Organizations must immediately begin post-quantum cryptography migration because adversaries are actively stealing encrypted data today, planning to decrypt it later when quantum computers become powerful enough to break current encryption algorithms; this is not a future problem but an urgent governance challenge requiring immediate action, as quantum computers can now demonstrate quantum supremacy and outperform classical supercomputers on specific tasks, threatening not just data confidentiality but the entire digital trust model including digital signatures and secure communications.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Disecting 'harvest now, decrypt later' strategies and what this means for you and your organization.
Added:[music] >> Welcome to Clarity, the show that brings you what you need to know now in the worlds of cybersecurity and artificial intelligence. My name is Shira Rubinoff, CEO of The Cybersphere Group. Today I'm joined by Jonathan Nguyen, CTO.
Jonathan, pleasure to be with you here today.
>> Yeah, thanks so much for this opportunity, Shira. It's really great to spend time with you always.
>> Always, thank you. So, Jonathan, right now your standard encryption algorithms have a ticking clock over them.
Adversaries are actively executing and harvest now, decrypt later strategies, stealing your encrypted intellectual property today, betting that a quantum computer will unlock it tomorrow. With NIST finalizing PQC standards, setting a hard line for compliance, this isn't just an IT upgrade. It's an urgent board-level governance challenge. And if your organization doesn't know its time to migration versus your data shelf life, you are already exposed. So, let's start by demystifying this that's the timeline. Security leaders hear about Q-Day, the theoretical moment quantum computers break public key cryptography, and often push it out to a 2030 problem.
So, Jonathan, how do you define Q risk to a board of directors who think this is a future sci-fi? And what is the immediate non-negotiable steps an enterprise must take right now to prepare for Q-Day before the multi-year migration runaway runs out?
>> Yeah. So, this is a challenging issue and it's moving faster than any industry I've seen in my 28 years in cybersecurity. You know, uh last year, 2025 was declared the year of quantum computing, and in 2026, 12 months later, it's the year of quantum security. So, we've gone from a theoretical in engineering exercise does quantum computing work? Is quantum computing viable? Have we hit something called quantum advantage today when you can demonstrate that a quantum computer can outpace a classical supercomputer. And today we have something called quantum supremacy where you can demonstrate that it absolutely outperforms. It can do things it can run essentially run algorithms that a classical supercomputer just simply can't match in a thousand years, right? And so in one fell year, we've gone from a theoretical exercise to the practical realities of how do we actually connect and protect that quantum computing now? And that took cybersecurity 18 years to go from point products to that convergence of networking and security we called SASE.
So, now it is a practical exercise every CIO in the Fortune 2000 is trying to stretch his or her team on how exactly they're going to leverage this capability to augment AI to do some pretty materially transformative things like discover the ability to actually well, the ability in quantum is to s- simulate as many if not all possible outcomes simultaneously. That's the end goal, right? But when you can model at that scale, you begin to accelerate and enhance the accuracy of your test. So, think pharmaceutical development. You know, the average pharmaceutical that gets to FDA approval takes seven years and upwards to seven billion to eleven billion dollars and even then there's a 40% failure rate. So, the ability to increase the accuracy of that, quality of life issues, accelerate the ability to look at material sciences and develop new types of materials, the ability to better forecast financial modeling, the ability to better forecast you know, your own life issues. So, if you're going to develop pharmaceuticals that will extend my life by 10 years, I want to make sure that my financial services provider is also modeling my 401k for all the possible ways I should be investing my money so it lasts to 93.
So, we're on the verge of what I think is a true fourth industrial revolution and that's the business reality of of of challenge. On the flip side, of course, when you begin to model all possible outcomes, you can see how an adversary can take this. The adversary is going to establish a level of industrial persistence that's going to better understand the target environment to detect vulnerabilities, to develop or orchestrate malware and exploits to generate attacks.
On this side of the fence, it's going to be the ability, well, how do I secure against an ability of an adversary to break my classical encryption, my RSA, my ECC today? And what does that mean?
