Post-quantum readiness: Where to start, key strategies, and what to avoid Todd Moore of Thales outlines post-quantum readiness essentials: Start with a cryptography inventory, build crypto agility, avoid point solutions, and act now before quantum threats arrive. "You can't fix something if you can't see it," warns Todd Moore, VP of Encryption at Thales. For most Fortune 500 companies, their cryptographic infrastructure remains dangerously invisible. Speaking with Dark Reading's Joan Goodchild at Black Hat USA, Moore stresses the need for a cryptography inventory, mapping every key, algorithm, and protocol before quantum computers render legacy encryption obsolete. With a 2029 regulatory deadline looming, time is running out. Moore argues the biggest mistake CISOs make is believing they can buy their way to quantum safety. Swapping in post-quantum algorithms without addressing protocols and infrastructure will disrupt banking systems, internet services, and enterprise applications. True readiness requires crypto agility — a hybrid architecture supporting old and new algorithms while transitioning systematically. There’s no single solution, only a phased plan. Moore also highlights an urgent convergence: AI agents are multiplying, relying on legacy cryptographic foundations now under threat. Encouragingly, AI can accelerate crypto discovery, helping organizations close gaps before quantum computers arrive. CISOs who fail to secure post-quantum budgets alongside AI investment today will likely regret it within five years. Todd Moore, VP of Encryption Products at Thales, focuses on data protection, encryption strategy, and cryptographic lifecycle management. With expertise in key management, hardware security modules, and post-quantum standards, Moore helps organizations build crypto agility frameworks to navigate evolving threats.