Post-Quantum Cryptography Report for Professionals

Explore top LinkedIn content from expert professionals.

  • View profile for Dr. Robert Campbell, FBBA

    IBM Quantum-Safe Executive | Post-Quantum Cryptography, AI Security & Federal Cryptographic Modernization | Former Naval Cryptology Officer | FBBA

    29,501 followers

    🚨 NEW PEER-REVIEWED RESEARCH: PQC Migration Timelines Excited to share my latest paper published in MDPI Computers: "Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks." The transition to Post-Quantum Cryptography (PQC) represents a watershed moment in the history of our digital civilization. Organizations planning for a 3-5 year "upgrade" will fail. The reality is a 10-15-year systemic transformation. Key Contributions: 📊 Realistic Timeline Estimates by Enterprise Size: Small (≤500 employees): 5-7 years Medium (500-5K): 8-12 years Large (>5K): 12-15+ years ⚠️ Critical Finding: With FTQC expected 2028-2033, large enterprises face a 3-5 year vulnerability window—migration may not complete before quantum computers break RSA/ECC. 🔬 Novel Framework Analysis: Causal dependency mapping (HSM certification, partner coordination as critical paths) "Zombie algorithm" maintenance overhead quantified (20-40%) Zero Trust Architecture implications for PQC 💡 Practical Guidance: Crypto-agility frameworks and phased migration strategies for immediate action. Strategic Recommendations for Leadership: 1. Prioritize by Data Value, Not System Criticality: Invert the traditional triage model. Systems protecting long-lived data (IP, PII, Secrets) must migrate first, regardless of their operational uptime criticality, to mitigate SNDL. 2. Fund the "Invisible" Infrastructure: Budget immediately for the expansion of PKI repositories, bandwidth upgrades, and HSM replacements. These are long-lead items that cannot be rushed. 3. Establish a Crypto-Competency Center: Do not rely solely on generalist security staff. Invest in specialized training or retain dedicated PQC counsel to navigate the mathematical and implementation nuances. The talent shortage will only worsen. 4. Demand Vendor Roadmaps: Contractual language must shift. Procurement should require vendors to provide binding roadmaps for PQC support. "We are working on it" is no longer an acceptable answer for critical supply chain partners. 5. Embrace Hybridity: Accept that the future is hybrid. Design architectures that can support dual-stack cryptography indefinitely, viewing it not as a temporary bridge but as a long-term operational state. 6. Implement Automated Discovery: You cannot migrate what you cannot see. Deploy automated cryptographic discovery tools to continuously map the cryptographic posture of the estate, identifying shadow IT and legacy instances that manual surveys miss. The quantum clock is ticking. Start planning NOW. https://lnkd.in/eHZBD-5Y 📄 DOI: https://lnkd.in/ejA9YpsG #PostQuantumCryptography #Cybersecurity #QuantumComputing #PQC #InfoSec #NIST #CryptoAgility

  • View profile for Malak Trabelsi Loeb

    Founder shaping quantum, AI, and space innovation. NATO SME. Driving high-stakes legal frameworks across national security, tech transfer, and policy at the frontier of sovereign systems. UNESCO Quantum100. 🇦🇪🇧🇪🇪🇺

