‘Generational’ Shifts In AI And Quantum Are Coming For Cybersecurity. Can The Channel Get Customers Ready In Time?

The clock is ticking for solution providers to prepare customers for these dual—and increasingly dangerous—threats.

**A**t the start of 2026, World Wide Technology executive Chris Konrad wrote a cybersecurity business strategy based, as usual, on his expectations for the year.

By July, the document was outdated.

“The strategy that we put in place at the beginning of this year, I just threw out, and I’m rewriting it,” said Konrad, vice president of global cyber at St. Louis-based WWT, No. 10 on CRN’s 2026 Solution Provider 500. “No longer do I have one-year business plans. I have to do six-month business plans.”

This new reality is one that many security-focused solution providers are facing today as two massive market shifts—each considered “once in a generation” in their own right—are converging on customers simultaneously and putting them at risk: the arrival of AI and the impending impact of quantum computing.

[RELATED: Why The Post-Quantum Shift Could Leave Older IT Systems Behind]

Following a cascade of frontier AI developments—including intensified risk from AI-driven vulnerability discovery and the rising threat of autonomous agentic attacks—cybersecurity-focused solution and service providers have had to ford uncharted waters as a regular course of business in 2026.

Those emerging AI-related cyberthreats are requiring solution providers to mobilize massive preparatory efforts for customers across the world, even as many organizations continue struggling to get a handle on security for surging AI adoption within their employee base.

At the same time, AI is not the only high-stakes risk on the horizon for security teams.

The threat posed to existing data encryption methods by the advancement of quantum computers stands as a more distant—but perhaps not that much more—area of monumental risk that experts say can no longer be legitimately ignored. This is particularly the case because of a simple fact: Making the transition to what’s known as post-quantum cryptography could take several years for most organizations.

In other words, solution providers have to prepare customers for “Q-Day”—the date when the quantum threat to data could appear—right alongside their efforts to remediate all of the new internal and external security challenges introduced by AI.

“I think there is just universal consensus that these are not ‘someday’ problems. They are pending problems,” said Rob Gregory, CISO at Denver-based cybersecurity powerhouse Optiv, No. 29 on CRN’s 2026 Solution Provider 500, regarding the massive risks expected from advanced AI-powered threats and encryption-busting quantum computers.

Ultimately, the situation “differs from other landscape changes where everything felt reactive,” Gregory said. “Largely, the industry is on the same page that we have to do something about these. And organizations must adapt. This isn’t one where you can sit idly by and have this amazing white paper that says exactly what to do. You can’t wait for that. Organizations fundamentally cannot do that with this risk landscape.”

For the channel, the challenge of preparing for these coming cybersecurity upheavals—spurred by a pair of almost unimaginably powerful technologies in AI and quantum computing—can without exaggeration be called unprecedented.

If solution providers can be adaptable and nimble enough to complete the preparations before the clock runs out and the full force of AI and quantum threats have arrived, it could also be the channel’s defining moment.

AI-Powered Vulnerability Discovery

For emerging AI-related security risks, the window for making those preparations may be closing much faster than most organizations expect.

Cybersecurity may need to undergo a transformation comparable to the changes that followed the emergence of the internet—but “within even just six to 12 months,” OpenAI co-founder and President Greg Brockman said during a recent on-stage discussion at CrowdStrike Fal.Con 2026.

The sentiments come in the wake of the disclosures earlier this year that AI companies have been developing ultra-powerful frontier AI models for vulnerability discovery and exploitation, such as Anthropic’s Claude Mythos model and OpenAI’s GPT Cyber models.

Brockman warned that cyber defense teams have a limited window of time to capitalize on their current access to advanced AI capabilities, particularly for discovering and patching vulnerabilities, before threat actors catch up. “Right now, we are in what I call the ‘defender’s window,’” he said.

“There’s this limited time period where we’ve seen the shape of what is going to be possible with AI-assisted vulnerability [discovery]—which can be used for two purposes,” he said. “It can be used by attackers to find threats and exploit them. But it can be used by defenders to find those same threats and to patch them before the attackers get there.”

As just one indicator, Microsoft’s September security update included patches for more than 900 vulnerabilities, which experts linked to accelerated discovery by AI-powered tools. Prior monthly patch releases from Microsoft, including as recently as earlier this year, often did not exceed 100 vulnerabilities for the month.

The likelihood is that while there has not been a requisite increase in disclosure of exploited, zero-day vulnerabilities, that will follow in a matter of time given the proficiency of the models at uncovering novel ways to exploit software, according to security experts.

For solution providers across the channel, the immediate result of this development is an environment where customers need more help than ever, executives told CRN. As AI uncovers more weaknesses in software that businesses rely on, organizations need to determine which findings demand action right away and move quickly to address them.

“We may not have the time to do the diligence that we’ve always done,” said Zack Finstad, vice president of cybersecurity at Logically, No. 332 on CRN’s 2026 Solution Provider 500.

‘The days of the traditional 30-day patch window for vulnerabilities are going to be gone. We’re going to all need to work toward moving those up to weeks, days—and then ultimately hours—after these vulnerabilities come out and these patches become available.’

—Rob Gregory, CISO, Optiv

That is a steep challenge for many organizations whose vulnerability management processes were designed around a much slower pace of discovery and exploitation of software flaws, according to Optiv’s Gregory.

“The days of the traditional 30-day patch window for vulnerabilities are going to be gone,” he said. “We’re going to all need to work toward moving those up to weeks, days—and then ultimately hours—after these vulnerabilities come out and these patches become available.”

Without a doubt, customers do generally recognize they will need to patch more quickly, Gregory said. Where they need help is figuring out how to make that happen in practice, including how to get business units comfortable with more frequent—and potentially, more automated—changes to their systems.

Traditional processes often involve requiring a patch to move first through a development environment, then a quality assurance environment, followed by more testing and then a final signoff before it reaches real-world environments. That can take weeks.

However, in the new world of AI-driven vulnerability discovery and exploitation, “those multiweek flows have to fall by the wayside,” Gregory said. “That’s where we’re having a lot of conversations on not only how to give them solutions like agentic security operation centers, but how to help them communicate to their board, communicate to their leadership, about the risk.”

Solution providers need to champion a massive rethinking of vulnerability management processes for many customers, according to Gregory and other solution provider CISOs who spoke with CRN.

“We’re going to have to get past the concern about automated patching or automated changes being done,” Gregory said. “All these really good governance practices that we’ve had for many years are going to have to adapt to a much more rapid threat landscape. And I think that is a situation where having someone come in and help you from an advisory standpoint is really beneficial.”

At the same time, deeply ingrained change management practices exist for reasons that cannot simply be dismissed, according to Troy Saunders, CISO at Troy, Mich.-based Logicalis U.S., No. 79 on CRN’s 2026 Solution Provider 500.

“We’re slow for a reason,” Saunders said. “We have many clients that we manage. So we have to get approvals before we make a change. We wait on client responses. We test servers before we deploy to the real server. There are a lot of constraints that we have that the bad guys don’t have. They click a button and they don’t care if they bring servers down. That’s a win for them. So it’s definitely challenging.”

One way that Logicalis is working with clients to narrow the gap is to agree up front on an expedited “emergency change process,” Saunders said. That process can enable the solution provider to establish what changes will be able to proceed without another round of approvals while also making sure that the actions are documented, he noted.

The result is that urgent security-related changes can be made “a lot faster than right now, where you’re actually either calling or waiting on a person to say yes,” Saunders said. “It’s about setting up all the parameters and [having an] agreement up front around what can we go ahead and patch without approval.”

At Optiv, that shift is influencing the design of new security services, according to Kathryn Hall, Optiv’s senior vice president of services. In recent months, Optiv has begun putting far greater emphasis on proactive exposure management as part of its MSSP practice, including with the debut of its Agentic Security Operations offering in August.

“It is not enough to do routine patching. It is not enough to do an annual pen test,” Hall said. “We need to be continuously scanning and understanding our highest exploitable exposures—and getting ahead of those before we’re detecting on them.”

In other words, management of exposures and detection and response needs to function in concert with each other, she said.

“What we’re signaling to the market is detection and response isn’t enough anymore,” Hall said. “They need to be working with a services provider that has the front end—the exposure management piece—integrated with the service so that it’s a continuum [of protection].”

Amid the urgency around accelerated vulnerability discovery and exploitation enabled by AI, the only reasonable answer is for vendors and partners to come together to meet the challenge, according to CrowdStrike Chief Business Officer Daniel Bernard.

