Close

Harvest Now, Decrypt Later: Why Post-Quantum Security Can't Wait | Eddy Zervigon

Eddy Zervigon on Quantum Xchange, Crypto Agility, and the Quantum Security Threat
Eddy Zervigon

Eddy Zervigon is CEO of Quantum XChange, a cybersecurity company protecting data against both current cyberattacks and the future threat posed by quantum computing. Before joining Quantum XChange, he spent 1997-2012 as a Managing Director in Morgan Stanley's Principal Investments Group and currently sits on the boards of Bloom Energy (NYSE: BE) and Maxar Technologies (NYSE: MAXR). He holds an MBA from Dartmouth's Tuck School of Business and was invited by the House Homeland Security Committee to testify on quantum security matters.

Eddy Zervigon is helping enterprises prepare for the shift to post quantum cryptography. As CEO of Quantum Xchange, Eddy is focused on helping organizations secure critical data before quantum computing changes the rules of encryption. Quantum Xchange recently won a Fortress Cybersecurity Award for its work helping enterprises build a more agile approach to cryptographic security.

In this episode, Russ and Eddy discuss why post quantum security is not just about choosing a new algorithm. Eddy explains that encryption has worked for decades because organizations could rely on a small number of trusted algorithms and predictable advances in computing power. But with quantum computing and AI advancing together, that model is breaking down.

The conversation dives into crypto agility and why Quantum Xchange believes companies need an architecture that lets them change cryptographic algorithms without bringing down the network. Eddy explains the importance of separating key generation and delivery from the data plane, giving organizations more control over their post quantum journey.

Russ and Eddy also discuss the “harvest now, decrypt later” threat, where adversaries collect encrypted data today and wait until quantum computers can break it in the future. That makes quantum security a current issue, not a distant one. Eddy argues that organizations should start by securing the biggest pipes carrying the most important data, including backup, data center, high value network, healthcare, financial services, and critical infrastructure traffic.

Along the way, Eddy covers NIST standards, federal timelines, cryptographic inventory, FIPS validation, vendor dependence, budget gaps, congressional testimony, and why real crypto agility means being able to hot swap algorithms without creating network downtime.

Topics Covered:

[00:00] Welcome and intro, Eddy Zervigon and Quantum Xchange

[01:06] What Quantum Xchange does

[01:30] NIST, post quantum algorithms, and architectural security

[02:14] Why encryption must keep evolving

[02:50] AI as the brains and quantum as the brawn

[03:33] Eddy’s background in investment banking and mission driven companies

[04:55] Separating cryptographic control from the data plane

[05:35] Why embedded endpoint encryption is no longer enough

[06:30] Why algorithm updates should not require downtime

[07:32] Why the post quantum threat is urgent

[08:21] Harvest now, decrypt later

[09:36] What happens if organizations do nothing

[09:51] Why cryptographic inventory alone may not be enough

[10:30] Securing the biggest data pipes first

[11:37] Why migration is harder than people assume

[11:52] Moving beyond set it and forget it encryption

[13:21] Reducing post quantum migration timelines

[14:10] How often algorithms may need to change

[14:26] NIST algorithms and future uncertainty

[15:42] Change nothing, change everything

[16:08] Comparing crypto control to identity and access management

[17:02] Why network engineers are cautious

[18:00] What the next two years may look like

[19:21] Guidance for smaller and mid-sized businesses

[19:41] Starting with the most sensitive data flows

[21:37] Deciding what needs to be quantum safe first

[22:59] Federal post quantum migration deadlines

[23:27] Standards, validation, FIPS, and common criteria

[24:19] Eddy’s congressional testimony

[25:38] Why budgets need to match timelines

[26:21] Defining real crypto agility

[26:40] Hot swapping algorithms without downtime

[27:41] Final thoughts on crypto agile versus crypto fragile

Close

Stay Up To Date

Be in the know about upcoming industry award programs, nominees, winners, finalists, and judges

Submit
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.