    39,570 followers

    📌The financial sector has now moved from quantum awareness to quantum execution. Europol , FS-ISAC , and the Quantum Safe Financial Forum (QSFF), together with major financial institutions, published: “Prioritising Post-Quantum Cryptography Migration Activities in Financial Services” ; a practical migration framework designed specifically for financial institutions. What makes this report particularly relevant for #boards, #regulators, and #CISOs? It introduces a structured prioritisation methodology based on two measurable dimensions: 1️⃣ Quantum Risk Score Derived from: • Shelf life of protected data • Exposure • Severity of compromise 2️⃣ Migration Time Score Derived from: • Solution availability • Execution cost and time • External dependencies Migration Priority is determined by combining both scores into a risk–time matrix (see pages 8–10) of the Report below ⬇️ . ♨️ This shifts the conversation from “When will Q-Day happen?” to “Which business use cases require action now, and which require long-term orchestration?” Two examples in the report illustrate this distinction: 🔹 Points of Sale (#PoS) Medium quantum risk but high migration complexity due to hardware lifecycles, ecosystem coordination, and standardisation uncertainty (pages 12–15) . ⛔️Early planning is essential to avoid costly out-of-cycle replacements. 🔹 Public Websites (#TLS_confidentiality) Medium quantum risk but low migration time due to hybrid schemes such as X25519MLKEM768 already supported by major browsers and CDNs (pages 16–19) . ⛔️This is one of the earliest practical deployment opportunities for quantum-safe protection in production environments. Another important contribution of the report is its focus on cryptographic antipatterns (pages 21–24) . Before large-scale PQC migration, institutions can implement no-regret actions: • Automate TLS certificate lifecycle management • Standardise TLS configurations (TLS 1.3 baseline) • Eliminate legacy cipher dependencies • Remove hard-coded credentials • Strengthen key management governance This approach aligns closely with supervisory expectations: #quantum_readiness must integrate into existing risk frameworks, asset lifecycle planning, and vendor coordination. For financial institutions, the message is clear: ❌Quantum safety is not a single migration event. ❌It is a prioritised, staged governance programme that integrates cryptography, procurement, architecture, and regulatory alignment. Full publication: Europol (2026), Prioritising Post-Quantum Cryptography Migration Activities in Financial Services Available via Europol Publications Office: https://lnkd.in/d2bgsVKm #PostQuantumCryptography #PQC #QuantumRisk #FinancialServices #CybersecurityGovernance #DigitalResilience #CryptoAgility #QuantumTransition #FinancialStability

  • View profile for Marin Ivezic

    CEO, Applied Quantum | Author, PostQuantum.com | Quantum Systems Integration, Quantum Security & Post-Quantum Cryptography (PQC) | ex-Fortune Global 500 CISO/CTO & Big 4 Partner

    34,951 followers

    We just published the full Applied Quantum PQC Migration Framework - the complete methodology for migrating enterprise cryptography to post-quantum standards - freely, under Creative Commons (CC BY 4.0). https://pqcframework.com The framework is an 8-phase lifecycle covering everything from executive mandate and business case through discovery, CBOM, risk scoring, roadmap, pilots, infrastructure modernization, and vendor governance. It includes cross-cutting sections on crypto-agility architecture, maturity models, metrics, regulatory mapping, and skills. It comes with four sector-specific extensions: - Financial Services (banking, payments, capital markets) - Telecommunications - Government & Defense - Critical Infrastructure / OT This is not another repackaging of NIST guidance or a theoretical migration model. I embedded some hard-earned lessons into it. The framework in parts deliberately diverges from conventional industry approaches where practical experience has shown they don't work. E.g. minimum-viable CBOM, risk-driven discovery scoping, vendor governance first. When I take these more pragmatic positions, I defend each one with evidence, and importantly, we've worked with regulators who have accepted and in some cases adopted these approaches. If you've been reading PostQuantum.com, you know I've always shared what I've learned openly - the articles on CBOM, crypto-agility, hybrid cryptography, vendor governance, the "Rethinking" series. This framework is the most structured version of that same commitment: putting the complete methodology out there so practitioners can use it, adapt it, and build on it. Publishing under CC BY 4.0 means anyone can use it - including commercially - with proper attribution. No ambiguity about where this work originates. If you're a CISO figuring out how to start, a program manager staring at a multi-year migration, a security architect navigating hybrid deployment, or a consultant helping clients get quantum-ready - this is for you. https://pqcframework.com #pqc #postquantum #quantumsecurity #quantumready #quantumresistance #pqcframework #pqcmigration #pqcmigrationframework

  • View profile for Alexander Leslie

    National Security, Defense & Cyber Intelligence | Senior Advisor, Recorded Future | Government Affairs, Strategic Communications & Executive Engagement | Cybercrime, Espionage & Influence Operations

    12,860 followers

    Recorded Future released a new Executive Insights Report that examines quantum risk through a practical security and policy lens, focusing less on speculative timelines and more on the consequences unfolding today. One of the most important points is that quantum risk does not begin with the arrival of a cryptographically relevant quantum computer. In many respects, it has already started. “Harvest now, decrypt later” activity fundamentally changes how organizations should think about sensitive data. The compromise occurs at the point of collection, even if decryption remains years away. For governments, critical infrastructure operators, defense contractors, and firms handling long-lived intellectual property, the exposure horizon is measured in decades. That dynamic has broader implications than encryption alone. Public-key cryptography quietly underpins digital trust across modern economies. The eventual disruption of those trust anchors would challenge the integrity assumptions embedded across global digital infrastructure. What makes the issue significant is the mismatch between uncertainty and infrastructure permanence. There is still no definitive timeline for cryptographically relevant quantum computers, but many systems being deployed today will remain operational long enough to encounter them. That means current decisions are becoming future security liabilities or future resilience advantages depending on how organizations prepare. The policy environment is beginning to reflect this reality. Post-quantum cryptography is moving from research priority to governance expectation. Over time, this will likely evolve into a market differentiator. Organizations able to demonstrate cryptographic agility and credible migration planning may increasingly be viewed as lower-risk partners across government and critical infrastructure ecosystems. There is also an operational dimension that deserves more attention. The convergence of AI-enabled automation with quantum-enhanced optimization has the potential to compress defender response windows substantially. The organizations most exposed may not be those lacking sophisticated security tooling, but those carrying accumulated security debt, rigid architectures, and slow remediation cycles. The encouraging reality is that the core mitigation pathways are already visible. Cryptographic inventory, crypto-agility, supplier scrutiny, and prioritization of long-lived sensitive data are actionable steps that can be pursued now, well before quantum capabilities mature. In that sense, quantum preparedness is becoming less about predicting “Q-Day” and more about institutional adaptability. The organizations and governments that approach this transition early will likely experience it as a managed modernization effort. Those that delay may eventually confront it as a compressed operational and regulatory crisis.

  • View profile for Alex Pruden

    CEO/Co-Founder of Project Eleven

    1,959 followers

    Trillions of dollars in digital assets are currently secured by cryptography that quantum computers will break. Project Eleven just released The Quantum Threat to Blockchains: 2026 Report, written with my co-author Conor Deegan. The core finding: Q-Day, when quantum computers can crack today's cryptography, could arrive by as soon as 2030. However, our model places Q-Day timing at a baseline of 2033, with optimistic and pessimistic scenarios at 2030 and 2042. Three major developments in the past year have accelerated the field: - Google, along with several other quantum hardware teams, have demonstrated quantum error correction below critical thresholds - Breaking Bitcoin's cryptography now requires as few as 10,000 physical qubits, and could be possible in as little as 9 minutes - Recent advances in error correction and algorithm optimizations have dropped resource requirements by orders of magnitude This report breaks down the quantum computing landscape, blockchain vulnerabilities, NIST post-quantum standards, and what migration actually requires. The trajectory of quantum development potentially follows a "nothing-and-then-all-at-once" exponential curve. Small improvements in error correction or qubit connectivity may compound to create feedback loops that may collapse the timeline with little warning. Blockchains face a unique challenge. Traditional systems can more easily rotate keys when necessary, compared with blockchain addresses that in some cases hold $B under the same keys for years. Migration across distributed networks could take up to a decade, which is longer than we may have under our baseline model forecast. The window to act is narrowing. Migration to quantum-resistant cryptography is no longer optional. It's imperative for any blockchain-based digital asset network expected to secure value into the future. Report link here: https://lnkd.in/djrnd2mD

  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 19,000+ direct connections & 54,000+ followers.

