The cybersecurity industry loves a roadmap. Faced with many difficult problems, we assess, discover, document, plan and eventually implement.
That makes sense for post-quantum cryptography (PQC). Organisations need to understand where cryptography sits, which applications depend on it, and what needs to change, but there is also a question that is often overlooked: what is protecting your sensitive data while all of that work is happening?
PQC migration is going to take years for many organisations. The data at risk does not have the luxury of waiting.
That creates what I call the “24-Month Exposure Gap”, and it may be one of the most significant weaknesses in current approaches to quantum readiness.
Planning is not protection
Cryptographic discovery is essential. You cannot manage what you do not understand. The problem is that discovery is often treated as the beginning of protection, when it is really the beginning of planning.
Our recent research, independently conducted by Freeform Dynamics, found that only 11% of organisations are confident they can achieve post-quantum readiness within expected timelines. That is hardly surprising when you consider what security teams are dealing with.
Cryptography is buried inside legacy applications, cloud platforms, business systems, third-party integrations and critical infrastructure. Some of those systems were designed decades ago. Rewriting applications or replacing infrastructure is expensive, disruptive and sometimes practically impossible.
Discovery and migration programmes can therefore take 18 to 24 months before meaningful change reaches the wider technology estate. During those 24 months, however, business carries on.
Customer information is exchanged. Payments are processed. Intellectual property moves between systems. Sensitive information passes through cloud environments and external partners.
The roadmap might be progressing beautifully. The data does not care.
The data is already at risk
This becomes particularly important when we consider “harvest now, decrypt later”.
An attacker does not need access to a cryptographically relevant quantum computer today to create a quantum-related data breach. They simply need to steal encrypted information, retain it and wait.
If quantum capabilities eventually make the encryption protecting that information vulnerable, data collected years earlier could suddenly become readable.
This matters enormously for information with a long shelf life.
Medical records, government information, intellectual property, financial records and commercially sensitive data can retain value for years or decades. An organisation might complete its PQC migration in 2030, but that does nothing to protect information stolen in 2026.
You cannot retrospectively encrypt data that has already left your control.
That is why I believe we need to separate two conversations that are too often treated as one: PQC readiness and quantum risk reduction.
The first may take years. The second should start now.
Start with the data that matters most
One of the things holding organisations back is the belief that meaningful action has to wait until every cryptographic dependency has been discovered, documented and mapped.
Complete visibility is important, but it should not become a reason to delay protecting the areas of risk you already understand.
Most organisations know which data matters most. They know which payment platforms are critical, which databases contain sensitive customer information, which identity systems would cause serious disruption if compromised and which operational systems the business cannot function without.
That is where action should begin.
Instead of asking, “How quickly can we migrate everything?”, security leaders should ask, “Where is our greatest data exposure, and how quickly can we reduce it?”
That changes the conversation.
PQC becomes a risk-based programme where organisations prioritise their most sensitive information and critical data flows while the broader discovery and migration process continues in parallel.
It also recognises a reality cybersecurity has been moving towards for years: infrastructure cannot be the only thing standing between an attacker and your data.
Security needs to follow the data
Applications will contain vulnerabilities. Credentials will be compromised. Cloud configurations will go wrong. Infrastructure will change. If protection depends on all of those things remaining secure, organisations are always one failure away from exposing the information attackers actually want.
We need to abstract security away from individual applications and infrastructure and attach protection to the data itself. That becomes particularly powerful in the context of PQC.
Instead of requiring every legacy application to be rewritten before stronger cryptography can be introduced, protection can be applied around critical data flows while the broader migration continues. The same principle leads us towards something even more important than a one-off PQC migration: crypto agility.
PQC is not the final cryptographic change organisations will ever make. Algorithms will evolve. Standards will change. Vulnerabilities will be discovered. What looks secure today may need replacing tomorrow.
We have already seen AI being used to accelerate cryptanalytic research. Assuming that any algorithm can simply be deployed and forgotten for another 20 years is increasingly unrealistic.
Organisations therefore need the ability to change cryptography without reopening application code or rebuilding infrastructure every time.
That is where the concept of a Cryptographic Abstraction Layer becomes important. By separating cryptographic protection from the applications and infrastructure underneath it, algorithms and policies can evolve while the systems carrying the data remain largely undisturbed.
Don't wait for the roadmap to finish
None of this means organisations should abandon cryptographic discovery or enterprise-wide PQC migration. Quite the opposite. Both are essential, but we should stop confusing preparation with protection.
If your PQC programme will take two years, ask what happens to your most sensitive information during those two years. If the answer is that it continues travelling through the same systems using cryptography you already know must eventually be replaced, you have an exposure gap.
Quantum readiness is a journey, but protecting critical data should not be something organisations leave until the end of it.
Start with the data that matters most. Reduce the exposure you already understand. Build crypto agility into the architecture. Then continue the migration because attackers are not waiting for your roadmap to be completed before they start collecting the data they hope to decrypt tomorrow.
Simon Pamplin
Simon Pamplin is CTO at Certes, the pioneer in delivering advanced cybersecurity solutions focused on Data Protection and Risk Mitigation (DPRM). Today, Certes extendis that leadership into the post-quantum era with a unique security platform that enables organisations to seamlessly protect legacy, cloud, hybrid, and edge workloads against both current and emerging quantum threats.


