Post-Quantum: What to do today (without panicking)

Security · 1 min

Articles by Luís Carvalho

The new NIST post-quantum standards are now defined. Learn about the steps organizations can start preparing today for a secure and gradual transition.

Post-Quantum: What to do today (without panicking)

TL;DR

Why preparation should start now

Quantum computing does not yet pose an immediate threat to most current systems. However, concern is growing about the Harvest Now, Decrypt Later model, where information encrypted today can be stored for future decryption when sufficient quantum capabilities exist. For this reason, organizations handling sensitive information with long-term confidentiality requirements should begin planning the transition.

A pragmatic roadmap

A structured approach can start with creating an inventory of cryptographic mechanisms used, followed by classifying systems according to risk and information criticality. Subsequently, [hybrid architectures](/en/solutions/cloud) combining classical and post-quantum algorithms can be adopted, preparing a gradual migration of the most critical infrastructures.

What to avoid

Among the most common mistakes are ignoring systems with very long lifecycles, such as industrial equipment or [IoT devices](/en/blog/5g-privado-e-wi-fi-7-quando-faz-sentido-cada-tecnologia), and treating post-quantum preparation exclusively as a technological project. In practice, it is a [risk management initiative](/en/blog/navegar-na-complexidade-gestao-de-riscos-na-supply-chain-digital) that should involve different areas of the organization.

Crypto-inventory in 3 weeks

We know where all your cryptography is — and what to risk.

Related

References

  1. NIST Post-Quantum Cryptography Project
  2. ENISA — Post-Quantum Cryptography: Current State and Quantum Mitigation
  3. NIST FIPS 203 (ML-KEM) Standard