AuIGF 2026 Panel Report: Is the Internet Ready for Q-Day? 

Executive Summary 

During auIGF 2026, we brought together experts across academia, industry, and internet governance to explore whether the internet is prepared for “Q-Day” (the point at which quantum computing becomes powerful enough to break modern cryptography). Moderated by Professor Robin Doss (Deakin Cyber Research & Innovation Hub), the panel examined the underlying mechanics of quantum computing, the specific technical and infrastructure risks facing protocols like DNSSEC, TLS, and PKI, and the practical and policy hurdles to migration.  

The overarching consensus among the panel is that while standardized post-quantum cryptography (PQC) algorithms are now available, the internet as a whole remains largely unprepared. On a scale of 1 to 10, the panelists gave the internet’s current readiness an average score of only 3 to 4. Panelists emphasized that migrating legacy infrastructure, incorporating post-quantum cryptography directly in protocols, ensuring cryptographic agility, preventing a “two-speed internet,” and driving government-led readiness planning are critical priorities before Q-Day arrives. 

Introduction 

Below are the findings and discussions of our panel discussion during the auIGF 2026 on “Is the internet prepared for Q-Day?”. During this panel, we posed the question of what will happen if quantum computers become reality and how we can mitigate their threats. We encourage readers to research this topic and think about how we can prepare the internet for such an eventuality. The report below is solely based on responses given by the audience and panelists. If readers are interested in more information about quantum computing, post-quantum cryptography, and Q-Day, we refer to the following resources: 

  1. Quantum Computing Explained 
  2. Can We Stop Quantum Computing Breaking the Internet? 
  3. What Is Post-Quantum Cryptography? 
  4. Q-Day has already begun. Are you ready? 

        What is Quantum Computing? 

        We asked the panelists to explain the differences between quantum computing and traditional computers. 

        Emeritus Professor Glenn Wightwick (auDA) outlined the fundamental differences between classical and quantum computing. Classical Computing is built on traditional computing models that use binary data (0s and 1s) processed through millions of transistors in microprocessors. Quantum Computing, on the other hand, uses principles of quantum mechanics to process information via quantum bits or “qubits”. Unlike standard bits, qubits can represent 0 and 1 simultaneously.  

        Assembling enough qubits allows a system to represent exponentially larger informational states than classical computers, enabling computations at a much larger and faster scale. A sufficiently powerful quantum computer can run specific studied algorithms to break cryptography by factorizing the product of very large prime numbers; the core mechanism underpinning most current public-key cryptographic algorithms. 

        Quantum Risks 

        The panelists highlighted several explicit technical, infrastructure, and operational risks introduced by quantum computing. 

        Cryptographic Vulnerabilities 

        Associate Professor Sushmita Ruj (UNSW) clarified that public-key (asymmetric) algorithms are vulnerable to being broken by quantum algorithms, whereas symmetric key algorithms are not affected in the same way.  

        Both Sushmita Ruj and Glenn Wightwick highlighted the threat of “Harvest Now, Decrypt Later”. Adversaries can steal and store encrypted sensitive data today (e.g., medical records or personal data). Even though it is safe against current classical technology, attackers can hold the data and decrypt it years down the road once a quantum computer is available.  

        Internet Infrastructure and Protocol Risks 

        Glenn talked about how quantum impacts certain protocols, such as DNS/DNSSEC. He explained that while DNS data itself is public (meaning “harvest now, decrypt later” is not a primary threat to DNS), DNSSEC relies on digital signatures to ensure records are not tampered with. A quantum computer could break this signature scheme, allowing attackers to re-sign DNS zones and maliciously redirect traffic (e.g., redirecting users visiting anz.com.au to steal money and credentials).  

        Dr. Syed Shah (Deakin Cyber Research & Innovation Hub) noted that post-quantum digital signature algorithms feature significantly larger signatures and keys. In DNSSEC, these larger payloads cause responses to exceed standard UDP packet limits, leading to packet fragmentation (which harms security) or forcing fallback to TCP (which adds connection overhead).  

