From awareness to action in the post-quantum era

Enterprises can reduce future risk by building crypto agility into today’s security architecture

complex technological infrastructure in a three-dimensional rendering
(Image credit: Getty Images)

Quantum risk becomes a business issue

For many IT and security leaders, post-quantum cryptography (PQC) has moved from research topic to board-level planning issue. The reason is simple. The cryptography that protects payments, identities, software, networks and sensitive records was designed for a world of classical computing. Quantum computing changes that risk model, and requires a new approach with tools and technologies to match.

That does not mean organizations should panic. It does mean they should make a disciplined plan. Chief information security officers, cryptography teams, PKI owners, security architects and risk leaders all have roles to play. So do DevSecOps, infrastructure, cloud and application teams whose systems depend on cryptographic services every day.

Thales is helping enterprises turn PQC awareness into a practical readiness program. Its guidance centers on crypto agility, cryptographic discovery, key management and the hardware roots of trust that support secure operations at scale. The launch of Luna 8, its next-generation hardware security module, extends that approach for an era shaped by AI, regulation and quantum-resistant algorithms.

Why PQC readiness cannot wait

Today’s widely used public-key algorithms, including RSA, elliptic curve cryptography and Diffie-Hellman, remain effective against classical attacks. The concern is that future quantum computers have the ability to solve the mathematical problems behind those algorithms far faster. That would put encrypted data, digital signatures and trust chains at risk.

The most urgent issue is harvest now, decrypt later. Attackers can collect encrypted traffic or data today, then wait for stronger quantum capabilities. Any information with long-term value is at risk and should become a top priority item to protect. Examples of long-term data include health records, defense information, financial data, intellectual property and government communications.

Thales reported that harvest now, decrypt later was the top quantum-related risk in its 2026 Data Threat Report. The company also stated that 59% of organizations are prototyping and evaluating PQC algorithms. That finding suggests many security programs have moved past awareness. The next step is organized execution.

Start with a cryptographic inventory

PQC migration starts with a basic question that is often hard to answer: Where is cryptography used? Enterprises need to identify algorithms, keys, certificates, protocols, libraries, hardware modules and applications. They also need to understand data sensitivity, data life span and operational dependencies.

A cryptographic inventory should not be a one-time spreadsheet. Modern environments change too quickly. Cloud services, containers, APIs, certificates and DevOps pipelines create constant movement. Automated discovery and continuous assessment help teams keep plans current and reduce surprises during migration.

This inventory also creates a shared language for stakeholders. CISOs can see risk exposure. Cryptography experts can identify algorithm dependencies. Application teams can plan testing. Risk and compliance leaders can map migration work to policy, audit and regulatory expectations.

Build crypto agility before the deadline hits

Crypto agility is the ability to change algorithms, keys, protocols and implementation choices without major disruption. To enable PQC, it is a strategic requirement. Standards, validation requirements and best practices will continue to evolve. Organizations that can adapt quickly will be better prepared for both quantum risk and ordinary cryptographic change.

Thales describes PQC as a migration from quantum-vulnerable toward algorithms and protocols designed to resist quantum computer attacks. Your migration should examine the quantum-safe NIST-standardized algorithms such as ML-KEM, ML-DSA and SLH-DSA and determine which one is best for your use case. In practice, many organizations will run hybrid environments while they test, validate and deploy new protections.

That hybrid period is why architecture matters. Security leaders should avoid hard-coded cryptography where possible. They should favor platforms that can support multiple algorithms, policy-based controls and centralized key management. This reduces friction when new requirements arrive.

The role of HSMs in a quantum-safe strategy

Hardware security modules (HSMs) remain foundational for organizations that need strong protection for cryptographic keys. HSMs help secure key generation, storage, use and lifecycle management in tamper-resistant hardware. They are especially important for PKI, code signing, payment systems, digital identity, cloud services and high-value transactions.

That foundation becomes more important as enterprises prepare for PQC. Migration will require testing new algorithms, protecting more key types and supporting higher cryptographic workloads. AI adoption adds another pressure point, because data pipelines, model access and automated services expand the need for trusted security controls.

Luna 8 is the foundation of digital trust for crypto agility and PQC migration, designed to help organizations make this transition and to thrive in a PQC world. The company says its HSM provides future-ready, quantum-resistant security for critical data and applications. It is powered by a Thales-designed cryptographic processor engineered for high performance and flexibility as requirements evolve, with quantum-safe security from the ground up, native PQC support for high-throughput workloads and cryptographic agility, built-in protection against side-channel attacks, and strong security isolation.

Luna 8 also supports multi-tenant security and scalable use across business needs. For security teams, that means a platform can support multiple environments while maintaining strong isolation and operational control. For IT leaders, it supports investment protection as cryptographic standards evolve.

Make PQC readiness an executive mandate

For executive readers, the business case is not only about replacing one algorithm with another. PQC readiness is a governance, architecture and resilience program. It requires a clear owner, measurable milestones and a funding model that recognizes cryptography as shared infrastructure. Boards and leadership teams should ask whether the organization knows which systems depend on quantum-vulnerable algorithms, which data must remain confidential for years or decades, and which vendors or managed services may create hidden migration dependencies.

That work should also include a practical risk-ranking model. Systems that protect long-lived sensitive data, issue certificates, sign software, support identity services or secure high-value transactions should be evaluated first. Leaders can then sequence migration by exposure, business criticality and implementation complexity. In many cases, the first visible benefit will be better cryptographic visibility and lifecycle control, even before a full PQC cutover occurs.

Plan for hybrid security operations

Technical teams should expect a transition period in which classical and post-quantum approaches operate together. Hybrid designs can help preserve existing assurance models as teams test new algorithms, update protocols, validate performance and confirm interoperability. This is where crypto-agile infrastructure matters most. Centralized key management, policy-based controls and HSM-backed trust anchors can reduce the operational burden of changing cryptography across applications, cloud services, PKI, code signing and digital identity systems.

Regulation is another reason to move now. Government and industry guidance continues to push organizations toward cryptographic inventories, migration planning and quantum-resistant protections for critical systems. The organizations that begin with discovery, testing and governance today will be in a stronger position to respond as standards, validation requirements and customer expectations mature.

Learn more about Luna 8

The path forward is clear: make cryptography visible, make security architecture adaptable and make PQC readiness part of enterprise risk planning. To learn more, watch the on-demand webinar, Defending Against the Attacks of the Future with Post-Quantum Cryptography, visit the Thales website to read further coverage on Luna 8 cryptographic security for the age of AI and PQC and Thales post-quantum crypto agility and PQC readiness.

ITPro

ITPro is a global business technology website providing the latest news, analysis, and business insight for IT decision-makers. Whether it's cyber security, cloud computing, IT infrastructure, or business strategy, we aim to equip leaders with the data they need to make informed IT investments.

For regular updates delivered to your inbox and social feeds, be sure to sign up to our daily newsletter and follow on us LinkedIn and Twitter.