Skip links

Post-Quantum Security: What Organizations Need to Know Now

Quantum computing is changing the way organizations need to think about long-term security.

Most digital systems today rely on cryptography that is considered secure because it would take classical computers an unrealistic amount of time to break it. But quantum computers could change that assumption. Once powerful enough, they may be able to break some of the cryptographic mechanisms that protect data, identities, communications, certificates and digital transactions today.

This does not mean organizations need to panic. It means they need to start preparing.

In our recent Post-Quantum Security Talks webinar, Gerard Cervell贸, CEO and Co-founder of Secrets Vault, Jordi Puiggal铆, CTO and Co-founder of Secrets Vault, and Aura Llanas, Business Advisor Cybersecurity at SandboxAQ, discussed the basics of the quantum threat, post-quantum cryptography and what organizations should start doing now.

Here are the main ideas security teams need to understand.

1. The quantum threat in simple terms

Modern cybersecurity depends heavily on cryptography.

It protects online communications, digital signatures, certificates, financial transactions, authentication systems, software updates and many other parts of digital infrastructure.

Much of this security is based on mathematical problems that are extremely difficult for classical computers to solve. The challenge is that quantum computers could solve some of these problems much faster.

This is especially relevant for public-key cryptography, which is widely used in secure communications, digital certificates, PKI infrastructure, digital signatures, key exchange, authentication flows and software updates.

Post-quantum cryptography is the response to this challenge. It refers to cryptographic algorithms designed to resist attacks from both classical and quantum computers.

The transition has already started. Standards are moving, vendors are preparing and regulated industries are beginning to assess what migration will require.

2. The risk already exists for long-term data

One of the most important concepts in post-quantum security is harvest now, decrypt later.

This means an attacker may capture encrypted data today, even if they cannot decrypt it yet. If that data remains valuable in the future, they may try to decrypt it once quantum capabilities become available.

The key question is simple:

How long does your data need to remain confidential?

Some information only needs short-term protection. Other data may remain sensitive for years or even decades.

Type of dataWhy it matters
Healthcare recordsThey remain sensitive for a lifetime.
Government and defense informationLong-term confidentiality is often critical.
Financial dataExposure can create regulatory, legal and reputational risk.
Legal documentsConfidentiality may need to be preserved for many years.
Intellectual propertyStrategic value can last well beyond the current business cycle.
Critical infrastructure dataSecurity exposure can affect essential services.

For these cases, the quantum threat is connected to decisions being made today.

If data captured now could still be sensitive in five, ten or twenty years, organizations need to understand their exposure.

3. Migration will not be instant

Moving to post-quantum cryptography will not be as simple as replacing one algorithm with another.

Cryptography is everywhere, but it is not always visible.

It can be embedded in applications, APIs, cloud services, internal systems, certificates, hardware devices, IoT environments, software libraries, authentication flows, legacy infrastructure and third-party vendor systems.

That is what makes migration complex.

Before changing anything, security teams need to understand what they have, where it is used and how critical it is. A post-quantum migration may require system updates, new certificates, new key management processes, vendor coordination, testing, compatibility checks and operational planning.

That takes time.

Organizations that wait until migration becomes urgent may face more complexity, higher costs and more operational risk.

4. Visibility comes first

The first step is visibility.

Security teams need to identify where cryptography exists across the organization and which systems depend on it. This is often referred to as a cryptographic inventory or a Cryptographic Bill of Materials, CBOM.

A useful inventory should help answer questions such as:

  • Which cryptographic algorithms are being used?
  • Where are they used?
  • What data do they protect?
  • Which certificates and keys are active?
  • Which vendors are involved?
  • Which systems will be difficult to update?

The goal is not to migrate everything immediately. The goal is to understand the environment well enough to make a plan.

Without visibility, post-quantum migration becomes guesswork.

With visibility, organizations can prioritize.

5. Crypto agility will matter

Post-quantum migration is not only about selecting new algorithms. It is also about making security architecture easier to adapt.

This is where crypto agility becomes important.

Crypto agility means the ability to change cryptographic algorithms, protocols or key management processes without rebuilding entire systems from scratch.

That matters because post-quantum standards, implementations and vendor support will continue to evolve. Some organizations may need to support hybrid approaches. Others may need to update algorithms over time or adapt to new regulatory requirements.

A rigid architecture makes every cryptographic change difficult.

A crypto-agile architecture gives teams more control.

For security leaders, this means future architecture decisions should consider how easily cryptographic components can be updated, replaced or combined with new mechanisms.

6. Identity and authentication are part of the transition

Post-quantum security is not only a data encryption issue. It also affects identity and authentication.

Many identity systems depend on cryptographic mechanisms to verify users, devices, services and transactions. Certificates, digital signatures, credentials, recovery mechanisms and authentication protocols can all be connected to cryptographic assumptions that may need to change.

This is especially relevant in environments that rely on PKI, certificate-based authentication, digital signatures, long-lived credentials, device identity or machine-to-machine authentication.

For this reason, identity resilience should be part of the post-quantum roadmap.

Security teams need to ask how users and systems prove who they are, how credentials are protected, how access is recovered and how authentication flows can remain secure over time.

At Secrets Vault, this is a core part of how we think about long-term security. Authentication should not depend on fragile assumptions, static secrets or architectures that are difficult to adapt.

Post-quantum readiness requires a broader view of identity, access and resilience.

7. What security teams can do now

Organizations do not need to complete post-quantum migration overnight. But they should start preparing.

A practical first step is to map the current environment: where cryptography is used, which systems protect sensitive or long-lived data and which parts of the infrastructure would be difficult to update.

From there, security teams can begin to prioritize.

Some actions can start now:

  • Build a cryptographic inventory or CBOM.
  • Review certificates, keys, PKI and authentication flows.
  • Ask vendors about their post-quantum roadmap.
  • Assess which systems are difficult to update.
  • Start testing hybrid or post-quantum-ready approaches.
  • Include crypto agility in future architecture decisions.
  • Connect post-quantum planning with identity and access management.

The most important step is to create ownership.

Post-quantum migration will affect security, IT, infrastructure, compliance, procurement and vendors. Without a clear owner, it can easily remain a future problem that no team is actively preparing for.

8. Preparation creates control

The quantum threat is complex, but the first steps are practical.

Security teams need to understand which data must remain confidential over time, where cryptography is used, which systems are exposed and how identity infrastructure may be affected.

This is not about panic. It is about preparation.

Post-quantum security will require time, coordination and architectural decisions. Organizations that begin now will be in a better position to migrate gradually, test safely and reduce risk before urgency arrives.

To explore these topics in more detail, watch the full Post-Quantum Security Talks webinar with Gerard Cervell贸, Jordi Puiggal铆 and Aura Llanas.

Leave a comment

Privacy Summary

This website uses cookies so that we can provide you with the best possible user experience. The cookie information is stored in your browser and performs functions such as recognizing you when you return to our site or helping our team understand which sections of the site you find most interesting and useful.