Welcome to the third installment in “A Walk in the Park,” a new short video series that explores the forces reshaping the future of digital trust. Over the next five weeks, we’ll take conversations out of the conference room and into the open air as our experts unpack some of the biggest challenges facing security leaders today. Watch the first, second and third episodes here.
There are three things you can count on in life. Death. Taxes. And cryptographic debt.
The first two, everybody gets. The third is a special gift for security teams.
Most people hear “debt,” and they think money. Cryptographic debt is simpler than that. It’s the gap between the cryptography you’re actually running and the cryptography you can account for. For most organizations, that gap is enormous.
I want to be direct about this, because it has quietly become one of the largest unmanaged risks in organizations today.
▶️ Watch the episode: Ryan and I discuss cryptographic debt in this episode of A Walk in the Park. Below, I go further into what it means and how to address it.
So what is cryptographic debt?
Here’s the plain version.
Cryptographic debt is when an organization doesn’t know what cryptography it has. The keys. The certificates. The algorithms, the protocols, the libraries. They’re everywhere, and they’re written down almost nowhere.
Anything you can’t see, you can’t manage. Anything you can’t manage is a risk. That’s the debt.
It built up honestly. For almost fifty years, the math under digital trust just worked. So teams could get away with a set-it-and-forget-it approach. Configure it once. Check it only when something breaks.
So now I walk into environments and find the same thing every time. Cryptographic assets scattered across the cloud, the network, the apps, the identity stack. The way I say it: where you have data, you have cryptography. Which means it’s everywhere.
Why this matters now
Here’s the part that gets missed.
People assume that because this cryptography has worked for decades, it can keep coasting. It can’t. The reason is simple. There’s a new set of quantum-safe algorithms that everyone is eventually going to have to move to. And that migration takes a long time to pull off without breaking the systems that use it.
The timeline also just got real.
In March 2026, Google set a 2029 deadline to migrate its own systems to post-quantum cryptography. That’s years ahead of where most guidance sat. Then, in June 2026, the White House signed an executive order pushing federal agencies to move high-value systems to post-quantum key establishment by the end of 2030, and signatures by the end of 2031. NIST’s own guidance deprecates today’s algorithms by 2030 and disallows them by 2035.
Read the room. When the people closest to building quantum computers are making the move by 2029 or 2030, that isn’t vendor noise. That’s the folks with the best view of the cliff telling everyone else how close the edge is.
If they’re moving, it’s time to move.
The part teams underestimate
The hard part isn’t the algorithms. It’s that all of this cryptography is codependent.
Keys, certificates, algorithms, protocols, libraries. They all lean on each other. You can’t just swap one piece at the top, or one at the bottom, and call it done. Change the wrong thing in isolation, and something breaks. Something fails. And that failure is disruptive.
So you can’t treat this like a line item. You have to see everything that needs to change, and change it together. That’s what makes the debt so dangerous. It isn’t a single bill. It’s a tangle.
Where to start
Nobody can do this all at once. It’s like trying to boil the ocean.
Start by getting one honest, collective view of the cryptography inside your organization. You’ve probably got several tools, each handing you a partial picture. Pull that into one centralized inventory. Then measure it against a known set of risk parameters. It’s called Cryptographic Posture Management.
Then prioritize. No two organizations have the same data, so no two will have the same answer. Ask the real questions. What are my most critical assets? What do I need to protect first? Line your cryptography up against the data and systems it protects, and move from there.
Over the long term, this is an investment. But there are things you can do today, with the tools and teams you already have, to start.
And everyone should start as soon as possible. We don’t know exactly when that cryptographically relevant quantum computer shows up. The closer you are to ready when it does, the better off you are. The organizations that don’t prepare are the ones that end up exposing data in the most predictable zero-day in cybersecurity history.
Cryptographic debt is the problem sitting underneath all the other problems. You can’t pay down a debt you can’t see. It’s time to tally yours.
Next up: Join me next week in the final episode of A Walk in the Park as I look at the threat from a different angle—harvest now, decrypt later.