Uploaded May 2026 | Updated September 2026, 8 hours ago
Arun Singh (Qualys, US)
Quantum computing is still emerging but its impact on today’s cryptography is already a security problem. RSA and ECC will not fail overnight, yet many organizations are storing data that must remain confidential for 10-20+ years while still relying on quantum-vulnerable algorithms and hard-to-change infrastructure. Today’s vulnerability management programs are excellent at tracking CVEs and patching software, but they rarely treat cryptography itself as an inventory item or risk object. In this talk, I reframe “quantum-era vulnerabilities” from the perspective of vulnerability management and large-scale detection engineering. We will look at: - How to define quantum-era risk in practical terms: harvest-now-decrypt-later, long-lived data, and fragile PKI. - Lessons from building detections for deprecated ciphers and protocols (TLS, SSH, IPsec) and how those patterns extend to post-quantum migration. - What “crypto-agility” really means for blue teams: crypto inventories, quantum-risk scoring, and policy-driven deprecation instead of one-off cipher clean-ups. - How vulnerability scanners, PSIRTs, and asset owners can collaborate to surface quantum-era issues as first-class findings-alongside traditional CVEs. Attendees will leave with a concrete, vendor-neutral playbook to start integrating post-quantum readiness into their existing vulnerability management processes today, without needing to be quantum-cryptography experts.
---
Arun Pratap Singh is a Security Research Engineer at Qualys, working on the Vulnerability Management, Detection and Response (VMDR) platform. Over the past eight years, he has worked across internal vulnerability management, FedRAMP audit support, threat research for XDR and EDR, and signature authoring for detections used by customers worldwide. His current interests include post-quantum readiness, crypto-agility, and practical ways to integrate cryptographic risk into vulnerability management programs.
Arun Singh (Qualys, US)
Quantum computing is still emerging but its impact on today’s cryptography is already a security problem. RSA and ECC will not fail overnight, yet many organizations are storing data that must remain confidential for 10-20+ years while still relying on quantum-vulnerable algorithms and hard-to-change infrastructure. Today’s vulnerability management programs are excellent at tracking CVEs and patching software, but they rarely treat cryptography itself as an inventory item or risk object. In this talk, I reframe “quantum-era vulnerabilities” from the perspective of vulnerability management and large-scale detection engineering. We will look at: - How to define quantum-era risk in practical terms: harvest-now-decrypt-later, long-lived data, and fragile PKI. - Lessons from building detections for deprecated ciphers and protocols (TLS, SSH, IPsec) and how those patterns extend to post-quantum migration. - What “crypto-agility” really means for blue teams: crypto inventories, quantum-risk scoring, and policy-driven deprecation instead of one-off cipher clean-ups. - How vulnerability scanners, PSIRTs, and asset owners can collaborate to surface quantum-era issues as first-class findings-alongside traditional CVEs. Attendees will leave with a concrete, vendor-neutral playbook to start integrating post-quantum readiness into their existing vulnerability management processes today, without needing to be quantum-cryptography experts.
---
Arun Pratap Singh is a Security Research Engineer at Qualys, working on the Vulnerability Management, Detection and Response (VMDR) platform. Over the past eight years, he has worked across internal vulnerability management, FedRAMP audit support, threat research for XDR and EDR, and signature authoring for detections used by customers worldwide. His current interests include post-quantum readiness, crypto-agility, and practical ways to integrate cryptographic risk into vulnerability management programs.










