Quantum Deadline Looms as Firms Struggle with Cryptography Management
IBM's Sourabh Mallick, ASEAN technical sales leader for data security and quantum safe, warned that the deadline for replacing cryptography vulnerable to quantum threats is approaching. According to him, discovery isn't just about finding assets but also about identifying gaps in accountability.
The team found digital certificates renewing themselves on schedule, year after year, attached to systems nobody could identify. The real red flag was that everyone assumed someone else owned them. This unowned certificate is one piece of four: an inventory most companies cannot produce, a compliance clock already started, and a migration path that breaks systems nobody has load-tested.
The quantum threat comes from two mathematical discoveries: Shor's algorithm, which can quickly solve problems that classical computers cannot, and Grover's method, which speeds up guessing. The remedy is to replace the first family of cryptography, which includes RSA and Diffie-Hellman algorithms, with new standards like ML-KEM and SLH-DSA. However, this process has been delayed due to a lack of budget allocation.
According to IBM's research, most organizations cannot yet describe their own cryptography, and only 21 out of 100 scored well on a readiness index. The same executives estimated that implementing quantum-safe standards would take 12 years, starting from where they stand today.