Maman Ibrahim is a cyber and digital risk executive, helping boards, CRO, CIO, and CISO turn risk work into decisions, delivery, and proof.gettyA quantum program launched last spring was effectively dead within nine months. It had a name, a budget line and a logo on the deck. It produced one tool evaluation and nothing else. The standards had not settled, so the committee shelved it. Nobody there was lazy. They had answered the wrong question quickly, with a full budget behind it. Ask what your quantum program is, and you will get a program. Programs start, spend and stop. Quantum is a risk class, and risk classes do not wait for a budget cycle.​Why Quantum Is An Input, Not An Initiative​Your architecture already has six control families: governance, risk, operational, third-party, incident and assurance. Every regulation on your desk belongs somewhere within those six, and so does quantum risk. It is a new input to that structure, not a reason to create another.Two timelines sit underneath it. The first is yours: find where your cryptography lives, then make it changeable. You control that pace and can measure it. The second belongs to someone else. Harvested encrypted data could become decryptable once a cryptographically relevant quantum computer exists. You do not control that timeline, and you will see no evidence of the copying.Both timelines run through all six families. That is why timing belongs inside each family, not in a seventh.​​Scoring The Six FamiliesScoring the six families below is not a rating of how prepared you feel; they are a measure of where evidence exists and where gaps remain.For each area, assign one word: heavy, medium or light. A heavy reading means the gap is significant or depends on decisions outside your immediate authority to close. A medium reading means you know what needs to happen but have not completed it. A light reading means you could produce the answer this week with evidence.Do this with the people who own architecture, vendor management, the data taxonomy, the incident playbook and decision approval. The goal is to identify which parts of your current operating model are already prepared and which ones depend on assumptions.​1. GovernanceAsk who signed the last quantum decision and what would reverse it. The evidence is a dated deferral naming an owner, a condition and what was accepted. Meeting minutes alone are not enough. A heavy reading is nothing in writing, with "we are watching the standards" serving as the policy. A light reading is as simple as a single page: we are not migrating X until Y because Z; owner; review date.2. RiskAsk two questions of your taxonomy: Which systems hold data whose confidentiality must outlive 2035? Which systems cross a network you do not control? If the answer comes in minutes, your inventory likely contains the attributes needed to make decisions. If it requires a new workshop or a series of stakeholder interviews, the information is not yet operationalized.The first improvement does not require a major program. Add one field to your inventory: a confidentiality horizon for each major data store—under three years, three to 10 years or more than 10 years. The data with the longest required protection period (especially when it moves across networks you do not control) becomes your priority list.​3. OperationalDo you know where your cryptography lives, and could you change it without launching a project? For the first question, you need an inventory of cryptographic libraries, certificate authorities, key stores and protocol versions. For the second, test the process rather than the intention: choose one high-value system and measure the effort required to replace its cryptographic algorithm. How many teams are involved? How many dependencies need to change? How much coordination is required?​​​​​4. Third-PartyYour cryptography also lives in vendors' products, suppliers' build pipelines and cloud key management systems, often under contracts that ignore it. Ask which vendors can name the algorithms they use, which responded the last time you asked and which contracts let you require a change rather than simply request one.You can instruct your own engineers. Suppliers can only be asked.5. IncidentAsk what happens the morning a working quantum machine is announced and who decides whether it is an incident rather than news. Then ask: could you re-key at scale without taking a service offline? Many organizations might read this as light because harvesting produces no alert, but the absence of a signal is not evidence of readiness.​6. AssuranceSomeone may read your 2026 reasoning in 2036 without you there. Would they find only the outcome, or the options, evidence and date behind it?​​Putting The Scores Next To The InvoiceSort last year's quantum spending by family. Discovery tooling, cryptographic engineering and consulting usually sit under operational. Then compare that investment with your heaviest-scoring family: what did it receive during the same period? A questionnaire? A contract clause in one renewal? A dedicated budget?Spending often follows what can be purchased and presented to a board, not where exposure actually sits. No product makes a supplier answer an email.The next step is already in your dependency map. Pick 10 critical dependencies and ask: Which algorithms are used? Which contract terms let us require a change? Who owns the answer? Sort the responses into those who named their algorithms, those who promised to investigate and those who did not respond. The third group is the finding: not a vendor problem, but a visibility gap in your risk model.The Gap Between Risk And Spend​People keep waiting for a quantum verdict that tells them whether they're prepared. The more useful measure is the gap between where risk sits and where effort is being spent. Compare your six family scores against your quantum spending. Where the two do not align, your resources are flowing somewhere other than where your exposure is greatest. In my experience, the scores rarely come out even.​That is also why the shelved program failed. It needed a finish line, so it invented one—and broke when reality declined to provide it. Replacing RSA with ML-KEM is a task you complete; crypto-agility is a capability you maintain. A firm that can change its cryptography in months does not need to predict which quantum announcement comes next.So score the six families, write down the six words and place them beside your spending. If the two disagree, you have the foundation of your next board paper—and it is not a procurement request. It is a risk decision.​​​Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?