Logo
Cybersecurity

The Next Cyber Skills Gap May Be Hidden in Your Encryption

Post quantum security sounds like advanced mathematics. For many cyber teams, the first challenge is considerably more practical: finding everything that needs to change.

ITSEC AsiaITSEC Asia
|
Sep 11, 2026
The Next Cyber Skills Gap May Be Hidden in Your Encryption

Quantum computing has a talent problem hiding inside a technology problem.

The discussion around post quantum cryptography often starts with algorithms. NIST has already standardized the first post quantum algorithms and continues to update technical standards. In June, it released working drafts for bringing post quantum cryptography into Personal Identity Verification credentials, including a model that supports gradual migration from classical cryptography.

NIST also finalized updated crypto agility guidance on 29 June. The concept is straightforward: organizations need the ability to replace cryptographic algorithms and implementations without causing major disruption.

Doing that requires people who understand considerably more than the names of new algorithms.

First, Find the Cryptography

Ask an organization where it uses encryption and the first answers may be predictable: VPNs, databases, certificates and websites.

Keep looking and the list grows.

Cryptography can be embedded in applications, APIs, identity systems, cloud services, hardware, third party software, backups, digital signatures and old systems that everyone politely avoids touching.

Preparing for a cryptographic transition therefore requires capabilities such as:

  • Discovering where cryptographic algorithms, keys and certificates are used
  • Identifying which systems depend on older cryptography
  • Understanding key management and certificate lifecycles
  • Assessing dependencies across applications and suppliers
  • Testing replacements without breaking interoperability
  • Prioritising systems according to data sensitivity and longevity

This is partly cryptography, partly architecture, partly asset management and partly the ancient cybersecurity discipline of discovering that a forgotten server is apparently still very important.

Indonesia Has a Reason to Start Early

The issue has already entered Indonesia’s cybersecurity discussion.

On 10 August, Nezar Patria warned about harvest now, decrypt later: attackers can steal encrypted information today, store it and attempt to decrypt it when more capable technology becomes available.

Days earlier, he had also said government, industry and digital infrastructure operators should begin studying post quantum cryptography as part of preparations for quantum computing.

That changes the timeline for workforce development. Organizations don’t need to wait for a cryptographically relevant quantum computer to appear before developing the people who will eventually manage the transition.

Crypto Agility Needs Practice

A useful training exercise doesn’t have to ask everyone to design a quantum resistant algorithm.

Give learners a simulated enterprise environment and ask them to locate certificates, cryptographic libraries and dependencies. Let them build an inventory, identify systems with long lived sensitive data and plan a staged migration. Then change one component and see what breaks.

That exercise develops a different capability: understanding cryptography as something that lives inside operational systems.

It’s an area where practical learning at ITSEC Cyber & AI Academy can help professionals connect cybersecurity concepts with architecture, implementation and real operational decisions.

The post quantum transition will involve sophisticated mathematics. Most organizations, however, will first face a much simpler question.

Where did we put all the cryptography?

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: Considerations for Achieving Crypto Agility, 29 June 2026 · NIST: Post Quantum Updates to PIV Standards, 12 June 2026 · Komdigi: Data Dicuri Hari Ini Bisa Dibuka Nanti, 10 August 2026 · Komdigi: Indonesia Perlu Mulai Mempelajari Post Quantum Cryptography, 6 August 2026

Share this post

You may also like

AI Agents Change What Security Teams Need to Know
Cybersecurity

AI Agents Change What Security Teams Need to Know

NIST is building an AI agent workflow for one of cybersecurity’s most widely used public resources. On 17 September, its Information Technology Laboratory presented work on an agentic workflow designed to help enrich vulnerability information in the National Vulnerability Database. NIST says the project is intended to help the NVD cope with the increasing scale and complexity of disclosed vulnerabilities, and the webinar covered its architecture, implementation issues and early results. The project illustrates a broader change. AI is moving from producing information toward performing multi-step tasks. NIST describes AI agents as systems capable of autonomous actions that can interact with external systems and internal data. For cybersecurity professionals, that means another layer of skills is arriving. SECURITY HAS TO FOLLOW THE ACTION A conventional AI application might receive a prompt and return an answer. An agent may have access to tools, data and permissions that allow it to continue working. That changes the questions a security professional needs to ask. * What systems can the agent access? * Which actions can

ITSEC AsiaITSEC Asia
|
Sep 18, 2026 3 minutes read
Data Protection and Cybersecurity Laws in the Asia-Pacific Region
Cybersecurity

Data Protection and Cybersecurity Laws in the Asia-Pacific Region

Info

Apart from sales and trade, the majority of internet users utilize it for socializing and interacting with peers online. For instance, there were 3.8 billion social media users in January 2020, which represents a 9 percent increase from the previous year. The advancements in internet and related communication technologies enable easy access to information from anywhere on the planet. For example, an online merchant operating in Thailand can offer their services to customers residing in the European Union and the United States. In order to address the dissemination of personal information, including financial, medical, and other types of personal data, worldwide through the internet, appropriate legal regulations need to be established to protect the personal data of citizens and the digital assets of organizations while working online. Following the implementation of the General Data Protection Regulation (GDPR) in the European Union (which came into effect on May 25, 2018), which governs data protection and privacy in EU countries and regulates the transfer of personal data outside the European Union and

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 11 minutes read
Cybersecurity Roadmap: Why It Is Essential for Managing Enterprise Risk Today
Cybersecurity

Cybersecurity Roadmap: Why It Is Essential for Managing Enterprise Risk Today

INTRODUCTION Many organizations invest heavily in security tools, yet still struggle to explain their overall security posture. This is not always due to lack of technology, but often due to lack of direction. As digital environments grow more complex, security decisions are made across cloud platforms, remote endpoints, third-party integrations, and increasingly, AI-driven systems. According to findings highlighted in the World Economic Forum [https://www.weforum.org/], cyber risk today is less about a single vulnerability and more about how fragmented security efforts accumulate across interconnected environments. Without a clear plan, security initiatives tend to be reactive. Controls are added in response to incidents, audits, or vendor recommendations, rather than as part of a coordinated strategy. This is where a Cybersecurity Roadmap becomes critical. A roadmap provides a structured way to define priorities, sequence improvements, and align security with business risk. Industry guidance from NIST Cybersecurity Framework [https://www.nist.gov/cyberframework] emphasizes that this approach enables organizations to move from isolated security actions toward a cohesive and resilient defense posture. WHAT IS A CYBERSECURITY ROADMAP? A Cybersecurity Roadmap is a strategic,

ITSEC AsiaITSEC Asia
|
Jan 22, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe