Summary
The session’s core message is that post-quantum cryptography is not only a technical migration but an ownership and governance problem: organizations need to know who is accountable for cryptography before quantum-capable threats turn weak or outdated algorithms into business risk. Nor Arifi opened by grounding the audience in quantum computers, PQC, and NIST algorithms, then explained why the issue is already relevant despite cryptographically relevant quantum computers not yet being available. The immediate concern is “Harvest Now, Decrypt Later,” where attackers intercept and store encrypted data today so they can decrypt it once quantum computers become powerful enough. Because cryptography is embedded across applications, systems, networks, identity platforms, VPNs, IAM, and OT environments, the transition to quantum-safe algorithms is positioned as broad, complex, and better started sooner than later.
The speakers then introduced their perspectives: Niels from Capgemini’s business technology team focused on emerging technologies and quantum technology; Siebe discussed his research on post-quantum cryptography adoption in the Dutch sector context, emphasizing that the challenge is not just technical but organizational and societal; and Nor connected PQC to security strategy, transformation, operating models, policies, processes, and controls. The agenda framed the talk around three angles: what it means to own cryptography and why it matters, what happens when no one owns it, and how organizations can prepare for the future.
Niels illustrated the ownership gap through a breach scenario in which the board asks who owns cryptography, but security, IT, application teams, and infrastructure all point to each other. In that example, an outdated algorithm remains in production because no one is responsible for tracking, governing, or replacing it. He argued that attacks may increasingly shift from credential theft and implementation flaws toward cryptographic vulnerabilities as quantum computing develops. His five core points were that cryptography is everywhere, no one typically sees the whole picture, unknown assets cannot be protected, attackers need only one vulnerability, and the cost of failure includes trust loss and system disruption rather than money alone.
The session compared the quantum transition with Y2K: Y2K had a fixed deadline, while quantum risk is probabilistic and uncertain. Niels noted that estimates such as a 25% chance of breaking RSA 2048 in 2030 still leave organizations unsure when to act, and worse, they may not know when a cryptographically relevant quantum computer actually exists. He argued that the first actor capable of breaking cryptography would likely stay silent to exploit systems rather than announce the achievement. The discussion then returned to the central practical question: ownership means having governance, responsible roles, authority, decision-making, inventory, change paths, risk tracking, and implementation accountability for cryptographic assets.
Key Topics
5 key topics from Adrian Neal, Siebe Spee and Norë Arifi at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Assign accountable ownership for cryptographic governance and decisions.
- Build an inventory of cryptography across systems and applications.
- Prepare for PQC before quantum deadlines become visible.
- Track outdated algorithms before attackers exploit one weakness.
- Connect PQC migration to operating models and controls.
“And what you don't know, also can't protect.”
Up Next



Next in agenda
Digital sovereignty: the hard way or the highway?



Also on cryptography
Strategic dependencies cryptographic products & services


Also on post quantum crypto
