Preparing Vulnerability Management for the Post-Quantum Era: From Legacy Cryptography Crypto-Agility @FIRSTdotorg
Preparing Vulnerability Management for the Post-Quantum Era: From Legacy Cryptography Crypto-Agility  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 8 hours ago
Arun Singh (Qualys, US)

Quantum computing is still emerging but its impact on today’s cryptography is already a security problem. RSA and ECC will not fail overnight, yet many organizations are storing data that must remain confidential for 10-20+ years while still relying on quantum-vulnerable algorithms and hard-to-change infrastructure. Today’s vulnerability management programs are excellent at tracking CVEs and patching software, but they rarely treat cryptography itself as an inventory item or risk object. In this talk, I reframe “quantum-era vulnerabilities” from the perspective of vulnerability management and large-scale detection engineering. We will look at: - How to define quantum-era risk in practical terms: harvest-now-decrypt-later, long-lived data, and fragile PKI. - Lessons from building detections for deprecated ciphers and protocols (TLS, SSH, IPsec) and how those patterns extend to post-quantum migration. - What “crypto-agility” really means for blue teams: crypto inventories, quantum-risk scoring, and policy-driven deprecation instead of one-off cipher clean-ups. - How vulnerability scanners, PSIRTs, and asset owners can collaborate to surface quantum-era issues as first-class findings-alongside traditional CVEs. Attendees will leave with a concrete, vendor-neutral playbook to start integrating post-quantum readiness into their existing vulnerability management processes today, without needing to be quantum-cryptography experts.

---

Arun Pratap Singh is a Security Research Engineer at Qualys, working on the Vulnerability Management, Detection and Response (VMDR) platform. Over the past eight years, he has worked across internal vulnerability management, FedRAMP audit support, threat research for XDR and EDR, and signature authoring for detections used by customers worldwide. His current interests include post-quantum readiness, crypto-agility, and practical ways to integrate cryptographic risk into vulnerability management programs.
Preparing Vulnerability Management for the Post-Quantum Era: From Legacy Cryptography Crypto-AgilitySocial Engineering in the Age of AI: Rethinking Security Awareness TrainingBuilding the Blueprint: Designing Effective Storyboards for Cybersecurity Tabletop ExercisesThe Dependency Mirage: Hidden Vulnerabilities in Your Compiled BinariesTransforming Vulnerability Management with Advanced Dependency Knowledge GraphsA Researcher Centric Approach to Coordinated Vulnerability DisclosureHow to Answer “What’s Affected?” in Open SourceSysmon Deep Dive: Real Detection Scenarios You Can ReproduceThe PR3TACK Initiative: Building the World’s First Preemptive Tactics & Countermeasures KnowledgebasGuardians of the HypervisorBest Practices for Data Privacy Breach Response: Lessons Learned from Social Media Case StudiesThe Ontology for SOC Creation Assistance and Replication (OSCAR)
FIRST |

Preparing Vulnerability Management for the Post-Quantum Era: From Legacy Cryptography Crypto-Agility

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER