AI May Be Dominating Cybersecurity, But Quantum Preparations Can’t Wait: Analysis
The quantum threat posed to existing data encryption is not something the channel can afford to put off until the AI challenges are addressed.
As many security teams and solution providers now recognize, providing enhanced security for AI usage and defense against agentic-powered attacks is not something that can be put off until tomorrow.
The problem is, AI is not the only new-on-the-scene security concern that requires a serious investment of time and budget right now.
As we detailed in our CRN Cover Story this month, the quantum threat posed to existing data encryption is not something the channel can afford to put off until the AI challenges are addressed.
Complicating matters is the fact that no one can say exactly when a quantum computer capable of defeating current encryption will arrive.
At the same time, the reality is that shifting to post-quantum cryptography could take years for many organizations.
This dilemma of prioritization around quantum and AI is a massive issue for the channel that will only become more pressing as the clock ticks down to “Q-Day”—the time when threat actors are able to access quantum computers capable of breaking existing data encryption.
Certainly, customers most likely don’t need to complete the post-quantum transition right away. Some estimates say Q-Day could arrive within five years, while others give longer time horizons.
And yet, waiting for a definitive timetable will, in all probability, leave too little time to make the most important changes for an organization’s cryptography.
“Quantum was much more of a popular topic before AI,” Timothy Hollebeek, industry technology strategist at digital certificate authority DigiCert, told me. “It used to be one of the top topics in security. And so there is a prioritization risk.”
Without a doubt, some solution providers are already seeing customers treat the issue with greater seriousness. World Wide Technology’s Chris Konrad estimated that quantum came up in nearly half of his conversations at the recent Black Hat USA conference.
“It’s really gone from whether we should prepare to ‘we need to start planning for long-term cryptographic resilience,’” said Konrad, vice president of global cyber at St. Louis-based WWT, No. 10 on CRN’s 2026 Solution Provider 500. “People are recognizing that we need to start planning for it and be ready for it.”
The hard part is taking that recognition and turning it into an achievable—and funded—project at the same time that AI is consuming so much of the oxygen.
The post-quantum transition involves understanding where cryptography is being used and which data must remain protected for years—as well as understanding which applications, devices and other systems will need to be shifted over.
For a large organization, changing encryption keys and methods—as well as potentially changing the underlying technology—could be a lengthy undertaking, according to Optiv’s Rob Gregory.
It’s also not a challenge that can be addressed with a single purchase of a new tool or service, said Gregory, CISO at Leawood, Kansas-based Optiv, No. 29 on CRN’s 2026 Solution Provider 500.
All of this complexity creates another variety of risk, according to Hollebeek. The risk is that organizations may treat the achievement of an exhaustive inventory and an ideal migration plan as the prerequisites for taking action of any kind, he said.
Hollebeek’s advice: Ruthlessly prioritize.
“You’re not going to transition everything,” he said. “Figure out the first, most critical thing you have to transition and start your transition journey.”