惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Threatpost
P
Privacy International News Feed
T
Tenable Blog
Know Your Adversary
Know Your Adversary
C
Cisco Blogs
P
Proofpoint News Feed
Spread Privacy
Spread Privacy
G
GRAHAM CLULEY
爱范儿
爱范儿
U
Unit 42
K
Kaspersky official blog
C
Cybersecurity and Infrastructure Security Agency CISA
Jina AI
Jina AI
O
OpenAI News
L
LangChain Blog
PCI Perspectives
PCI Perspectives
P
Privacy & Cybersecurity Law Blog
Latest news
Latest news
Cisco Talos Blog
Cisco Talos Blog
F
Full Disclosure
L
Lohrmann on Cybersecurity
V
V2EX
L
LINUX DO - 热门话题
S
Security Affairs
量子位
Martin Fowler
Martin Fowler
云风的 BLOG
云风的 BLOG
Schneier on Security
Schneier on Security
月光博客
月光博客
MyScale Blog
MyScale Blog
C
CERT Recently Published Vulnerability Notes
AWS News Blog
AWS News Blog
博客园 - 叶小钗
Forbes - Security
Forbes - Security
W
WeLiveSecurity
T
Troy Hunt's Blog
J
Java Code Geeks
Hacker News - Newest:
Hacker News - Newest: "LLM"
Google DeepMind News
Google DeepMind News
Attack and Defense Labs
Attack and Defense Labs
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
Google Online Security Blog
Google Online Security Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
TaoSecurity Blog
TaoSecurity Blog
H
Help Net Security
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Fortinet All Blogs

A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog Cyber Attacks Leveraging AI Require Behavior-First Security Training, Not Simply Better Awareness | Fortinet Blog The AI Era Needs a New SASE. Here’s What That Actually Looks Like. | Fortinet Blog Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula | FortiGuard Labs Update on Fortinet Use of Frontier AI | CISO Collective Fortinet Supports INTERPOL Operation CyberProtect III Targeting Online Exploitation From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach | FortiGuard Labs Fortinet Launches Its Product Carbon Footprint Calculator FortiSASE Training Builds Skills for Secure Access Success | Fortinet Blog Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog Teaching Cybersecurity the Way It’s Actually Used | Fortinet Blog Introducing FortiSOC: One Platform, Total Control | Fortinet Blog Public-Private Cooperation Is Critical to AI-Driven Cyber Defense | Fortinet Advancing Threat-Informed Defense through Fortinet’s Collaboration with MITRE CTID | Fortinet Threat Actors Weaponize AI Hype to Deliver AsyncRAT | FortiGuard Labs Fortinet Achieves 1 Million People Trained in Cybersecurity Goal Ahead of Schedule | Fortinet Blog While OT Security Is Maturing, Risk Is Not Slowing Down | Fortinet Blog AI Policy Meets Operational Reality: White House AI Cybersecurity Order Calls for Public-Private Coordination | Fortinet Blog Executive Q&A: Strong Q1 Momentum Driven by Differentiated Innovation and Customer Demand | Fortinet Fortinet Earns AV-Comparatives Certification for EDR Detection Visibility | Fortinet Blog Cybercriminals Are Targeting the FIFA World Cup 2026 | FortiGuard Labs Fortinet Achieves AV-Comparatives Certification for Process Injection Protection | Fortinet Blog Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | FortiGuard Labs Battling AI-Based Threats with FortiNDR | Fortinet Blog Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data Defending Critical Infrastructure: Why OT Security Demands a Threat-Informed Approach | CISO Collective Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise | FortiGuard Labs Fortinet Expands Cybersecurity Investment in the United Arab Emirates | Fortinet Blog PureLogs: Delivery via PawsRunner Steganography | FortiGuard Labs The Future of Connectivity | Fortinet Blog Fortinet at the World Economic Forum: Frontier AI models, AI-Driven Threats, Deepfakes, and the Future of Cyber Defense | Fortinet Blog The Fortinet 2025 Sustainability Report | Fortinet Blog Supercharged Security: Security in the Time of Mythos | CISO Collective Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign | FortiGuard Labs AI Security Is an Architectural Decision | Fortinet Blog Fortinet Training Institute Wins Industry Accolades | Fortinet Blog Shadow AI: The Invisible Risk Growing Inside Your Organization | Fortinet Blog Leading by Example in Sustainability: Fortinet Expands Global EPD Certification | Fortinet Blog When Cybercrime Becomes an Industry | Fortinet Blog FortiOS 8.0: Redefining Secure Networking in the AI and Quantum Era | Fortinet Blog Securing the Physical World as It Comes Online | Fortinet Blog Why the 2026 AI Cybersecurity Summit Matters | Fortinet Blog DPRK-Related Campaigns with LNK and GitHub C2 | FortiGuard Labs AI Is Changing Application Threats Faster Than Teams Can Adapt | Fortinet Blog Announcing the Fortinet Training Institute’s 2026 ATC Award Winners | Fortinet Blog Disrupting Cybercrime Networks at Scale Requires Sustained Global Collaboration | Fortinet Blog
From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog
Wei Ling Neo · 2026-07-23 · via Fortinet All Blogs

