The Next Cyber Skills Gap May Be Hidden in Your Encryption
Post quantum security sounds like advanced mathematics. For many cyber teams, the first challenge is considerably more practical: finding everything that needs to change.

Quantum computing has a talent problem hiding inside a technology problem.
The discussion around post quantum cryptography often starts with algorithms. NIST has already standardized the first post quantum algorithms and continues to update technical standards. In June, it released working drafts for bringing post quantum cryptography into Personal Identity Verification credentials, including a model that supports gradual migration from classical cryptography.
NIST also finalized updated crypto agility guidance on 29 June. The concept is straightforward: organizations need the ability to replace cryptographic algorithms and implementations without causing major disruption.
Doing that requires people who understand considerably more than the names of new algorithms.
First, Find the Cryptography
Ask an organization where it uses encryption and the first answers may be predictable: VPNs, databases, certificates and websites.
Keep looking and the list grows.
Cryptography can be embedded in applications, APIs, identity systems, cloud services, hardware, third party software, backups, digital signatures and old systems that everyone politely avoids touching.
Preparing for a cryptographic transition therefore requires capabilities such as:
- Discovering where cryptographic algorithms, keys and certificates are used
- Identifying which systems depend on older cryptography
- Understanding key management and certificate lifecycles
- Assessing dependencies across applications and suppliers
- Testing replacements without breaking interoperability
- Prioritising systems according to data sensitivity and longevity
This is partly cryptography, partly architecture, partly asset management and partly the ancient cybersecurity discipline of discovering that a forgotten server is apparently still very important.
Indonesia Has a Reason to Start Early
The issue has already entered Indonesia’s cybersecurity discussion.
On 10 August, Nezar Patria warned about harvest now, decrypt later: attackers can steal encrypted information today, store it and attempt to decrypt it when more capable technology becomes available.
Days earlier, he had also said government, industry and digital infrastructure operators should begin studying post quantum cryptography as part of preparations for quantum computing.
That changes the timeline for workforce development. Organizations don’t need to wait for a cryptographically relevant quantum computer to appear before developing the people who will eventually manage the transition.
Crypto Agility Needs Practice
A useful training exercise doesn’t have to ask everyone to design a quantum resistant algorithm.
Give learners a simulated enterprise environment and ask them to locate certificates, cryptographic libraries and dependencies. Let them build an inventory, identify systems with long lived sensitive data and plan a staged migration. Then change one component and see what breaks.
That exercise develops a different capability: understanding cryptography as something that lives inside operational systems.
It’s an area where practical learning at ITSEC Cyber & AI Academy can help professionals connect cybersecurity concepts with architecture, implementation and real operational decisions.
The post quantum transition will involve sophisticated mathematics. Most organizations, however, will first face a much simpler question.
Where did we put all the cryptography?
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: NIST: Considerations for Achieving Crypto Agility, 29 June 2026 · NIST: Post Quantum Updates to PIV Standards, 12 June 2026 · Komdigi: Data Dicuri Hari Ini Bisa Dibuka Nanti, 10 August 2026 · Komdigi: Indonesia Perlu Mulai Mempelajari Post Quantum Cryptography, 6 August 2026
.png)


