Uploaded December 2025 | Updated September 2026, 3 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/9a/PQC%20OWASP.pptx
Banking systems. Government data. Healthcare records. All of it encrypted today—and potentially breakable tomorrow by quantum computers.
While the arrival of quantum computing may feel distant to many, the security risk is already here. Bad actors can harvest encrypted data today and decrypt it later when quantum capabilities catch up. Post-quantum cryptography (PQC), designed to withstand both classical and quantum attacks, is the way forward. But identifying quantum-vulnerable cryptographic code and updating it across large and complex enterprise codebases is a massive undertaking.
In this session, we’ll walk through a real-world story of a large financial institution preparing for post-quantum threats. The organization had already identified 12 cryptographic anti-patterns—such as hardcoded certificates, insecure SSL/TLS configurations, and explicitly defined cipher suites. The challenge: these issues were deeply embedded across billions of lines of code.
We’ll demonstrate how to find and prioritize these vulnerabilities at scale using OpenRewrite recipes and a semantic code representation that goes beyond what text-based or AST-based tools can uncover. This includes leveraging multi-stage data flow analysis to track complex patterns across files and components. You’ll see how quickly cryptographic issues can be surfaced by running the PQC detection recipe across a real-world codebase.
And yes, AI can play a role here. We’ll briefly explore how coding assistants can help author custom detection recipes, and how those deterministic recipes can also be used by AI agents as tools to safely analyze and act on large-scale codebases.
What is your level of readiness for quantum-era threats? You’ll leave this session with a clear understanding of how to assess cryptographic risk across your applications and the technical approaches that make scalable detection and remediation possible.
What you will learn:
* What makes PQC readiness a security priority today—not tomorrow
* What cryptographic anti-patterns introduce quantum risk
*Why text-based and AST tools fall short at enterprise scale
* How LSTs and OpenRewrite enable accurate, cross-repo detection
* How AI can assist in recipe authoring and execution
* A scalable, repeatable approach to post-quantum remediation
Jonathan Schneier
Moderne
Co-Founder
Jonathan is co-founder and CEO at Miami-based Moderne which automates software maintenance activities at scale. He founded OpenRewrite at Netflix and went on to found the Micrometer project as a member of the Spring Team. Jonathan is the author of “SRE with Java Microservices” (O’Reilly). He is an Army veteran and two time bronze star recipient.
@jon_k_schneider
moderne.io (company)
typeshare.co/jonathanschneider (blog)
linkedin.com/in/jonkschneider
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/9a/PQC%20OWASP.pptx
Banking systems. Government data. Healthcare records. All of it encrypted today—and potentially breakable tomorrow by quantum computers.
While the arrival of quantum computing may feel distant to many, the security risk is already here. Bad actors can harvest encrypted data today and decrypt it later when quantum capabilities catch up. Post-quantum cryptography (PQC), designed to withstand both classical and quantum attacks, is the way forward. But identifying quantum-vulnerable cryptographic code and updating it across large and complex enterprise codebases is a massive undertaking.
In this session, we’ll walk through a real-world story of a large financial institution preparing for post-quantum threats. The organization had already identified 12 cryptographic anti-patterns—such as hardcoded certificates, insecure SSL/TLS configurations, and explicitly defined cipher suites. The challenge: these issues were deeply embedded across billions of lines of code.
We’ll demonstrate how to find and prioritize these vulnerabilities at scale using OpenRewrite recipes and a semantic code representation that goes beyond what text-based or AST-based tools can uncover. This includes leveraging multi-stage data flow analysis to track complex patterns across files and components. You’ll see how quickly cryptographic issues can be surfaced by running the PQC detection recipe across a real-world codebase.
And yes, AI can play a role here. We’ll briefly explore how coding assistants can help author custom detection recipes, and how those deterministic recipes can also be used by AI agents as tools to safely analyze and act on large-scale codebases.
What is your level of readiness for quantum-era threats? You’ll leave this session with a clear understanding of how to assess cryptographic risk across your applications and the technical approaches that make scalable detection and remediation possible.
What you will learn:
* What makes PQC readiness a security priority today—not tomorrow
* What cryptographic anti-patterns introduce quantum risk
*Why text-based and AST tools fall short at enterprise scale
* How LSTs and OpenRewrite enable accurate, cross-repo detection
* How AI can assist in recipe authoring and execution
* A scalable, repeatable approach to post-quantum remediation
Jonathan Schneier
Moderne
Co-Founder
Jonathan is co-founder and CEO at Miami-based Moderne which automates software maintenance activities at scale. He founded OpenRewrite at Netflix and went on to found the Micrometer project as a member of the Spring Team. Jonathan is the author of “SRE with Java Microservices” (O’Reilly). He is an Army veteran and two time bronze star recipient.
@jon_k_schneider
moderne.io (company)
typeshare.co/jonathanschneider (blog)
linkedin.com/in/jonkschneider
Managed by the OWASP® Foundation
owasp.org










