Preparing for the Quantum Era: Building Enterprise Cyber Resilience with Broadcom

"Where we're concerned is with data that has a lifecycle that's measured in years and in decades, because even that data, if it's encrypted today, is still of value and still in use years from now."
Michael Jordan, Distinguished Engineer, Cybersecurity & Compliance, Broadcom

That's Michael Jordan, joining Matt Kimball for a Cybersecurity Spotlight interview at the Six Five Summit: AI Unleashed 2026.

Jordan centers his argument on organizational readiness: enterprises that complete cryptographic discovery and inventory now control their own migration timeline, regardless of when a cryptographically relevant quantum computer actually arrives.

He points to Shor's algorithm as the mechanism that turns RSA and elliptic curve cryptography from a problem requiring millions of years to solve into one a sufficiently powerful quantum computer could break, with most estimates placing that capability in the early 2030s.

Jordan also treats Harvest Now, Decrypt Later as a specific and active threat: state-sponsored actors are already collecting encrypted data with a years-long shelf life, betting on future decryption capability.

Key Insights:
🔹 A cryptographically relevant quantum computer could use Shor’s algorithm to break RSA encryption. Most estimates place that threshold in the early 2030s, making the migration window increasingly narrow.

🔹 “Harvest Now, Decrypt Later” attacks are already happening, with state-sponsored actors collecting sensitive data today that could remain valuable for years or decades.

🔹 Organizations do not need a firm quantum deadline to act. Cryptographic discovery, inventory, and migration planning can begin now, reducing the risk of a rushed transition later.

🔹 Cryptographic inventories often expose more immediate risks, including technical debt and outdated algorithms that may become vulnerable well before quantum computing matures.

🔹 Frontier AI and quantum computing are expanding the attacker’s toolkit. Resilience will require organizations to prepare not only to prevent attacks, but also to detect, contain, and recover from a successful breach.

Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.

Explore more sessions from Six Five Summit: AI Unleashed 2026 at sixfivemedia.com/summit.

Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology audiences.

Michael Jordan:
Where we're concerned is data that has a life cycle that's measured in years and in decades, because even that data, if it's encrypted today, is still of value and still of use in years from now. And that's really where the concern is.

Matt Kimball: 

Hi, everyone, and welcome to the Six Five Summit, AI Unleashed 2026. We're continuing the conversation with another cybersecurity spotlight. I'm Matt Kimball, and in this session, we're exploring how enterprises can prepare for the coming era of quantum computing and what that means for cybersecurity and the strategies that enterprises are building around quantum. Joining me is Michael Jordan, Distinguished Engineer, Cybersecurity and Compliance at Broadcom, to discuss quantum, the risk associated with post-quantum cryptography or PQC, and the practical steps organizations should be taking today. And yes, we mean today. Hey, Michael, welcome to the Six Five Summit. It's great to have you. Yeah, it's great to be here. Thanks for having me. This is going to be a fun discussion because I think a lot of folks hear quantum and they think five years out, they think 10 years out, they think sometime in the future, even just a couple years out maybe, but they don't think about today. But as quantum computing continues to advance, we figure out kind of error rates and how to get better. Why should enterprise leaders view post-quantum cryptography as a business issue today versus tomorrow? And why is it a business issue rather than a technology problem for the future?

Michael Jordan: 

Yeah, sure. And actually, let's start by kind of bounding this a little bit. When we talk about post-quantum cryptography, We're not talking about cryptography that is done with a quantum computer or by a quantum computer. We're talking about cryptography that classical computers can use that is resistant to attacks from quantum computers. So everything we're gonna be talking about today is about the cryptographic algorithms that run on classical computers. And in terms of why this is a business problem versus a technology problem, It wasn't that long ago where cryptography was really a niche technology. And I think the industry that was probably the biggest user of cryptography in the early days was, you know, the banking industry where, you know, protecting, you know, ATMs and, you know, financial services transactions. But if we look at the last, I would say, you know, 10 to 15 years, cryptography has really evolved and has become ubiquitous. And it's really been an enabling technology for, you know, the larger IT modernization that's been, you know, taking transformation that's been taking place. So, you know, looking at web based applications, APIs, hybrid cloud, and even emerging technologies like cryptocurrency and asset tokenization, they all rely on cryptography. And cryptography really serves as the foundation of trust for our modern IT world. So going back to your question, this is a business problem, right? Because it has evolved to become that foundation of trust. And if it gets broken, we we have a business problem and a business challenge to address.

