← Back to list

Preparing for the Post-Quantum Era: What Companies Must Do Now

Thales PQC Palooza held during RSA Conference 2026 brought together a raft of distinguished guests who collaborate within the Thales PQC…

Steve Prentice in Thales Cybersecurity Products · 2026-05-11 12:41 · 1 claps · 3.4 min read
#quantum-computing #cybersecurity #rsac2026 #pqcpalooza #cryptography
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 🔒 · Cybersecurity ⚛️ · Physics 📊 · Economic Policy

Preparing for the Post-Quantum Era: What Companies Must Do Now

Thales PQC Palooza held during RSA Conference 2026 brought together a raft of distinguished guests who collaborate within the Thales PQC ecosystem to share their approaches to living in the post-quantum era.

For decades, modern cybersecurity has relied on cryptographic algorithms that are effectively unbreakable with today’s computing power. But quantum computing changes that equation. Once sufficiently advanced quantum machines become available, they will be able to break widely used public key algorithms such as RSA and ECC in a matter of hours or minutes. This isn’t a distant, theoretical concern. Nation-states and sophisticated adversaries are already harvesting encrypted data today with the intention of decrypting it later, a strategy known as “harvest now, decrypt later.”

This is why PQC has become one of the most urgent technology transitions of the next decade, and a key topic of discussion at RSAC. The U.S. National Institute of Standards and Technology (NIST) has already selected the first PQC algorithms for standardization, and global regulators are beginning to push organizations toward readiness. But the real challenge isn’t the algorithms themselves, but the migration. To be prepared for this, companies need a clear, structured approach to understanding their cryptographic posture and planning a safe transition. That begins with five foundational steps.

1. Build a Cryptographic Inventory

You can’t protect what you can’t see. Most organizations have cryptography embedded in hundreds of places, including applications, APIs, databases, network devices, cloud workloads, certificates, IoT devices, and vendor products. In many cases, cryptography is buried deep in legacy code or inherited systems that no one has touched in years. Building a cryptographic inventory is the process of cataloguing:

  • What cryptographic algorithms are in use
  • Where they are used
  • How they are implemented
  • Which systems depend on them
  • Who owns those systems

This inventory becomes the foundation for every PQC decision that follows, and without it, migration just becomes guesswork.

2. Conduct Cryptographic Discovery at Scale

Manual inventorying is impossible for large enterprises. Automated cryptographic discovery tools, which are sometimes built into modern security platforms, can scan codebases, binaries, network traffic, certificates, and configuration files to identify cryptographic usage patterns. Effective discovery should reveal:

  • Hard-coded keys
  • Deprecated algorithms
  • Weak key lengths
  • Non-standard or homegrown cryptography
  • Shadow IT systems using outdated libraries

Discovery must remain an ongoing capability, since new code is deployed every day. Organizations that treat it as such will be far better positioned for PQC migration.

3. Establish Cryptographic Posture Management

Cryptographic posture management (CPM) is emerging as a new discipline, one similar to cloud posture management or identity governance. It provides a centralized, real-time view of an organization’s cryptographic health. A strong CPM program includes:

  • Policies defining approved algorithms and key lengths
  • Automated monitoring for violations
  • Lifecycle management for certificates and keys
  • Reporting for compliance and audit teams
  • Integration with DevOps pipelines to prevent insecure cryptography from being deployed

In the post-quantum era, CPM will be essential. It ensures that once PQC algorithms are introduced, they remain consistently and correctly implemented across the organization.

4. Identify Where Vulnerable Cryptography Lives

Not all cryptography is equally urgent to replace. Some systems are highrisk because they protect longlived data like financial records, personal information, intellectual property, or governmentregulated data. Other systems may be lower risk because the data they protect has a short useful lifespan. Organizations should classify cryptographic assets based on:

  • Sensitivity of the data
  • Longevity of the data
  • Exposure to external networks
  • Regulatory requirements
  • Business impact if compromised

This prioritization helps companies focus their PQC efforts where they matter most.

5. Plan and Execute a PQC Migration Strategy

PQC migration is not a simple “drop-in replacement.” New algorithms have different performance characteristics, larger key sizes, and new operational requirements. Migration will require:

The organizations that succeed will treat PQC migration as a multi-year transformation program, not a technical patch.

The bottom-line message from the guests at PQC Palooza was that the time to act is now, that the window of opportunity is shrinking, and as one guest put it, it is “Y2K without a date.” Quantum-capable adversaries may seem years away, but with techniques like “harvest now, decrypt later” already known, the threat is here. Regulators are watching, customers are asking questions and boards are beginning to demand answers. Companies that start building their cryptographic inventory, discovery capabilities, and posture management programs now will be ready for a smooth PQC transition, but those that wait will face a rushed, expensive, and potentially risky scramble.

To learn more about what we learned at PQC Palooza, check out the special edition of the Thales Security Sessions podcast ‘Inside the Race to a Quantum Safe Future: PQC Palooza Live 2026 at RSAC’ or search Thales Security Sessions with your podcast provider of choice.


메타데이터
post_id
2bdb5aab4fcc
slug
preparing-for-the-post-quantum-era-what-companies-must-do-now-2bdb5aab4fcc
url
https://medium.com/thales-cybersecurity-products/preparing-for-the-post-quantum-era-what-companies-must-do-now-2bdb5aab4fcc
canonical_url
https://medium.com/thales-cybersecurity-products/preparing-for-the-post-quantum-era-what-companies-must-do-now-2bdb5aab4fcc
author_url
https://medium.com/@steve_prentice
status
ok
fetched_at
2026-06-15 20:49:13