QIZ Security Prepares Enterprises for Q-Day
Mike Vizard talks with Ben Volkow, co-founder and CEO of QIZ Security, about why post-quantum cryptography is becoming an urgent priority for enterprise cybersecurity leaders. Volkow explains that quantum computers are expected to eventually break widely used encryption methods such as RSA and ECC, creating a risk to the digital trust that protects emails, networks, databases, source code, suppliers, vehicles, financial systems and critical infrastructure. The conversation frames Q-Day as more than a future technical milestone. It is a business continuity issue that requires organizations to understand where cryptography exists today, which assets are most exposed and how long migration to quantum-safe encryption may actually take.
Volkow notes that standards bodies such as NIST have already advanced quantum-safe algorithms, but the challenge for enterprises is not simply choosing a new algorithm. It is discovering cryptographic assets across complex environments, mapping ownership, prioritizing risk and replacing vulnerable cryptography without disrupting operations. That makes post-quantum cryptography a multi-year transformation rather than a quick upgrade. For banks, federal agencies, defense organizations, critical infrastructure providers and large enterprises, the timeline is especially tight because migration programs can take five to 10 years while quantum risk continues to move closer.
The discussion also examines why AI priorities are competing for budget and attention even as quantum security deadlines approach. Volkow argues that organizations do not need to boil the ocean to get started. Instead, cybersecurity teams should begin with practical steps: build an inventory, secure the perimeter, address TLS, review algorithms and certificates, assess source code and work through third-party supplier exposure. His advice is to treat quantum readiness as a muscle that improves through action. By starting now, security leaders can build crypto-agility, reduce future disruption and prepare their organizations for a quantum-safe future before Q-Day forces the issue. The result is a clear roadmap for turning post-quantum cryptography planning into measurable security progress before quantum risk becomes an operational crisis.
Transcript
Hey guys, Thanks for Throw. We're here with Ben Volkov, who's the CEO of Keyz Security, and we're having a little chat about post-quantum cryptography. Sorry, easier said than done.
And they just raised $17 million in additional funding, and we're going to learn exactly what it is that they're going to solve us for problems. Ben, welcome to the show. Hi, Mike.
Thanks for having me. Excited to be here today. Right.
And happy to really to talk about the quantum risk, what it means for our life, and how we tackle it at Keyz. So there's a lot of players already in this space. So what exactly are you guys doing and what gap are you plugging or filling?
So quantum computers are coming, and they will do wonderful things. But one of the things they will do, which is good and bad, is they will break our existing encryption. Encryption is the base for digital trust.
It's everywhere. It's in our emails, our messaging, our networks, our databases, our source code, our third-party suppliers, our vehicles, our airplanes. What if I told you that it's expected that two years from now, all this will be broken?
Without this, there's no trust, there's no communication, and it's not a question of if it will happen, it's the question of when. There's an algorithm called Shor algorithm that shows how quantum computer will break the existing encryption. Things with names like RSA or ECC.
It's expected that it will happen in 2029, that we'll have quantum computers strong enough to break encryption. It's not me saying 2029. It's Google, it's IBM, it's Palo Alto, it's Gartner.
We even have a nickname for this day. We call it Q-Day, the day that existing encryption will melt down. And what we do at Keyz, we're helping organizations to prepare to this day and to be secured, hopefully in time when it will happen.
One of the things we do here is that there are encryption schemes that will thwart these attacks, at least hopefully. But replacing the existing ones with new ones is quite a heavy lift. So how do we automate some of that or get to the point now where maybe we can meet a deadline that while 2029 sounds like it's far, far away, it's probably less than 1,000 working days, right?
Exactly. So you are totally right. People weren't sitting idle.
This problem was well understood a couple of years ago. At least the standard body came up with five new algorithms that are quantum safe, or at least believed to be quantum safe because it's all theoretical. And what we do at Keyz, we are helping organizations to first map the existing cryptography, because you cannot protect what you don't know.
You need to understand where you have windows, where you have doors, what is locked, what is not locked, and then to prioritize it and of course, replace the existing cryptography with quantum safe cryptography as proposed by NIST. And you are totally right that two years is really behind the corner. When we talk to organizations, to banks, to critical infrastructure, to federal, to defense, they usually talk about 5 to 10 years to cross this Rubicon, to move from their existing cryptography to be quantum safe.
So if 2029, it's less than 5 to 10 years from now, there's definitely urgency to start the migration as soon as possible. How big a lift are we talking about? I think in the past, we have changed encryption schemes when required, but it seemed like it took weeks, months, sometimes even years for organizations to make that kind of lift.
So are we underestimating what kind of work is required here? So you are totally right. It's not the first time that we need to replace the cryptography.
It happened with SHA-1, I think about 15 years ago, and it took a number of years. I think right now we are talking about much bigger a challenge because technology and cryptography is much wider spread, and because we are talking about almost all existing cryptography. One of the interesting things there is that NIST was smart.
They said, "Okay, we done it with SHA-1 15 years ago. We're going to do it with RSA and ECC today. " So when NIST came and proposed a new post-quantum cryptography, PQC algorithms, they also proposed to change the architecture, the way we manage cryptography.
And I'm happy to elaborate about that. How we build also a future quantum safe crypto architecture, because quantum computer will continue to be stronger and stronger and stronger, and we don't want to do this drill again in 15 or 20 years. So that sounds like we're going to have maybe an architecture that's a little more modular so we can rip and replace the encryption schemes as we need to.
Is that how that evolves? Exactly. The NIST is calling it cryptoagility.
Hmm. Basically, what they're saying, let's take the cryptography out. Let's build dedicated servers for cryptography, and every time we want to send a message, an email, sign a document, we'll go to the server, we'll fetch the right cryptography, we'll package it, and we'll use it.