    54,290 followers

    NIST – Migration to Post-Quantum Cryptography Quantum Readiness outlines a comprehensive framework for transitioning cryptographic systems to post-quantum cryptography (PQC) in response to the emerging threat of quantum computers. Quantum technology is advancing rapidly and poses a significant risk to current public-key cryptographic methods like RSA, ECC, and DSA. This guide aims to assist organizations in preparing for and implementing PQC to safeguard sensitive data and critical systems. Key Points  The Quantum Threat Quantum computers are expected to disrupt cryptography by efficiently solving mathematical problems that underpin widely used encryption and key exchange methods. This would render current public-key systems ineffective in protecting sensitive data, emphasizing the need for cryptographic agility.  NIST PQC Standards NIST is spearheading efforts to standardize quantum-resistant algorithms through an open competition and evaluation process. These algorithms, designed to withstand quantum attacks, focus on two primary areas: 1. Key Establishment: Protecting methods like Diffie-Hellman and RSA key exchange. 2. Digital Signatures: Securing authentication processes.  Migration Framework The document provides a phased approach to migrating cryptographic systems to PQC: 1. Assessment Phase:    - Inventory cryptographic dependencies in current systems.    - Evaluate systems at risk from quantum threats based on sensitivity and lifespan. 2. Preparation Phase:    - Conduct pilot testing of candidate PQC algorithms in existing infrastructure.    - Develop a hybrid approach that combines classical and post-quantum algorithms to ensure interoperability during transition. 3. Implementation Phase:    - Replace vulnerable cryptographic methods with PQC in a phased manner.    - Ensure scalability, performance, and compatibility with existing systems. 4. Monitoring and Updates:    - Continuously monitor the effectiveness of implemented solutions.  Challenges in PQC Migration - Performance Impact: PQC algorithms often have larger key sizes, increased latency, and greater computational demands compared to classical algorithms. - Interoperability: Ensuring smooth integration with legacy systems poses significant technical challenges.  Best Practices - Use hybrid encryption to maintain compatibility while testing PQC algorithms. - Engage in collaboration with vendors, industry groups, and government initiatives to align with best practices and standards. Conclusion The transition to post-quantum cryptography is a proactive measure to secure data and communications against future threats. NIST emphasizes the importance of starting preparations immediately to mitigate risks and ensure a smooth, efficient migration process. Organizations should focus on inventorying dependencies, piloting PQC solutions, and developing cryptographic agility to adapt to this transformative technological shift.

  • View profile for Prof. Dr. Ingrid Vasiliu-Feltes

    Quantum & AI Governance I Deep Tech Diplomacy,Investments, Strategy I Innovation Ecosystem Builder I DLT-Web3 Architectures I Cyber-Ethics I Precision Longevity I Chairwoman & Advisor I Vice-Rector I Editor I Keynotes

    54,433 followers

    EY’s perspective on securing against #quantum #risks emphasizes that quantum #computing is rapidly evolving from a theoretical concern into a material cybersecurity threat that requires immediate strategic action. The core issue lies in the vulnerability of widely used cryptographic algorithms, such as RSA and elliptic curve cryptography, which could be broken by sufficiently advanced quantum computers. This creates a systemic risk to sensitive data, including financial information, intellectual property, and personal records. A central concept highlighted is the “harvest now, decrypt later” threat model, in which adversaries collect encrypted data today with the intention of decrypting it in the future as quantum capabilities mature. This makes quantum risk a present-day problem, particularly for data requiring long-term confidentiality. EY stresses that organizations must adopt a proactive and structured approach to quantum readiness. A foundational step is to conduct a comprehensive cryptographic inventory, identify sensitive #data, and map existing #encryption methods. This enables organizations to assess which systems are most exposed and prioritize remediation efforts. Transitioning to post-quantum cryptography (PQC) is a complex, multi-year transformation that requires careful planning, integration into existing #technology roadmaps, and alignment with emerging standards. Organizations are encouraged to build crypto-agility, allowing them to adapt encryption methods as technologies and standards evolve. EY also highlights the importance of #governance, #compliance, and #workforce readiness. Quantum resilience requires enterprise-wide coordination, including policy development, regulatory alignment, continuous monitoring, and personnel training. EY frames quantum cybersecurity not just as a technical upgrade but as a strategic #transformation initiative. Organizations that act early can strengthen resilience, improve cyber maturity, and gain a competitive advantage, while those that delay risk long-term exposure to data breaches, regulatory challenges, and erosion of #digital #trust.

