Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

5 Big Things To Know About Post-Quantum Security In 2026

CRN by CRN
October 9, 2026
Home News
Share on FacebookShare on Twitter


Here are five of the biggest takeaways about the expected threat from quantum computers to data security, as well as the main steps that solution providers and customers need to be taking now.

The already long-awaited arrival of quantum computing technology that is capable of defeating existing data encryption still doesn’t have a firm date, and it’s possible that it never will. But the need to prepare for the quantum paradigm shift—and the first steps that are most necessary to take—are already coming clearly into focus, solution provider and vendor executives told CRN.

As part of CRN’s Cybersecurity Week 2026, we’ve pulled together details on five of the biggest aspects of the expected threat from quantum computers to data security, as well as the main steps that solution providers and customers need to be taking now.

[Related: AI May Be Dominating Cybersecurity, But Quantum Preparations Can’t Wait: Analysis]

One of the most fundamental aspects of the transition to post-quantum security is that it promises to entail a lengthy process to successfully make the shift, meaning that there is some urgency involved here, executives said.

It’s not a challenge that can be addressed with a single purchase of a new tool or service, said Rob Gregory, CISO at Denver-based Optiv, No. 29 on CRN’s Solution Provider 500 for 2026.

“Dealing with post-quantum cryptography is a much more complicated solution that I think we’re all trying to work through and figure out the best way to navigate,” Gregory said.

What follows are five big things solution providers need to know about post-quantum security in 2026.

Prioritization Needs To Overcome Resistance

A key challenge is that the uncertainty surrounding the date when quantum computers will be capable of defeating existing encryption, or Q-Day, is making preparation more difficult to prioritize for some organizations, cybersecurity executives told CRN. And yet, the reality remains that businesses need to get started as soon as possible since it can take years to get ready, they said.

Some estimates say Q-Day could arrive within the next five years, but a sooner time frame, or further out than that, have both been aired as possibilities.

However, for security leaders with an array of more immediate demands, a threat without a set arrival date such as this will often struggle to receive top attention, executives said.

For many businesses, “there are so many priorities that it’s hard [for them] to think about the impact of something that might not happen for a couple of more years,” said Fred Rica, managing principal for the cyber practice at Chicago-based solution provider BDO USA.

Meanwhile, AI is making this competition for time and resources even more intense, according to Rica. Businesses may have barely caught their breath from the AI transition before quantum-related challenges will need to be confronted head-on, he said.

The best approach for most organizations is to approach quantum as another emerging threat requiring preparation, even as the debate continues over its potential time horizons, according to Kristin Lowery, field CISO at Leawood, Kan.-based Optiv, No. 29 on CRN’s Solution Provider 500 for 2026.

The bottom line is that with quantum’s potential to break existing cryptography and put data at risk, “this is another threat scenario to be prepared for,” Lowery said.

‘Harvest Now, Decrypt Later’

According to security experts, one thing is clear when it comes to the advancement of quantum technologies: Businesses may still be facing a future quantum-related risk even without the existence of quantum-enabled attacks today.

Under the scenario known as “harvest now, decrypt later,” it’s believed that adversaries are able to collect information that is currently encrypted and then retain that data until quantum computers become available that can compromise the cryptography.

Any data that remains relevant to a business—and that needs to remain confidential for many years into the future—is particularly at risk from the expected quantum threat, according to guidance from federal agencies.

Without a doubt, the possibility of attackers stockpiling encrypted information should factor into a company’s decisions about when and how to begin preparing, BDO’s Rica said.

That changes the calculus around the quantum threat, executives said, making it about more than simply asking when an advanced quantum computer might arrive. Instead, organizations should be asking how long particular data will retain its value.

In truth, businesses first need to understand the characteristics of the data they are protecting before they can make sound decisions about how to prioritize and protect it, Optiv’s Gregory said. That understanding can help organizations prioritize information based on sensitivity and its “data shelf life,” he said.

Post-Quantum Standards

The shift to post-quantum security already has an important basis for businesses to educate themselves on, experts said.

In August 2024, NIST finalized three principal post-quantum cryptography (PQC) standards. Having standardized algorithms, however, does not mean that an immediate transition is always possible, according to experts.

A major challenge has been around translating these advances in cryptography into the software implementations that businesses actually use, according to Timothy Hollebeek, vice president of industry standards at Lehi, Utah-based DigiCert. However, further progress is ahead in protocol standards and vendor support to expand the opportunities for organizations to begin experimenting, Hollebeek said.

