Logo
Cybersecurity

The Next Cyber Skills Gap May Be Hidden in Your Encryption

Post quantum security sounds like advanced mathematics. For many cyber teams, the first challenge is considerably more practical: finding everything that needs to change.

ITSEC AsiaITSEC Asia
|
Sep 11, 2026
The Next Cyber Skills Gap May Be Hidden in Your Encryption

Quantum computing has a talent problem hiding inside a technology problem.

The discussion around post quantum cryptography often starts with algorithms. NIST has already standardized the first post quantum algorithms and continues to update technical standards. In June, it released working drafts for bringing post quantum cryptography into Personal Identity Verification credentials, including a model that supports gradual migration from classical cryptography.

NIST also finalized updated crypto agility guidance on 29 June. The concept is straightforward: organizations need the ability to replace cryptographic algorithms and implementations without causing major disruption.

Doing that requires people who understand considerably more than the names of new algorithms.

First, Find the Cryptography

Ask an organization where it uses encryption and the first answers may be predictable: VPNs, databases, certificates and websites.

Keep looking and the list grows.

Cryptography can be embedded in applications, APIs, identity systems, cloud services, hardware, third party software, backups, digital signatures and old systems that everyone politely avoids touching.

Preparing for a cryptographic transition therefore requires capabilities such as:

  • Discovering where cryptographic algorithms, keys and certificates are used
  • Identifying which systems depend on older cryptography
  • Understanding key management and certificate lifecycles
  • Assessing dependencies across applications and suppliers
  • Testing replacements without breaking interoperability
  • Prioritising systems according to data sensitivity and longevity

This is partly cryptography, partly architecture, partly asset management and partly the ancient cybersecurity discipline of discovering that a forgotten server is apparently still very important.

Indonesia Has a Reason to Start Early

The issue has already entered Indonesia’s cybersecurity discussion.

On 10 August, Nezar Patria warned about harvest now, decrypt later: attackers can steal encrypted information today, store it and attempt to decrypt it when more capable technology becomes available.

Days earlier, he had also said government, industry and digital infrastructure operators should begin studying post quantum cryptography as part of preparations for quantum computing.

That changes the timeline for workforce development. Organizations don’t need to wait for a cryptographically relevant quantum computer to appear before developing the people who will eventually manage the transition.

Crypto Agility Needs Practice

A useful training exercise doesn’t have to ask everyone to design a quantum resistant algorithm.

Give learners a simulated enterprise environment and ask them to locate certificates, cryptographic libraries and dependencies. Let them build an inventory, identify systems with long lived sensitive data and plan a staged migration. Then change one component and see what breaks.

That exercise develops a different capability: understanding cryptography as something that lives inside operational systems.

It’s an area where practical learning at ITSEC Cyber & AI Academy can help professionals connect cybersecurity concepts with architecture, implementation and real operational decisions.

The post quantum transition will involve sophisticated mathematics. Most organizations, however, will first face a much simpler question.

Where did we put all the cryptography?

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: Considerations for Achieving Crypto Agility, 29 June 2026 · NIST: Post Quantum Updates to PIV Standards, 12 June 2026 · Komdigi: Data Dicuri Hari Ini Bisa Dibuka Nanti, 10 August 2026 · Komdigi: Indonesia Perlu Mulai Mempelajari Post Quantum Cryptography, 6 August 2026

Share this post

You may also like

AI Agents Change What Security Teams Need to Know
Cybersecurity

AI Agents Change What Security Teams Need to Know

NIST is building an AI agent workflow for one of cybersecurity’s most widely used public resources. On 17 September, its Information Technology Laboratory presented work on an agentic workflow designed to help enrich vulnerability information in the National Vulnerability Database. NIST says the project is intended to help the NVD cope with the increasing scale and complexity of disclosed vulnerabilities, and the webinar covered its architecture, implementation issues and early results. The project illustrates a broader change. AI is moving from producing information toward performing multi-step tasks. NIST describes AI agents as systems capable of autonomous actions that can interact with external systems and internal data. For cybersecurity professionals, that means another layer of skills is arriving. SECURITY HAS TO FOLLOW THE ACTION A conventional AI application might receive a prompt and return an answer. An agent may have access to tools, data and permissions that allow it to continue working. That changes the questions a security professional needs to ask. * What systems can the agent access? * Which actions can

ITSEC AsiaITSEC Asia
|
Sep 18, 2026 3 minutes read
Cybersecurity Skills Need Maintenance Too
Cybersecurity

Cybersecurity Skills Need Maintenance Too

A cybersecurity professional completes training on Friday. They’ve worked through the material, passed the assessment and returned to their job with a fresh set of skills. Six months later, the environment looks different. A cloud service has changed. The team has introduced AI tools. Attack techniques have evolved. Someone redesigned the incident process. Three new systems appeared and one old application that was supposedly retiring is, mysteriously, still alive. This is why cybersecurity training increasingly needs to behave less like an annual event and more like professional maintenance. NIST’s FISSEA Fall Forum on 15 September puts that idea into practice. Its agenda includes an interactive session on building a micro training module, followed by examples of cybersecurity learning tied to the NICE Workforce Framework and practical skill application. The format matters. Learning doesn’t always need another full week away from work. SMALL LEARNING CAN SOLVE SPECIFIC PROBLEMS CISA already uses micro learning as part of its cybersecurity training model. Its Continuous Diagnostics and Mitigation program offers short modules of roughly 3 to 10 minutes,

ITSEC AsiaITSEC Asia
|
Sep 14, 2026 3 minutes read
This is How Information Security Analysis Protects What Prevention Can't
Cybersecurity

This is How Information Security Analysis Protects What Prevention Can't

INTRODUCTION Organizations worldwide are investing more in cybersecurity than at any point in history, yet breaches are growing more frequent, more expensive, and more damaging. The global average cost of a data breach reached USD 4.88 million in 2024, the highest figure ever recorded. Even more alarming, the average time to identify a breach stood at 194 days, nearly half a year of undetected attacker activity inside a network before anyone realized something was wrong. These numbers raise an urgent question every business leader must answer honestly: if an attacker entered your network today, how long would it take your organization to find out? And once discovered, could you identify exactly what was accessed, how the attacker moved, and what vulnerabilities made it possible in the first place? For most organizations, the honest answer is: not fast enough, and not with enough certainty. That gap is precisely what Information Security Analysis (ISA) is designed to close. Prevention, including firewalls, antivirus, and multi-factor authentication, is necessary but not sufficient. When attackers

|
Mei 11, 2026 7 minutes read

Receive weekly
updates on new posts

Subscribe