In that backdrop, beginning a few years ago, we began to see governments around the world begin issuing mandates, requirements, and standards for the migration towards post-quantum safe cryptography. I will note this to you as a level of urgency.
At no time in the history of cybersecurity has any government, any standards body proactively said, "Make a change that will alter the architecture of your network, maybe alter the capabilities of your trust model, and oh, by the way, it'll take years and you're going to spend hundreds of millions of dollars to do that for a risk that hasn't evidenced itself in an actual incident." So, that's how real the the industry takes this threat and it is it is truly unprecedented because it is the first time we've actually been proactive, right? So, um that's what governments are saying.
That's why boards need to care because we're really talking about two things and and and I often think that uh folks are overfocused on the harvest now decrypt later which is the ability to compromise data right what they're overlooking and what just came out in the executive order this week where there digital signatures the digital signatures rely upon the same types of encryption that will become vulnerable and those digital digital signatures secure things like software updates documents firmware updates your entire trust model your transactions right so the immediate impact of Q day quantum day when classical encryption becomes vulnerable that compromise by cryptographically relevant quantum computer the threats now are far more than just the loss of your of your intellectual property your long list sensitive data it's about the very trust model that enables a digital enterprise >> Well thank you for that very well explained and a lot to think about for sure and and Jonathan every major framework emphasizes that you cannot protect what you cannot see yet discovery is notoriously difficult because cryptography is completely decentralized hidden in legacy code third party SaaS apps and deep infrastructure So Jonathan when a CISO sits out to build a cryptographic bill of materials what are the practical realities of finding this shadow crypto and what automated discovery tools or processes actually work >> Yeah >> and how do you prioritize which legacy algorithms to rip and replace first I know a whole mouthful of things but I know you got the answers >> Yeah so you know a lot of folks think that we can begin a migration when Q day happens that it's like patching I've heard amazingly they they'll say well all we have to do is swap algorithms it's it's crypto agility and nothing more complex than swapping algorithms and I will say look um managing and detecting risks and mitigating them at scale is incredibly complex and it's hard. I know this because I spent 15 years at Verizon where we were working on that Verizon data breach report. And the latest issue, the 2026 report dropped a few weeks ago and it said 32% of all the reasons that lead to the entree into a network that leads to a data breach were caused by um attacking and exploiting known vulnerabilities. So, in So, we actually are have a lot of trouble with change management. We have trouble with vulnerability management.
And so, essentially what you're asking people to do today is you need to first identify all the places where cryptography is utilized. You need to understand the sources of that cryptography. Is it yours? Is it someone else's? Someone else's a vendor's provided that? Did you get it from a customer?
Where did you get that and what is its state? Is it already vulnerable? You're going to find MD5. You're going to find all types of fully deprecated and vulnerable forms of encryption still in production today because anytime you do an audit, you still find things that you thought were were no longer in production but are still alive.
And so, the first exercise is understand the level of complexity you're about to undertake because you're saying, "I'm going to be able to identify, assess, and manage cryptography across my network and to manage the intervals at which those things will be updated to make sure that I don't break any business processes." That is an incredible undertaking, right? So, the first thing we do in all forms of cybersecurity is first you understand your current state before you buy anything, think about buying anything, or or what your desired state may or may not be. Find out where you are today.
You know, running Find out where you're running RSA. Find out where you're running ECC.
Make sure that you're actually running current levels of encryption that have not already been obsolete. We still find all kinds of things.
Once you understand your current state, make sure that is as complete as possible. That's That sounds a lot easier than not, right? Because >> Do you think there's a lot of legacy organizations that really just rely on that because it's almost a set it and forget it and just moving on to something else?
>> There is the more I talk to people, the more I realize that there is a tremendous amount of what is called technology or crypto debt.
Um I'm still shocked by the number of organizations that are still about to undertake their zero trust journey. They haven't done that yet. And we're not talk We're not talking small mom-and-pop businesses or or or mid-size companies.
