惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
IT之家
IT之家
Google DeepMind News
Google DeepMind News
罗磊的独立博客
爱范儿
爱范儿
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
U
Unit 42
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
B
Blog
博客园 - 叶小钗
月光博客
月光博客
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt
As Q-Day looms, 90% of systems are unprepared for PQC | T...
Craig Galbraith · 2026-06-24 · via Search Security Resources and Information from TechTarget

Quantum computing could break encryption in the next several years, and research suggests that few organizations are ready. Experts say CISOs must act now.

Cybersecurity executives have a long way to go before they are ready for a quantum computing world, researchers warn -- and they're likely running out of time.

A new report from Forescout Research Vedere Labs found that 90% of systems remain unprepared for Q-Day -- when a quantum computer can first break today's public-key cryptography. Some experts anticipate that moment will arrive by 2030, leaving enterprises with only a few years left to prepare. And while many organizations are slowly upgrading their SSH and TLS protocols to become post-quantum cryptography (PQC)-compliant, significant gaps remain.

It's time to adjust the mindset. We still talk to people who ask, 'Does that really affect my industry? Do I need to care?'
Daniel dos Santos, vice president of research, Forescout

"This isn't theoretical anymore," said Daniel dos Santos, vice president of research at Forescout. "It's happening. Whether we get a quantum computer [capable of defeating public-key encryption] by 2030, at this point, is somewhat irrelevant. It's time to adjust the mindset. We still talk to people who ask, 'Does that really affect my industry? Do I need to care?'"

When Vedere Labs started tracking the PQC transition a year ago, dos Santos said he would have rated the level of urgency CISOs should feel as a 2 or 3, on a scale of 1 to 10. Today, he rates it as higher than 5.

"It's not as simple as clicking a button and everything is migrated," he said, noting how comparable transitions -- to TLS 1.3 and IPv6 protocols, for example -- are still ongoing due to their complexity. "We're talking about road maps here for two, three, four, even five years to actually become PQC-safe and compliant."

Quantum computing risks and challenges

One group CISOs should probably assume is preparing for Q-Day: malicious hackers.

"Governments and cybersecurity agencies have warned for years that sophisticated adversaries may be collecting encrypted data today in anticipation of future decryption," said Lina Dabit, executive director of the office of the CISO at cyber advisory firm Optiv Canada, and formerly an inspector in the Royal Canadian Mounted Police's cybercrime team.

The public sector faces particular risk, with significant, ongoing nation-state campaigns targeting critical infrastructure and governmental organizations, Dabit added. Potentially compounding PCQ transition challenges is the fact that critical infrastructure, such as power facilities and water treatment plants, has long struggled with timely patching. That's something governments and the people they serve can ill-afford to overlook as quantum threats evolve.

According to experts, quantum is also particularly challenging for medical facilities and financial institutions, since they manage extremely sensitive data and operate under some of the most stringent regulatory requirements. Dos Santos said medical devices and ATMs are among the most difficult to secure.

As the former CISO and CIO of Silicon Valley Bank, Nick Shevelyov is well aware of the pending PQC threat and its potential impact on the financial sector. But he argued that previous transitions have prepared the industry for the current challenge, citing the industry's migration off the SHA-1 algorithm and the rollout of EMV chips on credit cards.

"Banking has run this play before," said Shevelyov, now founder and CEO at cybersecurity advisory firm vCSO.ai. "The lesson is that a long transition is won or lost on governance, not on technology. Resilience is execution, held together by governance."

The second lesson, he added, is to evaluate and quantify quantum risk much as an underwriter at a bank would: assess the value of the assets at risk, identify annual loss expectancy, and define tolerable and intolerable levels of risk.

"A migration nobody has put a number on is a migration nobody will fund," Shevelyov said.

How CISOs can prepare for Q-Day

While high-risk industries are leading the way in PQC readiness, experts warn that any organization with private or sensitive data must start preparing for Q-Day.

"The first thing you need to do is have visibility into your network to make sure that you know what is or isn't PQC-safe already," dos Santos said.

Security leaders must then get on the same page with their suppliers, he added. A CISO should consider any current equipment purchase, whether it has a five-year depreciation period and whether it will still be active when PQC is mandated. "These conversations need to start happening right now," dos Santos said.

Beyond identifying areas of quantum risk and planning migration, Vedere Labs recommended that organizations begin employing secure remote access to protect every interaction between a user and an unmanaged asset.

Chris Butera, acting executive assistant director for cybersecurity at CISA, said the transition to PQC is a "complex, challenging multiyear process" that requires collaboration with government and industry partners.

"We urge organizations to begin preparing now by creating quantum-readiness roadmaps, conducting inventories, applying risk assessments and analysis, and engaging vendors," he said, adding that it is important to update systems using a risk-based approach to incorporate current and future quantum-resistant encryption and safeguards.

What's ahead

The G7 nations, comprising the U.S. and six of its closest allies, adopted a roadmap targeting 2030 as a cutoff date for migration, anticipating that's when a quantum computer will be able to break encryption -- or be close to it. And while no penalty structure is in place for noncompliance just yet, it's likely to become a requirement for doing business as a vendor in many countries.

In other words, the clock is ticking as a quantum computing reality draws near.

Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company that provides writing, editing, video hosting, podcasting, onstage presentation and consulting services to the technology industry.

Dig Deeper on Risk management