{"id":9361,"date":"2026-09-09T09:00:00","date_gmt":"2026-09-09T09:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9361"},"modified":"2026-09-09T09:00:00","modified_gmt":"2026-09-09T09:00:00","slug":"post-quantum-cryptography-adoption-and-the-national-security-implications","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9361","title":{"rendered":"Post-quantum cryptography adoption and the national security implications"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">Quantum computers have advanced significantly in capability and compute power in the last several years and are turning theoretical vulnerabilities in modern cryptography into real-world threats.\u00a0 The shift to post-quantum cryptography (PQC) needs to start now, but several challenges need to be overcome.\u00a0 One is: How do you convince people of the urgency that this not-quite-ready new technology represents?\u00a0 I will argue that this technology will favor the nation-state actors over cyber criminals and ransomware gangs and therefore make it harder to convince those that aren\u2019t already a target of nation-states of the threat.\u00a0 This dynamic will create gaps that governments can exploit either covertly, as part of an open conflict or through state-sponsored economic espionage.<\/p>\n<h2 class=\"wp-block-heading\">The current state of quantum compute<\/h2>\n<p class=\"wp-block-paragraph\">Because quantum computers have computers in the name, many people think these systems will replace their existing traditional computers.\u00a0 The better way of thinking about them is as specialized devices that augment existing computers like graphics cards do today.\u00a0 Quantum computers are being designed to run specific algorithms that are specialized in solving specific problems, such as breaking cryptographic systems.<\/p>\n<p class=\"wp-block-paragraph\">Quantum systems, like <a href=\"https:\/\/quantumai.google\/quantumcomputer\">Google\u2019s Quantum AI<\/a>, are also physically big, with supporting infrastructure usually taking up an entire room.\u00a0 The significant capital and know-how required to build these systems will likely make them off-limits to all but a handful of corporations and governments for the foreseeable future.\u00a0 Unless there is a major breakthrough in quantum computers with size and cost, there will likely remain a significant barrier to entry and <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cloud-based_quantum_computing\">gatekeepers to public access<\/a> akin to the early days of computers with mainframes and terminals.\u00a0 We saw this play out briefly when Anthropic released Mythos and the <a href=\"https:\/\/www.anthropic.com\/news\/fable-mythos-access\">US Government immediately put restrictions<\/a> on it due to national security concerns.\u00a0 This is in contrast to the democratizing nature that AI has had with cyberattacks, regardless of the model.<\/p>\n<p class=\"wp-block-paragraph\">There is still a significant debate as to when quantum computers will be able to break modern asymmetric cryptographic systems like RSA or Elliptic Curve Cryptography (ECC).\u00a0 <a href=\"https:\/\/www.rsa.com\/resources\/blog\/zero-trust\/setting-the-record-straight-on-quantum-computing-and-rsa-encryption\/\">RSA, for example, claims<\/a> we are still a ways off before this is a realistic threat, if ever.\u00a0 Google, on the other hand, says it may be as soon as 2029.\u00a0 Both of these companies have skin in the game, but even independent cryptographic experts like Filippo Valsorda are sounding the alarm.\u00a0 Valsorda argues convincingly, \u201cThe bet is not \u2018are you 100% sure a CRQC [cryptographically relevant quantum computer] will exist in 2030?\u2019, the bet is \u2018are you 100% sure a CRQC will NOT exist in 2030?\u2019 I simply don\u2019t see how a non-expert can look at what the experts are saying, and decide \u2018I know better, there is in fact &lt; 1% chance.\u2019<\/p>\n<h2 class=\"wp-block-heading\">Assigning a risk value<\/h2>\n<p class=\"wp-block-paragraph\">How do you assign risk to a future threat like quantum?\u00a0 Impact and likelihood are the two classical inputs to risk.\u00a0 The impact that quantum computers pose to existing asymmetric encryption is very high and can potentially result in uncovering significant amounts of encrypted data in motion or at rest.\u00a0 The impact is obvious for organizations such as banks, governments, military and anyone that deals with confidential information.\u00a0 This threat also opens up the door to attackers <a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/harvest-now-decrypt-later-hndl\">harvesting now and decrypting later<\/a> when the quantum matures.\u00a0 This means hackers with existing access to a network or encrypted communications link can collect encrypted information with the intent of decrypting it later.\u00a0 This may be trivial if the information is time-sensitive and long since expired, but the damage could be severe in cases such as encrypted intellectual property.<\/p>\n<p class=\"wp-block-paragraph\">So, the impact is pretty evident, but it\u2019s the likelihood where things get complicated.\u00a0 First, there is the likelihood that this won\u2019t happen at all, as well as that it won\u2019t happen on a time scale that matters for current investment strategies.\u00a0 The remaining likelihood points to an increasingly near-term threat.\u00a0 How do the players that will have access to the technology play into this?\u00a0 As mentioned, quantum will likely remain confined to governments and large companies, with the remaining public likely vetted and monitored.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">So, if your organization isn\u2019t currently targeted by a nation-state actor or groups that have access to future quantum computers, is there an impact to them?\u00a0 If most of the time the only compromise is to confidentiality, but relatively little monetary impact, is the risk acceptable to most organizations?\u00a0 With the exception of North Korea, few nation-states cause financial damage as a result of their activities (beyond possible regulatory\/compliance fines).