Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Quantum-Safe Cryptography: Zscaler's Post-Quantum Strategy

Zscaler
07/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


we are here to talk about a very exciting topic, post-quantum cryptography. See, over the last few years, there are two big topics which we all hear. There isn't a conversation where AI doesn't come in, but we are starting to see quantum as another big topic of interest for our customers. And that's a space where we have been laying a lot of investments over the last few years in the research and in terms of the overall architecture and how we think about making our customers quantum safe and eventually become a trusted partner for them in the migration to the post-quantum era. And this is a space where a lot of advancements have happened in the industry over the last few years. And joining us is our Chief Scientist, Alex Lowe. You've spent a lot of time on these topics in many industrial events. Tell us a little bit about how is quantum computing accelerating and how is that changing? Thank you very much, Satish. So quantum computing itself is not a new concept. Quantum computing has been around as an idea for decades. However, until recently, it remained as a very theoretical physics subject. What we have seen recently is many organizations, both commercial and public entities, started to invest literally billions of dollars into quantum computing. The quantum computing promises us to give significant advantages in solving problems such as training of AI models, doing environmental studies, solving problems associated with big systems. However, as we know, quantum computing is also posing threats to cryptography. Many cryptographic algorithms that we use widely today will be trivially solved by sophisticated large enough quantum computer. Have you heard specific concerns from the customers regarding threats of quantum computing specifically for cryptography? Yes, absolutely. So what I've heard is just like AI, there's good side to it and people leveraging that for bad use as well. From a customer standpoint, this has definitely been a big conversation. What we have seen bubble up over the last year or so. I think we primarily see this for three different reasons. One is we are all aware of the big investments from large organizations in the quantum chips. Every time there is a new headline in the news, we often get this question from customers, when is the big Q&A coming up? That's the million dollar question which customers want to know, are we there yet? I think the investments in quantum computing, which they constantly see in the market, is driving this need for this conversation more. The second topic, what we often see is from the client side adoption. We have seen some of the mainstream browsers like Chrome have adopted the latest quantum key exchange algorithms over the last year. So as that picks up speed, customers have noticed that this is happening in my organization now, so they're starting to think about what does my migration path look like to the post-quantum world. The third point is really about the regulations. As Zscaler, we have many large 1,500 financial sector customers. What I'm starting to see is they have been asked by regulatory needs, they've been asked to put a formal process on their quantum migration plan. So things are picking up speed and rapidly evolving in this space. But there's a lot happening in the NIST space as well. And I know you actively participate in IETF, the Incoming Internet Architecture Board, and NIST as well. Tell us a little bit more about what does FIP 203 mean? What does the standard really mean? Look, before we dive into those lovely details of specific cryptographic standards and regulations, I would like to take a step back and cover a little bit on what exactly is the threat. There is a very common misconception that quantum computers will make all our current cryptography irrelevant, and that is not correct. Only two components of all the complicated cryptographic stack that we're normally using today will be affected by quantum computers. So one is key exchange, and the second one is digital signatures. Now, when it comes to key exchange, that is perceived as the more urgent problem. We don't yet know when large enough quantum computers that will be able to break modern cryptography arrive. Researchers are working hard on building large enough quantum computers, but there are many fundamental problems that they need to solve. There is a common guesstimate that quantum computers that would be large enough might arrive by 2030, but it could happen next year. It could happen by 2050. We don't know exactly when. Now, a specific problem when it comes to threats of quantum computers for key exchange is the so-called harvest-now-decrypt-later attack vector. So if an adversary would be able to capture communication that is strongly encrypted today, the adversary cannot do anything meaningful with this communication. They can store those packets for a long time, and once a large enough quantum computer will be available, as long as they have captured this initial key exchange, they will be able to open up that key exchange and decrypt the rest of the communication. So if the data that you're transmitting today over a strongly encrypted channel will still be relevant when a quantum computer arrives, then, of course, that will create threats to organizations. So let's say if you're transmitting financial information, medical records, or other regulatory sensitive or personally sensitive information that will still be very sensitive by when quantum computers arrive, whenever it happens to be, you certainly want to adopt post-quantum key exchange or key exchange algorithm that is as strong against attacks from quantum computers as it is from classical computers as soon as possible. And that is one of the reasons why regulators started accelerating the pace and why we see adoption of post-quantum key exchange in modern web browsers. The second part of the problem that quantum computers will bring for modern cryptography is digital signatures. Digital signatures are everywhere. It's not just X.509 certificates that we use on public internet so that you know that you're connecting to a correct website. It's not only user certificates. Digital signatures are everywhere. When you unlock a modern car, you actually use elliptic curve signatures. When you're using credit card transaction, it's also authenticating using elliptic curve signatures and all of that would need to be replaced. The good news, it's not as urgent problem as it is for key exchange because there is no retrospective attack vector here. If I will be able to forge certificate and present myself to the world as Satish, if that certificate was valid 10 years ago and is no longer trusted, then well, there is no damage I really can do with that. Right now, the industry is very focused on adoption post-quantum key exchange as a priority to make sure that whenever quantum computer will actually arrive, all data that we're transmitting today will stay safe and secure. Does this reflect what you hear from customers? Do they express this concern when it comes to Harvest Now Decrypt Later attack vector? Absolutely. I think you kind of highlighted the key concerns about this. I think the fact that Harvest Now Decrypt Later doesn't necessarily require a quantum computer to be available today and then the notion of somebody harvesting your data today is what is top of mind in terms of quantum specific threats for our customers. See, in general, what we have seen is quantum cryptography, the whole conversation was very early in the primary conversations. Customers used to ask us, what is Zscaler strategy around this? I've seen the shift from there to this being part of the regulatory requirements, being an active requirement in the very early engagements about finding the right solution to enable them on zero trust journey. Another way of saying this is really, it has really come out of being in sci-fi homegrown science project to kind of really coming out and then being seen in the real world, right? So what we kind of see is different customers are at different places. Based on each vertical, we hear different things. But if I have to pick some three common themes on what we hear, what's top of mind, what is the problem they're trying to solve? I think the first problem is really about getting that visibility into what does my crypto