This modular approach means that if the existing NIST algorithms will be broken, what we will need to do in the future is update the server, the cryptography server, instead of going through all the source code, the third parties, the networks again. It's really, I want to believe, a future-safe architecture, because what is safe today for quantum, we are not sure will be safe in 10 or 15 years when quantum computers will be on steroids, even more stronger than initially they will be. We talk about Q-Day as if it's like a holiday.
But if and when it does come, I don't think anybody's going to announce that they have figured out how to break these encryptions. So it may happen sooner, and for all we know, it may have already happened because the people who invest in quantum computers essentially are nation-states? You're totally right.
" Whoever will have this capability will want to keep it quiet so he can go and touch and see everything, party. And so I think they will keep it quiet. Not me, but experts believe that the first place that we'll see that this capability exists will be around crypto coins.
Hmm. There's a lot of weaknesses there. There's no standard body that takes care.
So most probably that will be the place where we see the first signs emerging, but time will tell. And many people talk about Q-Day, and they compare it, we both, I think, are old enough to remember Y2K, bug 2000. And I think it has similarities, but it's very different.
With Y2K, we knew exactly when it will happen, but we didn't know the effect. With Q-Day, we don't know when it will happen, but we definitely know the effect. Encryption will melt down.
So there are similarities, but also different things here. Do I need to start prioritizing what it is that I'm going to replace? Because I don't think I'm going to get there in time for everything, so do I have to start making some choices?
It's a very good point. As we said, organizations are typically looking at five to 10 years migration time across the Rubicon to be quantum safe. So assuming it will happen Q-Day in '29 or '30 or '31, it's too late.
So prioritization is very important, and there are best practices around it. Where to start, what to prioritize, how to handle it. There's also maybe an important point to touch.
Some organizations, they try to boil the ocean. They say, "Okay, I need to cover 100% of my cryptography. " And that's not the case.
Like many other things in life, 20% of the work can cover 80% of the risk. So building the right prioritization and putting the right priorities in place is the right path to be ready in time for this watershed event. Are adversaries today kind of collecting encrypted data on the assumption that they're going to be able to crack it at some point?
And how big a risk does that represent? " You're touching a very good point. The risk is actually not in the future, but already today.
There's something called Harvest Now Decrypt Later, HNDL, where adversaries are already recording data today. " I don't know, credit card numbers, the list of NSA agents in China. So this is part of the reason there's urgency already today, and we cannot wait until those capabilities of quantum will be out.
Recently, President Trump has issued an executive order, I think on June 22, which is really, in my view, it's a very important thing that he did. He's really pushing the market forward. He's asking federal entities to have a post-quantum cryptography expert in 30 days, to start to move the needle in three months, and cut the readiness timelines drastically.
I should maybe mention that it's not just the US with the executive order. We see regulation and similar executive orders coming everywhere. In Australia, in Switzerland, in France, across the EU.
Many countries around the world understanding this risk and are really tightening the regulation framework, and partly because of Harvest Now Decrypt Later, which is already a risk as we speak. Will we use AI maybe to help with this migration? Is there any hope on that front, or is this one of those rare instances where something defies even AI?
You're touching a good point. So I don't think AI will solve the problem. But AI will do good and bad, like many other things, depends how you use it.
And bad actors will use AI to create an inflation of a text around cryptography. You can change keys. You bombard with certificates.
AI could be used in a bad way, but AI can also be used in a good way in order to understand the different risk, prioritize in a smart way, build the right remediations, and put it in place in time. So I don't think AI will solve the problem. AI, on one side, will accelerate the problem, and on the other end, might help us to confront the problem in a wiser way.
" So how do I kick this up the priority list? You're touching a good point. I think that a lot of it is already happening.
Last year, when you were asking Gartner or IBM when Q-day is expected, the answer was 2033. And over the last 12 months, we saw those expectations coming down to 2029. Hopefully, they won't keep coming down.
And so I think there's a lot of market education happening. I think that what is also happening in the market education is the regulation, the executive order, and the visibility that different standard bodies are giving it. You are touching a good point that organizations today prioritize mostly AI.
And we'll see source telling us, "Look, we believe that Q-day is real. We know quantum computers are coming, but this is a 2029 problem. " So in many ways, the challenges around AI are taking some of the efforts and the work needs around the quantum risk, but it's the same breath, I would tell you it totally makes sense because you need to prioritize the problems today over the problems in two years.
I wish there was a way to handle both because two years is really behind the corner, as you said, less than 1,000 days of working days. All right. So what's your best advice to cybersecurity leaders right now?
What should they be thinking about? Because they, too, have a long list of priorities, and so how do you make time for this? I think that the most important thing is start to move.
Don't boil the ocean. And post-quantum readiness is a muscle, a muscle you need to practice and build. Start today.
Start with part of the organization. Start with a group. Start with a source code.
But pick something and start to move and grow from there. And also, maybe if I can try to give another advice, don't boil the ocean. There are best practices, how to do it, where is the higher risk, where is the lower risk.
Usually, for example, the recommendation is to start from the perimeter, secure the perimeter, then move to your source code, then move to the third-party suppliers. Also, on the perimeter, don't do it all at once. Start with the foundation, what is called TLS.
Then go a layer up. Go to the algorithms. Once you finish with the algorithms, go to the certificates.
So really cutting this enormous project into small pieces and starting now with no delay, in my view, is the most important thing. There you go. Hey, folks, you're hearing it here.
They say it's a lot easier to change the direction of something that's in motion than it is something that is standing still. I think we're going to find that out the hard way, but hopefully we'll get started sooner than later, and it won't be as bad as we think. Hey, Ben, thanks for being on the show.
Thanks, Mike. Thanks for having me, and have a quantum safe day. All right.
And back to you guys in the studio.