        Dr. Dongxi Liu (CSIRO) emphasized that quantum risks extend well beyond replacing basic RSA/elliptic-curve algorithms. Cryptosystems are more than only the cryptographic algorithm; there is also the protocol itself. Changes need to happen on the protocol level as well as the cryptographic level to become quantum safe. 

        Dr. Warren Armstrong (Quintessence Labs) pointed out that newly standardized PQC algorithms have received relatively limited public examinations compared to classical algorithms. He noted that candidate algorithms have previously fallen apart late in the standardization process due to classical cryptanalysis, a risk that may increase if AI begins synthesizing different fields of mathematics. 

        What is Q-Day? 

        The term “Q-Day” is often used in the media, but what exactly does it mean? We asked our panelists. 

        Sushmita Ruj explained that Q-Day refers to a future point in time when quantum computers become capable of breaking classical public-key cryptography. She also noted a common misconception: Q-Day will not be a single catastrophic day where the entire internet instantly stops, all bank accounts are suddenly hacked, or everyone’s messages are decrypted at once. 

        The exact arrival of Q-Day is unknown. Panelists noted that unlike Y2K, which had a fixed, definite deadline that forced urgent code rewrites and system migrations, Q-Day has no fixed date.  

        We asked the panelists and the audience what would happen in the first 24 hours after Q-Day. 

        Warren Armstrong noted that an announcement would likely come from a public or commercial entity rather than a government nation-state (which would likely keep the capability secret). He added that an immediate risk would be losing the ability to rely on digitally signed audit records and financial log files, causing trust to collapse.  

        Glenn Wightwick stated that impact depends on who holds access, predicting a potential surge in ransomware where adversaries monetize previously harvested, newly decrypted data.  

        Sushmita Ruj noted it could trigger widespread geopolitical disputes, sector riots, or societal panic depending on the sensitivity of exposed data. 

        How Prepared Are We for Q-Day? 

        When asked to rate the internet’s current readiness on a scale of 1 (completely unprepared) to 10 (fully prepared), the panel scored it as follows:  

        • Glenn Wightwick: 1 to 2  
        • Sushmita Ruj: 2  
        • Warren Armstrong: 3  
        • Dr. Dongxi Liu: 4  
        • Dr. Syed Shah: 4 to 5  

        Dr Syed Shah gave some more context regarding his score, noting positive movement in standardized algorithms and industry testbeds, but balanced by the massive installed base of legacy systems and Q-Day timeline uncertainty. 

        On Average, the panelists gave a score of 3 to 4 out of 10.  

        Sector and Organizational Awareness 

        Warren Armstrong observed that awareness varies significantly. In regions like the US, Australia, Singapore, and parts of the EU, awareness is higher, whereas visibility is limited in places like New Zealand and Indonesia. Critical sectors (like banking and ASX Top 50/150 companies) are actively engaged due to governance requirements, while many other organizations are distracted by immediate AI threats.  

        Major Migration Obstacles 

        Sushmita Ruj emphasized that the sheer size and interconnected complexity of the internet make seamlessly stitching new algorithms into protocols a massive hurdle.  

        Syed Shah and Glenn Wightwick highlighted that updating TLS, digital certificates, VPNs, software, and decades-old legacy hardware across the entire internet will take years. 

        Glenn Wightwick warned that while well-resourced cloud providers (e.g., Google) and large enterprises will migrate safely, small businesses, rural communities, and developing economies lack the resources and attention span to transition, risking a broad digital security divide.  

        Responsibility and Policy Roles 

        Dongxi Liu argued that vendors bear primary operational responsibility to integrate standardized PQC algorithms into commercial products so customers can deploy them easily.  

        Warren Armstrong and Glenn Wightwick stressed that governments must establish mandatory readiness milestones for critical infrastructure. Government elevation provides necessary visibility to corporate boards, elevates priority alongside broader cybersecurity agendas, and acts as a neutral arbiter. However, Warren cautioned that technical implementation and algorithm selection should remain with engineering and standards bodies (e.g., IETF, ICANN). 
         

