Compliance won’t save you, but culture might
Why cybersecurity leaders are shifting from compliance to culture, and how building a security-first workforce strengthens organisational resilience.
Read More
Cybersecurity has a habit of preparing for yesterday's problem. Cloud, ransomware and generative AI all hit commercial use faster than many organisations anticipated, forcing security teams to adapt at speed. And as Margarita Rivera (Global CISO at Carnival Corporation) points out, that’s a weakness:
"I think it's one of the things we see the most in our industry, where our folks are more reactive rather than proactive."
Rivera believes quantum computing presents an opportunity to change that pattern before it’s too late.
"We know quantum computing is here, it's coming, it's going to become more pervasive – just like we see with AI. We really have to be more proactive in the way that we look at that."
Her comments reflect a wider shift taking place across governments around the world. In June 2026, for example, the White House issued an Executive Order on securing the nation against advanced cryptographic attacks, alongside an Office of Management and Budget (OMB) memorandum directing federal agencies to begin executing the migration to post-quantum cryptography.
This sends a strong message: preparation for quantum is becoming an operational priority.
For many organisations, quantum computing still feels like a distant concern. Practical, large-scale quantum computers capable of breaking today's encryption are not yet widely available.
But that doesn't mean the risk isn’t here yet.
Marcos Marrero (CISO at H.I.G. Capital) has spent the last two years preparing for exactly this challenge.
"I've spent the better part of about the last two years continuously talking about quantum. My internal team from security operations are working on quantum-resistant cryptography."
His concern centres on a scenario commonly known as ‘harvest now, decrypt later’. Adversaries can steal encrypted information today, hold onto it, and wait until quantum computers become powerful enough to decrypt it.
"The world will change once quantum computing enters the private sector,” Marrero says. "Let's make no mistake about it. Nation states have access to it now, but when it becomes democratised and it's now available to the public, that is when we're going to start seeing a lot of bigger problems."
That concern is echoed in the latest US quantum strategy, which warns that adversaries may already be collecting encrypted information now with the intention of decrypting it once quantum capabilities mature.
One of the biggest misconceptions around quantum readiness is that organisations simply need to replace their encryption algorithms.
In reality, the challenge is much broader.
Recent guidance from the National Institute of Standards and Technology (NIST) and the OMB encourages organisations to begin by identifying where cryptography exists across their environments, understanding which systems rely on vulnerable algorithms and working closely with suppliers on migration plans.
The guidance also highlights the importance of cryptographic agility – building systems that can replace cryptographic algorithms with minimal disruption as standards evolve.
Marrero believes vendors have a critical role to play.
"I've started asking vendors over the last eight to nine months what quantum computing controls or tactics they've implemented within their platforms."
His assessment is mixed – with many vendors meeting his questions with “blank stares”.
"There are a few vendors that are at the forefront of quantum computing. Most tend to lag behind. They don't see it as an immediate problem."
That vendor conversation is likely to become even more important as organisations assess supplier readiness alongside their own migration strategies.
Technology is one thing, but Rivera argues that the cybersecurity profession itself needs to evolve if organisations are going to stay ahead of emerging technologies.
"Technology is changing quite quickly, and learning and being able to prepare for attacks is going to take folks that are willing to put in the time to learn and to grow and to prepare themselves and their teams."
That means investing in people as much as platforms – because upskilling is a key challenge for CISOs today.
"We can't approach security with 10-year-old tactics or 10-year-old approaches or mindsets. We have to continue to evolve."
Learning, she argues, extends well beyond formal training.
"Partnering definitely with network communities, with peers… coming to events like this and hearing from other thought leaders and how they're approaching things around quantum computing… really does help that growth curve."
No one can predict precisely when quantum computing will become a mainstream enterprise risk. But it’s clear that governments, standards bodies and leading CISOs have already moved beyond debating if organisations should prepare. The conversation has shifted to how.
The US government’s roadmap recommends organisations begin by understanding where cryptography is deployed, building cryptographic inventories, engaging suppliers and developing phased migration plans rather than waiting until quantum computers become commercially viable.
Rivera believes the industry has a chance to avoid repeating the mistakes it made during previous waves of technological disruption.
"I think we're going to see a lot more proliferation and preparedness for quantum computing. It is definitely on the docket."
Because if AI taught cybersecurity anything, it’s that waiting until a technology becomes mainstream usually means waiting too long. Now, we have an opportunity to prepare for quantum before the disruption hits.
Listen to the full interview with Margarita Rivera and Marcos Marrero on The Black Hat Files.
Join the newsletter to receive the latest updates in your inbox.
Why cybersecurity leaders are shifting from compliance to culture, and how building a security-first workforce strengthens organisational resilience.
Read More
Mobile devices have become AI's new frontline. Discover how embedded AI, mobile apps and limited visibility are influencing enterprise AI governance and cybersecurity.
Read More
Phishing attacks no longer stop at the click. Learn how encrypted traffic, MFA bypass and 21-second attack timelines are forcing organisations to change their phishing defence.
Read More