
Cybersecurity Awesomeness Podcast · 2026-06-26 · 16 min
Key moments - from our scoring
Substance score
40 / 100
Five dimensions, 20 points each
Post-quantum cryptography (PQC) has moved from theoretical future concern to urgent business risk, driven by the "harvest now, decrypt later" threat and accelerating quantum computing timelines. Simon Pamplin, CTO at Certes AI, discusses with EMA analysts Chris Steffen and Ken Buckler how threat actors are stealing encrypted data today to decrypt when quantum computers become available, why enterprises should treat this as a data-centric business risk rather than purely a network security problem, and how lattice-based PQC algorithms combined with quantum-safe key management can protect sensitive information now. The conversation covers the critical distinction between immediate data loss vulnerabilities (which exist today) and future quantum threats (expected 2026-2030 per Google and Cloudflare reassessments), the role of true quantum random numbers and customer-controlled key components in robust encryption, and why waiting for Q-Day is negligent when solutions already exist to mitigate these risks without organizational disruption.
Bad actors steal encrypted data today with the expectation that future quantum computing power will be sufficient to break current encryption and monetize the data later. Enterprises should care because all data has value and represents business risk - financial, reputational, operational, and legal - if compromised at any point in the future.
Simon Pamplin predicts Q-Day within five years (around 2029-2030), and Google and Cloudflare recently reassessed their own infrastructure timelines to 2029, down from previously stated 2035-2040 targets, due to simplifications in quantum algorithms and increasing quantum compute power.
Traditional encryption relies on the mathematical difficulty of factoring large prime numbers, while post-quantum cryptography uses lattice-based algorithms that are mathematically harder to crack. More importantly, PQC combines these stronger algorithms with quantum-safe key management using true quantum random numbers and customer-controlled key components that must be rotated regularly.
CISOs default to network and infrastructure security perspectives because that has been the investment and focus for 20 years, but data loss from quantum decryption is actually a business risk with C-suite and legal implications, not a network problem that runs on top of network infrastructure.
Enterprises should implement post-quantum cryptography solutions immediately rather than waiting for Q-Day, as solutions already exist to mitigate risks without disruption and applying strong data-centric security now ensures data remains protected when quantum computing becomes generally available.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of useful data points (Google/Cloudflare revising their quantum-safe deadline, Cambridge's 200-qubit purchase) and a serviceable distinction between Harvest Now Decrypt Later risk and future Q-Day risk, but large stretches are filled with host commentary, repetition, and platitudes that dilute the useful material across 16 minutes.
the leaps and bounds in technology are happening day in day out with the increasing qubits and the size of compute power of quantum computing that that date that mythical q date is getting closer and closer
it's not because quantum computing is getting that much faster It because they realising the amount of quantum computing power required to break existing cryptography is a lot less than they initially thought
Most content recycles widely-circulated PQC talking points (Harvest Now Decrypt Later, Q-Day timelines, lattice-based crypto) without adding a novel angle; the one mildly differentiated idea - that key management matters as much as the algorithm choice - is mentioned briefly and not developed.
one of my hates really when we're talking about post-quantum is people focus just on the algorithm the algorithm is the mathematical path the important bit is the encryption keys
the problem with our industry as a whole is that when you mention security, people automatically think network and infrastructure security because that's what they've done for 20 years
Simon Pamplin is a working vendor CTO with nearly two decades of direct product experience in encryption, which is relevant and practitioner-level, but the episode functions partly as a vendor promotional vehicle for CERTES, limiting the candor and depth you'd expect from a purely independent expert.
what we've done recently is apply the NIST-standardised post-quantum algorithms to the solutions that we've been selling to various customers for close on 20 years now, believe it or not
So last year I was saying that I believed that Q day was within five years. So I was looking at the 2029, 2030 mark. Google's backing me up on that.
There are a handful of concrete specifics - Google and Cloudflare revising their quantum-safe deadline from 2035-2040 to 2029, Cambridge's 200-qubit commercial purchase, NIST-standardised algorithms - but no customer case studies, breach data, cost figures, or named CVEs to back up broader claims about data loss risk.
Google and Cloudflare came back with a reassessment of their own internal infrastructure that had to be quantum safe by 2029. And that's down from previously 2035 or 2040 that people were talking about
the University of Cambridge in the UK has just purchased its first quantum computer with 200 qubits
The host questions are bundled and broad (asking simultaneously how PQC works AND when Q-Day arrives), follow-ups mostly echo and affirm the guest rather than probe or challenge, and a significant portion of airtime is consumed by host monologues that crowd out guest depth.
It's a two part question. The first part is how, so traditional encryption really relies on the difficulty of factoring large prime numbers. How does post-quantum cryptography work differently than traditional encryption? And then finally, when do you think Q-Day is going to be?
We already told him that we wouldn't. And really just wanted to have a general conversation.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen and co-host Ken Buckler are joined by Simon Pamplin, CTO of Certes AI, to demystify the urgent threat of quantum computing. The conversation pivots away from the "mythical" future of quantum and focuses on the pressing reality of "Harvest Now, Decrypt Later" attacks, where adversaries exfiltrate encrypted data today with the intent to monetize it once quantum-enabled decryption becomes viable. Pamplin challenges the industry’s tendency to frame quantum risk solely as a network security issue, arguing instead that it is a critical business risk that carries profound legal and reputational consequences. The hosts and Pamplin explore the transition to lattice-based post-quantum cryptography (PQC) and the vital importance of robust key management. As the consensus on "Q-Day" - the point at which current encryption is rendered obsolete - accelerates toward the 2029 - 2030 timeframe, the episode serves as a vital call to action: prioritizing data-centric security hygiene is no longer optional for modern enterprises.
Transcribed and scored by The B2B Podcast Index.
Hello, and welcome to the Cybersecurity Awesomeness Podcast, hosted by Enterprise Management Associates, an industry-leading IT analyst research firm that provides deep insights across the full spectrum of IT and data management technologies. The Cybersecurity Awesomeness Podcast will take a deep dive into the security topics that are top of mind for information security practitioners, IT professionals, and technology business leaders. Join security experts Chris Steffen, VP of Research at EMA, and Ken Buckler, Research Analyst at EMA, for some truly awesome topics.
Chris and Ken, take it away. Good morning, good afternoon, good evening. Welcome to the Cybersecurity Awesomeness Podcast. I am your host.
My name is Chris Steffen. Joining me today is my friend and colleague, Mr. Ken Buckler. Also joining me today from Circe's AI is my friend and somebody who I met just shortly ago in London, Simon Pamplin.
He is the, I think you're the CTO at Circe. Is that true, Simon? Yeah, that's correct, Chris. Yeah.
Great to have you on our podcast today. Circe's is a PQC vendor. We have already talked on this podcast about PQC, why it's important, so on and so forth. So I decided that it would be great to have Simon on specifically to get a real world expert's opinion and perspective on what's going on in this market.
Ken and I have already talked about this. We have a lot of questions. We're going to hit Simon with all the hardest things that you could ever imagine. We already told him that we wouldn't.
And really just wanted to have a general conversation. So, Ken, I know that you had a couple of questions. Why don't you start and then I'll throw a couple in there as well. Yeah, sure.
So, Simon, really great to meet you. And, you know, I think really the first question I really add is really kind of an introduction to PQC. And, you know, of course, we know what, you know, quantum cryptography is, you know, the ability for quantum computers to break current cryptography. But can you talk to us a little bit about the attack strategy that we're already seeing related to quantum with the harvest now decrypt later?
What exactly does that mean for you? What does that mean for enterprises? And what steps can they take to protect against that now? Yeah, thanks, Ken.
Nice to meet you, too. That's a very well-packed question. Let's put it that way. So post-quantum cryptography, as we all know, is when we finally get commercially available quantum computers having cryptography that is up to sustained attacks from that data being decrypted.
but what we're seeing at the moment as you said is the harvest now decrypt later approach that's that's happening with data loss and i think that the reason that's important to people is that people have realized that all of their information now has a value and so have the bad guys all the bad actors have realized that there's no such thing really as just a piece of sensitive information or sensitive data because all data could be argued to be sensitive and all data has a value.
And when they steal data in a currently encrypted format, what they're doing is they're banking on a day in the future when there's enough compute power with quantum computing to be able to break that encryption, today's encryption, and allow them to monetize the data that they've stolen. So the Harvest Now Decrypt Later is stealing your data today to monetize it later on and profit from it. And what we're looking at with the post-quantum cryptography is applying a set of data protection or data-centric security that is strong enough that even when quantum computing becomes generally available, your data is still protected.
So we're trying to give that sort of future runway and future to your data today so when the quantum computing world actually kicks in and I sure you going to ask me when that going to be the data is still protected. And that's really what CERTES has been doing for many years, pre-quantum algorithms being made available. And what we've done recently is apply the NIST-standardised post-quantum algorithms to the solutions that we've been selling to various customers for close on 20 years now, believe it or not.
Yeah, and I appreciate what you guys are doing. That's why we're actually here talking today. One of the biggest problems that I have, and when I talk to CISOs in general, is that one, they either believe that this is not really a thing that, Ken will tell you that there are, he actually talked with a CISO not that long ago that believes that QDay is actually a myth, that's something that's not going to happen. And I do not believe that, but there are others that out there that probably do believe such things.
But even apart from that, there's the conversation that this is someone else's problem, right? That this problem is so far off in the future that technology will have morphed a gazillion times between now and then that makes worrying about this today instead of worrying about, I don't know, whatever other cybersecurity issue you have today. And there's plenty. that it makes it almost kind of foolhardy to be doing this instead of taking and doing something else.
My question to you, Simon, is that I believe that we are way closer to Q-Day than most people, I think. And there's a lot of real concrete and anecdotal evidence to support that claim. But the question that I have for you, when you talk to your customers, when you talk to and evangelize on this subject, how do you convince people that this is something that needs to be worried about today and not tomorrow? I think there's two things in that, and people tend to mix these two things up.
There's the real and present danger today of data loss in its entirety, and then there's the future threat of quantum, which is going to render any encryption you use today completely useless. So there's really two things, and unfortunately most customers are kind of lumping the two things together and saying, well, quantum computers aren't going to be around for a while. Therefore, I don't have to worry about this. That's kind of what you're saying.
And they're ignoring the fact that their data is just walking out the door through CVE vulnerabilities and existing infrastructure that they don't deal with. And I think we've talked about in the past, Chris, that when people are looking at security or traditional security, they've looked at a defensive strategy they've looked at someone has identified this problem therefore I'm going to apply a patch so that problem doesn't hit me the problem with that is that that problem's had to exist before they can do something about it so they're always behind the game which means they're always vulnerable to losing data and data loss in a business is a business risk it can have financial reputational operational and legal aspects to it that could destroy a company and there's enough case history to prove that so there's a real and present danger today with data loss which is partly why the harvest now decrypt later is getting such a a lot of press but the future of quantum is real and people need to wake up to the fact that um that the leaps and bounds in technology are happening day in day out with the increasing qubits and the size of compute power of quantum computing that that date that mythical q date is getting closer and closer.
And I think it was only a couple of weeks ago that Google and Cloudflare came back with a reassessment of their own internal infrastructure that had to be quantum safe by 2029. And that's down from previously 2035 or 2040 that people were talking about. So that date is getting a lot closer. And it's not because quantum computing is getting that much faster It because they realising the amount of quantum computing power required to break existing cryptography is a lot less than they initially thought So you got a simplification of the algorithms from one side and an increasing compute power from the other.
And they're both resulting in that date getting a lot closer than most people think. But fundamentally, it's a business risk. And a business has to take a choice. You either do nothing and potentially be classed as negligent, or you do something and you fix the problem today.
Yeah, I completely agree with you, Simon. I mean, I guess at the end of the day, it's about complete cyber hygiene, right? When you start talking about data security, data security is one of those things that unfortunately, I think we overlook. Everybody knows that you have to have it.
Everybody classifies their data a little bit different, and everybody takes and classifies the risks associated with their data a little bit different. But the reality of it is, is that unless you're living under a rock, your data pose some level of risk to your organization, whether it be positive, negative. You wouldn't go through the efforts that you do to either protect it or collate it or back it up or classify it or whatever have you today if it posed no risk at all. Take whatever intellectual property your organization has.
You believe that that stuff is important to you or arguably you just wouldn't be in business. So again, in my way of thinking, this is basically a data security hygiene, data security 101 kind of thing. And this needs to be part of that conversation. Those that are not part of that conversation, as you mentioned, are going to be liable for the risks.
And those risks and those exploits are coming way, way faster, as you indicated, than we previously thought. There is, like I mentioned before, there is some anecdotal information that there might already in small scales on a state level, a national exploit level, already exist some level of quantum computing. And it wouldn't surprise me in the slightest. We'll see.
I'm not here to take and purport some kind of conspiracy theory. That's not what we're here for. But the goal is really to make people really aware of what's going on. And I don't feel that we are aware enough.
Yeah, I totally, totally agree. And I was just reading earlier today in some of the trade press that the University of Cambridge in the UK has just purchased its first quantum computer with 200 qubits, which isn't a huge amount. But it is a commercially available quantum computer that can mathematically work a lot faster than traditional computers. So they are real.
They are being sold today. It is a commercial thing. But coming back to something you said just now, the problem with our industry as a whole is that when you mention security, people automatically think network and infrastructure security because that's what they've done for 20 years. They've invested in routers and particular monitoring tools, and they see the quantum data loss as a network security problem.
And it's not. It's a business risk. It happens to run over the top of network infrastructure, but it's a business risk. Therefore, the C-suite of businesses have to take this seriously because they are the ones that are liable, in some cases, legally, personally and reputationally.
So it's a business thing. Simon, this has been an absolutely fascinating conversation. And, you know, so I know we're getting close to the end of the podcast, but I wanted to ask you. It's a two part question.
The first part is how, so traditional encryption really relies on the difficulty of factoring large prime numbers. How does post-quantum cryptography work differently than traditional encryption? And then finally, when do you think Q-Day is going to be? When do you think that this is actually going to be okay oh my gosh you know the technology is finally affordable and now we have to worry about this stuff actually happening See, we told Simon that we were just going to give him the easy questions, not the ones that were going to make his head spin, right?
Hey, I love making a prediction. I can do that. I can do that. So the differences between traditional, as you said, Traditional is basically around the mathematical calculations around very difficult to create prime numbers.
And that's something that's been sufficient for quite a long time. And there's certain algorithms that are still considered to be relatively safe in the short term. When we get to post-quantum, we change the way that those algorithms work and the way that the math's behind it. And it's more lattice-based approach on the algorithms.
but one of my hates really when we're talking about post-quantum is people focus just on the algorithm the algorithm is the mathematical path the important bit is the encryption keys that are used with that algorithm so we've got both true quantum random numbers we've got components of a key that are provided by the customer themselves to keep it sovereign and unique to them and you need to rotate those keys on a very regular basis so the whole post-quantum shouldn't just be looked at as purely the algorithms.
The algorithms are important, yes, because they are stronger and tougher to crack than traditional algorithms we've used for encryption. But it's also the combination of the algorithm with a very clever key management solution that keeps that data safe and keeps it from prying eyes. But on to my prediction. So I think last year I was saying that I believed that Q day was within five years.
So I was looking at the 2029, 2030 mark. Google's backing me up on that. What can I say? Great minds think alike.
You're being very, very, very optimistic. I think that it's actually going to be sooner than that. The rate of technical innovation at this point is so skewed. And I mean, no offense by this, Simon, but you're a graybeard like me.
When you look at innovation through our lens where innovations used to take somewhere measured in months or years, that is a reasoned and realistic outcome. But here in reality land, innovation is happening in days, if not hours, and it's faster and the velocity is greater than at any time in history. So I'll take your 2030 number, I'll acquiesce to it, and I'll say that it'll be then for sure or if not sooner. Yeah, and the great thing, Chris, is that people can do something about it today.
That's the whole reason that we as an organization exist. That's the sort of solution that we've been talking to customers about. So customers should not wait until Q Day to do something about this. There is a clear and present danger today, and there are solutions out there that can help customers mitigate those risks without having to wait for it to be either someone else's problem or for the mythical Q day to actually arrive anywhere between 2026 and 2030.
Yeah, again, I totally agree with you. I really appreciate you coming on the podcast today. Anybody who is interested in a really great PQC solution, head over to CERCES, C-E-R-T-E-S.ai.
You can take a look up stuff there. Simon, again, absolutely a pleasure to have you here today. Really love having real world experts on our podcast to give us a good perspective and make certain that we're not crazy. Ken, great to talk to you as always.
I hope that this has been a great podcast for you. And until next time, thanks for listening. Thanks, Chris and Ken, for all your great insights on today's topic. Make your next podcast awesome when you work with EMA security experts, Chris Steffen or Ken Buckler.
Educate your prospects, differentiate your solution, and add the credibility of a third-party expert to your message. Visit cybersecurityawesomeness.com to listen to past episodes.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.