certificates, keys, algorithms, software libraries and third-party dependencies, scattered across on-premises systems, hybrid estates and multiple clouds, and few organisations have ever mapped it in one place. The first Quantum 360 service, Q-Lens, is designed to do that mapping and produce a Cryptographic Bill of Materials, or CBOM, an inventory that works for encryption in the way a software bill of materials works for code, showing what is in use, where it runs and what depends on it.
Zinn explained why the arithmetic behind today’s encryption stops holding once quantum machines mature. Classical computers, however many are combined, would need an impractical length of time to break a modern algorithm, and that gap is what current security relies on.
“Theoretically, we could throw all of the world’s supercomputers at a particular encryption algorithm today, and maybe in a few tens of thousands of years crack that algorithm. Quantum is going to make that a reality,” he said.
He argued that the risk compounds when quantum capability arrives in an environment already reshaped by artificial intelligence, where attackers can automate reconnaissance and exploitation at a scale that was impossible a few years ago.
“With the combination of quantum supremacy and AI power at everything, our future is at risk. We need to address that today,” Zinn said.
A migration plan has to work without a deadline anyone can name
Once an organisation knows what it holds, the second service, Q-Path, turns that inventory into decisions. It assesses exposure and readiness, ranks priorities, defines a target architecture and sets out a phased migration roadmap aligned to regulatory obligations. Help AG’s position is that no two organisations will follow the same route, because the right sequence depends on how sensitive the data is, how long it must remain secret, how critical the systems are and what level of assurance regulators demand.
Dr Aleksandar Valjarevic, Chief Executive Officer of Help AG, described the change in the questions boards are asking in the company’s launch announcement. “The quantum conversation is moving from ‘when will it happen?’ to ‘are we ready when it does?’ Organisations need to understand where cryptographic assets exist today, what is most exposed and what needs to change first,” he said.
The third service, Q-Seal, handles implementation for the most sensitive environments, including quantum-safe link encryption and quantum key distribution for communications that require the highest assurance. Zinn said the portfolio was designed around the one certainty in the field, which is that the timing remains unknown.
“We know Q-Day approaches, we don’t know when it will arrive, and we want to help highly regulated customers be ready for that whenever it happens,” he said.
Help AG has not disclosed which organisations are using Quantum 360, how many have completed a cryptographic inventory, or how long a typical migration takes, and those figures will determine whether the portfolio moves regulated enterprises faster than their own internal programmes would. Zinn described the launch as the industry’s best response as things stand, a claim no independent benchmark yet tests, and said the services would change as the underlying technology and standards mature.
Quantum readiness depends on controls that were due long before Q-Day
For all the attention on quantum machines, Zinn’s advice to security leaders pointed back to the controls their teams have been told to get right for two decades, on the basis that no post-quantum migration can succeed on an estate that is poorly governed to begin with.
“Everyone should double down on the fundamentals. We are focusing, of course, on the new and emerging tech, but let’s be honest. The fundamentals are still fundamental for a reason. We need to focus on governing identities, securing workloads, restricting networks, protecting our data,” he said.
Quantum 360 follows the same logic, since its opening step is an inventory exercise any security team would recognise. For an organisation whose encrypted traffic may already have been copied, a complete map of where its keys and algorithms live is the piece of quantum preparation it can begin this quarter, and for UAE government entities it is the step the national encryption policy now expects to see in their transition plans.


