Post-Quantum Security: Why Organizations Must Start Preparing Now
Key insights from our Post-Quantum Security Talks & Drinks in Barcelona
Quantum computing is moving rapidly from research labs to strategic planning discussions in cybersecurity.
During our Post-Quantum Security Talks & Drinks event in Barcelona, security professionals gathered to discuss what the transition to the quantum era means in practice. The session featured a technical talk by Jordi PuiggalĂ (Co-founder & CTO at Secrets Vault) followed by a roundtable discussion with Aura Llanas (SandboxAQ) and JesĂşs Huerta (Qilimanjaro Quantum Tech).

The goal of the event was simple: move the conversation around post-quantum security from theory to practical preparation.
Here are the main takeaways.
1. The quantum threat is not unexpected
One of the central ideas from Jordi PuiggalĂ’s presentation was that the coming cryptographic disruption is fundamentally different from previous ones.
During the talk, Jordi compared the situation to the story behind The Imitation Game and the breaking of the Enigma cryptosystem during World War II. The key difference is that, today, organizations are equipped with advanced warning systems.
“We know that the breach will happen, and we can prepare ourselves to prevent it from becoming a security problem in the future.”
Unlike historical cryptographic breaks, the cybersecurity community now has time to understand the risks and prepare infrastructure before quantum computers become powerful enough to break current algorithms.
This shift is what makes post-quantum readiness an architectural and strategic issue rather than just a research topic.

2. “Harvest Now, Decrypt Later” is already a real threat
A key topic discussed during the event was the Harvest Now, Decrypt Later (HNDL) attack model.
In this scenario, attackers collect encrypted data today and store it until quantum computers become capable of breaking the cryptographic algorithms protecting it.
As Jordi explained during the presentation:
“Attackers may gather encrypted information today that cannot be decrypted now, but once quantum computers are available, they will be able to decrypt it.”
This risk is particularly relevant for long-lived sensitive information, such as:
- Confidential documents
- Intellectual property
- Government data
- Authentication credentials
- Digital signatures
Organizations that rely on long-term confidentiality must consider that data encrypted today may still need protection decades from now.

3. The first step toward post-quantum readiness is visibility
One of the strongest points raised during the roundtable was that many companies are still at the earliest stage of preparation.
Before migrating to new cryptographic algorithms, organizations need to answer a fundamental question:
Where is cryptography actually used across our systems?
JesĂşs Huerta emphasized that preparation must start with understanding the data being protected.
“The most important topic is understanding what data you have, why it needs to be protected, and for how long.”
Without this visibility, it becomes almost impossible to plan a safe migration toward post-quantum cryptography (PQC).
Building a cryptographic inventory and identifying long-term data exposure are essential first steps.

4. Crypto agility will define future security architectures
Another major theme in the discussion was crypto agility.
Aura Llanas explained that organizations should avoid treating the post-quantum transition as a single migration project.
Instead, systems should be designed so they can evolve as algorithms and standards change.
I would recommend not migrating to quantum solely for the sake of quantum, but with the goal of becoming crypto-agile.
Crypto agility means building systems that allow organizations to replace cryptographic algorithms quickly when necessary.
This flexibility is critical because:
- New vulnerabilities may appear
- Standards may evolve
- New post-quantum algorithms may be adopted
Organizations that are crypto-agile will be able to adapt faster when the transition accelerates.

5. Technical debt is one of the biggest risks
Legacy infrastructure also emerged as a major challenge.
Companies with large amounts of technical debt often struggle to identify where cryptography is embedded in their systems.
As discussed during the roundtable:
Companies with hardware or infrastructure 20–30 years old face significant unknowns when trying to evaluate their cryptographic exposure.
These legacy systems can create blind spots that will complicate post-quantum migration.
For many organizations, reducing technical debt will be a necessary step before implementing new cryptographic standards, as outdated systems may hinder the adoption of more secure algorithms and protocols required for post-quantum cryptography.
Preparing for the post-quantum era
One message became clear throughout the event:
The transition to post-quantum security will not happen overnight, but preparation must start now.
Organizations do not need to deploy new cryptography immediately. Instead, they should begin by understanding:
- Where cryptography is used
- Which data must remain confidential long-term
- How their systems can evolve toward crypto agility
At Secrets Vault, we focus precisely on this challenge: helping organizations prepare their authentication systems, credentials, and sensitive data for a future where cryptographic assumptions may change.
The first step toward post-quantum readiness is simple but essential: visibility into your cryptographic landscape.