
The Authority On... · 2025-12-15 · 12 min
Key moments - from our scoring
Substance score
36 / 100
Five dimensions, 20 points each
The episode addresses post-quantum cryptography as an imminent security concern, not a distant future problem. Jim Walker explains that attackers are already executing "harvest now, decrypt later" attacks, capturing encrypted data today that will become readable once quantum computers mature - making this a current threat for any data requiring confidentiality beyond 10-15 years. The conversation covers why organizations struggle with the transition: cryptographic algorithms are embedded across TLS, VPNs, code signing, PKI hierarchies, and countless legacy systems with incomplete documentation. Walker emphasizes that crypto agility - the ability to swap algorithms and key sizes without breaking systems - is essential. IoT and edge devices present special challenges due to constrained hardware, long lifecycles (7-15 years), and limited update paths. The discussion centers on practical migration strategies: inventory your cryptographic assets first, establish flexible PKI and key management systems that support hybrid deployments, then execute phased rollouts. For organizations managing critical infrastructure, healthcare, or financial data, this isn't optional - NIST standardization work and government guidance make it a regulatory imperative.
Attackers capture encrypted sensitive data today knowing that once quantum computers mature, they'll be able to break today's public key encryption in seconds, making the data readable in hindsight. This makes quantum risk a current threat for any data requiring confidentiality for 10-15+ years.
Cryptographic algorithms are embedded across dozens of systems (TLS, VPNs, code signing, PKI hierarchies) over decades with incomplete documentation and no centralized visibility. Organizations must inventory their crypto landscape, establish flexible key management to support hybrid deployments, and execute phased migration without disrupting critical services.
These devices have constrained hardware, long lifecycles (7-15 years), and limited or expensive update paths. If deployed with algorithms that can't be upgraded, entire fleets become stuck in the pre-quantum era, requiring costly forklift replacements in remote locations.
Crypto agility is the ability to swap algorithms, key sizes, and certificate profiles without breaking systems. Building this flexibility into PKI, key management, and application architectures now allows organizations to deploy hybrid classical and post-quantum solutions during the coexistence period.
Start with a complete inventory of where cryptography lives across applications, devices, protocols, and certificates - including legacy and shadow IT systems. Only with this map can organizations build proper PKI flexibility and execute a realistic migration strategy.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers a handful of legitimate PQC concepts (HNDL attacks, crypto agility, IoT lifecycle risk) but at a shallow depth; most claims are well-known in security circles and the 12-minute runtime is further diluted by repetition and sign-off outtakes.
attackers don't need to work in quantum computer today to create this risk. They just need to capture the sensitive encrypted data now
If you don't have that map, everything else is really guesswork
Every talking point - harvest-now-decrypt-later, NIST standardization, crypto agility, inventory-first - is standard PQC boilerplate that has circulated widely since at least 2022; there is no contrarian angle, no first-principles framing, and no unexpected insight.
NIST post standardization work, national strategies, and sector-specific guidance are all sending a clear signal. Start planning now
Inventory first, then strategy
Jim Walker is a General Manager of Service Delivery at a solutions partner, a relevant but mid-tier practitioner role; he speaks competently but without the depth of a CISO, cryptographer, or standards-body participant who has operated at scale on this problem.
you always you start thinking about maybe the the Marvel movies with Ant-Man and the quantum realm
That's where strong partners and platform-driven architecture matters
A few concrete timeframes are given (7 - 15 year IoT lifecycles, 10 - 20-year data sensitivity windows) and a useful list of protocol categories, but no NIST algorithm names, no customer case studies, no dollar figures, and no threat-actor or incident data are provided.
these devices tend to have long life cycles, 7, 10, sometimes 15 years
You've got TLS, VPNs, code signing, document signing, S-MIME, device identity, API security
Questions are pre-scripted softballs that function as topic prompts rather than genuine probes; the host never challenges a claim, asks for evidence, or follows up on vague assertions, and the session reads as coordinated partner marketing rather than an interview.
quantum computing still feels very futuristic to many people, but security leaders are treating it as urgent. Why are they growing concern right now, do you think, Jim?
Yeah, that's great advice, Jim
Computed from the transcript - who did the talking, and the words that came up most.
Device Authority's Molly Marks welcomes back Jim Walker from Olympus Solutions to discuss one of the hottest topic in cybersecurity and further afield - Post-Quantum Cryptography.
Transcribed and scored by The B2B Podcast Index.
Welcome to The Authority On, a podcast brought to you by Device Authority. Welcome to The Authority On, the podcast from Device Authority, where we explore the technologies and trends, redefining cybersecurity and digital trust. I'm your host today, Molly Marks, Senior Director of Partner Sales at Device Authority. And today we're talking about one of the biggest shifts on the horizon, post-quantum cryptography.
Joining me again is Jim Walker, General Manager of Service Delivery at Olympus Solutions. Jim, it's great to have you back on The Authority On. Hey, Molly. Hey, it's great to be back and continue the conversation.
So, you know, as you know, post-quantum is one of those topics that sounds very theoretical until you realize a lot of the systems we're deploying today are still going to be running when practical quantum attacks show up. So the decisions people make now about certificates, keys, and architectures are either putting them on a smooth glide path or setting themselves up for a very painful scramble later. Yeah, you know, quantum computing still feels very futuristic to many people, but security leaders are treating it as urgent.
Why are they growing concern right now, do you think, Jim? Yeah, you know, Molly, it's an interesting topic in that regard because it's hard to get folks' attention because you hear quantum. And, you know, you always you start thinking about maybe the the Marvel movies with Ant-Man and the quantum realm. Right.
It feels very sci fi. But but in all honesty, the risk model is very real. You know, the first big issue that we're seeing today and these attacks are happening today are the harvest now and decrypt later problem or handle attacks. You know, in those particular cases, attackers don't need to work in quantum computer today to create this risk.
They just need to capture the sensitive encrypted data now, things like long-term intellectual property, medical records, national security data, long-lived credentials, and they just store it because they know once a quantum computer is viable and mature enough, they'll be able to break today's public key algorithms in seconds, and then that data becomes readable in hindsight. So for any data that needs to stay confident for 10, 15, 20 years or more, the quantum risk is effectively a current threat and not a future one.
Second, we've got very long-lived systems, typically IoT and operational technology devices, that will be in the field for a decade or more. They often run constrained hardware, have limited update paths, and are hard or expensive to replace. If those devices are deployed with crypto that can be upgraded or can support quantum algorithms you baking in technical debt that very hard to unwind And third this isn just a vendor or marketing push Governments and standards bodies are driving this very hard NIST post standardization work, national strategies, and sector-specific guidance are all sending a clear signal.
Start planning now. So the urgency comes from that combination. Attackers already harvesting data, long-lived systems that are hard to change, and a very clear signal from regulators in the industry and standards bodies that wait and see is not a responsible strategy. So the risk just isn't about future quantum computers, but about the data being stored today that might be decrypted tomorrow.
Exactly. Exactly. It's less someday quantum will be scary and more and more. We're already laying down records that quantum will be able to read.
If your organization has any long-term sensitive data, government, healthcare, critical infrastructure, financial, you have to assume that some of it is being collected and collected by someone with a longer-term horizon than your current budget cycle. Post-quantum is about making sure that that data is still protected when that day comes. And so what makes the move to post-quantum photography so complex for organizations? So, you know, if there were just a flip one algorithm and you're done, we probably wouldn't be having this conversation.
You know, the complexity comes from the sheer amount of legacy cryptography that's been quietly embedded everywhere for decades. You've got TLS, VPNs, code signing, document signing, S-MIME, device identity, API security, and any number of PKI hierarchies, all built on classical algorithms. In many organizations, nobody has a complete map of where that cryptography is used, how it's configured, and which systems depend on it. It's fragmented key management at scale.
That's why crypto agility is such a big theme. You need the ability to swap out algorithms and key sizes, introduce hybrid or post-quantum algorithms and roll these changes through your environment without breaking everything. If your crypto is hard-coded, brittle, and undocumented, transitioning to post-quantum becomes a huge risk. Then there's the coexistence period.
We're going to live in a world where classical and quantum-safe algorithms run side-by-side for quite a while, and protocols, certificates, and devices. This means your infrastructure needs to handle hybrid certificates, new algorithms or new algorithm suites, and new key management patterns. So the real challenge isn just adopt post and it good It really you got to discover where your cryptography lives establish that inventory modernize your PKI and key management so that it agile and capable of supporting both and then execute a phased migration that doesn't take down your critical services.
That's where strong partners and platform-driven architecture matters. Doing this system by system manually with spreadsheets is really a good way to burn out your security teams and still miss the important stuff. You know, it sounds pretty daunting, but really that's where visibility and automation become essential. You need to know where cryptography is used before you can modernize it.
Exactly. Inventory first, then strategy. If you try to jump straight into let's roll out post-quantum everywhere without understanding your crypto landscape, you'll either move so cautiously that you don't reduce risk at all, or you'll move so aggressively that you cause outages. Neither is a great career move.
So the organizations that do this well are the ones that treat crypto like an asset that needs lifecycle management and not just a checkbox and a config file. That's really true. And then, you know, IoT and edge environments already have unique challenges today. So how do you fit into the how did they fit into the post-quantum discussion?
They're right in the middle of the blast radius. You know, IoT and edge devices often have limited processing power, memory, and bandwidth. That makes adopting new, sometimes heavier algorithms, and in this case, likely heavier algorithms, more challenging. You don't have the luxury of just increase the CPU and RAM on a sensor that's bolted to the side of a bridge.
You know, on top of that, these devices tend to have long life cycles, 7, 10, sometimes 15 years. So if you deploy them with crypto that can't handle post-quantum or can't be updated, you may end up with entire fleets of devices that are effectively stuck in the pre-quantum era. That's why lightweight post-quantum algorithms and efficient protocol designs are going to be critical. You need approaches that are secure against quantum threats but still realistic for constrained devices.
Then there's the update problem. How do you securely deliver firmware updates? How do you route credentials and keys at scale? How do you prove that a device is running the expected trusted software stack?
You need secure update and credential rotation strategies baked in from the start with strong device identity and attestation. Not just, we'll push some firmware when we get around to it. Designing for crypto agility now is by far the cheapest, most cost-effective thing you can do. If you architect your IoT and edge environments so that they can support new algorithms and certificate profiles without a forklift replacement you really bought yourself some options If you don your future self will be sending some very expensive trucks to some very remote places Exactly No one wants to be replacing devices in a few years because they can't handle new encryption standards.
Right. Nobody wants the quantum tax to show up as a surprise hardware refresh bill. A little architectural discipline now goes a long way later. So, Jim, if you could give CISOs and architects one piece of advice about preparing for post-quantum, what would it be?
You know, Molly, I'd cheat and give them a two-part answer. You know, first, I'd start with the inventory. Know where your cryptography lives, what apps, what devices, which protocols, you know, which certificates. And that includes your shadow IT, legacy systems and that temporary service that somehow became mission critical.
We all have them. If you don't have that map, everything else is really guesswork. And second, build agility in now. Even before you touch post-quantum algorithms, make sure your PKI key management application configs are flexible enough to support the change, hybrid deployments, new algorithm suites, and phased rollouts.
And if you can get to a place where changing crypto is a managed, repeatable process, instead of a bespoke adventure every time, you're really in a great position. Then as the post-quantum standards mature and vendors ship support and things continue to mature and shift, you can move with confidence instead of panic. Yeah, that's great advice, Jim. So future-proofing trust really just comes down to understanding your current landscape.
100%. If you know what you have and you're designed for change, post-quantum becomes a roadmap problem and not a crisis. Jim, I want to thank you again for joining us and for such a practical look ahead at what's coming. I don't know why I have to do this again.
Okay. So, Jim, thank you again for joining us and for such a practical look at what's ahead in post-quantum cryptography. cryptography. And to our listeners, thank you for turning into The Authority On to learn more about how Device Authority and Olympus Solutions are helping organizations prepare for the next era of digital trust.
If you'd like to learn more, please visit our notes section and you can find our websites there. I'm Molly Marks, and this has been The Authority On Post-Quantum Cryptography. Stay secure and we'll see you next time. Thank you for listening to this episode of The Authority On, a podcast brought to you by Device Authority.
If you have any questions about the subject matter in this podcast, please head to the Device Authority website, deviceauthority.com. See you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.