The Road to Post Quantum Cybersecurity

Presented by Arqit & Carahsoft

A future quantum computer capable of breaking widely used encryption could expose government information that adversaries are collecting today. Nick Nilan, General Manager for the U.S. at Arqit, says agencies should begin preparing for post-quantum cryptography now rather than waiting for that capability to arrive.

Speaking at the Billington Cybersecurity Summit 2026, Nilan notes that post-quantum cryptography has moved from a specialized technical concern into a mainstream government priority.

Federal guidance is prompting agencies to develop plans, discover where cryptography exists in their environments and determine how they will migrate vulnerable systems. That work will span several years and require coordination among cybersecurity teams, application owners, infrastructure managers and technology suppliers.

The first step is understanding the scope of the challenge.

Finding the Cryptography Across the Enterprise

Cryptography is embedded throughout an organization. It protects data, supports authentication and allows users and systems to establish trusted connections.

Agencies need an inventory that identifies the cryptography used in applications, networks, operational technology and other mission systems. They can then determine whether each implementation is secure against current attacks and whether it will remain secure in a post-quantum environment.

Automated discovery tools can help because many organizations do not have a

Preparing the Navy to Fight Through a Cyberattack

Screenshot 2026-09-17 at 5.44.20 PMCyber has traditionally supported military operations by enabling intelligence, command and control, fires and other warfighting functions. But Chris Page, Acting Assistant Deputy Chief of Naval Operations N6N9C for the U.S. Navy, says defense leaders must prepare for a future conflict in which cyber becomes the main effort during a battle, a phase of operations or even an entire campaign.

Speaking at the Billington Cybersecurity Summit 2026, Page explains that this possibility should shape how the Navy designs its architecture, operates its systems and organizes its personnel.

Cyber capabilities can remain inside an environment for an extended period, giving an adversary continuing access to sensitive systems and information. They can be used to steal intellectual property, undermine public confidence and place military forces at risk.

Those capabilities also complicate escalation. Page says the line between espionage and attack can be thin and easily crossed, creating difficult questions about how military and national-security leaders should manage a crisis.

Applying Damage Control to the Cyber Domain

The Navy has long trained sailors to continue operating when their ships are damaged. Crews learn to fight fires, stop flooding and manage casualties because the objective is to keep the ship afloat and in the fight.

Page believes the Navy should apply that same damage-control philosophy to cybersecurity.

“We know we’re going to take battle damage, so we need to think about how we fight through that,” he says.

The first requirement is a confident and prepared workforce. Sailors should understand that a cyberattack does not necessarily mean the mission must stop. That confidence depends on established procedures, preplanned responses and exercises that allow crews to practice operating under degraded conditions.

Training is particularly important because the first hours of an attack may be the worst possible time to determine responsibilities and develop a response. Crews that have already rehearsed the scenario are more likely to act quickly and effectively.

Operating When the Network Is Unavailable

A successful cyberattack could interrupt communications or prevent a ship from accessing information and services beyond its own systems. The Navy must therefore ensure that crews can maintain situational awareness and continue operating when disconnected.

Page says ships already have many of the tools needed to do that. Active and passive sensors provide local awareness regardless of whether a platform is connected to a larger network. Ships also carry data gathered by those sensors, along with information loaded before deployment and updates received whenever communications are available.

That information can support navigation, equipment maintenance and an understanding of both the surrounding environment and the adversary.

Page describes the Navy’s nearly 300 battle-force ships as “300 floating data centers.” Each carries substantial computing capacity and information that can support operations at the edge.

The systems may not provide the same level of capability available when fully connected, but resilient applications and locally available data can prevent a complete loss of operational effectiveness.

Sailors Remain the Most Important Asset

Technology is only one part of cyber resilience. Page says experienced sailors remain the Navy’s most important resource when systems are damaged or communications are unavailable.

Maintainers understand how equipment should perform and can recognize when something is wrong. Navigators can continue operating with local information. Intelligence specialists understand the indicators and physical phenomena associated with their missions.

That expertise gives commanders options even when digital systems are degraded. It also gives the American public confidence that the Navy can continue fighting through a cyberattack.

Artificial intelligence will add another level of complexity. Page is particularly concerned about convergence—the possibility that an adversary could combine several AI-enabled capabilities into a coordinated operation.

A sophisticated phishing campaign may be strengthened with synthetic media, compromised data and a stolen identity. Individually, each element may be manageable. Used together, they could create a much more dangerous threat.

Preparing for that convergence requires the Navy to consider the adversary’s most dangerous potential course of action, not simply respond to each technology independently.

Key Takeaways

  • Cyber could become the primary focus of a future battle or military campaign rather than merely supporting other warfighting functions.
  • The Navy can apply its damage-control philosophy to cyber by preparing crews and systems to continue operating after an attack.
  • Local data, resilient systems and experienced sailors are critical to sustaining missions when communications are disrupted.