Logo
Cybersecurity

You Don’t Need to Be a Cryptographer to Start Preparing for Post Quantum Security

The first workforce challenge isn’t inventing a new algorithm. It’s finding every place the old ones are hiding.

ITSEC AsiaITSEC Asia
|
Sep 29, 2026
You Don’t Need to Be a Cryptographer to Start Preparing for Post Quantum Security

Ask a security team where the organization uses cryptography and the first answers will probably be obvious: TLS certificates, VPNs, encrypted databases and authentication systems.

Then keep asking.

What about APIs? Code signing? SSH? Embedded devices? Software libraries? Cloud services? Machine identities? Third party applications?

The list gets longer rather quickly.

That matters because NIST is now telling organizations to begin migrating toward post quantum cryptography. Its first three finalized PQC standards have been available since 2024, and NIST says products, services and protocols will need updates as organizations move away from quantum vulnerable public key algorithms. NIST

The workforce problem starts before anyone changes an algorithm.

First, Find the Cryptography

NIST’s Migration to Post Quantum Cryptography project describes cryptographic inventory as a record of cryptography used across systems, applications, services, devices and data flows. It can include algorithms, protocols, keys, certificates and the components that depend on them. NIST Pages

Building that inventory requires more than a specialist who understands the mathematics behind ML-KEM or ML-DSA.

Organizations need people who can:

  • Identify cryptography embedded in applications and infrastructure
  • Understand TLS, SSH, VPNs, certificates and digital signatures
  • Trace which business systems depend on particular cryptographic services
  • Assess how long sensitive data must remain protected
  • Work with application owners and technology suppliers
  • Test whether replacement mechanisms remain interoperable
  • Prioritize migration according to risk

Suddenly post quantum readiness looks much more like an engineering and asset visibility problem.

Migration Crosses Team Boundaries

Consider a certificate used by an internal application.

Changing its cryptography may affect the application, identity infrastructure, operating system, network components and other systems that trust the certificate. Older devices may not support the replacement. Performance characteristics may change. A third party dependency might sit somewhere in the chain.

NIST’s June work on post quantum updates for Personal Identity Verification illustrates this transition problem. Its proposed approach includes a dual stack model, retaining existing classical credentials while introducing PQC capabilities to support backward compatibility and gradual deployment. NIST

That’s migration work, not a simple software update.

The people doing it need to understand dependencies, testing and change management alongside security.

Put Cryptographic Discovery Into Training

A useful PQC exercise doesn’t have to begin with advanced mathematics.

Give learners a simulated enterprise containing web applications, certificates, VPN connections, code signing, APIs and several older systems. Ask them to build a cryptographic inventory.

Then introduce a migration requirement.

Which systems should move first? Which dependencies create risk? Where is cryptography controlled internally and where does the organization depend on another provider? What needs to be tested before anything changes?

This is where practical training becomes useful. At ITSEC Cyber & AI Academy, hands on cybersecurity environments can help professionals connect emerging subjects such as post quantum security with the infrastructure, risk and operational decisions they already encounter.

Quantum computing may be an advanced field.

Preparing an organization for it begins with a much more familiar cybersecurity skill: knowing what you actually have.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: Post Quantum Cryptography · NIST NCCoE: Migration to Post Quantum Cryptography FAQ · NIST: Post Quantum Updates to PIV Standards · ITU Academy: Quantum Communications and Post Quantum Cybersecurity, 14 September–2 October 2026

Share this post

You may also like

AI Is Raising the Bar for Cybersecurity Talent
Cybersecurity

AI Is Raising the Bar for Cybersecurity Talent

For cybersecurity teams, AI is quickly moving from something experimental to something people actually use. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 77% of surveyed organizations had adopted AI for cybersecurity. It is already being used for tasks such as phishing detection, intrusion response and user-behaviour analysis. That sounds like good news for teams struggling with workload. And mostly, it is. But AI doesn’t remove the need for skilled cybersecurity professionals. It changes what those professionals need to be good at. AUTOMATION CAN DO MORE. SO HUMANS HAVE TO DO MORE TOO. The same WEF research found that 54% of organizations considered insufficient knowledge or skills a barrier to using AI effectively in cybersecurity. Another 41% pointed to the need for human oversight. That second number matters. AI can analyse enormous amounts of information quickly. What it still struggles with is context: whether an unusual event is genuinely dangerous, how a technical issue affects the business and what action makes sense when the available information is incomplete. Cybersecurity professionals increasingly need

ITSEC AsiaITSEC Asia
|
Sep 02, 2026 — 3 minutes read
Cybersecurity Has More Entry Doors Than We Think
Cybersecurity

Cybersecurity Has More Entry Doors Than We Think

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security. That route exists. It’s hardly the only one. ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today. NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework. That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one. CYBERSECURITY BORROWS SKILLS FROM EVERYWHERE Someone moving into cybersecurity doesn’t arrive empty-handed. A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands

ITSEC AsiaITSEC Asia
|
Sep 11, 2026 — 3 minutes read
Supply Chain Attacks Are Growing: Why Third-Party Risk Needs Continuous Testing
Cybersecurity

Supply Chain Attacks Are Growing: Why Third-Party Risk Needs Continuous Testing

Introduction Third-party involvement in data breaches doubled from 15 percent to 30 percent in a single year, the largest one-year shift ever recorded in the Verizon 2025 Data Breach Investigations Report. That is not a gradual trend line, it is a structural shift in how attackers reach their targets. Rather than breaching a company directly, they go after the vendor, the software dependency, or the service provider sitting quietly inside that company's trust boundary. As Indonesia's leading cybersecurity company, ITSEC Asia works with organizations across finance, healthcare, and technology who are only now realizing that their own defenses were never the whole picture, because a breach can start three vendors away and still land squarely on their desk. Source: Supply Chain Attack Statistics 2026, Stingrai Research · Supply Chain Attack Statistics for 2026, Swif The Numbers Behind the Shift A supply chain compromise now costs an average of 4.91 million US dollars and takes 267 days to identify and contain, the longest lifecycle of any breach vector tracked in IBM's Cost

ITSEC AsiaITSEC Asia
|
Jul 31, 2026 — 4 minutes read

Receive weekly
updates on new posts

Subscribe