Skip to Content

All Things Internal Audit

Quantum Computing Risk: What Internal Auditors Need to Know

In this episode, Richard Penfil talks with Cory Missimore about how quantum computing could threaten current encryption, why “harvest now, decrypt later” attacks require organizations to prepare today, and how internal auditors can assess quantum readiness. They also discuss cryptographic inventories, third-party exposure, crypto agility, regulatory developments, and practical steps organizations can take to prepare without overreacting.

Host:

Richard Penfil 

Founder, AssureSwarm

Guest:

Cory Missimore, CISSP, CDPSE, CISM, CIPP

Senior Information Security Compliance Analyst, American Institutes for Research

Key points

  • Introduction [00:00–00:47]
  • Quantum Computers vs. Traditional Computers [00:47–01:44]
  • Why Organizations Should Prepare Now [01:45–03:18]
  • Cryptographic Inventories and Accountability [03:19–05:27]
  • “Harvest Now, Decrypt Later” Attacks [05:28–07:42]
  • The Emerging Regulatory Landscape [07:43–09:33]
  • Three Questions for Assessing Quantum Readiness [09:34–13:11]
  • Third-Party and Vendor Exposure [13:12–15:01]
  • Integrating Quantum Risk Into Existing Audits [15:02–17:49]
  • Warning Signs and Regulatory Developments [17:50–20:27]
  • How Quantum Computing and AI Could Develop Together [20:28–22:13]
  • Practical Steps Organizations Can Take Today [22:14–24:42]
  • Final Thoughts [24:43–25:36]

January 21, 2026