We're talking major municipalities, government agencies, and you know, the parts of enterprise businesses who are still under about to undertake their zero trust journey, let alone go through their PVC migration. So, there's Our networks are dynamic things. They are not set and forget it. So, our networks grow and change because of business requirements. They grow and change because of shadow IT. They grow and change because of M&A activity. They grow and change on a continuous basis.
So, one of those lessons across 28 years is that controls and architectures are perishable. And this is not a one-time exercise. So, you need to continuously undertake that crypto posture management. You need to be able to say, "Here's where I am today. Here's where I need to be in the next 3 5 years, wherever you are in that journey. Uh and then here's the path to get there.
Here's my prioritized my risk-based prioritization of what I'm going to do first. I'm going to make sure that my IP VPNs uh that are running RSA or ECC are all now utilizing a post-quantum algorithm." And and those things change.
There are six currently approved and released by NIST. Next year, there will be nine additional ones. Uh the Indians, the Brazilians, the Chinese, the Russians, the Europeans, the the Brits over in the UK, the Australians, they will all at some time release their own algorithms as well. So, you're talking about a challenge in terms of visibility and control over a highly disparate network that is both your own network, your carriers' networks, and all their peering points, and then your cloud ecosystem. And you need to identify every place where cryptography is utilized, which is everywhere, right?
>> [laughter] >> And then you've got to make sure that when those changes happen, they happen in a seamless fashion. And so, you're going to need AI for co-pilots to model how these changes look. Think about what you do with a CMDB today, or you do with an IT service management platform. You know, a tremendous amount of identification, assessment, validation, testing, and then migration. And all of that needs to be done seamlessly. Not like when I got started and there was like a 2:00 a.m. Greenwich Mean Time when the enterprise went offline. It it the analogy I heard was, "Well, we're no longer mechanics because we can't turn off the car and work on the parts. We're more akin to like a cardiologist who now has to to to work while the heart's still beating and make these changes, all right? And the enterprise can't slow down." So, yeah, first understand your current state, uh identify a risk-based approach to mitigate that. One of those things is just to make sure that that your next-generation firewalls are running your SD-WAN, your they are. Are they the same ones? Are there interoperability? The biggest challenge that people overlook today, beyond just uh the trust model breaking down, is that no one has actually done a migration under load.
No one has really tested to to "As I introduce longer uh algorithms and more complex handshakes between those certificates, will there be network degradation? Will my next generation firewall that runs on software or hardware like ASICs, will that impact uh my network performance? And the research suggests that you may have a degradation of maybe up to 1%, but you talk to a CIO or CISO from financial services firm that's running high volume transactions, you say, "Hey, you may experience a 1% degradation of network performance."
You're That's not That's not going to work, right? And so, yeah, there's a lot of complexity, but start off with understanding where you are today and where you need to be tomorrow and help your boards understand, your leadership understand that this is a multi-year cross-functional exercise that will require some level of discipline, but that this is what's needed to sustain the enterprise.
>> I want to echo what you just said cuz I think that's a critical piece for every organizations. Understand where you are today and know where you need to be tomorrow and going down in the future.
It's not this bleak, terrible picture we're painting. It's really understanding what you need to do and not be comfortable in the space you're in, but be ahead of it and move forward.
>> Yeah.
>> And the regulatory landscape just fit shifted dramatically, Jonathan, as you know, and with the White House issuing executive order 14409 setting strict 2030 deadlines for federal systems and contractors. And NIST FIPS 203, 204, and 205 standards finalize the commercial sector is next.
So, Jonathan, how will these federal and international mandates ripple into standard commercial compliance frameworks like PCI DSS 4.0 or SOC 2?
And how should CISOs leverage these new mandates to secure board-level budgets for post-quantum migration today. So, exactly as you said before, things are changing, things are moving. Please help us out here.