All in all, the efforts around the industry and channel represent “the greatest mobilization in cyber that there may have ever really been,” Bernard said.

Autonomous Cyberattacks

Meanwhile, the rising specter of autonomous attacks raises the stakes even further.

The autonomous compromise of AI platform Hugging Face, recently carried out by rogue OpenAI agents, has been viewed by many cybersecurity experts as a preview of the capabilities that threat actors may soon possess.

That’s especially the case because the autonomous attack was quickly followed by a disclosure of similar incidents involving Anthropic’s Claude models as well as some of Meta’s AI models.

The incidents raise the likelihood that accelerated attacks—at speeds previously unimaginable—may be here very soon.

For instance, Austin, Texas-based cybersecurity giant CrowdStrike for years has been tracking “breakout time,” the time it takes for an attacker to move from one compromised host to another host. But with the advent of autonomous agent-driven cyberattacks, “breakout time is over,” CrowdStrike co-founder and CEO George Kurtz said during Fal.Con 2026. “We’re going to have to come out with another metric—because it’s gone.”

‘This industry is transitioning from defending against human-speed attacks to preparing for autonomous, machine-speed attacks and cyber operations. Everybody’s rethinking everything.’

—Chris Konrad, VP, Global Cyber, World Wide Technology

That stunning development is giving defenders even greater necessity to find ways to move faster, solution providers told CRN.

“This industry is transitioning from defending against human-speed attacks to preparing for autonomous, machine-speed attacks and cyber operations,” WWT’s Konrad said. “Everybody’s rethinking everything.”

A key lesson from the Hugging Face incident, he said, was that common security mistakes—such as shared logins and exposed credentials—could be exploited with far greater speed and at much higher volume.

“Every mistake it [exploited] was one that any skilled human in cyber really could have probably found,” he said. “What changed isn’t necessarily the cleverness of it. It’s [the need for] defending at the speed of AI. It’s the speed and it’s the volume. And that is what defenders now have to plan for.”

‘Especially with agentic AI, you’ve got a technology that doesn’t take holidays, doesn’t take weekends. It will work relentlessly. So in the hands of the bad guys, that can now be taken and pushed to the forefront—and really compress that timeline tremendously.’

—Phillip Tobolski, Director, Cybersecurity, Logicalis U.S.

Agentic capabilities also create the potential for attacks that are able to continue without interruption, which would normally be a constraint for human threat actors, according to Phillip Tobolski, director of cybersecurity at Logicalis U.S.

“Especially with agentic AI, you’ve got a technology that doesn’t take holidays, doesn’t take weekends. It will work relentlessly,” Tobolski said. “So in the hands of the bad guys, that can now be taken and pushed to the forefront—and really compress that timeline tremendously.”

Without question, autonomous attacks will require changes in how defenders detect threats, according to Ryan Whelan, managing director and global head of cyber intelligence at Dublin, Ireland-based Accenture, No. 1 on CRN’s 2026 Solution Provider 500.

This will mean “new detection approaches to go and find that autonomous activity. We’re going to have to try and figure out how to test and stay ahead of that autonomous activity,” Whelan said. “Our work is going in with clients and trying to figure out how do we anticipate and get ready for that eventuality? In the next six to 12 months, I think we’re going to see it.”

That, of course, leaves customers with limited time to prepare for the coming changes in how attacks are going to be carried out and detected, he noted.

“You can’t go back to a [business]-school study from 20 years ago to figure out how I should think about this problem because it didn’t exist,” he said.

A crucial aspect for many organizations is the need to address longstanding security weaknesses that could make AI-powered attacks damaging—regardless of how the intrusion begins, solution providers told CRN.

When attackers compromise a third party and steal credentials belonging to another organization, for instance, the attempt to use those credentials can have little impact when the account is set up with the fewest-necessary permissions, according to Gary Brickhouse, CISO at Herndon, Va.-based GuidePoint Security, No. 32 on CRN’s 2026 Solution Provider 500.

In a recent third-party incident of this sort, the attackers “weren’t able to really do anything of any significance to that organization because that account had least-privilege [permissions],” Brickhouse said.

This type of lesson is particularly relevant for customers that currently are trying to prioritize among multiple emerging areas of heightened cyber risk. Organizations need an architecture that can withstand a range of attacks, both existing and new, Brickhouse said.

An organization “can’t afford to build a new defense every time a new threat shows up,” he said.

“I’ve got to have this core, functioning architecture and infrastructure that’s based on defense-in-depth principles,” Brickhouse said. “There’s some novelty that we need to account for, but I know that I’m going to be protected against 90 percent of what comes my way.”

Finding the funding to close those gaps is another key part of the challenge.

Even for existing, already-present challenges around securing AI usage, many CISOs are not seeing increases in the cybersecurity budget, according to Chris Schueler, CEO at Kansas City, Mo.-based Cyderes, a major MSSP and No. 124 on CRN’s 2026 Solution Provider 500.

Unfortunately, it may take a major, high-profile AI security incident to change this trajectory, Schueler said. And the same could be said for coming risks around AI-powered vulnerability discovery and autonomous attacks, solution providers said.

“We may just be in slightly uncharted territory—where we’re in a state where the risk is increasing at a pace that absolutely exceeds these budget increases that we hear from cybersecurity leaders,” Optiv’s Gregory said.

For smaller customers, the shortfall can be especially daunting, MSP executives said.

As an example, many rural health-care organizations already struggle to keep up with patching—even before we get to widespread exploitation of vulnerabilities through the use of AI tools, according to Donald Monistere, president and CEO of General Informatics, a Baton Rouge, La.-based MSP.

“We’re trying to do as much as we can, as affordably as we can,” Monistere said. “And so the thought of it getting worse is pretty daunting.”

And yet, he said, there’s little question that “it will get worse—because the speed at which you can exploit a vulnerability is going to go up tremendously.”

The Quantum Challenge

The urgency around the myriad security impacts of AI means that preparations for a quantum-enabled future—and the resulting quantum-powered risk—can be even more difficult to prioritize for many organizations, according to experts.

‘Quantum was much more of a popular topic before AI. It used to be one of the top topics in security. And so there is a prioritization risk.’

—Timothy Hollebeek, Industry Technology Strategist, DigiCert

While AI has been generating immediate demands from customers and executives, the threat to existing methods of data encryption has no fixed date of arrival. Some estimates say Q-Day could arrive within the next five years.

“Quantum was much more of a popular topic before AI,” said Timothy Hollebeek, industry technology strategist at digital certificate authority DigiCert, Lehi, Utah. “It used to be one of the top topics in security. And so there is a prioritization risk.”

At the same time, some solution providers are seeing increased interest in quantum preparations, such as WWT—where Konrad estimated that quantum featured in nearly half of his conversations at the recent Black Hat USA conference.

“It’s really gone from whether we should prepare to ‘we need to start planning for long-term cryptographic resilience,’” he said. “People are recognizing that we need to start planning for it and be ready for it.”

The lengthy process and unavoidable complexity of that work are behind the case for starting now, according to solution providers.

Gaining visibility into where cryptography is actually being used across an organization—including through a comprehensive inventory of cryptographic assets—has widely been considered a critical first step. Organizations have been urged to first create a map of all encryption use, then prioritize critical systems for migration to post-quantum cryptography.

“Transitioning encryption keys and method of encryption—and, potentially, encryption technology—for a large organization is a very extended project,” Optiv’s Gregory said. “And so starting that now probably behooves all of us, regardless of size or sector that we’re in.”

Crucially, in this case, the familiar process of buying a product to address a newly identified security problem is simply not going to work, he said.

For transitioning to quantum-resilient methods of cryptography, “it’s not like it’s [a single] product you go buy and put it in place and then you’re fine,” Gregory said. “Dealing with post-quantum cryptography is a much more complicated solution that I think we’re all trying to work through and figure out the best way to navigate.”

In truth, the transition deeply affects the infrastructure that organizations rely on and must keep secure at all costs, experts said.

“It’s not just certificates. It’s not just cryptography,” DigiCert’s Hollebeek said. “It’s a fundamental upgrade to authentication and communication across the internet.”

Given the massive scope of the transition ahead—and the potential that many organizations may not have the time they need to be fully ready for the approaching arrival of quantum computing—it is possible that the industry’s emphasis on asset discovery and inventories can become an obstacle to taking prioritized action, he said.

Hollebeek said he is now recommending that most organizations identify the most critical application they have—the one that must transition above all else—and start doing the work.

“You’ve got maybe two or three years before the deadline, so you’re not going to transition everything,” he said. “Figure out the first, most critical thing you have to transition and start your transition journey.”

Going forward, automation will be essential to making the work of the post-quantum transition manageable, according to Jason Soroko, a veteran cryptography specialist and senior fellow at Scottsdale, Ariz-based Sectigo, a provider of digital certificate management.

“The complexity just adds up massively,” Soroko said. “Automation is going to be a complete necessity.”

‘When you think about the whole supply chain—in terms of their sharing networks of data that have got to be shared—any kind of weakest link there can expose data.’

—John Ackerly, Co-Founder, CEO, Virtru

Notably, the post-quantum risk also reaches outside an organization’s own infrastructure, experts said, since any data transferred to a third-party supplier means that the supplier must likewise have quantum-resistant encryption.

“When you think about the whole supply chain—in terms of their sharing networks of data that have got to be shared—any kind of weakest link there can expose data,” said John Ackerly, co-founder and CEO at data security vendor Virtru, Washington, D.C.

Many organizations already underestimate how much sensitive information their third parties can access, according to Accenture’s Whelan.

“We see that all the time, where organizations didn’t even realize that they had entrusted that level of visibility to a third party,” he said. “I think the starting point is just helping organizations better capture and understand, who are those critical vendors? How do we define those critical vendors?”

That issue could quickly turn quantum readiness into a requirement for doing business, experts told CRN. Customers may eventually request evidence of quantum preparations, alongside the types of security and business continuity information that are typically already provided.

“There will be an industry standard—it’s going to be a quantum readiness assessment that we will have to submit as part of that package,” Whelan said. “It’s just a question of timing, and when we see that that starts become a norm.”

It’s not just enterprise customers and large solution providers that need to take heed. MSPs and their SMB clients are in no way exempt from the need to prepare for the quantum transition—although in many cases, MSPs are relying on the large technology providers to equip their platforms for quantum readiness.

“If your operating system is vulnerable, if your email system is vulnerable, produced by these providers, then there’s only so much that an MSP can do to protect [clients],” said Chesley Choudhury, founder and chairman of TanChes Global Management, a Houston-based MSP. “That responsibility really relies on that top-tier tech company—providing secure hardware, secure software—and they have the funds and the means to do it. The regular MSP does not.”

At the same time, keeping up with the developments related to quantum computing—and the potential threat to the security of all data in coming years—is an absolute obligation for MSPs, Choudhury said.

“Our No. 1 job as an MSP, before anything else, is our client security,” he said. “So if we are not ahead of the curve in studying and analyzing the trends, then we are definitely doing our clients a disservice. So [quantum] has to be brought to the attention of MSPs.”

Whether it’s quantum- or AI-related capabilities, smaller MSPs in the future may also be able to obtain some expertise through other providers that have more specialized capabilities—similar to what has occurred with the rise of compliance-focused MSPs, according to Mike DePalma, vice president of business development at OpenText Cybersecurity.

“What I honestly think is that you’re going to see specialty MSPs that might focus on one of these problems—and you’re going to see MSPs outsourcing some of that work to them,” DePalma said. “We’re starting to see it on the compliance side. I think [AI and quantum] will be the same thing. I think you’re going to find somebody that is going to make that investment—and most MSPs are going to be like, ‘I don’t have the bandwidth or the money to create a whole team that’s going to be prepared for this. But I could outsource it.’”

For solution and service providers of all sizes, the key going forward—whether it’s around AI-accelerated attacks or quantum data security risks—will be to help customers prepare at a faster clip than they’ve been used to in the past, executives and experts said.

A silver bullet to AI-driven cyberattacks doesn’t exist, and the quantum transition will demand continued work across a customer’s environment over a lengthy period, according to experts.

The biggest danger, experts said, is allowing uncertainty to get in the way of starting the necessary work—allowing the window for preparations to close.

Ultimately, “there are so many unique, and in many ways, generational changes in the threat landscape,” Optiv’s Gregory said. “These aren’t hypotheticals. These are things that cyber leaders need to do now. The key is, how do they do that? That’s where I really think partners can help.”