Skip to content

Education

Shor's algorithm for CISOs (no math degree required)

You do not need quantum physics to understand the business risk: Shor's algorithm breaks the public-key math your TLS, VPNs, and code signing depend on today.

Shor's algorithm threat map for CISOs.
How Quantum Computers Break Encryption | Shor's Algorithm Explained Watch on YouTube

The one-sentence version

A sufficiently large quantum computer running Shor's algorithm can factor the large numbers and solve the discrete logarithm problems that make RSA, Diffie-Hellman, and elliptic-curve cryptography secure today.

What breaks vs what mostly survives

CategoryExamplesQuantum impact
Public-key encryption & key exchangeRSA, ECDHBroken by Shor's
Digital signaturesRSA-PSS, ECDSABroken by Shor's
Symmetric encryptionAES-256Weakened by Grover's — use larger keys
Hash functionsSHA-256, SHA-3Grover's reduces effective strength — generally manageable

NIST's PQC overview focuses migration on public-key systems. See our Grover's algorithm explainer for symmetric crypto guidance.

How Shor's works (conceptually)

  1. Pick a random number related to the target composite (N).
  2. Find the period of a modular exponentiation function — classically hard, quantum-friendly.
  3. Use number theory to recover factors from the period.

The IBM Quantum Shor's tutorial shows code; PennyLane's period-finding demo illustrates the core idea interactively.

What CISOs should do

  1. Watch the embedded minutephysics video and read PostQuantum.com's Shor's article.
  2. Inventory quantum-vulnerable algorithms on external TLS and critical dependencies.
  3. Begin hybrid PQC pilots aligned to NIST IR 8547.

Quantum-vulnerable does not mean broken today — but harvest-now-decrypt-later means long-lived secrets need action now.

Continue on the Q-Day hub: What is Q-Day? guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.