In this episode of Trust.ID Talk: The Digital Certificate and Identity Security Podcast, host Steve Hall is joined by Julian Weeber and Sarah Zügel from essendi it Group to decrypt the complexity surrounding post-quantum cryptography, the “harvest now, decrypt later” threat, and the concrete steps enterprises must take to ensure cryptographic resilience before quantum computers arrive.
In this episode of Trust.ID Talk: The Digital Certificate and Identity Security Podcast, host Steve Hall is joined by Julian Weeber and Sarah Zügel from essendi it Group to decrypt the complexity surrounding post-quantum cryptography, the “harvest now, decrypt later” threat, and the concrete steps enterprises must take to ensure cryptographic resilience before quantum computers arrive.
What You’ll Learn:
- How to distinguish between quantum computing, post-quantum cryptography, and quantum cryptography
- The three-step framework to quantum readiness
- How crypto agility enables quantum preparedness while solving current cryptographic challenges
- Why the 47-day certificate renewal mandate accelerates quantum readiness
Julian Weeber is Head of Professional Services and a cryptography and quantum security specialist at essendi it, known for his expertise in post-quantum cryptography (PQC) preparedness and secure communication strategies. With vast knowledge of cryptographic vulnerabilities and organizational readiness, Julian has contributed to developing best practices for transitioning enterprise systems to quantum-safe infrastructure.
Sarah Zügel is Managing Director at essendi it, specializing in post-quantum cryptography strategy and organizational security transformation. With a background in cryptographic system design and customer-centric security solutions, Sarah has led market research initiatives and developed awareness programs that bridge the gap between technical experts and enterprise stakeholders.
If you enjoyed this episode, make sure to subscribe, rate, and review on Apple Podcasts, Spotify, and YouTube Podcasts, instructions on how to do this are
here.
Episode Resources:
Key Takeaways:
- [02:27] The Threat That’s Already Happening
Adversaries are already collecting encrypted data today, waiting for quantum computers to crack it open. Emails, phone calls, signed contracts, anything transmitted now can be stored and decrypted later. The threat is already underway, and the data being harvested today doesn’t expire.
- [06:06] The Three Types of Customers in the Market Today
Research shows three camps: the ‘wait and see’ majority holding out for regulations and best practices, a smaller group starting to gather information, and a tiny fraction actually running proof-of-concept projects. The gap between expert urgency and market action is significant, and closing it starts with putting PQC on the agenda now.
- [14:02] Three Steps to Quantum Readiness
Start now with three clear steps: build knowledge on post-quantum cryptography instead of waiting for final standards, use the transition as a chance to map your critical processes and understand where cryptography lives in your organization, and execute the migration when the technology and standards are ready. The groundwork you do today is what makes the actual shift manageable tomorrow.
Quotes:
- “We are really trying to set here a best practice on how to prepare for post-quantum cryptography and use this also as awareness, but also as a strategy which we can provide to the customers to be prepared.” — Julian Weeber
- “The first step is to collect knowledge. Get as much knowledge as you can get about post-quantum cryptography. Don't say we leave it up till the solution is there.” — Julian Weeber
- “Crypto agility means first having an inventory of your crypto assets. For example, know where all your certificates are, which kind of algorithms you're using, and then begin automating your processes around it.” — Sarah Zügel
- “We need to change as a user of cryptography and second we need to change our products as well. Then we have the product enhancements itself, and it begins with the new algorithms but then we go farther to database changes, to process changes.” — Julian Weeber