Quantum computing usually feels like a problem for later. In Singapore, it now has a calendar.
Under the Cyber Security Agency of Singapore’s (CSA) new Quantum-Safe Handbook released in July 2026, operators of Critical Information Infrastructure (CII) face a strict timeline. Industries including the banking, telecoms, utilities, aviation, transport and healthcare sectors must submit post-quantum readiness plans by March 2027 while new systems need to be quantum-ready by January 2028. Full compliance is required by the end of 2031.
A day after the global launch of Luna 8 in Las Vegas, French technology group Thales, held a media briefing in Singapore to introduce the next-generation hardware security module (HSM). The session also drew data from the 2026 Thales Data Threat Report: Quantum & AI Trends, produced with 451 Research by S&P Global.
Two Trends, One Pressure Point
The report polled 3,120 respondents from 20 markets, including Singapore and six other markets in Asia-Pacific. It describes the time as a convergence of two forces: AI and quantum computing.
AI is less about creating new threats and more about exposing old gaps. 65 percent of respondents cited poor data governance as a leading barrier to AI adoption, while 61 percent pointed to security risks from exposed data. In addition, 51 percent said AI initiatives are moving too fast to be properly secured.
Quantum adds pressure measured in years, not release cycles. The top concern, cited by 61 percent of respondents, is Harvest Now, Decrypt Later (HNDL) which represents the risk that data intercepted today could be decrypted once quantum computers mature. Future encryption compromise (57 percent) and secure key distribution (51 percent) followed.
Beyond HNDL, 59 percent say testing post-quantum cryptography (PQC) is their top priority for the next two years, and 98 percent say they now consider AI and quantum together, not as separate problems.
“Across Asia Pacific, organisations are moving quickly to capture the opportunities of AI, cloud and emerging technologies,” said Andy Zollo, SVP Application & Data Security at Thales CSP. “But the next competitive divide will not be defined by who adopts these technologies first. It will be defined by who can secure them with the right data visibility, cryptographic resilience and migration readiness. Quantum readiness is not a future compliance exercise. It is a strategic infrastructure decision that organisations need to start planning for now.”
Singapore’s Head Start
Singapore’s own activity backs this up. Local banks have tested quantum-safe approaches. Singtel has launched what it calls Southeast Asia’s first hybrid quantum-safe network.
The report also found that AI leaders tend to be further ahead on quantum readiness. Organisations leading in AI security are more likely to know where all their data is stored (36 percent versus 28 percent of laggards) and to fully classify it (43 percent versus 35 percent). Quantum leaders, in turn, report stronger progress on post-quantum security work, including public key infrastructure and enterprise key management. The report describes this as leadership that “spills across disciplines, with each reinforcing the other.”
The Hardware Behind the Deadline
Luna 8 is the latest in a product line dating back to 1994, when the first Luna HSM was built for government use. Luna 7 launched in 2017. Luna 8 arrives nine years later, built around a Thales-designed cryptographic processor.
Shared at the media briefing, Daniel Toh, Area Vice President of Sales Engineering, APJ, Thales confirmed that the Luna 8 delivers up to 10 times faster performance than Luna 7 on traditional algorithms like RSA-2048.
On post-quantum algorithms such as ML-KEM-768, Luna 8 claims up to 100 times faster performance. Thales also cited internal testing showing Luna 8 outperforming competitors by 3 to 8 times, depending on the algorithm.
The core pitch for Luna 8 is crypto agility. Luna 8 is designed to support new algorithms as standards evolve, without replacing the hardware. This matters because PQC standards are continually evolving, with digital signature candidate HAWKrecently withdrawn from the National Institute of Standards and Technology (NIST) evaluation process in July 2026 after Anthropic’s Claude Mythos Preview AI model found a flaw that halved its key strength in roughly 60 hours – a vulnerability two years of human review had missed.
“Enterprises need to build post-quantum readiness through cryptographic agility,” said Zollo. Jack Zhou, CIO at early adopter HKVAX, added that the flexibility “helps us maximise hardware investments.”
Luna 8 is available now as a network appliance, though Thales representatives said at the briefing that first units for some early customers are expected to ship as early as December. It is still undergoing independent assessment for FIPS 140-3 Level 3 and EU Common Criteria certification, standards often required for government and banking use.
For Singapore’s operators of CII, the takeaway is simple math. Five years isn’t a long runway, especially when many organisations still can’t fully map their own data.
