Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireLogical SecurityCybersecurity News

Cyber leaders must prepare quantum security now, research finds

By Jordyn Alger, Managing Editor
Burst of light

FlyD via Unsplash

March 14, 2025

It is estimated that commercial availability of quantum computers capable of compromising conventional asymmetric cryptography is five to 10 years away. Nevertheless, a new report asserts that security and risk professionals must prepare for it in the present. 

According to the report, quantum security consists of a range of technologies, such as: 

  • Post-quantum or quantum-computing-resistant key exchange
  • Digital signatures
  • Cryptographic algorithm discovery and inventory
  • Cryptographic algorithm change management (cryptoagility)
  • Key generation and management
  • Quantum key distribution  
  • Certificate management

The report also suggests that quantum computing will affect all types of security, including authentication, data encryption and digital signatures, certificate and key management, and transport layer security and secure communications. 

Below, security leaders share their thoughts on the report as well as the state of quantum computing. 

Security leaders weigh in

Tim Mackey, Head of Software Supply Chain Risk Strategy at Black Duck:

The promise of quantum computing to decrypt harvested data may become a reality, but the value that an attacker might get from older harvested data is only justifiable for the most valuable and targeted data. This is one reason why various governments have quantum resilient efforts underway rather than “quantum proof” solutions. Since we are talking about a future state for cryptographic capabilities in applications, performing a risk assessment focused on cryptographic usage within an application should be a priority for any organization working with the most sensitive of personally identifiable information (PII). At a minimum, that risk assessment should focus on what the impact to the system might be if weak encryption were used. Such an assessment would then become a gap analysis covering where sensitive data isn’t being properly managed and help identify where quantum resilient approaches to system design and deployment should be employed.

Tim Callan, Chief Compliance Officer at Sectigo:

The shift to shorter certificate lifespans will certainly help organizations prepare for the next era of postquantum cryptography (PQC). This is why the term cryptographic agility becomes important. Cryptoagility is crucial in today’s fast-evolving digital environment, where new technologies, algorithms and security challenges require constant adaptation. This need for agility will become even more critical as we approach the PQC era, with the potential for rapid algorithm deprecation. IT professionals can no longer rely on the same cryptographic strategies. Shorter certificate lifespans promote cryptographic agility by speeding up the adoption of stronger algorithms and ensuring compliance with evolving security standards. For example, the deprecation of SHA-1 was delayed significantly when certificate lifespans were as long as three years. In the uncertain postquantum era, shorter certificates can help mitigate delays in adopting advanced solutions.

Longer certificate lifespans, on the other hand, tend to encourage complacency. Many businesses and enterprises may not proactively adopt improved cryptographic standards or security practices until forced by certificate expirations to seek stronger certificates through renewal.

This year, we will see the beginning of the death of legacy technology stacks, forced upon organizations by post-quantum cryptographic preparations. Legacy systems often rely on cryptographic algorithms like RSA and ECC but as the push for PQC standards are adopted, these older systems will struggle to integrate new algorithms, leading to obsolescence or requiring a significant overhaul of existing technology. Organizations holding on to legacy technology infrastructures will be forced to confront the limitations of their outdated infrastructures. Organizations need to act now to carefully plan and execute their transition — while challenging — to ensure they remain secure and compliant in the quantum era.

Additionally, we can expect a wave of official statements from the most forward-thinking vendors regarding their PQC capabilities. These announcements will not signify the immediate availability of PQC solutions but rather a pledge to transition towards PQC standards by 2026. With organizations like NIST finalizing PQC deadlines, vendors will need to show their preparedness to implement these standards and help customers transition smoothly. These announcements will serve several strategic purposes, highlighting vendors’ market leadership and differentiation, reinforcing their proactive stance on cybersecurity. By doing so, they are aiming to build customer confidence and ensure compliance with upcoming regulations.

