Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Post-Quantum Cryptography: Preparing for the Quantum Threat

Commvault
03/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I can confidently state that many organizations are actively working on cyber-resilient strategies, plans, and runbooks that include not just their core infrastructure, but also the supply chain components of their business. But at the same time, not many seem to have given the risk exposure from post-quantum computing much thought yet. But having that as a general notion, it's probably because it's probably several years away. But the stark reality is that post-quantum cryptography is definitely on an accelerated timeline. Based on what you're seeing across the industry, what do you think the IT and security leaders should be asking of their technology vendors, their ecosystem players about post-quantum readiness? Yeah. So I'll probably start with everything being highly connected, whether they be ecosystems or infrastructure. We know everything is really going to be as strong as the weakest link. So it would be great to see other software and technology vendors really implementing post-quantum algorithms and post-quantum resistant encryption across the board to prevent widespread damage. Working with partners, we're starting to see forced security behavior. And I know that many of the customers that I talk to, they first feel uncomfortable about it. But at the end of the day, they understand that everyone's really trying to keep everything from left to right secure. I completely agree with you on that. And not just that, but I'm also seeing a massive resistance given the kind of performance overheads that post-quantum cryptography imposes. I mean, I can understand the fact that it certainly cannot be a strategy for all the data in an IT landscape. I can definitely see a hybrid cryptographic architectural deployment taking place where you would have the classical side coexisting with the post-quantum cryptography architectures. Certainly the word of the day is going to be crypto agility. And for me, I sum it up as the ability for a system to quickly and seamlessly switch to the most appropriate cryptographic algorithms or protocols. And with NIST constantly releasing recommendations and providing supportability for them, it's super important for our customers to be secure against these quantum threats. And we built our PQC implementation with crypto agility in mind. As we know, the quantum landscape is going to continue to evolve with better, faster, cheaper algorithms and machines. So it's really important that we provide and extend that capability as the threat landscape continues to change. And as you pointed out, like all encryption, there's some compute penalty. So having access to different algorithms and key links is important for us to balance the flexibility between having something that's super secure and something that is also cost effective from a compute standpoint. Makes perfect sense. So given what we just discussed, what would you think is the first logical, practical step for an organization as they start taking these baby steps towards quantum resistant security? I wouldn't frame it as out of possible, right? NIST has been providing guidance for a couple of years now. There's primary and secondary recommendations and we've already made them available. So we strengthen cyber resiliency for today, tomorrow and the foreseeable future because we built these frameworks. It is also worth mentioning that we don't need to understand quantum to enable PQC. We've made it super easy for our customers to implement it. So it's just a checkbox in a group configuration to get protected. But what I would say is if folks really want to start to get down that journey, I would say they should first evaluate long-term sensitive data to understand where they're going to actually use PQC, which again is why crypto agility is super important because you don't have to apply today, you could apply it tomorrow. But having that capability embedded is super important if you need to make quick pivots. And then sometimes you just discovered a whole bunch of sensitive data. So now you want to quickly have that protected with the latest algorithms. And again, security and cost could be part of that consideration. If you don't know where your sensitive data is, like we talked a lot to customers where they're like, I think I have something here. I know where a lot of like my super high sensitive data is, but I may not know where all of it is. We have capabilities like Cobalt risk analysis that allows you to do data discovery and classification so that you could apply the correct level of encryption to those particular scenarios. And if you don't know what your encryption levels are, you could leverage something like security IQ. So you can see like we're building this ecosystem around really having customers understand their data, understand their levels of encryption and where to find this information. And then again, PQC just becomes part of that. And one of the good things about our post-quantum cryptography as part of the platform or the security part of our platform, it's free. So as long as you're on CPR 2024E or newer, you can enable this immediately. So customers should still remain vigilant against data breaches and threats to the network on infrastructure or data silos. Again, exfiltration is one of those things that you may not be aware of, but you should remain vigilant against those things. And as you can see, like we're really building a solid frame of discovery, recommendations, implementation, and still making sure that customers deploy other controls so that we can provide that total cyber resiliency across the board.

TL;DR

  • Post-quantum cryptography is an accelerated threat arriving in 5-10 years, yet most organizations haven't begun planning for quantum-resistant security despite active cyber-resilience initiatives.
  • Crypto agility—the ability to quickly switch between cryptographic algorithms—is essential for adapting to evolving quantum threats and NIST recommendations while balancing security with performance costs.
  • Organizations should start by discovering and classifying long-term sensitive data, then implement hybrid cryptographic architectures that allow selective application of post-quantum encryption where it matters most.

Summary

This discussion addresses the urgent need for organizations to prepare for post-quantum cryptography (PQC) threats, which experts predict will materialize within 5 to 10 years. Despite widespread focus on cyber-resilience strategies, most organizations have not yet considered quantum computing risks. Commvault experts explain that the quantum threat timeline is accelerating, making it critical for IT and security leaders to evaluate their readiness now. The conversation covers the performance challenges of post-quantum encryption algorithms, the importance of crypto agility for seamless transitions between classical and quantum-resistant security, and practical implementation steps including data discovery, classification, and risk analysis. The experts emphasize that hybrid cryptographic architectures—where classical encryption coexists with post-quantum solutions—will become the standard approach, allowing organizations to balance security requirements with computational costs while maintaining flexibility as the quantum landscape evolves.

Chapters

0:00 - The Post-Quantum Readiness Gap
0:52 - Vendor Ecosystem Responsibilities
2:06 - Crypto Agility and Implementation
3:27 - Practical Steps for Organizations

Key Quotes

0:20 "Not many seem to have given the risk exposure from post-quantum computing much thought yet."
0:34 "The stark reality is that post-quantum cryptography is definitely on an accelerated timeline."
1:52 "I can definitely see a hybrid cryptographic architectural deployment taking place where you would have the classical side coexisting with the post-quantum cryptography architectures."

Categories:
  • » Webinar Library » Commvault
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Data Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Compliance & Governance
  • Technical Deep Dive
  • Best Practices
  • Post-Quantum Cryptography
  • Crypto Agility
  • Quantum Computing Threats
  • Data Classification
  • Hybrid Cryptographic Architecture
  • NIST Standards
  • Cyber Resilience
  • Encryption Performance
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Post-Quantum Cryptography: Preparing for the Quantum Threat

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version