>> So, uh post-quantum maturity or readiness is now a contract contingency, and you'll see that reflected in the Federal Acquisition Regulation. So, those are the actual places where you want to see this codified because it will state that in order to sell to the US government, the largest consumer of anything in the world today, and just about the customer of very Fortune 2000 enterprise, you have to be quantum ready. And so, that means you will have for your high-valued assets by 2030 have by the end of 2030 have have your key generation capabilities be PQC safe, right? So, you're going to use post-quantum algorithms for that. By the end of the following year, your digital signatures need to be based upon post-quantum capabilities. And so, that's going to be reflected in the Federal Acquisition Regulations. You can now as a CIO as a CISO demonstrate that uh your business to the with the federal government relies upon this. Your standing as a reasonable level of care for a Fortune 2000 should be this body.
Even though FS-ISAC and FinServ are the only industry that have specific requirements for this, you'll see it next over in HIMSS and healthcare, but you'll see it cascaded across critical national infrastructure. But, the practical reality for any of my recovering CISOs out out there in the you know, from the reasonable care standard, this is something we should undertake. You You ought to be at this point at least on your your IPVPNs and your SASE services, your SD-WAN, utilizing a PQA, and that of course is making sure that your underlying vendors demonstrating that. Um and then moving forward, but this is this is not just a risk management exercise, it's not just a governance exercise, it's a resilience exercise, and it's also a business requirement now as well Um to sell but also if you are trying to leverage quantum to get those transformative business outcomes. If you're in life sciences, material science, financial services, you absolutely need to ensure that that your data and your models are quantum safe. Because the crazy thing about both AI and quantum is that it relies upon trusted data. You and trusted data meaning data protection at rest in transit and in use and now you believe you can see the scale of what you're undertaking. This is not just about algorithms. This is about making sure that your the trusted data model in your enterprise and in the ecosystem that you exist you know, is actually authentic.
>> Yeah. Well, the next thing you really touched upon early in our conversation, the swapping out RSA or elliptic curve cryptography isn't like a standard patch. NIST PQC algorithms have vastly different key sizes, processing speeds, and a network overhead. A straight rip and replace runs a massive risk of breaking production environments. So, Jonathan, what does true crypto agility look like in an enterprise network architecture? And how forward-looking organizations successfully leveraging hybrid classical PQC deployments to test these algorithm algorithms in production without disrupting business continuity?
>> So, that's uh that's a great issue.
Interoperability, orchestration, um the word seamless comes to mind. And it's not just in the NIST algorithms, right? It's the all the other algorithms. The algorithms that will be mandated and issued by the Gulf states, the ones that the Israelis will use, the ones that the Chinese will use, the Brazilians will use. And if you're a CISO on a global enterprise, the question becomes, well, how do I ensure interoperability across my network that spans multiple parts of the world? How do I abide by data sovereignty requirements?
And so, you begin to to address this notion that the path forward, I said this on a recent panel just last week, that if I'm a CISO, it's going to be a hybrid. I'm going to continue to use classical encryption in cases where there's very low to zero risk. There's no need to swap that out because there's there's no risk associated with that particular data flow or asset. After that, I'm going to use PQAs wherever possible. And I'll rely upon this as a standard, but I'm also need to make com- compensating controls for how I support operations in India, and Brazil, and in other places in the European Union.
You're You're beginning to see that nations and organizations recognize that technological innovation is a foundation of sovereignty, both sovereign as a country but sovereign as a data owner.
And and they're going to impose their requirements. So, we as operators have to have flexibility in form factor. So, I'm going to use classical wherever I can that that's there was no risk. I'm going to use PQAs wherever I can, especially the ones that are are implemented by my vendors. So, if I'm if I'm using a next generation firewall, I'm using routers, I'm using network equipment. I'm going to rely upon my vendors to do that integration for me, right? I'm going to take on the other challenges as as we'll discuss. And finally, for for networks and use cases that absolutely cannot afford to go down, cannot have that disruption, need to be future-proofed, and in environments where PQAs are not going to be addressable, I'm going to use symmetric keys. Symmetric keys are the standard by which the intelligence community utilizes and defense utilizes for secure communications. It has traditionally been hampered by hardware and very manual and cumbersome approaches. We now have the availability of software-based encryption that delivers symmetric keys. And so, now you as you think about quantum sensing and and the idea that you have sensors that monitor the Earth's electrical field to determine location that's not GPS-based, to to deliver um um surgeries at a microscopic level based upon the electric field in your body or in your brain and you've got sensors that are embedded in concrete and road systems on these sub and submarine surfaces on the ocean floor and low Earth orbit, you simply cannot go about traditional maintenance cycles that were hardware-related. I think the Anduril applications come to mind in that case.