  • View profile for David Duong, CFA

    Institutional Crypto Markets | Former Global Head of Research, Coinbase | Board Director & Advisor focused on research-to-commercial impact, macro/on-chain integration

    10,933 followers

    *** The Quantum Threat (Part 2) *** Mitigating Quantum Risks A plausible roadmap is taking shape to counteract these vulnerabilities. The primary long-term strategy is to integrate post-quantum cryptography into the network – using new algorithms that are resistant to quantum attacks. The U.S. National Institute of Standards and Technology (NIST) has a short list of PQC protocols that include CRYSTALS-Dilithium, SPHINCS+, and FALCON. Note too that we have established the Coinbase Independent Advisory Board on Quantum Computing and Blockchain, a group of world-renowned experts convened to evaluate the implications of quantum computing for the blockchain ecosystem and provide clear, independent guidance to the broader community. Guidance from Chaincode Labs – a bitcoin research and development center – sketches two multi-year processes to mitigate the risk. First, if quantum computing experiences a sudden breakthrough, a short-term contingency path could be implemented within two years that quickly deploys protective measures to secure the network by prioritizing migration transactions exclusively. On the other hand, if quantum breakthroughs do not occur, a longer-term path could be used to standardize quantum-resistant signatures via a soft fork, though post‑quantum signatures are larger and slower to verify than today’s signatures, so wallets, nodes, and fee economics need time to adapt. This could take up to seven years to fully implement. Fortunately, the most advanced quantum machines today have fewer than 1,000 qubits, far short of what would be needed to compromise the cryptography that secures blockchains like Bitcoin. Promising technical proposals to address the quantum threat include: 🔹 BIP-360 (Pay-to-Quantum-Resistant-Hash) to keep public keys off-chain and pave the way for post quantum signatures 🔹 BIP-347 (re-enabling OP_CAT to support hash-based one-time signatures) 🔹 Hourglass (rate-limiting spends from vulnerable outputs to stabilize the transition) Best practices include avoiding address reuse, moving vulnerable UTXOs to unique destinations, and developing client-facing materials to institutionalize quantum-ready operations. This approach is supported by the current understanding that vulnerable scripts are not in production and that per-address fund limits mitigate concentration risk. Overall, we do not view quantum computing as an imminent threat because today’s machines are orders of magnitude too small to break Bitcoin’s cryptography. That said, we are glad that the open-source community remains vigilant about engineering post-quantum migration paths.

  • View profile for Mary Lacity

    David D. Glass Chair and Distinguished Professor of Information Systems

    8,130 followers

    IS YOUR ENTERPRISE READY FOR "Q-DAY"? "Q-day" (or Quantum Day) is the point in time when quantum computers become powerful enough to break the public-key encryption (like RSA or ECC) that currently secures global digital, financial, and government infrastructure. Our current best estimates is that Q-Day will happen by 2029! Huge thanks to Dr. Rob Campbell, FBBA. , IBM Global Quantum-Safe Executive and IBM Quantum Ambassador, for guest lecturing to our University of Arkansas ­- Sam M. Walton College of Business EMBA students. His insights into the "Quantum-Safe" transition provided a crucial roadmap for how leadership must navigate the next few years of cybersecurity. Here's what we learned: Adversaries are currently collecting encrypted data to store and decrypt once quantum computers are powerful enough to calculate private keys—a strategy known as "Harvest now, decrypt Later". Because enterprise cryptographic migrations can take 5 to 15+ years, many large organizations will still be in transition when quantum computers become capable of breaking current encryption. What enterprises can do NOW: Dr. Campbell emphasized that Post-Quantum Cryptography (PQC) is a leadership issue, not just a technical one. To preserve trust and resilience, leaders should authorize these "low-regret" actions immediately: - Inventory cryptographic dependencies: identify what you have before you plan what to change. - Prioritize high-value data: Focus on data with the longest confidentiality horizons, not just the most "critical" systems. - Invest in crypto-agility: Design systems for the permanent ability to swap algorithms without rebuilding the entire architecture. - Pilot PQC today in non-mission critical systems: PQC standards were finalized by NIST in 2024 and are ready for deployment on classical computers now. Enterprises can learn in these lower risk systems. - Communicate metrics to boards in non-technical jargon. Dr. Campbell noted, the question is whether we manage this change deliberately now or inherit it under pressure later. He stressed the importance of wide-spread education. To that end, Professor Daniel Conway will be offering the Walton College's first Quantum Computing class this fall! Adam Stoverink, Ph.D.; Shaila Miranda; Brian Fugate; Brent D. Williams; James Allen Regenor, Col USAF(ret) #QuantumSafe #PQC #CyberSecurity #Leadership #EMBA #DigitalTransformation #RiskManagement

Explore categories