up:: The Human & Organizational Side MOC
Why Is the Quantum Threat So Easy to Ignore?
At a quantum security summit in Washington D.C. this summer, I was the only person on the stage who talked about people. Everyone else talked about qubits, lattices, standards, and timelines, and all of it was correct. Afterward a line formed of engineers and executives who wanted to tell me the same thing in slightly different words: that the human part was the part they actually recognized from their own organizations, and the part nobody else was naming. I’ve thought about that line ever since, because it confirmed something years of doing this work had already taught me. The hardest problem in the post-quantum transition is a human one.
The cryptography is close to solved. NIST has published the replacement algorithms, a capable engineer can deploy them, and the architecture for doing it safely is well understood. What holds the transition back is the way the human mind handles a threat that refuses to feel urgent, and the way the people who have to carry out the change quietly protect themselves from it. If you’re holding a finished roadmap that refuses to move, the thing holding it there is the psychology of the people standing around it, yourself included. This is Why Post-Quantum Migrations Stall, told from the inside of the mind.
A threat the mind is built to wave off
Human risk perception evolved for the predator in the grass rather than for the slow statistical shadow. We react fast and hard to dangers that are vivid, immediate, and personal, and we heavily discount the ones that are abstract, distant, and gradual. Decades of research on how people judge long-horizon risk keep landing on the same finding: a threat that arrives slowly and quietly barely moves us, even when we understand it perfectly well on paper.1
Two well-documented quirks of judgment make it worse. We estimate how likely a danger is by how easily a vivid example comes to mind, so a threat with no dramatic picture attached feels improbable regardless of the real odds.2 And we mentally construe distant events in abstract, bloodless terms, which makes them far easier to defer than to act on.3
Now line the quantum threat up against that machinery. The computer that breaks today’s cryptography doesn’t exist yet, so there’s no vivid picture of it. The harm, an adversary quietly recording encrypted data now to open it years later, is invisible while it happens. The payoff sits a decade or more away, and the victim is a future version of you. The threat has almost every property the mind is wired to discount, which is why it stays frightening to nearly no one and therefore acted on by nearly no one.
It also lacks the one thing every earlier security era had, which was a loud, survivable warning shot. Reagan watched a movie about a computer nearly starting a war and signed the first national computer-security directive 15 months later.4 Worms and breaches gave each prior generation a scare it could learn from before the real damage arrived.
The quantum break offers no such favor. Whoever first builds the machine and uses it for collection has every reason to reveal nothing, because the moment the capability is disclosed, every target on earth starts migrating and the advantage evaporates. So the most consequential cryptographic event in modern history is precisely the one least likely to announce itself. The absence of an alarm is exactly what this threat looks like on its way in.
The reassurance we hand ourselves
There’s a second, subtler move the mind makes, and it turns honesty into a trap. When a careful expert says a cryptographically relevant quantum computer is probably 10 to 15 years away, the listener keeps the comforting half of that sentence and quietly drops the rest. “10 to 15 years” becomes “not a problem for this budget cycle.” The audience amputates the warning down to its most reassuring clause, and the more responsible and calibrated the expert was, the cleaner the clause they handed over.
This is why the most honest briefings on quantum risk are often the least funded. It’s an old pattern with distant threats. A serious, carefully hedged government warning about infrastructure risk in the late 1990s was received, and remembered, mostly as “not imminent,” and the urgency inside it never carried. Climate communication has lived the same fate for a generation. A warning about something slow and far off gives people the room to weight the part that lets them relax, and they reliably take it.
Smart people do this. It’s ordinary judgment meeting a threat that sits below the horizon, so the answer is a better felt sense of the risk rather than a scarier number. Handed to a mind that’s already looking for permission, more information just becomes more room to relax.
Overwhelm is a form of self-defense
When people do finally look at the quantum problem head-on, the field has arranged things so the reaction is to freeze. The knowledge is gatekept behind academic jargon and layered complexity, presented as so vast and technical that a competent, capable person concludes this must be somebody else’s job. Freezing is what a capable person feels when a task is framed as impossible to start, and it’s a way of defending yourself from the discomfort of a problem that looks too big to touch.
The overwhelm is a lie told by complexity. The transition breaks down into a small number of ordinary, sequenced steps, and the freeze lifts the moment the first one turns out to be doable. That’s why the single most useful thing you can hand an overwhelmed team is a first move small enough to actually make. More urgency only tightens the freeze, and I’ll come back to why that particular medicine works.
The fear nobody says out loud
The people who have to carry out the migration, the engineers, are often quietly afraid of what it means for them, and this is the piece of the psychology I see missed most often. Cryptography is specialized, hard-won expertise that took years to earn. A migration can land as a message that the thing you’re expert in is becoming obsolete, it exposes gaps (“I’ve never deployed a KEM”), and it can read as a verdict that the design you chose before was wrong. Those are destabilizing things to have said to you, so the mind defends against them.
We weight a threatened loss far more heavily than an equivalent gain, so the possibility of losing standing and competence looms larger than any promised benefit of modernizing.5
That fear almost never shows up as an argument, because nobody stands up in a meeting and says the migration scares them. It shows up as friction. A request for more analysis, a quiet deprioritization, a “let’s wait for the standards to settle,” a pilot that stays perpetually next quarter. A hundred small delays are what a stalled migration is actually made of, and every one of them is fear with a professional explanation attached. Treat the resistance as a knowledge problem and you’ll answer questions the team wasn’t really asking. The way through runs through the fear itself, which is the whole subject of Change Management for Cryptographic Migration.
