Logo
Cybersecurity

You Don’t Need to Be a Cryptographer to Start Preparing for Post Quantum Security

The first workforce challenge isn’t inventing a new algorithm. It’s finding every place the old ones are hiding.

ITSEC AsiaITSEC Asia
|
Sep 29, 2026
You Don’t Need to Be a Cryptographer to Start Preparing for Post Quantum Security

Ask a security team where the organization uses cryptography and the first answers will probably be obvious: TLS certificates, VPNs, encrypted databases and authentication systems.

Then keep asking.

What about APIs? Code signing? SSH? Embedded devices? Software libraries? Cloud services? Machine identities? Third party applications?

The list gets longer rather quickly.

That matters because NIST is now telling organizations to begin migrating toward post quantum cryptography. Its first three finalized PQC standards have been available since 2024, and NIST says products, services and protocols will need updates as organizations move away from quantum vulnerable public key algorithms. NIST

The workforce problem starts before anyone changes an algorithm.

First, Find the Cryptography

NIST’s Migration to Post Quantum Cryptography project describes cryptographic inventory as a record of cryptography used across systems, applications, services, devices and data flows. It can include algorithms, protocols, keys, certificates and the components that depend on them. NIST Pages

Building that inventory requires more than a specialist who understands the mathematics behind ML-KEM or ML-DSA.

Organizations need people who can:

  • Identify cryptography embedded in applications and infrastructure
  • Understand TLS, SSH, VPNs, certificates and digital signatures
  • Trace which business systems depend on particular cryptographic services
  • Assess how long sensitive data must remain protected
  • Work with application owners and technology suppliers
  • Test whether replacement mechanisms remain interoperable
  • Prioritize migration according to risk

Suddenly post quantum readiness looks much more like an engineering and asset visibility problem.

Migration Crosses Team Boundaries

Consider a certificate used by an internal application.

Changing its cryptography may affect the application, identity infrastructure, operating system, network components and other systems that trust the certificate. Older devices may not support the replacement. Performance characteristics may change. A third party dependency might sit somewhere in the chain.

NIST’s June work on post quantum updates for Personal Identity Verification illustrates this transition problem. Its proposed approach includes a dual stack model, retaining existing classical credentials while introducing PQC capabilities to support backward compatibility and gradual deployment. NIST

That’s migration work, not a simple software update.

The people doing it need to understand dependencies, testing and change management alongside security.

Put Cryptographic Discovery Into Training

A useful PQC exercise doesn’t have to begin with advanced mathematics.

Give learners a simulated enterprise containing web applications, certificates, VPN connections, code signing, APIs and several older systems. Ask them to build a cryptographic inventory.

Then introduce a migration requirement.

Which systems should move first? Which dependencies create risk? Where is cryptography controlled internally and where does the organization depend on another provider? What needs to be tested before anything changes?

This is where practical training becomes useful. At ITSEC Cyber & AI Academy, hands on cybersecurity environments can help professionals connect emerging subjects such as post quantum security with the infrastructure, risk and operational decisions they already encounter.

Quantum computing may be an advanced field.

Preparing an organization for it begins with a much more familiar cybersecurity skill: knowing what you actually have.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: Post Quantum Cryptography · NIST NCCoE: Migration to Post Quantum Cryptography FAQ · NIST: Post Quantum Updates to PIV Standards · ITU Academy: Quantum Communications and Post Quantum Cybersecurity, 14 September–2 October 2026

Share this post

You may also like

Post-Quantum Cryptography Readiness with ITSEC
Cybersecurity

Post-Quantum Cryptography Readiness with ITSEC

For decades, public-key cryptography has been the backbone of protecting sensitive information, such as financial transactions, personal data, corporate communications, and government secrets. Whether logging into a secure banking app, shopping online, or browsing encrypted websites (like HTTPS), public key infrastructure (PKI) protects your data from cybercriminals. However, the rise of quantum computing introduces transformative and potentially disruptive challenge to this foundation of digital trust. THE QUANTUM REVOLUTION Quantum computers can perform complex computations faster than even the most advanced current supercomputers. While this capability promises breakthroughs in drug discovery and healthcare, materials science or Artificial Intelligence (AI), it also poses a significant threat to current cryptographic systems. Quantum computers could break widely used publickey cryptographic systems (e.g., RSA, ECC), compromising critical infrastructure security such as energy grids, financial systems, and sensitive government communication networks. Compromised public-key cryptography could lead to forged digital certificates or signatures, undermining trust in banking, healthcare, and government services. Quantum cryptography attacks could also compromise billions of connected devices, from smart homes to Industrial Control Systems (ICS), by

ITSEC AsiaITSEC Asia
|
Jul 11, 2025 — 4 minutes read
How IoT Devices Are Expanding the Cybersecurity Attack Surface
Cybersecurity

How IoT Devices Are Expanding the Cybersecurity Attack Surface

INTRODUCTION When people hear “IoT security, [https://itsec.asia/services/ot-ics-cybersecurity]” they often assume it’s something only IT teams need to worry about. In reality, IoT security affects everyday users, households, and businesses alike.* From smart home devices to office surveillance systems, connected devices are now part of critical daily operations. The more devices we connect, the wider the potential attack surface becomes. Here’s the part no one really talks about: Many IoT environments are deployed quickly for convenience, not necessarily designed with security as the top priority. It’s not negligence. It’s just how fast technology moves. Source: aciano.net [https://aciano.net/blog/iot-security-risks/], cio.com [https://www.cio.com/article/3990581/iot-security-challenges-and-best-practices-for-a-hyperconnected-world.html?] THE IOT LANDSCAPE NOWADAYS Security used to focus on protecting networks with firewalls and perimeter defenses. Today, attackers are shifting their focus to easier targets: user credentials, weak device authentication, misconfigured cloud dashboards, and unpatched firmware.  Today, attackers are more interested in: * User credentials * Weak device authentication * Misconfigured cloud dashboards * Unpatched firmware IoT devices often rely on cloud platforms for monitoring, analytics, and control. That means IoT security is no longer just about the

ITSEC AsiaITSEC Asia
|
Mar 06, 2026 — 5 minutes read
Here is How Application Security Works to Protect Your Systems and Data
Cybersecurity

Here is How Application Security Works to Protect Your Systems and Data

INTRODUCTION Nowadays applications are at the center of digital business operations. From mobile banking and e-commerce platforms to internal enterprise systems, organizations rely heavily on applications to serve customers and manage data. However, as applications become more complex and interconnected, they also become one of the most common targets for cyberattacks. In fact, web applications are responsible for a large percentage of data breaches worldwide. The Verizon 2024 Data Breach Investigations Report indicates that cybercriminals frequently exploit web applications as an attack vector. This growing threat raises an important question, “Are your applications truly secure against modern cyber threats?” One of the most effective ways to protect applications is through application security, a proactive approach to identifying and fixing vulnerabilities before attackers can exploit them. Source: verizon.com [https://www.verizon.com/business/resources/reports/dbir/],    A REAL-WORLD EXAMPLE: WHEN AN UNSECURED API EXPOSES MILLIONS Let's look at something that actually happened to Trello in early 2024.In January 2024, a hacker found a weakness in Trello's system, specifically, a part of the app called a REST API. This API had a

ITSEC AsiaITSEC Asia
|
Apr 17, 2026 — 6 minutes read

Receive weekly
updates on new posts

Subscribe