New: Upgrading to a Quantum-Safe Future
In today’s fast-paced digital landscape, the advent of quantum computing presents both excitement and concern. As these powerful machines threaten to outstrip conventional cryptography with speed and efficiency, organizations face a critical need to upgrade their security measures. The good news? Transitioning to quantum-safe cryptography is a manageable endeavor that, with careful planning and collaboration, can be pulled off effectively.
### Initial Steps: Governance and Assessment
The journey toward quantum readiness begins with establishing governance and policy frameworks. Organizations need to assess their current cryptographic exposure—understanding where vulnerabilities lie is key. This initial audit paves the way for prioritizing remediation efforts across the entire infrastructure, including the supply chain. Building a comprehensive roadmap is essential for guiding these internal updates and setting up contractual mechanisms that ensure vendors adhere to the upgraded standards.
Marc Manzano, the general manager of the cybersecurity group SandboxAQ, emphasizes the importance of modern cryptography management solutions in this transition. “The first step to reclaim control over decades of cryptographic sprawl across IT is to leverage these solutions,” he explains. Such tools provide critical observability and reporting capabilities that help organizations keep track of their cryptographic assets.
### Updating Encryption Algorithms
Upon completing the initial assessment and setup, organizations can dive into updating their encryption algorithms. In August 2024, the National Institute of Standards and Technology (NIST) announced new standards featuring encryption algorithms designed to withstand quantum attacks. These methods alter how data is encrypted and decrypted, ensuring they remain secure even as quantum computing evolves.
Currently, traditional encryption relies on complex mathematical problems, such as large-number factoring, which are too challenging for contemporary supercomputers to solve. However, the power of quantum computers could change the game, making these encryptions quickly crackable. The NIST standards pivot away from such vulnerabilities, opting instead for lattice-based and hash-based problems that present a level of complexity sufficient to deter even quantum computers.
### Industry Leaders Making the Switch
Tech giants are already stepping up to the challenge. Following the release of NIST’s updated standards, Apple revamped its iMessage application to incorporate quantum-secure encryption methods. Meanwhile, Google has integrated the new standards into its cryptographic libraries and plans to implement them in its Chrome web browser. IBM, with its extensive investment in quantum technology, is also leading the way by incorporating post-quantum cryptography into several of its platforms. Microsoft joins the ranks, announcing plans to add quantum-safe algorithms to its cryptographic library.
### Collaborative Efforts: Migration to Post-Quantum Cryptography
In 2021, NIST launched the Migration to Post-Quantum Cryptography (PQC) project through its National Cybersecurity Center of Excellence (NCCoE). This project has attracted over 40 collaborators, all bringing a diverse toolkit of cryptographic discovery and inventory solutions to the table. The initiative focuses on demonstrating how these tools can facilitate organizations in planning for their quantum transitions.
Collaborators within this project also emphasize testing the PQC algorithms for use within various protocols. They aim to understand these algorithms’ performance and interoperability, which are critical factors as organizations gear up to implement PQC in their products.
Bill Newhouse, co-lead for the Migration to PQC project, underscores the importance of understanding current cryptographic usage. “An organization needs to grasp where and how it employs cryptographic products, algorithms, and protocols to begin moving towards quantum-readiness,” he states. The tools and analyses generated from these collaborative efforts support risk assessment, enabling organizations to prioritize which systems should migrate to PQC first.
### Engaging with the Future of Cryptography
The road to a quantum-safe future requires a collaborative approach anchored in thorough evaluation and planning. Organizations that proactively engage with updated cryptographic standards and embrace modern management solutions will find themselves better equipped to safeguard their data against the looming threat posed by quantum computing. The shift may be challenging, but with the right structures in place, it promises to enhance the security landscape, ensuring that sensitive information remains protected in the age of quantum technology.

