Why The Post-Quantum Shift Could Leave Older IT Systems Behind: Experts

Security experts tell CRN that budget constraints, aging infrastructure and unupgradable hardware could leave critical technology vulnerable for years, creating both major risks for customers and new opportunities for solution providers.

Post Quantum Cryptography and Quantum Resistant Cryptography - PQC - New Cryptographic Algorithms That Are Secure Against Quantum Computers - Conceptual Illustration

While it’s entirely possible that many businesses will succeed at protecting their most essential IT systems before the arrival of quantum-powered attacks that can overpower classic encryption, the picture that’s emerging is that not all IT systems may be able to make the transition, post-quantum security experts told CRN.

Due to factors such as cost and the amount of effort involved, older technology that still works and serves a business purpose may be left vulnerable to attack—possibly for years, experts said.

“There’s just a lot of detritus from the past that is just going to bite us,” said Jason Soroko, a veteran cryptography specialist and senior fellow at digital certificate management provider Sectigo, Scottsdale, Ariz. “I actually think that we’re going to live well past 2029, 2030, 2035, where we’re going to have legacy systems that are fully operational—and utterly insecure.”

[RELATED: ‘Generational’ Shifts In AI And Quantum Are Coming For Cybersecurity. Can The Channel Get Customers Ready In Time?]

Since the ability of a legacy IT system to keep doing its job is likely to outlive the expiration date of its cryptography in the predicted quantum era, businesses could face a major dilemma in coming years, according to experts.

Many customers will face tough decisions about technology they had every expectation of being able to continue using—given the fact that, among other things, some legacy IT systems simply cannot be upgraded to support post-quantum cryptography, the experts said.

As a result, the post-quantum preparation effort will create a bigger channel opportunity than just updating software for customers, according to Chesley Choudhury, founder and chairman of TanChes Global Management, a Houston-based MSP.

“This also creates a huge hardware opportunity that’s coming up,” Choudhury said. “There’s hardware that needs to be changed.”

The U.S. Cybersecurity and Infrastructure Agency in January, for example, identified a list of technology categories where products that already use post-quantum computing standards are available, including networking hardware such as routers, switches and firewalls, SAN appliances and even peripherals such as wireless keyboards and headsets.

However, for customers, identifying the necessary changes—and finding the resources to carry them out—are going to be different types of challenges, experts told CRN.

The most likely scenario is that post-quantum migration efforts will encounter a familiar pattern, where ambitious plans give way to budget constraints, according to Timothy Hollebeek, industry technology strategist at digital certificate authority DigiCert, Lehi, Utah.

“There’s always the first, beautiful plan. And then there’s the second one—which is the minimum version that we can all live with,” Hollebeek said. “And then there’s the third one, which is the version that isn’t as good as the minimum one but we can all afford.”

And then ultimately, even that realistic plan “takes three times as long as the schedule said it was going to,” he said. “I think we’re going to see a lot of that [type of] cycle happening.”

Determining what can, and cannot, be safely left behind in the post-quantum shift will be pivotal going forward for many businesses, according to experts.

This requires, for instance, understanding how long the data being protected will remain valuable to the company and to hackers, experts said.

Such “data shelf life” considerations reveal that while some information can lose its significance over time, other data could remain sensitive well into the future, according to Rob Gregory, CISO at Denver-based Optiv, No. 29 on CRN’s 2026 Solution Provider 500.

That distinction can help customers prioritize their post-quantum migration work, Gregory said.

For Sectigo’s Soroko, the hope is that businesses will at least be able to successfully protect their most critical assets by the time threat actors can access quantum computers capable of defeating existing encryption, colloquially known as Q-Day. But the reality is that unfinished work will in all probability remain a substantial problem, he said.

“I’m crossing my fingers very hard that people will do what they have to do to solve [post-quantum encryption for] the important crown jewels,” Soroko said. “But there’s going to be an enormous class of legacy systems [where] it just won’t happen for a very long time.”

On the bright side, it’s clear that many customers are beginning to make the shift to post-quantum encryption a bigger focus than in prior years, Optiv’s Gregory said.

“AI probably shifted the focus away from it a little bit,” Gregory said. “But it does seem to be a topic that’s now coming back to the top of mind when I meet with clients and CISOs—when they start to look at their risk appetites or risk profiles—and then ultimately, when they work with us around advisory on where they should start to allocate their time and efforts.”

Without a doubt, he said, post-quantum cryptography “is now coming more to the forefront.”