TechChannels Expert Insights

Q&A: Yubico’s Albert Biketi Advises on Preparing for the Post-Quantum World: Why Crypto Agility Has to Start Now

Written by Teri Robinson | Oct 3, 2026, 12:49:29 AM

The arrival of a cryptographically relevant quantum computer may still be somewhere over the horizon, but the security implications are already here. Sensitive information that needs to remain confidential for decades can be collected today and potentially decrypted later, creating a risk that organizations must address long before quantum computers are capable of breaking current cryptographic protections. At the same time, the sheer volume of digital information, the complexity of modern encryption architectures and advances in quantum error correction are adding urgency to the transition.

Preparing for that future is not as simple as swapping one encryption algorithm for another. Organizations first need to understand where sensitive information resides, identify their encryption dependencies and determine how cryptography is embedded across interconnected systems. For many enterprises, that discovery process alone could take years. And because cryptographic approaches can change as new weaknesses emerge, Albert Biketi, Chief Product and Technology Officer at Yubico, in Part One of a wide-ranging interview, argues that organizations need more than a migration plan—they need crypto agility, or the ability to adapt without disrupting critical business processes.

Q. What is the fundamental security risk organizations need to understand about the post-quantum world?

A. It’s often helpful to start with just the most basic thing, which is that some information needs to remain confidential for a long time, for decades even. But we now live in a world where it's plausible that attackers can collect encrypted information today, and then potentially decrypt it later because the algorithms to protect the information were designed at a time when computers had capabilities that meant that if they tried to crack those encryption algorithms, they would not do it in a feasible timeframe.

However, math and technology being what it is, we now are living in a transitional period where the preparation has to happen before that capability arrives, and that capability is what we call a cryptographically relevant quantum computer.

Q. Is the arrival of cryptographically relevant quantum computing happening faster than expected?

A. Yes, but it's not as simple as just saying, "Yeah, it's coming really fast.” There are a couple of things at play. The first one being that just the amount of information that we've turned to digital trails everywhere has become enormous. So much so that everything we rely on as critical infrastructure has some kind of digital component to it. And that also means that the volume of information that might be amenable to this kind of attack and have consequences has become enormous.”

The second thing is not even about being alarmist. It's just that sorting through everything that you have to do to have protections in place is non-trivial. It does take a while to actually understand all the places where you would have information that depends on something that could be superseded.

Q. What technological developments are potentially accelerating the quantum timeline?

A. One is that the error correction in the algorithms that quantum computers use to generate the state in which they can actually do computationally useful things has improved dramatically. As you start to improve error correction, you start to get compounding, and what people are also realizing is that in some cases, the larger you make some of these systems, the more resilient they become.

The second thing is the technology itself. All the investment going into post-quantum computing is doing so for very good reasons. It's worthwhile to invest in it because there are some problems that were previously considered to be intractable, even by very large supercomputers, that can be solved reasonably in the kind of time that could accelerate and create human benefit. So, there is going to be investment in this area to continue to drive progress. And what those two things do is that they just bring the timetable closer and closer.

Q. Why is it difficult for organizations to prioritize post-quantum preparation before the threat fully materializes?

A. It's a mixed answer. The nuance is that there are many problems that have very clear costs, but highly distributed benefits, and those tend to be very difficult to mobilize until you really have to mobilize. The challenge isn't in people making investments; it's that it's very difficult to coordinate something so distributed, where there's a very narrow field of expertise around how to think about the problem, and bandwidth in terms of just human attention is constrained because you're dealing with 40-50 other things.

So, what you sometimes find is that even in large organizations, there's usually a very small group of people who've been thinking about this for a long time, and those people will frequently have a small number of other counterparts in other companies that are thinking about the problem deeply.

Q. What role are governments and regulators playing in driving the transition?

A. Regulators will start asking people to put in place all the measures they have. For example, there are some monetary authorities in other jurisdictions, and including the United States, where you start to see national actions. There's an Executive Order 14412 to double-check around securing the nation against advanced cryptographic attacks. That was the first binding mandate that required civilian federal agencies to migrate high-value systems to NIST-approved post-quantum compute. These kinds of things take time, but agencies, for example, in the United States are now required to complete post-quantum transitions for one specific thing, which is key exchange and for digital signatures, which is another key thing to think about by the end of 2031. That's just because this thing that people call HMDL, harvest now decrypt later, is really going to become a big problem, and people need to know that you can steal information today that will still have very high value when decrypted two, three, or evenive years from now.

Q. Are organizations taking action quickly enough?

A. The G7 has similar initiatives happening and on the military front, there's similar things going on. People are taking action, but like anything, procrastination is both the thief of time and something that is just protective because organizations usually have to prioritize.

Q. How can organizations protect their existing technology investments while preparing for a post-quantum world?

A. A lot of organizations will work through this in ways that give them the flexibility to exist in what we call the classical world and the quantum world, the post-quantum world with logical investments where things take time. What’s being recommended is not just how fast you move to transition, but how agile you are to change if things change, and part of this is just a lesson that comes from just advances in mathematics, advances in artificial intelligence, and the incredible power of the models that we have now.

Q. Why is crypto agility so important during the transition?

A. One of the things that came through in the competition to establish the algorithms that would be approved by NIST as standardized algorithms for post-quantum is that there were algorithms that everybody thought were going to be finalists that were then very trivially overcome. And so that was that was a big surprise, and I think for people who've been in cryptography a long time, we've seen this before, where people think that there's a particular approach and it feels and looks very promising, and then, lo and behold, there's some kind of attack that shows up.

The lesson is that organizations will have a multi-year rollout for this, but they need an agile framework architecture around how they do things, so that if they need to swap out some underlying primitives, they can do that without completely freezing their organization or breaking critical processes.

Q. How should organizations weigh the cost of acting now against waiting for greater certainty?

A. In a lot of the conversations you have with organizations about what this transition looks like, there's the cost of waiting for certainty. Then there's the cost of building in a way that gives you crypto agility. And there’s the cost of mobilizing an entire organization to be behind an effort where it needs everybody to be behind it. As people prioritize this approach of getting to be more agile about how to respond to things it is going to be at the forefront of everything. I cannot remember another time in technology when things moved as quickly as they are moving today.