Why AI And Quantum Computing Safety Both Require Cryptographic Posture Management

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
The organizations best positioned for shifts in AI and quantum computing will treat cryptographic posture management as an ongoing operational discipline.

gettyArtificial intelligence (AI) and quantum computing dominate nearly every conversation about the future of technology. AI promises unprecedented productivity, automation and software development velocity. Quantum computing promises breakthroughs in scientific research, optimization and materials science.

Despite these benefits, both AI and quantum computing will also have negative consequences for cybersecurity. Most organizations treat these as separate conversations. They shouldn’t, because in both cases, safety guardrails will require proper cryptographic posture management.

Both technologies are exposing the same weakness: our ability—or inability—to adapt cryptography quickly, safely and at scale. The future isn’t simply about adopting AI or preparing for quantum. It’s about building the operational capability to continuously manage cryptography as threats, standards and business requirements evolve.

The organizations best positioned for both shifts will be those that treat cryptographic posture management as an ongoing operational discipline, not a one-time security initiative.​

Think about a high-performance sports car. The reason it can travel at 180 miles per hour isn’t simply because it has a powerful engine. It can do so because it also has exceptional brakes, steering, suspension and traction control. Without those systems, speed becomes a liability. Good brakes aren’t just there to stop the car; they help make high speeds possible in the first place. Technology is entering a similar phase.

AI is dramatically increasing the speed at which software is written, vulnerabilities are discovered, infrastructure changes and security research advances. Quantum computing is increasing the urgency of replacing cryptographic algorithms that have protected digital systems for decades, including algorithms that underpin public key infrastructure.

Organizations are adding more horsepower to their technology environments. Many have not built the controls needed to manage that speed safely.​

Generative AI is already transforming software development. Development teams are producing code faster, modernizing applications more rapidly and introducing new services at unprecedented rates. Security researchers are benefiting as well.

However, history has shown that cryptography rarely fails because the mathematics are broken. More often, failures occur because implementations contain subtle mistakes.

As AI continues improving vulnerability research, organizations should expect more frequent discoveries affecting cryptographic implementations that underpin digital privacy and trust. When that happens, the question is no longer whether cryptography needs to change. The question becomes: Can your organization identify everywhere the affected cryptography exists and replace it before attackers can exploit it?

While AI is increasing the pace of operational change, quantum computing requires structural change. Entire categories of public-key cryptography will eventually require replacement with post-quantum algorithms. This isn’t a simple software upgrade. Cryptography exists everywhere: applications, identity systems, PKI, VPNs, databases and more.

Many organizations don’t have a complete inventory of where cryptography is being used today. Replacing algorithms becomes exponentially harder when you don’t know where they exist. The quantum transition is therefore less about implementing new algorithms and more about managing enterprise-wide cryptographic change.

Crypto-agility has often been described as the ability to swap algorithms without rewriting applications. That’s necessary, but increasingly insufficient.

Modern crypto-agility also requires organizations to answer operational questions in near-real time. Where are vulnerable algorithms being used? Which systems depend on them? Which applications are already using approved post-quantum algorithms? Which cryptographic libraries need updating? What business systems would be affected by a change? Which risks should be remediated first?

Without those answers, organizations cannot move quickly with confidence.​

This is where a strong cryptographic posture management strategy matters. Rather than treating cryptography as static infrastructure, organizations must treat it as an operational asset that requires continuous monitoring, governance, inventory, prioritization and life cycle management.

Turning cryptographic posture management into a continuous discipline involves tackling people, process and technology aspects. Because of this, it must be tackled holistically and programmatically.

On the people side, establish an ownership and accountability structure. In many organizations, cryptographic posture management, along with overall cyber-related risk management, would fall under the CISO organization. While CISOs would bear the ultimate accountability and budget ownership, there would typically be a senior manager or director-level person running daily operations. In most mature organizations, that person would oversee a cryptographic center of excellence (CCOE). An exact structure will be rightsized to each organization.

On the process side, find a way to integrate the cryptographic posture management process into your organization’s overall risk management or vulnerability management process, rather than creating a separate process. This will help streamline organizational adoption by building on the muscle memory that you already have. While the subject matter might be novel, risk management processes don’t need to be invented from scratch.

Equally important, cryptographic posture management should be approached as an iterative and continuous process rather than a traditional waterfall project with a defined beginning and end. Continuously discover, assess, prioritize, remediate and reassess cryptographic risk as technology environments, threats and standards evolve.

On the technology side, assess what you need to be successful. While many technology vendors will tell you that the first step is to purchase their tool, a better starting point is to assess what existing telemetry you may already have that provides visibility into cryptographic use. For instance, SIEM tools, network scanning tools or static analysis tools may already provide insights into cryptographic use within an organization. Any purpose-built cryptographic discovery solution should provide the ability to ingest existing telemetry your enterprise already has.

Every major technology wave has required a corresponding operational discipline: Cloud computing brought cloud management, containers brought orchestration, and software supply chains brought new approaches to software security.

AI and quantum computing are creating a similar inflection point for cryptography. Success won’t be determined by who adopts AI the fastest or deploys post-quantum cryptography first. It will belong to the organizations that can continuously understand, govern and adapt the cryptography protecting their business.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/22/why-ai-and-quantum-computing-safety-both-require-cryptographic-posture-management/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business