From the Summer 2026 Issue

From the Editor-in-Chief

Adam Firestone
Editor-in-Chief | United States Cybersecurity Magazine | SIX3RO

adam-firestone

Hello,

For years, the cybersecurity community has comforted itself with the belief that Cryptographically Relevant Quantum Computers (CRQC) and the transition to Post-Quantum Cryptography (PQC) were distant, highly specialized concerns, matters for researchers and/or a narrow technical elite.  That belief is no longer defensible. Executive Order (EO) 14409, signed by President Trump on June 22, 2026, makes the requirement for action immediate and, while the EO is nominally targeted at federal agencies, what it does in a larger sense is place responsibility squarely where it belongs: with organizational leaders across every sector.

The EO confronts the Harvest Now, Decrypt Later (HNDL) threat head on.  It establishes a national policy to safeguard national security and maintain technological leadership by transitioning federal information systems to NIST-approved, post-quantum cryptography and assisting critical infrastructure owners and operators with their own transitions.  It requires each agency to designate a PQC migration lead within 30 days. It also directs the Office of Management and Budget (OMB) to issue binding guidance within 90 days.  That guidance must require agencies to review inventories of high-value assets and high-impact systems, develop prioritized migration plans, and complete the transition of those systems to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031, significantly accelerating the previous PQC horizon of 2035. It launches a NIST pilot project, calls for guidance on Cryptographic Bills Of Materials (CBOM), strengthens procurement rules for federal contractors, and coordinates support for critical infrastructure sectors.

Analysis of the environment into which the EO was thrust exposes a deeper problem. Cybersecurity has long been presented as an esoteric discipline beyond the ken of organizational leaders. The post-quantum transition is often portrayed as even more impenetrable, an arcane realm of advanced mathematics, specialized hardware, and quantum physics accessible only to a select few. This framing produces two damaging outcomes. First, it creates leadership paralysis. Executives, boards, and agency heads conclude the subject lies beyond their capacity for informed oversight and therefore defer, delay, or outsource planning and decision making entirely. Second, it empowers a self-appointed consultant class that frequently amplifies perceived complexity to create demand for its services. Many in this class possess no demonstrably superior command of the underlying cryptography or migration engineering than the organizations they advise. Both outcomes retard progress and waste resources at the precise moment when disciplined, time-efficient action is required.

The cybersecurity profession has an obligation to reject both tendencies. Knowledge acquisition is a core duty of leadership, not an optional technical specialty. Leaders already make high-stakes decisions on cloud migrations, legacy system modernization, regulatory compliance updates, and major technology refreshes. The post-quantum transition follows the same proven playbook. It is the same kind of disciplined, methodical work that IT teams have been doing for decades; understanding what the organization actually controls and can impact, rejecting hype in favor of ground truth, maintaining asset inventories, managing hardware and software lifecycles, tracking vendor roadmaps, applying patches and firmware updates, testing changes in staging environments, deploying in phases with rollback plans, and monitoring through normal operations. This work centers on the software libraries, firmware modules, and hardware components in which cryptography is implemented, rather than on abstract ideas.  Leaders do not need to become cryptographers. They simply need to direct the familiar governance, budgeting, upgrading, and project management disciplines their organizations already execute successfully every day.

Executive Order 14409 supplies the national framework, including designated accountability leads, required plans, concrete deadlines, technical guidance from NIST and CISA, procurement incentives, and mechanisms for visibility and coordination. It removes the excuse of ambiguity. Leaders, in turn, need to exercise the same strategic oversight and resource allocation they apply to every other category of enterprise risk and technology investment.

Our responsibility in the cybersecurity community is to put those leaders in every part of the American economy, from law firms to logistics, from defense to consumer electronics, and from energy companies to education, back in the driver’s seat. We must supply meaningful advice, practical implementation roadmaps, validated tools, and clear metrics for success. We must translate technical requirements into business language rather than gatekeep behind jargon. We must support execution rather than foster perpetual dependency. This is an ethical duty to the organizations, employees, customers, and citizens we serve. It is also a patriotic duty. As the United States marks its 250th anniversary in July 2026, securing the cryptographic foundations of our digital systems, economy, communications, and national security stands as a direct contribution to preserving American strength and institutional resilience for the next quarter-millennium and beyond.

The choice before us is between two very different outcomes, one destructive, one generative. We can allow the perception of inaccessibility to persist, tolerate paralysis, and permit exploitative practices to slow the nation’s progress. Or we can fulfill the higher calling of our field: to demystify the challenge, to empower competent leadership at every level, and to ensure that every organization, regardless of sector, can navigate its own post-quantum transition with confidence and competence.

Build it right, America.

Adam Firestone sig
Adam Firestone
Editor-in-Chief

Leave a Comment