Why we look away from our own exposure
There’s a reason discovery, the unglamorous work of finding where your cryptography actually lives, is the step organizations most avoid. A test you run becomes a finding you’re on record as knowing about. An inventory that surfaces thousands of exposures creates a documented liability that someone now owns, while the exercise you never run indicts no one. Looking away is the safer move for the individual, even when it’s the worse move for the organization, and that quiet arithmetic is why the map so rarely gets drawn.
Layered on top of that is a second effect that psychologists have studied for half a century. When responsibility for something is spread across many people, each one feels less personally accountable and assumes someone else will step in, so no one does.6
Cryptography is the perfect victim of that effect. Everyone touches it and no one owns it, so it sits in the seams between engineering, procurement, security, and governance while each function assumes another one holds it. Diffuse ownership feels like coverage and functions like a vacuum, which is why naming a single accountable person is the true first move of any migration. That’s the whole argument of Cryptographic Ownership, and underneath it is a piece of social psychology rather than anything technical.
Knowing is different from being convinced
A board can hold every fact about quantum risk and still not move, because knowing a thing and being convinced of it are two different states of mind. The information has been in the room for years in most organizations. What’s missing is conviction. People are moved far more by what they experience directly than by what they’re told, and a threat they’ve only heard summarized stays filed under “interesting” rather than “act now.” This is why more slides rarely change the outcome. The gap between a room that understands the risk and a room that acts on it is an emotional one, and closing it is a different skill from explaining the science.
The way through is psychological before it’s technical
Every fear I’ve named has the same antidote, and it’s a single design choice rather than a program. Make the first step reversible, and you have the whole lever. When a first step can be undone with a config flag, the anxiety that drives the resistance has nothing to grip. A hybrid handshake on one internal service, a discovery pass on a single system, a post-quantum-capable library switched on but not yet in the path: each one can be turned off and returned to exactly where you were, so nothing the team tries can strand them.
Watch how that one design choice dissolves the whole psychology. The overwhelmed engineer gets a task small enough to finish, which converts a frozen “where do I even start” into ordinary work. The engineer afraid of exposing a gap gets a low-stakes, private place to learn where a mistake is cheap. The distant threat becomes concrete and present the moment someone touches it with their own systems, which is the closest thing to the direct experience that actually builds conviction. And because the move is reversible, it never reads as a verdict on the old design or a bet the team can’t take back.
The framing matters as much as the size. Lead with what people gain in their own terms, which is less firefighting later and the durable skill of being able to move an estate, rather than with what’s being taken away. Choose that second one carefully, because naming mastery of a specific successor algorithm offers someone an asset that depreciates at the next parameter change. Present the change as the new baseline instead of a crisis, because people adopt a new normal far more readily than they answer an alarm. Let the small wins compound into evidence that the next step is safe. All of this is deliberate psychological design, and it’s the part almost no other resource treats as real work.
So the truest thing I can tell you about the post-quantum transition is that it’s a change-management problem first and a cryptography problem second. The math is ready and waiting. The migration that has to actually happen is happening in people, in how they perceive a quiet threat, what they’re afraid to look at, and whether they believe they can begin. That belief is the whole game, and it’s earned, because the overwhelm really is a lie told by complexity and a capable team really can do this. Handle the human system with the same care you’d give the cryptography, and the roadmap you already have finally starts to move.
The precedent
Damocles was a courtier of Dionysius, tyrant of Syracuse, and kept telling him how fortunate he was. Dionysius offered to trade places for one evening. Damocles was seated on the throne at a full banquet with attendants around him, and Dionysius had a sword hung from the ceiling above the chair by a single horsehair. Damocles could not eat and asked to be let go. Cicero’s point in telling it is not really about Damocles. It is that Dionysius had been eating under that sword every day for years.
Cicero, Tusculan Disputations V.61–62
The moral: the sword was equally real for both of them. Only the one who had just arrived could still see it.
A risk that has been true for a decade stops being visible to the people living under it, and the mechanism is ordinary habituation rather than denial. Nobody in the organization thinks the threat is fake. They have carried it long enough that it generates no feeling at all, and an unfelt risk cannot compete for budget against a felt one. It is also why an outside assessment surfaces things the internal team already knew: the finding is not new information, it is the same information delivered by somebody who has not adjusted to it yet. Dionysius was not in denial about the sword. He had hung it there himself.
Everything here is the map, given freely. When your team needs the human and organizational side of the transition planned and run as deliberately as the cryptography, so a finished roadmap actually turns into motion, that’s the work I do.
Last verified 2026-08-17 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.
Footnotes
-
Elke U. Weber, “Experience-Based and Description-Based Perceptions of Long-Term Risk: Why Global Warming Does Not Scare Us (Yet),” Climatic Change, 2006. doi.org/10.1007/s10584-006-9060-3 ↩
-
Amos Tversky and Daniel Kahneman, “Availability: A Heuristic for Judging Frequency and Probability,” Cognitive Psychology, 1973. doi.org/10.1016/0010-0285(73)90033-9 ↩
-
Yaacov Trope and Nira Liberman, “Construal-Level Theory of Psychological Distance,” Psychological Review, 2010. doi.org/10.1037/a0018963 ↩
-
The account that the 1983 film WarGames prompted President Reagan’s review, which led to NSDD-145 (National Policy on Telecommunications and Automated Information Systems Security, 1984), opens Fred Kaplan, Dark Territory: The Secret History of Cyber War (Simon & Schuster, 2016). ↩
-
Daniel Kahneman and Amos Tversky, “Prospect Theory: An Analysis of Decision Under Risk,” Econometrica, 1979. doi.org/10.2307/1914185 ↩
-
John M. Darley and Bibb Latané, “Bystander Intervention in Emergencies: Diffusion of Responsibility,” Journal of Personality and Social Psychology, 1968. doi.org/10.1037/h0025589 ↩