Enterprises should treat post-quantum cryptography as a current business issue rather than a distant technology concern, according to Michael Jordan, Distinguished Engineer for Cybersecurity and Compliance at Broadcom NASDAQ: AVGO.
Speaking during The Six Five Summit's AI Unleashed 2026 event, Jordan said post-quantum cryptography, or PQC, refers to cryptographic algorithms that run on classical computers but are designed to resist attacks from quantum computers. The issue is increasingly important because cryptography has become foundational to modern IT operations, including web applications, APIs, hybrid cloud environments, cryptocurrency and asset tokenization.
"Cryptography really serves as the foundation of trust for our modern IT world," Jordan said. "Because it has evolved to become that foundation of trust, and if it gets broken, we have a business problem and a business challenge to address."
Quantum Risk to Existing Encryption
Jordan explained that widely used encryption approaches such as RSA and elliptic curve cryptography depend on mathematical problems that are impractical for classical computers to solve. Public and private keys are mathematically related, but deriving the private key from the public key would take millions or billions of years using conventional computing resources, he said.
Quantum computing could change that calculation. A sufficiently capable quantum machine, sometimes described as a cryptographically relevant quantum computer, could run algorithms such as Peter Shor's algorithm to factor integers and compromise RSA encryption, Jordan said.
Once the mathematical components underlying a public key can be calculated, an attacker could derive the associated private key, he added. That possibility is driving the push for organizations to identify where their current cryptography is used and plan eventual migration to quantum-resistant alternatives.
Planning Must Begin Before the Deadline Is Known
Jordan said a major complication is that organizations do not have a fixed deadline for completing a PQC transition. Estimates point to the early next decade, beginning around 2030, for quantum computers capable of solving the relevant mathematical problems, but technological advances could occur sooner.
He cited the surprise market reaction to the emergence of China's DeepSeek AI model as an example of how technology can advance faster than many observers expect.
However, Jordan said the more immediate challenge for enterprises is understanding how long their own migrations will take. Without discovery, inventory and planning work, organizations cannot accurately estimate the resources, dependencies and timeline needed to move from existing cryptography to PQC.
"There's nothing that's stopping us from doing that planning work now," Jordan said. He recommended that companies identify where they use cryptography, build an inventory, and understand internal and external dependencies before beginning the migration process.
Jordan characterized a successful migration as one that "beats the clock" before quantum capabilities can compromise current encryption.
Harvest Now, Decrypt Later Concerns
Jordan also said the risk commonly described as "harvest now, decrypt later" should not be viewed as a scare tactic. Under this scenario, well-funded actors collect large volumes of encrypted data today with the expectation that they could decrypt it later once sufficient quantum computing capabilities become available.
He said concern over the practice is particularly associated with governments and the threat of state-sponsored actors rather than individual attackers. The risk is greatest for information with a useful life measured in years or decades, rather than data that loses value within minutes.
More aggressive PQC migration timelines in some geographies and organizations are partly driven by efforts to reduce exposure to this type of threat, Jordan said.
He added that the discovery process can uncover security weaknesses that extend beyond the quantum issue. Organizations may find technical debt, including systems using weaker cryptographic algorithms than leaders realized. Addressing those weaknesses and applying the strongest currently available technology can reduce exposure to harvest-now, decrypt-later risks, he said.
Risk-Based Migration and Cyber Resilience
For organizations deciding which systems to update first, Jordan recommended a risk-based approach. Inventory efforts should capture metadata about protected assets, the applications involved and internal and external dependencies, he said.
Companies can then assess the potential business impact if an asset is compromised and prioritize the migration of their most critical systems.
- Identify all cryptographic use cases across the enterprise.
- Document the assets, applications and dependencies tied to those implementations.
- Assess the business impact of compromise for each protected asset.
- Prioritize migration efforts around the highest-risk and most critical systems.
- Address existing technical debt and weaker cryptographic implementations.
Jordan said PQC should also be considered within a broader cyber-resilience strategy. Quantum computing and frontier AI models represent disruptive technologies that could expand the capabilities available to threat actors, he said. Quantum systems could threaten encryption, while AI models could help identify vulnerable or misconfigured systems and code.
As a result, organizations need not only preventive controls, but also the ability to detect attacks, respond to incidents and recover when defenses fail, Jordan said. That preparation requires coordination across the organization, he added.
About Broadcom (NASDAQ:AVGO)
Broadcom Inc NASDAQ: AVGO is a global technology company that designs, develops and supplies semiconductor and infrastructure software solutions for a broad range of markets. The company's semiconductor business provides components and systems for wired and wireless communications, enterprise and cloud storage, networking and broadband access, serving original equipment manufacturers, cloud service providers, telecommunications carriers and industrial customers worldwide. Broadcom is headquartered in Irvine, California, and operates globally with research, development and sales organizations across North America, Europe and Asia.
On the semiconductor side, Broadcom's portfolio includes system-on-chip (SoC) and application-specific integrated circuit (ASIC) solutions, radio-frequency and connectivity components, Ethernet switching and PHY devices, storage adapters and controllers, optical transceivers and other networking silicon.
This instant news alert was generated by narrative science technology and financial data from MarketBeat in order to provide readers with the fastest reporting and unbiased coverage. Please send any questions or comments about this story to contact@marketbeat.com.

Continue following MarketBeat
Add MarketBeat as your preferred source on Google to see our latest stories in your feed.
Before you consider Broadcom, you'll want to hear this.
MarketBeat keeps track of Wall Street's top-rated and best performing research analysts and the stocks they recommend to their clients on a daily basis. MarketBeat has identified the five stocks that top analysts are quietly whispering to their clients to buy now before the broader market catches on... and Broadcom wasn't on the list.
While Broadcom currently has a Moderate Buy rating among analysts, top-rated analysts believe these five stocks are better buys.
View The Five Stocks Here
MarketBeat just released its list of the 7 hottest IPOs expected to hit Wall Street in 2026. See which companies are preparing to go public and why investors are watching closely.
Get This Free Report