Monthly Archives: July 2026

The 2026 Global Study on Postquantum and Cryptographic Security Trends

The purpose of this research is to provide important information about trends in post quantum, cryptographic security, PKIs and HSMs. Ponemon Institute surveyed 4,149 IT and IT security practitioners who are familiar with the use of these technologies in their organizations.

The countries in this research are the United States (552 respondents), United Kingdom/Ireland (573 respondents), Canada (396 respondents), DACH (553 respondents), Indonesia (369 respondents) and Singapore (482 respondents).

The post quantum threat is coming quickly, but will organizations be prepared? Quantum computing is a rapidly emerging technology that harnesses the laws of quantum mechanics to solve problems too complex for classical computers. The quantum threat, sometimes referred to as “post quantum”, is the inevitability that within the decade it will be capable of breaking traditional public cryptography such as RSA and ECC.

Only 38 percent of respondents say their organizations are preparing for the post-quantum threat, a slight decrease from 41 percent in last year’s report. Of these respondents, 44 percent from 2024 and 2025 are building a post-quantum cryptography strategy.

Thirty-two percent of respondents say their organizations are taking an inventory of their cryptographic assets and/or ensuring they are crypto agile. This is a decline from 38 percent of respondents in last year’s report. Testing within organizations’ systems and applications increased significantly from 10 percent of respondents to 21 percent.

The following summarizes the most significant research trends in postquantum and cryptographic trends

Organizations believe the PQ threat is imminent. Seventy-five percent of respondents agree and say a quantum computer will be capable of breaking traditional public key cryptography within 5 years (51 percent) or in 5 to 10 years (24 percent). Only 12 percent say it will never happen.

 The biggest challenge to reducing the quantum-threat and migration to post quantum cryptography (PQC) continues to be the inability to improve the discovery/inventory of their organizations’ cryptographic assets. Forty-one percent of respondents in this year’s study vs. 43 percent of respondents in last year’s study say the inability to improve visibility into their cryptographic assets is the greatest concern. Two concerns that have increased significantly are the lack of an adequate budget (39 percent in this year’s study vs. only 31 percent in last year’s study) and lack of in-house expertise (38 percent in this year’s study vs. only 28 percent in last year’s study).

Fifty percent of respondents say a successful quantum attack would have a serious impact on their organizations and industries. Fifty percent rate the potential impact as serious, but only 36 percent of respondents rate the adequacy of government policy and public-private coordination on quantum readiness as more than adequate. A successful quantum attack against organizations and industries could result in the loss of access to encrypted critical infrastructure (58 percent of respondents) and exposure of long-term sensitive data such as health records and trade secrets (59 percent of respondents).

The lack of visibility into the cryptographic estate, certificates and keys and secrets puts organizations’ cryptographic security at risk.  Only 43 percent of respondents say their organizations have full or complete visibility into their organizations’ cryptographic estate and only 43 percent of respondents say they have full or complete visibility into certificates across the organization and only 40 percent say they have full or complete visibility into keys and secrets across the organization.

Private cloud-based applications and mobile device authentication applications that use PKI credentials declined significantly from 2024. Private cloud-based applications using PKI declined the most (56 percent of respondents in 2024 vs. 32 percent of respondents this year). Mobile device authentication decreased from 60 percent of respondents to 41 percent of respondents). The top applications using PKI credentials are private networks (52 percent of respondents), SSL certificates for public facing websites and services (50 percent of respondents) and document/message signing (45 percent of respondents).

Internal corporate certificate authorities (CAs) are most often used to deploy PKIs but have declined since last year. Forty-six percent of respondents in this year’s report use CAs to deploy PKI and 60 percent of respondents in last year’s study. Business partner provided service increased the most from 18 percent of respondents in last year’s report to 40 percent of respondents in this year’s study. Private CAs running within a public cloud increased from 21 percent of respondents last year to 37 percent of respondents this year.

The most important security certification when deploying PKI infrastructure is Common Criteria EAL Level 4+ (54 percent in this year’s study vs. 57 percent of respondents in last year’s study). The second most important certification is FIPS 140-2 Level 3. However, its importance has declined significantly from 55 percent of respondents to 32 percent of respondents.

The biggest uncertainty and concern about the evolution of PKI are PKI technologies and external mandates and standards. When asked what the greatest areas of change and uncertainty to PKI will be, 49 percent of respondents say it is PKI technologies, an increase from 43 percent in 2024 and external mandates and standards, an increase from 37 percent of respondents in 2024. Budget and resources, increased significantly to 43 percent of respondents vs. 30 percent of respondents.

More organizations use HSMs and use HSMs to secure PKI. Sixty-six percent of respondents in this year’s research vs. 55 percent of respondents in last year’s research say their organizations use HSMs. Sixty-three percent of respondents in this year’s research vs. 51 percent of respondents in last year’s research say their organizations use HSMs to secure PKI.

The top areas of deployment to secure PKI are online roots and offline roots. According to last year’s research, 47 percent said they are deployed to secure PKI in online roots and 42 percent said they are deployed to secure PKI in offline roots.  

Part 2. Key findings

 In this section we present the research results in detail. The compete audited findings are shown in the Appendix. The report is organized according to the following topics. Whenever possible, trends in research findings from last year’s Entrust study are included. 