        Conclusion 

        The panel concluded that solving the Q-Day challenge requires far more than just mathematical algorithms; it requires a coordinated, multi-year overhaul of protocol engineering, legacy hardware, and governance frameworks.  

        To prepare effectively, each panelist offered a closing priority for the internet community: 

        • Dr. Syed Shah: Modify protocols and transport modes (e.g., exploring QUIC or Merkle-tree authentication) to accommodate PQC requirements.  
        • Dr. Warren Armstrong: Design systems for cryptographic agility, the architectural flexibility to swap algorithms on the fly as threats evolve.  
        • Emeritus Professor Glenn Wightwick: Educate, build national plans, and invest in testing and remediation.
        • Dr. Dongxi Liu: Map system vulnerabilities and clarify roles across the migration lifecycle.  
        • Associate Professor Sushmita Ruj: Drive broad education and awareness across all sectors of society.  

        Moderator Robin Doss closed the session with an open challenge to the audience: “If Q-Day arrived earlier than expected, would we be able to say as an internet community that we have done enough?” 

        Can We Stop Quantum Computing Breaking the Internet?

        This video, “Can We Stop Quantum Computing Breaking the Internet?”, is presented by Je Sen Teh, a Deakin Lecturer and one of our project members. It explores the urgent question of how quantum computing could threaten internet security and highlights ongoing research at the Deakin Cyber Research and Innovation Centre to develop safeguards for critical cyber infrastructure, supported by the .au Domain Administration (auDA).

        The Need for DNSSEC

        Despite underpinning almost every Internet interaction, the Domain Name System Security Extensions (DNSSEC) remains significantly under adopted across the world. DNSSEC was introduced by the Internet Engineering Task Force (IETF) to protect the Domain Name System (DNS) — often described as the Internet’s “address book” — from manipulation and tampering. Without DNSSEC, attackers can exploit weaknesses in DNS infrastructure to redirect users to malicious websites, intercept communications, steal credentials, distribute malware, or conduct large-scale phishing and fraud campaigns.

        The risks are no longer theoretical. Cybercriminal groups and nation-state actors increasingly exploit DNS vulnerabilities as part of sophisticated cyber operations. Recent incidents involving DNS hijacking and malicious DNS manipulation have enabled scams, malware delivery, espionage, and large-scale service disruption. In 2025 alone, global cybercrime losses were estimated to exceed USD 10.5 trillion, with impacts extending far beyond financial damage to include privacy violations, operational disruption, misinformation, and erosion of public trust in digital systems.

        Yet adoption of DNSSEC remains alarmingly low. According to the Internet Society Pulse platform, only around 35% of global DNS queries are currently validated using DNSSEC. While several top-level domains support DNSSEC, meaningful implementation across domains, resolvers, and organisations remains inconsistent. Many websites and Internet service providers still operate without DNSSEC protection, leaving users and services exposed to avoidable cyber risks.

        This gap presents a serious challenge for building a trustworthy and resilient Internet. As governments, businesses, schools, healthcare providers, and communities become increasingly dependent on digital services, the security of foundational Internet protocols becomes essential for maintaining trust and ensuring safe digital participation. A lack of DNSSEC adoption leaves users more vulnerable to cyber harms such as fraud, scams, credential theft, malware infections, service outages, privacy breaches, and misinformation.

        Understanding why DNSSEC adoption remains low is therefore critical. Technical complexity, limited awareness, operational concerns, compatibility issues, lack of automation, ecosystem coordination challenges, and insufficient policy incentives are often cited as barriers. However, these factors have not been comprehensively studied at a global level. Without a clear understanding of the barriers to adoption, efforts to improve Internet trustworthiness and resilience will remain fragmented.

        Accelerating DNSSEC adoption is not simply a technical issue — it is a necessary step toward strengthening the security, integrity, and trustworthiness of the Internet itself.