And then for people like Telcos, where you're trying to deliver a consistent quality of service, think critical national infrastructure, what you know, during my time at Verizon we called life and limb issues, um and you can't afford disruptions, how are you going to ensure PQA traffic across that long distance around the world across different carriers and peering points and different protocols.
I will tell you you're going to use symmetric keys. It's already in production today on the world's backbone carriers where they're using symmetric keys to essentially future-proof uh in in two ways. One, symmetric keys uh can be automatically rotated. They're not at the mercy of a rotation in technology like like algorithms. Second, by definition, as I was on a panel last week and one of my heroes in this space, I will not name the person, but is definitely an icon on on the Mount Rushmore of quantum computing and security, said, "Look, uh symmetric keys are inherently immune from the threats of a quantum computer." And so, as a CISO, try to think about how you're going to do that hybrid and more importantly, leverage AI and leverage platforms that give you the visibility to do the orchestration. The orchestration will be the hardest component. Is that it's not where you whether you swap out one algorithm or another, it's that in swapping out, are you missing anything?
Did you miss one part of that chain uh where you didn't make that swap? And you're not making that swap. A vendor may be making that swap. A A partner, a carrier, a cloud provider, a customer may be making that swap. And if one is missed, then that trust chain breaks down, that business process gets degraded, and revenue gets affected. So, I think we're just beginning to scratch the surface of just how complex this will be. I suspect that most CISOs will need the ability to have hybrid solutions, and that they're going to decide for those really, really critical use cases where they can't afford to have uh degradation of service or disruptions, um they're going to use symmetric keys, but they'll use PQAs when they can, yeah.
>> Well, Jonathan, you certainly left us a lot to think about, and very important things that we need to think about.
Thank you. As we wrap up today's conversation, let's look at the bigger picture. Imagine your enterprise infrastructure as a massive bank vault.
For decades, we have focused on making the walls thicker and the guards more alert. But the reality of Q risk means our adversaries aren't trying to blow open the doors today. Instead, they are quietly taking pictures of lock mechanisms, copying the key shapes, and patiently waiting for the day a skeleton key is forged. If you wait until Q-Day to change your locks, you're already too late. The transition to post-quantum cryptography isn't just a technical patch. It's an architectural evolution.
By starting your cryptographic discovery today, building your C bomb, and enforcing cryptographic agility, you aren't just protecting today's transactions, you are ensuring that when the skeleton key is finally created, your organization has already changed the locks. Jonathan, thank you for joining us here today on Clarity and diving deep into this very important topic. Truly, you gave us so much to think about, and your wisdom is super very much appreciated.
>> Oh, thank you for this opportunity.
Really appreciate it.
>> Thank you. And to our audience, thank you for taking time today and we hope you enjoyed the show. Thank you.
Related Videos

Multi Vendor Multisig w/ Seed Signer, Hodl Dee & QnA
BitcoinMagazine
985 views•2024-09-05

Oasis Week in Review: Latest blog articles, workshops and more
OasisFoundation
135 views•2024-10-18

Kaspa: How ZK Turn Blockchains Into Settlement Layers (Part II)
cxc
1K views•2025-12-19

以言會友 EP13|當比特幣屢破紀錄 區塊鏈技術能帶來什麼?
dotdotnews
293K views•2021-01-05

Soroban Development: Ecosystem Growth, and the Rise of 70+ Smart Contract Projects
SorobanOfficial
1K views•2023-07-19

Balaji Srinivasan I The Fiat Crisis | Pragma Tokyo 2023
ETHGlobal
37K views•2023-05-06

$22 million NFT scammers arrested (insider evidence)
coffeezillaextras
806K views•2025-02-03

SYMMETRICAL TRIANGLE HOLDS THE KEY TO NEXT MOVE" DON'T IGNORE
xrpfuturemillionaire
800 views•2026-03-15
Trending

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23

SuperBike Factory Has Gone... What's Next for the Motorcycle Industry?
thatbikersimon
11K views•2026-07-22