A federal IT exec makes the case, post quantum cryptography isn't optional homework for later

Started by Amber Tiger, Jul 17, 2026, 11:15 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: A federal IT exec makes the case, post quantum cryptography isn't optional homework for later   Views(Read 148 times)

Amber Tiger

In a commentary for Federal News Network, Electrosoft Services COO Jamie Holcombe argues that by the time an organization recognizes quantum computing as an immediate threat, it's usually already behind. His core point, today's public key cryptographic systems, RSA and elliptic curve cryptography, protect financial transactions, intellectual property, classified communications and supply chains precisely because they rely on math problems classical computers can't efficiently solve, and sufficiently powerful quantum systems running algorithms like Shor's would eventually defeat exactly those protections

Holcombe's real emphasis, though, isn't on the distant hardware milestone itself, it's on the fact that adversaries are already collecting encrypted data today specifically to decrypt it later once quantum capability matures. That reframes the entire timeline, information stolen right now may still hold real strategic value decades from now, meaning organizations can't afford to wait for an actual Q-Day before acting, since by then the data in question may already be thoroughly compromised

His broader argument is that post quantum cryptography shouldn't be treated as a standalone project bolted onto existing systems later, it needs to be built directly into modernization efforts already underway, cloud adoption, zero trust architecture, and AI integration all depend on the same underlying cryptographic trust that quantum computing eventually threatens. AI systems are only as trustworthy as the data feeding them, and zero trust architecture depends entirely on strong, resilient cryptography to verify users, devices and behavior continuously, meaning PQC functions as a foundational layer sitting underneath both of those other initiatives rather than a competing priority

The piece pushes back specifically against framing this purely around a single dramatic future event. The bigger risk, Holcombe argues, isn't the sudden arrival of quantum capability itself, it's institutional inflexibility, organizations weighed down by technical debt and rigid legacy architecture that simply can't adapt fast enough once cryptographic standards actually change. His prescription is cryptographic agility, designing systems now so cryptographic components can be swapped or upgraded without tearing apart entire operational environments, arguing that disciplined, incremental modernization beats both panic and complacency, and that the organizations who adapt fastest, not necessarily the ones with the biggest budgets, will be the ones that come out ahead

PlanckLimit81

Framing institutional inflexibility as the real danger rather than the sudden arrival of quantum hardware itself is an useful reframe, most coverage fixates purely on the hardware timeline and misses this angle entirely

Router53

The point about AI only being as trustworthy as the data feeding it, and that data's integrity depending on cryptography that quantum computing threatens, ties these two hot topics together in a way I hadn't seen articulated this clearly before

ArcMage14

Cryptographic agility as the actual practical goal rather than a fixed migration deadline seems like the more realistic target for organizations that can't overhaul everything overnight anyway

KeyboardWarrior

Harvest now decrypt later showing up again here from a completely different angle, government modernization strategy this time rather than pure cybersecurity, shows how central that specific argument has become across every domain touching this issue
Press F to pay respects

ElPresidente

Coming from someone whose actual job is government IT modernization gives this practical weight beyond just theoretical concern, this is the perspective of someone who has to actually execute this transition

AustinTheory18

Disciplined incremental progress beating both panic and complacency is solid, grounded advice, avoids both the doom framing and the it's fine, we have time complacency that dominate most public discussion of this topic
Here more than I should be

NatureBoyOwen16

Cryptographic agility feels like the only sane framing here. Trying to pick a single migration date assumes too much certainty about timelines.

Instead, building systems that can swap algorithms without massive rewrites is a much more durable approach.

Think of it like abstraction layers in software.

You do not hardcode dependencies if you expect change.

Crypto should follow the same principle.
The truth is usually more complicated than the headline

Joanne94

The "harvest now, decrypt later" threat is what makes this urgent.

Even if quantum machines capable of breaking current encryption are years away, data stolen today can be stored indefinitely.

Sensitive data with long lifetimes becomes vulnerable.

That changes the risk calculation.

It is not just about future systems, it is about current exposure.

Runtime Arrow

One challenge is inventory.

Many organizations do not even have a clear map of where cryptography is used across their systems.

Legacy apps, embedded devices, third-party integrations.

You cannot migrate what you cannot see.

So discovery becomes step one.

Eastern Aaron

There is a tendency to treat this as a purely technical problem, but it is also organizational.

Policies, procurement, vendor requirements all need to align.

If one part of the stack upgrades and another does not, you still have weak links.

Coordination is the hard part.

HeartbreakKidOscar97

Performance trade-offs are another factor.

Some post-quantum algorithms have larger key sizes and slower operations.

That impacts bandwidth and latency.

For high-throughput systems, this is not trivial.

Engineering teams will need to balance security with efficiency :-\

Penguin79

There is also a talent gap here.

Cryptography expertise is already scarce.

Scaling up migrations across industries will stretch that even further.

Training and tooling will need to catch up.
Trained so hard the GPU asked for a break

Quiet Glacier

The comparison to Y2K comes up a lot, but this feels different.

Y2K had a fixed deadline and a known issue.

Post-quantum migration is more gradual and uncertain.

That makes it easier to delay, which is part of the risk.

NeuralTrace

Vendor ecosystems will play a big role.

If major cloud providers and platforms adopt post-quantum standards early, others will follow.

Standardization helps reduce friction.

Without it, adoption becomes fragmented.

QuoteMiner36

Some organizations might overcorrect and rush into immature solutions.

Not all post-quantum algorithms are equally vetted yet.

Choosing poorly could introduce new vulnerabilities.

So caution is still needed.

SystemWarden64

The "optional homework" framing is spot on.

It is easy to push this into the future because nothing is visibly broken today.

But by the time it becomes urgent, the window for smooth transition may be gone.

Preparation buys flexibility.

Leo68

Hybrid approaches seem like a practical bridge.

Using both classical and post-quantum algorithms together provides defense in depth.

Even if one fails, the other holds.

It is not elegant, but it is effective during transition.

EdgeNodeCoder

Embedded systems are going to be a headache.

Devices with long lifecycles, limited update mechanisms, and constrained hardware.

Think industrial control systems or medical devices.

Those cannot be patched easily.

Planning ahead matters a lot there.
Be excellent to each other

BinaryMonk95

Cloud-first architectures might have an advantage here.

Centralized control makes it easier to roll out updates.

Compared to fragmented on-prem systems, agility is higher.

That could influence migration speed.

Related Topics (4)

Save money on everyday spending Free cashback on thousands of retailers
View offer