The reality is, however, that an algorithm can be standardized while the products and integrations needed for deploying them are still developing, experts said.

The best approach is for businesses and solution providers to start gaining experience wherever the technology is sufficiently ready for doing so, Hollebeek said. That can include asking vendors for pre-production versions of software to evaluate in a test environment, for instance, as well as determining what might ultimately prevent a key application from making the post-quantum transition.

Another reason for organizations to build internal expertise is that different uses of cryptography will likely present different migration challenges, Hollebeek said.

Key Steps To Take Now

Before businesses can consider replacement of quantum-vulnerable cryptography, they also need to understand where it is currently being used, experts said.

That involves not just assembling a list of encrypted databases, they said—public key infrastructure (PKI) certificates, keys and application dependencies will all need to be considered.

Without a doubt, weaknesses in basic cryptographic management can undermine efforts within an organization at working toward post-quantum readiness, said Gary Brickhouse, CISO at Herndon, Va.-based GuidePoint Security, No. 32 on CRN’s Solution Provider 500 for 2026.

For example, “if you don’t already have an inventory of your PKI infrastructure and the keys that you have—if you don’t have a good key management program in place—how are you going to rotate your keys anyway?” Brickhouse said.

Ultimately, when it comes to quantum readiness efforts, “if we don’t have those fundamentals in place, it’s going to be infinitely harder to do any sort of more mature program approach,” he said.

At the same time, Hollebeek said he sees a risk that organizations may treat the achievement of an exhaustive inventory and an ideal migration plan as the prerequisites for taking action of any kind. At this point, however, getting started ASAP should be the main priority, he said.

“You’re not going to transition everything,” Hollebeek said. “Figure out the first, most critical thing you have to transition and start your transition journey.”

Meanwhile, a core part of the preparations should involve providing in-house cryptography specialists with greater attention and support as soon as possible, according to Optiv’s Lowery.

“In every environment I’ve been in, there’s always been a couple of talented people that are really good at cryptography,” she said. “Those individuals need to be elevated right now.”

Broad Solution Provider Opportunity

The complexity of post-quantum migration creates massive opportunities for solution providers, executives and experts told CRN. Major areas of focus can include initial assessments, vendor evaluation and implementation, as well as ongoing management, they said.

Customers need substantial assistance with creating inventories and understanding their cryptographic assets, while prioritizing systems and coordinating changes across key platforms are going to be additional ongoing needs, experts said.

Fortunately, for a growing number of businesses, the conversation is already shifting toward action, according to solution provider executives.

“It’s really gone from whether we should prepare to ‘we need to start planning for long-term cryptographic resilience,’” said Chris Konrad, vice president of global cyber at St. Louis-based World Wide Technology, No. 10 on CRN’s Solution Provider 500 for 2026.

WWT, for instance, has established a dedicated PQC-focused team that is bringing together specialists to help customers with addressing the transition, Konrad said.

For McLean, Va.-based solution provider Merlin Cyber, meanwhile, federal migration requirements are already prompting customers to seek out help with identifying high-value assets and creating inventories of their cryptography, according to Miguel Sian, CTO and senior vice president of technology at Merlin Cyber.

PQC has become a major reason for federal agencies “to reach out to Merlin and say, ‘Hey, we need help with meeting some of these deadlines that are being imposed on us,’” Sian said.

The bottom line is that it’s the role of solution and service providers to anticipate emerging threats and help customers prepare, and the quantum scenario is no different, according to Chesley Choudhury, chairman and founder of TanChes Global Management, a Houston-based MSP.

“Our No. 1 job as an MSP, before anything else, is our client security,” Choudhury said. “So if we are not ahead of the curve in studying and analyzing the trends, then we are definitely doing our clients a disservice.”



Source link

Tags: AI AgentsAI ApplicationsAI InfrastructureApplication and Platform SecurityCloud SecurityCyberattacksCybersecurityData breachesData ProtectionEndpoint SecurityManaged SecurityManaged Service Providersnetwork securitySecurity operations
CRN

CRN

Next Post

KONST Raises $30M Series B funding Led by ADATA Technology to Scale Up AI Data Center Buildout in Asia and Advance Its Token Factory Strategy

Recommended.

Top 2026 Application Lifecycle & Release Management Platforms Named Champions in Info-Tech Research Group Report

September 10, 2026
Stocks making the biggest moves after hours: Apple, Amazon, Coinbase, Netflix and more

Stocks making the biggest moves after hours: Apple, Amazon, Coinbase, Netflix and more

October 30, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio