85% of security leaders believe quantum computers will break existing standards.
Simon Pamplin, CTO of Certes
Following the insights released by DigiCert into why the deployment of quantum-safe certificates at scale is greatly lagging awareness of the threat, US government mandates, and large corporate transitions, Simon Pamplin, CTO of Certes, commented:
These findings highlight a growing disconnect between awareness and action. If 85 per cent of IT and security leaders believe quantum computers will break today’s encryption within the next decade, yet only 7 per cent have deployed quantum-safe solutions at scale, it’s clear that organisations understand the risk but are struggling to turn strategy into execution.
What’s particularly concerning is that more than a third of UK organisations believe over a quarter of their encrypted data is already vulnerable to ‘harvest now, decrypt later’ attacks. For organisations handling financial data, customer records and personally identifiable information, this is no longer a future planning exercise. Data being stolen today will be exposed years from now if it isn’t adequately protected.
The biggest obstacle isn’t awareness, it’s the absolute complexity of implementing cryptographic change across legacy applications, hybrid environments and edge infrastructure that were never designed with crypto agility in mind. That’s why organisations need to stop thinking about post-quantum cryptography as simply replacing algorithms. They should be focusing on protecting the data itself with a data-centric, crypto-agile approach that reduces risk today while creating a practical path to long-term quantum readiness.
Editor’s note: Simon Pamplin, CTO of Certes, will be speaking at PQC+IQT, which is coming to New York City October 25-26.