Casey Ellis, Founder at Bugcrowd:

The consensus is five to 10 years for quantum computers capable of breaking RSA-2048, however, I’d argue that’s a conservative estimate. Recent advancements, like Microsoft’s scalable qubit breakthroughs, suggest the timeline could shrink, especially with nation-state investment accelerating progress. The uncertainty itself, combined with the “all or nothing” threat model associated with Q-day, is a reason to act now.

Implementing QRC is a cybersecurity problem which suffers from a unique case of the “Chicken Little” problem. While most systemic changes in support of cyber resilience happen in response to a security trash fire of some sort, the challenge is that post-quantum is an all-or-nothing thing. Pragmatically, The “harvest now, decrypt later” threat is real. Adversaries are already stockpiling encrypted data, knowing it will become readable once quantum decryption is viable. Sensitive information — like state secrets, intellectual property or long-term financial data — retains value well beyond a decade. Waiting to adapt is a gamble with potentially catastrophic consequences.

The biggest hurdles are awareness, cost and complexity. Many organizations underestimate the threat or lack the resources to inventory and update their cryptographic infrastructure. Standards bodies like NIST are making progress with PQC algorithms, but adoption will require significant investment and coordination.

In the short term, quantum readiness builds trust with customers and partners. Medium-term, it reduces the risk of catastrophic breaches. Long-term, it ensures operational continuity in a post-quantum world. The cost of inaction far outweighs the investment in preparation.

Dr. Adam Everspaugh, Cryptography Expert at Keeper Security:

Predicting the arrival of a quantum computer capable of breaking today’s public key cryptography is highly challenging. If technological progress followed a linear trajectory, we could confidently estimate that such systems are still hundreds of years away. However, history has shown that technological breakthroughs often follow an exponential curve, where early progress appears slow but rapidly accelerates as innovations build upon each other.

The recent advancements from Google and Microsoft highlight the reality that quantum development isn’t stagnant — it’s actively progressing. While these announcements don’t provide a definitive timeline, they reinforce the need for vigilance. Powerful quantum computers capable of breaking current cryptology could emerge in the next five to 10 years, or it could take decades more. The uncertainty itself is a risk, making early preparation not just prudent but essential for long-term security.

The risk of quantum computing isn’t just theoretical — it’s already influencing cybercriminal tactics today. The “harvest now, decrypt later” threat means attackers are actively collecting encrypted data, betting that quantum advancements will eventually allow them to decrypt it. Sensitive information sent over public networks like Wi-Fi and WANs is particularly vulnerable. Organizations should act now by integrating hybrid Quantum-Resistant Cryptographic (QRC) solutions into their security frameworks. Transitioning to QRC is a complex, multi-year process, requiring upgrades to protocols, hardware and software across industries.

NIST and the broader cryptographic community have invested years into developing quantum-resistant algorithms, but new cryptography always carries risks. These algorithms, while mathematically promising, haven’t been battle-tested in real-world adversarial environments. History has shown that many cryptographic schemes are eventually broken — not by quantum attacks, but by the ingenuity of mathematicians, cryptographers and researchers exploiting unforeseen weaknesses. This is why deploying QRC in a hybrid approach is critical. Combining quantum-resistant cryptography with established public key cryptography ensures that an attacker must break both, significantly increasing security resilience. Adaptability is key in this evolving landscape.

KEYWORDS: cybersecurity planning cybersecurity preparedness quantum computing threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • security-threats-podcast.png

    The top security threats leaders must prepare for in 2023

    See More
  • Office hallway with glass walls

    2026 Enterprise Security Trends: What Leaders Must Prepare For In An Interconnected Risk Landscape

    See More
  • Here are the top political and security risks for 2021 that your organization needs to take prepare for

    Organizations must prepare for these 2021 security risks now, or may fail to make it in a post-COVID world

    See More

Related Products

See More Products
  • 9780367339456.jpg.jpg.jpg

    Cyber Strategy: Risk-Driven Security and Resiliency

  • 9780815378068.jpg.jpg

    Biometrics, Crime and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing