Why CIOs must pivot to post-quantum cryptography now

Date:



The digital bedrock of the modern enterprise—the encryption that secures every financial transaction, medical record, and state secret—is approaching an expiration date. While the arrival of a cryptographically relevant quantum computer (CRQC) remains uncertain, the threat it poses is already present. For today’s CIO, post-quantum cryptography (PQC) is no longer a futuristic research project; it is a critical pillar of contemporary risk management and infrastructure resilience.

The urgency is underscored by the fact that the National Institute of Standards and Technology (NIST) has already finalized PQC standards and directed organizations to begin migrating now, with widely used encryption algorithms such as RSA and ECC scheduled for deprecation by 2030 and removal from NIST standards by 2035.

The looming Y2Q moment

To understand the urgency, we need to understand the vulnerability. Most of today’s public-key infrastructure (PKI) relies on mathematical problems—specifically integer factorization (RSA) and discrete logarithms (elliptic curve cryptography)—that are practically impossible for classical computers to solve.

However, Shor’s Algorithm, a quantum algorithm developed in 1994, proves that a sufficiently powerful quantum computer could crack these codes in hours, if not minutes. This isn’t just a theoretical vulnerability; it’s a systemic risk to the global economy.

The most immediate danger is the “harvest now, decrypt later” strategy. Adversaries are currently intercepting and storing encrypted sensitive data, waiting for the day quantum processing power can unlock it. For industries with long-tail data—defense, healthcare, and long-term financial trusts—the breach has effectively already happened. CIOs must act now to ensure that data being stored today remains secure in a decade.

The new standards: A roadmap for resilience

In August 2024, NIST finalized FIPS 203 for ML-KEM, FIPS 204 for ML-DSA, and FIPS 205 for SLH-DSA, giving CIOs a standards-based starting point for PQC migration planning. NIST released the first three finalized post-quantum cryptography standards. These algorithms—ML-KEM (formerly Kyber), ML-DSA (Dilithium), and SLH-DSA (Sphincs+)—are designed to withstand attacks from both classical and quantum computers.

For CIOs, these standards provide a clear, actionable roadmap for transitioning to quantum-resistant security. However, swapping out encryption protocols is not a simple patch. It is an architectural overhaul that requires:

  1. Crypto-agility: The ability to update cryptographic algorithms without rewriting the underlying application or disrupting the infrastructure.
  2. Performance balancing: PQC algorithms often require larger key sizes and more computational heavy lifting than their predecessors.
  3. Hybrid deployment: Using a dual-signature approach where data is protected by both classical and PQC algorithms during the transition period to maintain compatibility with legacy systems.

The compute challenge: Why infrastructure matters

The transition to PQC introduces a significant computational tax. PQC algorithms are inherently more complex and require more memory and processing cycles. In a high-frequency trading environment or a massive IoT network, this added latency can be catastrophic.

This is where the synergy between HPE’s hybrid cloud leadership and NVIDIA’s accelerated computing becomes vital.

Accelerated cryptography with NVIDIA

For high-throughput environments such as financial services, telecommunications, and cloud infrastructure, GPU-accelerated PQC libraries such as NVIDIA cuPQC can help teams evaluate and implement NIST-standardized PQC operations without turning cryptography into a performance bottleneck. Production use should still follow enterprise security validation and compliance requirements.

Resilient foundations with HPE

HPE provides the silicon root of trust to protect the hardware from tampering at the supply chain level. As we move toward PQC, HPE’s ProLiant server and Alletra storage systems offer the scale and management tools necessary to inventory cryptographic assets across a hybrid estate. The focus is on observability: you cannot protect what you cannot see. HPE’s management frameworks allow CIOs to identify where legacy RSA or ECC is still in use and automate the migration to NIST-approved PQC.

Strategic steps for CIOs

The journey to quantum readiness should follow a structured framework so there aren’t any gaps left in the security perimeter:

1. The inventory phase

The first step is a comprehensive audit. CIOs must identify every instance of cryptography within their organization—from web servers and VPNs to internal databases and third-party SaaS integrations. Tools that provide a cryptographic bill of materials (CBOM) are becoming essential for this visibility, allowing teams to track exactly which algorithms are protecting which assets.

2. Prioritize based on data longevity

Not all data needs PQC today. A session token that expires in ten minutes is a lower priority than a patent filing that must remain secret for 30 years. Categorize your data based on its frequency of use. If the data will still be sensitive in 2030, it needs PQC protection now to mitigate the “harvest now” threat.

3. Build for crypto-agility

Avoid hard-coding specific algorithms into your software. Move toward a modular architecture where cryptographic providers can be swapped out via configuration rather than code changes. As NIST refines its standards or if a specific PQC algorithm is found to have a flaw, your organization can pivot instantly without a total system redesign.

4. Leverage the ecosystem

The quantum threat is too large for any single organization to tackle alone. Partnering with leaders like HPE and NVIDIA allows enterprises to leverage pre-validated architectures. By using AI-optimized, secure-by-design infrastructure, CIOs can reduce the complexity of the transition.

The intersection of AI and the HPE Sovereign AI Factory

The rise of generative AI has made PQC even more urgent. AI models are trained on massive datasets that must be protected against future decryption. Furthermore, attackers are using AI to find vulnerabilities in existing code faster than ever before.

The HPE Sovereign AI Factory, a joint initiative from HPE and NVIDIA, provides a secure foundation for these workloads. In this solution, data remains under strict organizational and jurisdictional control while leveraging accelerated computing to handle the heavy computational demands of new, quantum-resistant encryption standards. A quantum-secure AI strategy ensures that the models you build today remain your protected intellectual property tomorrow.

Lead, don’t follow

The transition to post-quantum cryptography is perhaps the most significant shift in digital security since the dawn of the internet. It is not merely a technical update; it is a business continuity imperative.

CIOs who act now will gain a competitive advantage. They will protect their brand reputation, provide long-term data integrity, and build a foundation of trust with their customers. By leveraging the combined power of HPE’s secure infrastructure and NVIDIA’s accelerated computing, enterprises can turn the post-quantum cryptography threat into an opportunity to modernize and harden their entire digital estate.

The clock is ticking toward Y2Q. The question for the modern CIO is no longer if they will migrate to PQC, but how quickly they can achieve quantum resilience.

See NVIDIA’s quantum computing resources. Learn more about HPE’s quantum technology leadership.

*************

As AI becomes increasingly central to economic competitiveness, scientific advancement, and national priorities, organizations require infrastructure that balances performance with security and sovereign control. Together, HPE and NVIDIA co-engineer rack-scale AI systems that integrate AI computing, high-performance networking, and supercomputing expertise to support large-scale AI workloads. This provides enterprises, governments, and research institutions with a trusted foundation for sovereign AI initiatives while maintaining control over critical data, models, and operations.


Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

10 European funding vehicles dedicated to women founders

Europe’s startup ecosystem has a stubborn funding problem. Women...

Prominent entrepreneur Hajj Flemings presents “Leveraging AI for Entrepreneurial Innovation”

Register for the "Leveraging AI for Entrepreneurial Innovation" workshopWe...

Germany’s SPRIND and the Netherlands’ NADI launch €40 million challenge to fast-track European AI chip design

Germany’s Federal Agency for Breakthrough Innovation (SPRIND) and its...

Fledgling Cyber Startups Draw Outsize Funding – WSJ

Fledgling Cyber Startups Draw Outsize Funding  WSJ