The shift to Post-Quantum Cryptography (PQC) is no longer just an academic topic. It is now a key focus in areas such as security, architecture, procurement, and compliance.

The White House Executive Order “Securing the Nation Against Advanced Cryptographic Attacks” marks an important step in the federal government’s transition to PQC. It establishes December 31, 2030, as the deadline for federal high-value assets and high-impact systems to use PQC for key establishment, followed by December 31, 2031, deadline for their transition to PQC digital signatures.

The order also initiates a separate rulemaking process for federal contractors. It directs the Federal Acquisition Regulatory Council to publish a proposed rule amending the Federal Acquisition Regulation that would require covered federal contractors, by December 31, 2030, to comply with applicable NIST Federal Information Processing Standards, including standards that incorporate PQC algorithms.

While these requirements are primarily aimed at federal agencies and contractors, their effects are expected to extend across critical infrastructure, technology providers, regulated industries and the broader federal supply chain. For many organizations, 2026 and 2027 should therefore be treated as critical planning years for establishing ownership, inventorying cryptographic dependencies, assessing vendors, incorporating PQC requirements into procurement decisions, and developing migration roadmaps ahead of the principal 2030 and 2031 implementation deadlines.

This does not imply that organizations must replace every cryptographic algorithm immediately. The shift to PQC will take several years. The urgent focus should be on practical steps: increasing visibility, assessing risks, enhancing crypto-agility, and targeting the systems most vulnerable to “harvest now, decrypt later” (HNDL) threats.

Why Post-Quantum Readiness Matters Now

Industry experts warn that adversaries with quantum capabilities may eventually compromise widely used public-key cryptography, which underpins today’s digital communications. This poses an immediate risk, since encrypted data collected now could be decrypted in the future as quantum technology advances.

Organizations face the challenge of not just replacing cryptography but also ensuring operational readiness. Security and infrastructure teams must identify where cryptography is employed, determine which systems safeguard long-term sensitive data, and evaluate vendors, technologies, and architectures capable of supporting a future transition to quantum-safe standards.

Organizations should begin by asking three questions:

  1. Where are unsafe, weak, or legacy cryptographic algorithms used today?
  2. Which systems protect long-lived sensitive data or high-value communications?
  3. Which technologies, vendors, and architectures can support PQC migration?

Answering these questions requires a structured approach that integrates security visibility, risk reporting, and protection for the most critical encrypted pathways.

Where to Start

Discover unsafe cryptography now

Organizations cannot manage cryptographic risk without visibility. The first step is to identify where cryptography is used across their managed infrastructure, applications, devices, certificates, protocols, and encrypted communications.

This discovery process should identify unsafe or legacy algorithms, systems dependent on aging cryptographic components, and high-value services needing urgent remediation. It should also assist security teams in understanding where cryptographic decisions are embedded in configurations, vendor products, or application architectures.

FortiManager with FortiAI-Assist helps teams develop cryptographic inventory checklists, review configurations of managed Fortinet devices, and detect the usage of unsafe or outdated cryptographic algorithms. This offers security teams a practical foundation for understanding cryptographic vulnerabilities and developing an actionable plan for remediation.

FortiManager can then help organizations translate that plan into consistent action across a large FortiGate fleet. Rather than updating devices individually, teams can centrally standardize and deploy PQC-related configurations, policy changes, and broader configuration optimizations at scale. This centralized approach can also support complex initiatives such as SD-WAN migrations, helping organizations reduce configuration drift, improve operational consistency, and manage cryptographic modernization more efficiently.

Measure and report cryptographic risk

After organizations determine their cryptographic exposure, they need a way to assess risk and track improvements. Executives, security leaders, compliance teams, and infrastructure managers must have a common understanding of where risks are, which systems face the greatest exposure, and how remediation efforts develop over time.

This report should emphasize practical business and security concerns, such as unsafe algorithms, externally accessible systems, high-value applications, and the implementation of quantum-safe methods when applicable. Clear reporting can also assist organizations with procurement decisions, vendor discussions, and communication with the board.

