Businesses may have years to prepare for quantum-powered cyberattacks. The problem is that some of their technology may never be ready.
Aging infrastructure, tight budgets and hardware that cannot be upgraded to support post-quantum cryptography could leave parts of customer environments vulnerable long after organizations begin protecting their most critical systems, security experts told CRN.
That creates a difficult question for MSPs and their customers:
What happens when the technology still works, but the encryption protecting it no longer does?Legacy technology could become a long-term security problem
Much of the post-quantum security conversation has focused on replacing encryption algorithms before sufficiently powerful quantum computers can break widely used cryptography.
But changing the algorithm may only be part of the challenge. Many organizations still depend on older systems because replacing them is expensive, disruptive or simply unnecessary from an operational standpoint. Some of that technology may continue performing its intended function for years while becoming increasingly difficult — or impossible — to secure against future quantum attacks.
Jason Soroko, senior fellow at Sectigo, expects fully operational legacy systems to remain insecure well beyond 2035. Some older systems simply cannot be upgraded to support post-quantum cryptography, according to the report.
That leaves organizations facing an uncomfortable tradeoff: replace technology that still works, or accept a growing security risk.
And for many customers, the decision may ultimately come down to money.
The perfect migration plan may collide with the budget
Organizations can build ambitious roadmaps for moving to post-quantum security. Executing them is another matter.
Timothy Hollebeek, industry technology strategist at DigiCert, believes that migration projects are likely to follow a familiar pattern: organizations begin with an ideal plan, scale it back to a minimum acceptable version and then reduce it again to fit available budgets. Projects may also take considerably longer than expected.
That means protecting everything at once may not be realistic. Instead, customers will need to determine which systems must be upgraded first, which can remain in service temporarily and which risks they may have to tolerate.
One factor could be the lifespan of the data itself. Rob Gregory, CISO at Optiv, pointed to “data shelf life” as an important consideration. Some information loses value relatively quickly, while other sensitive information could remain useful to attackers for years, making it a higher priority for post-quantum protection.
That turns post-quantum migration from a simple technology refresh into a much larger risk-management exercise.
The head fake: This may become a hardware story
At first glance, post-quantum readiness sounds primarily like a cryptography and software problem. It may ultimately become a major hardware replacement cycle.
The Cybersecurity and Infrastructure Security Agency has already identified categories of products using post-quantum standards, including routers, switches, firewalls, storage appliances and some peripherals.
Chesley Choudhury, founder and chairman of TanChes Global Management, noted that the transition therefore represents a significant hardware opportunity for the channel.
For solution providers, that changes the conversation. A post-quantum assessment may not end with a software update. It could reveal networking equipment, appliances and other infrastructure that cannot be brought forward at all.
And that creates another question:
How much of a customer's environment will ultimately need to be replaced rather than upgraded?MSPs could have years of migration work ahead
Some security experts express optimism that organizations will protect their most critical assets before quantum systems capable of breaking today's encryption become available.
But they also expect a substantial amount of legacy technology to remain vulnerable for much longer. That gap could create an important role for MSPs and other solution providers.
Providers can help customers inventory cryptographic dependencies, identify systems that cannot support new standards, evaluate the lifespan of sensitive data and build migration plans around business risk rather than attempting to replace everything at once.
The opportunity may extend well beyond cybersecurity consulting. It could drive hardware refreshes, infrastructure modernization, advisory services and ongoing cryptographic management across customer environments.
Post-quantum cryptography is also moving higher on the agenda. The issue is increasingly resurfacing in conversations with CISOs as organizations evaluate their risk profiles and decide where to allocate resources.
For MSPs, that means the post-quantum transition may not be a problem to worry about someday.
The migration decisions — and the business opportunities surrounding them — are beginning now.Source:
CRN