  • Postquantum: The Threat and the Readiness Journey
  • Cryptographic Security and Management
  • Trends in PKI Security and HSMs

To read key findings and the rest of this report, visit Entrust’s website here. 

As AI enteres the real world, it’s going to crash into the Plateau Effect

Bob Sullivan

We just learned that Waymo is recalling about 4,000 self-driving cars because they can’t read highway construction signs.

According to Road & Track, some Waymo cars “failed to recognize and drove past ramp closure signs into pre-planned freeway construction zones; Waymo recorded six of these events in April 2026 in Phoenix, Arizona. In an additional seven incidents in May 2026 in San Francisco, California, the offending Waymos drove between cones designating lane closure.”

That’s a) terrifying b) a ridiculous engineering failure.  Construction is hardly a rare condition of highway driving. How did cars not equipped for this get released into the world?

Because someone, somewhere, believes certain sacrifices must be made for progress.

Waymo’s mistake is a very bad example of the kind of real-world exception conditions that have been derailing self-driving cars for more than a decade. Those same pesky, weird realities will soon make many wild promises about artificial intelligence look a equally silly — and cost a lot of investors a lot of money.

A few years ago, I wrote a book called The Plateau Effect with Hugh Thompson, former CEO of Symantec (this piece is my opinion alone, fyi).  The concept of the book is simple: plateaus appear everywhere in life, and they bedevil everything and everyone that seems to be making quick progress. People losing weight hit plateaus; people learning guitar or a new language hit plateaus; drugs hit plateaus. Once you start to look, you see plateaus everywhere. A simple example for geeks: Finding the first 99% of bugs in software is relatively easy. Finding the last few is often a nightmare — finding the last 1 percent can take longer than finding the first 99 percent. Sometimes, they’re never found. And so it will be for AI.  The Plateau Effect looks like one of those calculus curves where you approach…but never reach…a limit.

The Plateau Effect in Learning. Anything. (phuongvu.me)

Life is full of these kinds of exception conditions.  Shit happens. One might say Murphy’s Law suggests that weird stuff like this is normal. Computers don’t do well with irregular inputs, as I’m sure you know. “That….does….not….compute…”


This is part 2 of a three-part miniseries on Artificial Intelligence.
Read part 1: Disarm AI, yes, but the Pope was just getting started
Read part 2: Artificial Intelligence needs a police blotter. Wait, it already has one!


Were a tech mogul sitting here, he’d furiously grab my keyboard at this point and tell me that millions of miles of data will solve this problem — there are only so many exception conditions on the roads, and eventually the supercomputer in the sky will be prepared to deal with all of them.  Even without The Plateau Effect, this feels foolishly optimistic to me. Exhibit A is Waymo’s current inability to deal with road construction.  But assuming that can be fixed, there will be weird, pesky, unexpected road conditions for as long as humans roam the Earth.  Dealing with the first 99% won’t be so hard.  Dealing with that last 1 percent will be very, very hard.  It’s not going to happen soon, with self-driving cars and many AI applications.

Elon Musk has been promising full self driving cars will be ready in a year or two since…2013.  There’s nothing new about this kind of hype cycle.  It’s meant to generate excitement and investment so early investors can make off with a lot of cash, funded by later investments.  And this pattern keeps working as long as investors believe in tomorrow.  Forget autonomous cars; the real future is on Mars!  And so it goes.

See, it’s easy to make a car that can ride on highways which can follow predictable patterns — roads you could drive with your eyes closed.  But when an 18-wheeler loses a tire tread and cars in front of you start to swerve and dart, well, your eyes better be open.  Another example, shared with me recently by Sean McGregor of the AI Incident database: When a dog gets loose in stop-and-go traffic, What Would Waymo Do?

But what about all the dire warnings of AI software teaching itself how to destroy humanity? First off, if you were actively building a tool that would blow up the world, wouldn’t someone at these firms throw the assembly line emergency stop switch? But more to my point here: I suspect AI investors don’t mind all these doomsday scenarios because they help build buzz. I’ve watched entire documentaries about scary AI futures that don’t even raise the question: Are we sure this stuff will actually work? The a priori assumption that we’re successfully building God is pretty valuable to these early investors.

I’m *NOT* saying none of this stuff works.  AI is great at writing perfectly trite emails, though my smartphone recently replied “how are you?” to someone on my behalf when I had no intention of asking.  That was awkward.  Can a Tesla in FSD mode drive better than a teenager playing with his smartphone? Yes, I think so. I drive a car with a lot of automated safety technology that I think works great.  But can a Tesla on autopilot deal with a dog on the highway better than a human with good judgment? Not yet. And, I’ll wager, not for a long time.

I’m harping on this point because ignorance of The Plateau Effect sets up a perfect situation for those who benefit from AI hype.   Tech moguls and PR firms generate a lot of attention and money with wild promises about tomorrow. At trade shows, I used to call this the ‘next quarter’ game.  People would hawk all kinds of great new hardware and software through amazing demos in Q3, then promise it would be ready by Q4. But in tech, Little Orphan Annie is a liar. Tomorrow is much more than a day away.

I don’t care so much about people who want to play this game with investment cash. That’s their business. What I care about is the “sacrifices” that tech firms will decide are acceptable as they run harder and harder into the Plateau Effect.  Regulators and voters have to be ready to recognize the dangers we are about to encounter, and the language that will used to distract us. Like Google itself, AI will be in beta mode for a long time.