FortiAnalyzer monitors unsafe algorithm usage in web and application traffic and offers visibility into the adoption of quantum-safe algorithms when applicable. This enables security teams to assess cryptographic risks, pinpoint high-priority applications, and demonstrate progress to leadership through measurable metrics.

Protect external boundaries first

Not all cryptographic risks carry the same urgency. Organizations should focus on encrypting traffic and systems that are most vulnerable to untrusted networks, such as site-to-site connections, partner communication channels, branch networks, remote access points, cloud integrations, and data center interconnections.

These external pathways are especially crucial since they frequently handle sensitive business, operational, or regulated information outside trusted environments. They can also be more exposed to interception and prolonged collection by advanced adversaries. A boundary-first approach helps organizations reduce HNDL exposure while broader cryptographic modernization continues.

The FortiGate IPsec hardware acceleration enables organizations to secure external boundaries and vital encrypted tunnels. This focus allows prioritizing protection for high-value communications, leaving trusted networks and minimizing long-term risks by reducing encrypted traffic that could be captured and stored now and later decrypted.

A Practical 90-Day PQC Readiness Plan

Transitioning to PQC does not have to begin with a large-scale transformation program. Organizations can initiate a targeted readiness sprint to establish ownership, increase visibility, and pinpoint immediate priorities.

Days 0–30: Assign PQC ownership and create a working group

Gather stakeholders from security, architecture, infrastructure, procurement, legal, compliance, and risk management teams. Since PQC readiness impacts technology choices, vendor relations, regulatory standing, and long-term data protection, responsibility should be shared across multiple teams.

Outcome: Clear ownership plus cross-functional accountability

Days 30–60: Build a cryptographic inventory

Identify the use of cryptography throughout infrastructure, applications, certificates, protocols, keys, VPNs, web services, and third-party dependencies. This inventory should separate systems that safeguard short-term data from those protecting long-term or high-value information.

Outcome: Improved visibility into algorithms, certificates, protocols, keys, and crypto dependencies

Days 60–90: Prioritize external boundaries and high-value systems

Begin your initial planning by focusing on systems most vulnerable to HNDL threats. This includes encrypted communications over untrusted networks, systems managing sensitive or regulated data, and essential services with long-term operational needs.

Outcome: An initial roadmap for remediation, vendor engagement, and PQC migration planning

Build for Crypto-Agility, Not a One-Time Migration

Quantum migration is not a one-time upgrade or a matter of deploying a single PQC algorithm and moving on. As standards mature, organizations may need to adopt different algorithms for different use cases, including key exchange, digital signatures, device identity, VPNs, TLS, and code signing.

Each option may also introduce different operational and performance considerations, such as larger keys, bigger handshakes, increased CPU or memory requirements, and added latency. The right approach may therefore vary by application, device, connection, and business requirement.

Organizations should build toward crypto-agility: the ability to update algorithms, certificates, policies, and supporting infrastructure over time as standards evolve, interoperability improves, and performance requirements become clearer. This flexibility will be essential to managing PQC as an ongoing operational discipline rather than a one-time technology replacement.

Leveraging the Fortinet Security Fabric

The Fortinet Security Fabric assists organizations in transitioning from policy awareness to operational execution through a practical readiness framework.

Discover → Measure → Protect → Modernize

  • Discover unsafe cryptography with FortiManager and FortiAI-Assist
  • Measure exposure and progress with FortiAnalyzer reporting
  • Protect high-value external communications with FortiGate IPsec capabilities
  • Modernize toward crypto-agile architectures that can adapt as PQC standards, products, and requirements continue to mature

This approach encourages organizations to view PQC not as a one-time replacement project but as a continuous operational practice. It involves understanding cryptography usage, assessing exposure, focusing on the riskiest areas, and developing adaptable architectures that can evolve with changing requirements.

Laying the Foundation for Post-Quantum Cyber Resilience

The transition to post-quantum security will probably span years. However, organizations should not wait until quantum threats create compliance or operational crises. The most prepared organizations for the upcoming cryptographic security challenges will be those that identify where cryptography is employed, assess their level of exposure, and focus their protection efforts on their most vital systems and data.

Fortinet assists organizations in taking the first practical steps toward PQC readiness by identifying vulnerable cryptography, reporting potential exposure, and safeguarding essential encrypted connections. Transitioning from awareness to action now enables organizations to develop the visibility, resilience, and crypto-flexibility necessary for the coming quantum era.

Watch our on demand webinar in which we explore how enterprises can address quantum risk and begin the shift to quantum‑resilient security.