A Risk-Based Approach Can Turn an Overwhelming Migration Into a Workable Plan
As organizations navigate the complex landscape of cryptography and its impending evolution, many are finding it increasingly challenging to identify all the areas where cryptographic measures are deployed. This task becomes even more daunting when considering the critical need for rapid transitions to new standards without impacting existing applications and infrastructures. It’s a multifaceted problem that requires careful planning and foresight, especially as the deadlines for adopting post-quantum cryptography (PQC) draw nearer.
Francis Gorman, who leads the Security and Resilience Center of Excellence at Bank of Ireland, emphasized the importance of understanding existing environments as a foundational step in this migration process. He noted that organizations must locate not only certificates but also hard-coded credentials and various cryptographic libraries that may have been embedded throughout their applications, codebases, and network infrastructures. This encompasses a thorough examination of cryptographic frameworks, libraries, and dependencies that may not be readily visible.
The urgency surrounding this issue has escalated as the National Institute of Standards and Technology (NIST) finalized its first set of three PQC standards in 2024. NIST has urged organizations to begin implementing these standards immediately, with plans to phase out quantum-vulnerable algorithms by 2035. As high-risk systems are anticipated to transition well before this deadline, companies are being pressured to accelerate their own migration timelines. Concurrently, major technology companies like Google have set their sights on personal PQC migration by 2029. Google’s announcement underscores the accelerated pace of advancements in quantum computing and the pressing risk that attackers could be capturing encrypted data today for decryption tomorrow.
However, many organizations remain underprepared. Jitin Shabadu, an analyst at Forrester, articulated a prevalent sentiment, noting that companies have traditionally viewed encryption as a binary choice—a simple checklist item. The lack of proactive measures to prepare for the migration from older algorithms to newer, quantum-secure ones has left many organizations ill-equipped to adapt.
While the introduction of PQC is the immediate concern, experts stress the broader objective of fostering "crypto agility." Andrew Gault, CEO of ZeroTier, articulated this concept, emphasizing that organizations should strive to adopt practices that not only address current needs but also facilitate future adaptations as cryptographic standards evolve. The focus is not solely on implementing PQC but on ensuring that organizations can seamlessly adjust their cryptographic practices in the future.
The journey towards achieving this level of adaptability begins with a clear understanding of the organization’s existing cryptographic landscape—the first crucial step involves conducting a comprehensive inventory of all cryptographic assets within the environment. Gorman advises against attempting to assess this data all at once; instead, a phased approach is recommended. An uncoordinated scan could highlight numerous issues but leave organizations unclear about where to prioritize their efforts.
To effectively manage this intricate landscape, Gorman suggests beginning with identifying public certificates—a critical area of focus given their diminishing lifetimes. As organizations work to strategically renew these certificates, they should also establish effective processes for automation and orchestration. Building these foundational capabilities will serve them well in transitioning to quantum-resistant cryptographic measures in due time.
A comprehensive inventory must capture essential details beyond mere asset names; it should also identify protocols, cipher suites, and associated metadata, while linking these components to relevant business services and sensitive data. This holistic approach to inventory management is critical; as Shabadu emphasizes, organizations cannot protect or remediate what they cannot see.
Once an inventory is established, organizations should proceed to prioritize their cryptographic assets based on business exposure. Gorman encourages focusing first on systems that generate revenue or support vital services. Within these critical systems, organizations must assess which data needs to be safeguarded and for how long. This is especially crucial for sensitive information such as biometric records and identity documents, which are vulnerable to "harvest now, decrypt later" threats.
Having a clear prioritization list enables organizations to allocate resources efficiently, allowing them to systematically tackle the most pressing concerns first. Gault highlights that not all encrypted communications carry the same risk; for instance, a casual video call lacks the long-term ramifications associated with customer financial data or personally identifiable information.
Experts caution against rushing escape from legacy cryptographic measures without a structured approach. Gorman elucidates the importance of governance, robust processes, and automated systems to safeguard critical services during transitions. This approach creates a framework that facilitates rapid adaptations in response to evolving threat landscapes while ensuring compliance and integrity.
While internal measures are paramount, organizations must also assess the agility of their technology vendors. Evaluating vendors based on their responsiveness to changing standards and requirements will help ensure that organizations are equipped with the most current cryptographic solutions. Gault advises incorporating specific service level agreements (SLAs) regarding crypto agility into contracts to prevent reliance on vague product roadmaps.
As organizations grapple with the complexities of adopting PQC and ensuring lasting crypto agility, the pivotal step is establishing measurable outcomes for these initiatives. By setting tangible goals—like managing 80% of public certificates by a designated year—organizations can chart a clear path forward.
In the rapidly evolving landscape of cryptography, leaders are encouraged to take decisive action. Procrastination may leave organizations vulnerable to the advancing capabilities of quantum technology. With the unprecedented challenges posed by post-quantum threats on the horizon, it’s clear that the time for proactive measures is now.