inventory look like? You called about all of this current ciphers, right? The standard ciphers, whether it's RSA or elliptical curve, there are a lot of applications which use that today. Those are the mainstream encryption algorithms. But if Chrome and other browsers are starting to adopt this, they need to really understand and build that inventory in-house, essentially build that crypto bill of materials to get visibility into these are my applications. That's the question they're asking themselves. I need to get a good understanding of what does my crypto inventory look like? And then let me go through the journey of prioritizing the most important ones and start going on to the quantum PQC migration journey. So that's the first question. And the second question really comes back to harvest and decrypt later, right? So if somebody is really harvesting my data right now, how do I mitigate this? So the question really here is, do I have a security solution which can really talk the latest quantum ciphers, the ones which are the most, which are standardized by Nest? And at the same time, we often get this question about just like every other technology transition, we have seen this, whether it's from IPV4 to IPV6, it can take a long time. The concept of, are you as a security solution able to support the classic ciphers and then the quantum ciphers at the same time? So customers understand that this is going to be a long journey. So we have seen this play out very well, where for a large complex organization, trying to build a crypto inventory can take more than a year, right? So while doing that, how do I make sure that I am secure and I'm having inspection for security reasons done with the latest quantum ciphers and mitigate that harvesting threats? That's two. And then the third piece is, how do I make sure my secure connectivity from the get-go, from my client, from my end user device, or even from my branch location, going out in terms of Zscaler, these are all Zscaler customers, send the traffic to Zscaler, how do I make sure my first leg of communication is secure as well? I think we have made significant investments in the space. Last year, we announced the visibility aspect. We have many large customers who now have built crypto bomb and inventory based on the visibility, what we provide for all of the traffic without any additional configuration needed on their side, a centralized view into their crypto inventory. Now, what we are really excited about is the second phase of we as Zscaler Zero Trust Exchange talking and using the quantum safe algorithms, right? That means that between the client and the server, we start using on both ends, wherever the client and the server support, we can start using quantum safe algorithms and help mitigate the quantum, the harvest node decrypt threats. So a lot of interesting innovation happening in this space, really excited for the big launch, which is coming up in a few weeks from now. So I think that's when we really talk about and want to really showcase how we can do things in action. That sounds really exciting. One area that I particularly like about Zscaler approach when it comes to visibility is that unlike traditional inventory solutions that just crawl through all the software on all the endpoints, probably missing something, probably building an inventory of some software that just lies dormant, Zscaler has access to the ground truth, to actual packets on the wire. So what is being used for communication and helping customers prioritize, not just some theoretical threats to some software that is not in action, but something that is being actively used for communication, especially when it comes to transfer of confidential sensitive data. When it comes to adoption of post-quantum key exchange, post-quantum ciphers, on one hand, we're in reasonably good place as an industry. There is now a very well-defined standard, originally finalist of NIST competition, so ML-CAM or FIPS-203, that is intended to essentially replace Elliptic Curve Diffie-Hellman key exchange, providing a way to establish a shared secret between two parties that would be as secure against attacks from classical computers as it is from attacks by quantum computers. However, many regulators and many industry bodies believe that this new ML-CAM algorithm is still quite young. It's 15 years old, the module lattices cryptography is about 15 years old, which is relatively young by cryptographic standards. So the way that industry recommends deployment of this algorithm is in so-called hybrid mode, when it is combined with classical Elliptic Curve Diffie-Hellman. So the attacker would need to crack both ML-CAM and Elliptic Curve Diffie-Hellman with fMRL key exchange, so that provides additional security guarantees for communicating parties that their data is staying confidential, even in the unlikely event that there is some flaw discovered in ML-CAM or in particular implementation of ML-CAM. And then one final note that I'd like to add here is when it comes to Zscaler approach and particularly because we are cloud service, we embrace cryptographic agility, meaning that if something happens in the regulatory space, if for example regulators will decide that we really need to drop this hybrid approach and go full speed ahead on ML-CAM or higher tier ML-CAM is required or there is a new exciting key exchange mechanism that is now recommended, we will be able to adapt very quickly because of our cloud scale and because of our software agility. Absolutely, I think these are a couple of points. What we are hearing from customers is the fact that there is no new crawling or new agents to be deployed to build that inventory, just because of the architectural advantage what we have with Zscaler being a service in the cloud. For all the inline traffic, we do this automatically, build a comprehensive report for them, makes it easier operationally. And number two is that the scale at which we can operate for them. Imagine trying to do this inspection with the latest quantum ciphers and doing the key exchange at that scale in trillions of transactions on a daily basis. That's the advantage both from simplicity standpoint and scale what we bring to the help our customers really have that simplified migration path and we become a trusted partners on their post-quantum migration journey. What makes Zscaler approach to post-quantum cryptography special? Yeah, I think there are quite a few things here. See at the core of it, I really believe that it's the Zscaler architecture which we have built this on really makes it very compelling and easy for customers to go on that migration journey. So when we launch the capability to do the discovery and build that visibility into their crypto inventory last year, we have received a tremendous positive positive feedback on how simple it was for a large enterprise to build the crypto inventory across all of their devices and users just over a period of few weeks. So I think that notion without having the requirement to install a net new agent or do the whole process of crawling across their organization infrastructure makes it very simple and easy for our customers to leverage it. And then the second piece is the scale at which we can do this, right? Imagine we're talking about large enterprises who have transactions in billions, how do we kind of handle at that scale while we are doing SSL inspection with the latest quantum safe ciphers? So I think that scale and simplicity is what our customers have really given a very positive feedback on and it's very interesting and where we are going from now here is we completely understand, as you were saying, it's a hybrid world which we're going to live in where there will be classic ciphers. Now RSA elliptical curve will continue to exist and the ML chem, the quantum key exchange algorithms. We want to give the flexibility to our customers. We have a wide range of customers across different verticals. We understand one size doesn't fit for all. We want to give the flexibility to our customers and to pick and choose what specific ciphers would they want to use for the inspection capabilities what we offer. I think that flexibility when you combine that with simplicity and scale just makes it very compelling and we really have invested in this space to make the become the trusted partner for our customers to take on that big journey of the post-quantum migration, right? We want to make that migration as simple and easy for them.

TL;DR

  • Quantum computers threaten current cryptography through harvest-now-decrypt-later attacks, where adversaries capture encrypted data today to decrypt once quantum computers arrive, making immediate action necessary for sensitive data protection.
  • Enterprise quantum readiness is accelerating due to three factors: major quantum computing investments, mainstream browser adoption of post-quantum algorithms, and regulatory mandates requiring formal migration plans, particularly in financial services.
  • Zscaler provides quantum migration capabilities through automated cryptographic inventory discovery, hybrid classical/quantum-safe cipher support, and cloud-scale inspection using ML-KEM (FIPS-203) without requiring new agents or infrastructure changes.
  • The platform's architectural advantage lies in analyzing actual network traffic for ground truth cryptographic visibility, enabling enterprises to complete crypto inventory assessments in weeks and prioritize migration based on real-world usage patterns.
  • Zscaler's cryptographic agility allows rapid adaptation to evolving post-quantum standards, supporting flexible cipher selection across different verticals while maintaining performance at scale for trillions of daily transactions.

The Quantum Computing Threat to Modern Cryptography

This discussion explores the emerging threat quantum computing poses to current cryptographic systems and Zscaler's approach to helping enterprises prepare for the post-quantum era. Chief Scientist Yaroslav Rosomakho explains that while quantum computing has existed as a theoretical concept for decades, recent billion-dollar investments from commercial and public entities are accelerating its development. The primary cryptographic vulnerabilities lie in key exchange mechanisms and digital signatures, with the harvest-now-decrypt-later attack vector presenting the most urgent concern. This threat allows adversaries to capture encrypted communications today and decrypt them once quantum computers become available, making immediate action necessary for organizations transmitting sensitive data like financial records or medical information.

Customer Concerns and Regulatory Pressures

Senior Director Satish Madiraju identifies three key drivers pushing quantum readiness to the forefront of enterprise security planning. First, high-profile announcements about quantum chip development create urgency around the question of when cryptographically relevant quantum computers will arrive. Second, mainstream browser adoption of quantum-safe algorithms, particularly Chrome's implementation of post-quantum key exchange, signals that the transition is already underway in production environments. Third, regulatory requirements are forcing action, with financial sector customers being mandated to develop formal quantum migration plans. Customers consistently express three primary needs: visibility into their cryptographic inventory, the ability to support both classical and quantum-safe ciphers during the transition period, and secure connectivity using post-quantum algorithms from endpoints to cloud services.

Zscaler's Architectural Advantage for Quantum Readiness

Zscaler's cloud-native architecture provides distinct advantages for quantum migration compared to traditional security approaches. The platform automatically builds cryptographic inventories by analyzing actual network traffic rather than crawling endpoints for installed software, providing ground truth about what cryptographic algorithms are actively in use. This approach eliminates the need for new agents or complex deployment processes, allowing large enterprises to complete crypto inventory assessments in weeks rather than months. The platform supports hybrid mode deployment of ML-KEM (FIPS-203) combined with classical Elliptic Curve Diffie-Hellman, following industry recommendations for defense-in-depth during the transition period. Zscaler's cloud scale enables inspection of trillions of daily transactions using quantum-safe ciphers while maintaining performance, and the platform's cryptographic agility allows rapid adaptation to evolving standards and regulatory requirements.

Chapters

0:00 - Introduction to Post-Quantum Cryptography
1:08 - Quantum Computing Acceleration and Investment
2:15 - Customer Concerns and Market Drivers
4:14 - Understanding the Cryptographic Threat
8:10 - Harvest-Now-Decrypt-Later Attack Vector
9:52 - Customer Requirements and Use Cases
12:59 - Zscaler's Quantum Readiness Capabilities
14:10 - ML-KEM Standard and Hybrid Deployment
17:15 - Architectural Advantages and Scale

Key Quotes

2:04 "Many cryptographic algorithms that we use widely today will be trivially solved by sophisticated large enough Quantum computer."
5:28 "If an adversary would be able to capture communication that is strongly encrypted today, the adversary cannot do anything meaningful with this communication. They can store those packets for a long time, and once a large enough Quantum computer will be available, as long as they have captured this initial key exchange, they will be able to open up that key exchange and decrypt the rest of the communication."
9:06 "I've seen the shift from there to this being part of the regulatory requirements, being an active requirement in the very early engagements about finding the right solution to enable them on zero trust journey."
9:24 "It has really come out of being in sci-fi homegrown science project to kind of really coming out and then being seen in the real world."
13:29 "Unlike traditional inventory solutions that just crawl through all the software on all the endpoints, probably missing something, probably building an inventory of some software that just lies dormant, Zscaler has access to the ground truth, to actual packets on the wire."
16:08 "We will be able to adapt very quickly because of our cloud scale and because of our software agility."

FAQ

What is the harvest-now-decrypt-later attack and why does it require immediate action?

Harvest-now-decrypt-later is an attack where adversaries capture encrypted communications today and store them until quantum computers become available to decrypt them. This is urgent because it doesn't require quantum computers to exist now—attackers can harvest sensitive data today and decrypt it years later when the technology arrives. Organizations transmitting data that will remain sensitive for years (financial records, medical information, regulatory data) need to adopt quantum-safe encryption immediately to protect against this threat.

How does Zscaler help enterprises build a cryptographic inventory without deploying new agents?

Zscaler's cloud architecture analyzes actual network traffic passing through the Zero Trust Exchange to identify cryptographic algorithms in active use. This provides ground truth visibility into what's actually being used for communication rather than crawling endpoints for installed software. The approach automatically builds a comprehensive crypto bill of materials across all devices and users within weeks, helping organizations prioritize migration efforts based on real-world usage patterns and data sensitivity without additional infrastructure deployment.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Compliance & Governance
  • Zero Trust
  • Technical Deep Dive
  • Webinar
  • Post-Quantum Cryptography
  • Quantum Computing Threats
  • ML-KEM
  • FIPS-203
  • Harvest-Now-Decrypt-Later Attacks
  • Cryptographic Inventory Management
  • Zero Trust Architecture
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Quantum-Safe Cryptography: Zscaler's Post-Quantum Strategy

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    03

                    Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                    08/03/202611:00 AM ET
                    • Aug
                      06

                      Safeguarding Sensitive Data in the Era of AI Adoption

                      08/06/202604:00 AM ET
                      • Aug
                        06

                        Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                        08/06/202602:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/03/2026
                          11:00 AM
                          08/03/2026
                          Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Safeguarding Sensitive Data in the Era of AI Adoption
                          https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version