\u00a0 Much of their activities are driven by national security concerns like intelligence collection and posturing for future cyber support to a real-world conflict, not financial.<\/p>\n<p class=\"wp-block-paragraph\">Organizations that are already targets of nation-state actors, such as governments, tech companies, large financial companies and nuclear facilities, will be the first to adopt PQC technology, while thinner-margin companies will likely push it to the back burner due to lack of perceived risk and limited resources.\u00a0<\/p>\n<h2 class=\"wp-block-heading\">National security risk<\/h2>\n<p class=\"wp-block-paragraph\">These conditions will likely leave large numbers of organizations vital to national security unable or unwilling to upgrade and therefore open themselves up to exploitation by nation-state actors.\u00a0 The gap between individual organizations\u2019 desire to pay and the cost of collective defense needs to be covered somehow.\u00a0 This will also amplify the already existing cybersecurity issues with critical infrastructure, creating even more vulnerable networks.<\/p>\n<p class=\"wp-block-paragraph\">Sectors like municipal utilities, small hospitals, critical manufacturing and local government emergency services will likely struggle to upgrade systems to PQC.\u00a0 This vulnerability will further enable nation-state actors to leverage existing access to critical infrastructure, as seen in <a href=\"https:\/\/media.defense.gov\/2025\/Aug\/22\/2003786665\/-1\/-1\/0\/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.PDF\">attacks like Salt Typhoon<\/a>, to gain access to new networks and data.<\/p>\n<p class=\"wp-block-paragraph\">This could enable collecting sensitive information such as classified materials or corporate intellectual property.\u00a0 It can also enable access to networks to position for effects during a time of conflict.\u00a0 Things like disrupting communications, destroying data or gaining access to control systems for physical equipment.<\/p>\n<p class=\"wp-block-paragraph\">Nation-state actors could also enable state-aligned hacking groups to conduct operations that they themselves don\u2019t want attribution towards.\u00a0 All of this happens now, but access to quantum computers will blow the doors off previously inaccessible systems and sensitive data.<\/p>\n<h2 class=\"wp-block-heading\">Possible solutions<\/h2>\n<p class=\"wp-block-paragraph\">Solutions are already widely available, with NIST publishing PQS standards (FIPS 203-205) and multiple commercial companies offering PQC solutions.\u00a0 But adoption will be slow due to the large amounts of critical software and hardware that will have to be upgraded.\u00a0 Five things can help with the transition.\u00a0 The new solutions will also need to be agile in case vulnerabilities in the new systems arise, known as <a href=\"https:\/\/csrc.nist.gov\/projects\/crypto-agility\">crypto agility<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">First, government mandates can require adoption.\u00a0 The <a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2026\/06\/securing-the-nation-against-advanced-cryptographic-attacks\/\">recent Executive Order EO 14412<\/a> establishes a more rapid adoption of PQC systems within the Federal government.\u00a0 Governments should further look to incentivize critical infrastructure companies to adopt PQC systems by either further mandates or potentially tax incentives.\u00a0 Further regulations and compliance standards can force PQC adoption; for example, PCI DSS or ISO 27001 could explicitly require PQC.<\/p>\n<p class=\"wp-block-paragraph\">A second method for wider adoption is having cloud service providers, network stacks (TLS) and software libraries switch to PQC algorithms by default.\u00a0 In many cases, this will transparently migrate many users to the new standards.\u00a0 Organizations can potentially use the quantum threat to push for greater cloud integration where PQC systems are already offered (i.e. <a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/announcing-quantum-safe-key-encapsulation-mechanisms-in-cloud-kms\">Google<\/a>, <a href=\"https:\/\/aws.amazon.com\/security\/post-quantum-cryptography\/\">AWS<\/a>).<\/p>\n<p class=\"wp-block-paragraph\">If costs and complexity are too great, a third option would be to prioritize the most critical network elements and storage systems.\u00a0 Then upgrade these systems to either newer PQC systems or if even that is too difficult, update the existing keys to larger keys, for example, RSA 2048 to RSA 4096 or AES-128 to AES-256 to buy some more time.<\/p>\n<p class=\"wp-block-paragraph\">Fourth, awareness of the need for PQC among cybersecurity professionals narrowly and business executives broadly.\u00a0 Corporate boards and senior executives will be the ones making the call on whether to upgrade vulnerable systems and need to understand the risks of this technology.<\/p>\n<p class=\"wp-block-paragraph\">Lastly, in line with the fourth, universities and colleges should expand class offerings to include quantum computing as well as specific cybersecurity solutions in order to build a workforce capable of both harvesting the power of quantum as well as guarding against the ramifications of this new technology.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Quantum computers have advanced significantly in capability and compute power in the last several years and are turning theoretical vulnerabilities in modern cryptography into real-world threats.\u00a0 The shift to post-quantum cryptography (PQC) needs to start now, but several challenges need to be overcome.\u00a0 One is: How do you convince people of the urgency that this [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9362,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9361","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9361"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9361"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9361\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9362"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}