Industry

Quantum threat forces enterprises into cryptography overhaul by 2029

As quantum computing capabilities grow, organizations are shifting from planning discussions to executing a sweeping rebuild of the encryption systems protecting their applications and infrastructure. Industry leaders say the work must begin immediately to meet converging deadlines.

3 min read
Quantum readiness moves from blueprint to build as 2029 deadlines converge

The cryptographic systems that have safeguarded internet communications for decades are nearing obsolescence. Quantum computing's advancement is compelling enterprises to undertake a massive reconstruction of the encryption underpinning every application, device and digital certificate in their infrastructure.

The conversation has moved beyond theoretical concerns into concrete execution. Organizations have progressed through skepticism toward acceptance that quantum readiness demands immediate action, according to Amit Sinha, chief executive officer of DigiCert Inc.

It is a once in a 30-year upgrade to the core trust foundations of the internet. So, it is more like a skyscraper. But the important point I tell every customer is you don't need to build a skyscraper in one shot. You don't need the full final blueprint. You need to start with the foundations, build the next floor and then stack up floors on top.

Amit Sinha, CEO of DigiCert Inc.

Sinha made these remarks during an exclusive interview at World Quantum Readiness Day, speaking with John Furrier, executive analyst of theCUBE Research, on theCUBE, SiliconANGLE Media's livestreaming platform.

Encryption inventory is the first step toward quantum safety

Skepticism is no longer the primary barrier. The real challenge lies in the sheer scale of a migration that spans every cryptographic component across an organization, while the teams responsible for executing it have historically received inadequate funding.

I think it's the scope of the project. In many cases, PKI teams who are underfunded and now they look at this massive, Y2K-like times 10 event that is going to hit them. What we tell customers is you don't need a perfect inventory, you need a good enough inventory. Identify crown jewels in your application suite that you want to attack first.

Amit Sinha

A comprehensive catalog of machines, software and libraries serves as the foundation for what the sector refers to as cryptographic posture—a risk evaluation tool that DigiCert introduced through Quantum Central in July.

Shortening certificate validity periods are reinforcing the push toward greater automation, Sinha observed. The timeline for achieving cryptographic flexibility aligns with the post-quantum cryptography transition, with both initiatives converging on the same 2029 target.

The road to crypto agility with the 47-day mandate is kind of the same road to post-quantum cryptography. Both of those deadlines are now 2029. So, having a good system in place, bringing public and private PKI together, having last-mile automation capabilities that give you crypto agility, foundational steps — both for the 47-day mandate that we have today and the migration to post-quantum cryptography.

Amit Sinha

Public key infrastructure modernization and the shift to post-quantum encryption represent a single integrated initiative rather than separate undertakings.

Prioritize the migration to quantum safety. PKI modernization is long overdue. And the deadline to do that is 2029. If you don't start today, you're already out of time.

Amit Sinha

Source: SiliconANGLE · Reporting supplemented by The Silicon Ledger staff.