Matt Kimball: 

That's a great, great answer. I'm glad you kind of bound the discussion up front as well. Kind of, you know, for folks that might be watching or listening in and don't fully kind of get what post-quantum, you know, what the threat of, you know, post-cryptography could be or having the right algorithms. Can you quickly, you know, and say, you know, the kind of elevator pitch of, you know, What's going on that, you know, the thing called Shor's algorithm, right? That's causing people to freak out a little bit today.

Michael Jordan: 

The elevator pitch. So I guess we got three minutes to get from the ground floor to the 22nd floor or something like that. So the elevator pitch is when you look at cryptography, like RSA or elliptic curve, The security of that cryptography relies in the fact that there are certain mathematical problems that are difficult to solve. And the public and private keys are mathematically related for these algorithms. And for classical computers, solving these problems is measured on the orders of millions, if not billions of years. And with quantum computing, the door and aperture opens to new sets of algorithms that you can't run practically on classical computers, which means this math that we were relying on to be really tough to solve And if you can solve that math and you can break the cryptography, that math becomes easy to do on a quantum computer. And when you have such a quantum computer, they refer to that as a cryptographically relevant quantum computer. So it has enough qubits to run, as you alluded to, something like Peter Shor's algorithm that can do the integer factorization and break you know, RSA cryptography. So all those keys we thought were unbreakable.

Matt Kimball: 

Exactly.

Michael Jordan: 

Yeah. And the net of it is, you know, the public key and the private key are computed using the same components. And if you can calculate those components from the public key, then you can go calculate the private key. That's really what we're worried about. I got you.

Matt Kimball: 

So listen, I talk to enterprise IT all the time, and I think the industry and companies like Broadcom have done a good job about educating on post-quantum cryptography, the challenges, the threat that's coming, and it's something that has to be taken seriously. But the other thing I hear from them is, I don't know where to start, right? Like what's square one? When you think about this, and someone who's been living in this, what does that migration journey look like from like, figure out what you got to, you know, we're fully secure on the other end of it?

Michael Jordan: 

There's a couple points I want to make here. And the first one, actually, you mentioned where to start. The other important point I think that needs to be addressed, I view this as kind of the elephant in the room, is when to start, because I think that's often overlooked. And I think post quantum cryptography suffers from the fact that there is no specific deadline in place for this yet. And that it's when the quantum computing technology evolves to the point where it can break that math. And the problem, obviously, is it's an emerging technology, and we don't know exactly when that's going to be. I mean, we have some idea and there's some estimates, you know, that the expectation is sometime in the early next decade. So, you know, 2030 and beyond, we'll have quantum computers that have enough qubits to actually do that, solve those hard math problems that we were just talking about. There is some concern that there's some kind of technology breakthrough and that happens sooner rather than later. That's always a concern. I think a really good example was a few years ago, DeepSeek, the AI model that China developed, caught everyone off guard and nobody knew that technology had evolved to that point. And then Everyone, the market kind of reacted to that, you know, with quantum, if there's a breakthrough that happens, you know, we could all be kind of scrambling. And I think the other, you know, contributing factor is until you've done, I would say all of the upfront work, you know, the discovery, the inventory, the planning that is needed. you don't know how long it's going to take you to get from point A to point B, which means until you've done that work, you don't know when to start. Even if you say, okay, I've got five years or I've got six years, if you haven't done the upfront work to do that planning, then you don't know when to begin, and, and, and therefore, or how much resource, you're going to need, you know, to apply to this and so, you know, I think the one takeaway that I would like everyone to kind of get from this would be. do that. There's nothing that's stopping us from doing that planning work now. We can discover where we're using crypto. We can build that inventory and understand the dependencies and understand everything it's going to take us to get from point A to point B. And then from there, you are much better prepared to move forward. And in terms of what a successful migration looks like. It's a migration where you're kind of, you beat the clock, right? If you don't beat the clock, then it's not a, I don't view that as a successful migration.

Matt Kimball: 

Quick question, maybe a little bit of a tangent, but it's worth a minute or two of talking. So, I think one of the things that gets thrown out there and it is the market and vendors have done a good job of scaring enterprise IT appropriately. But I think there might be a little bit of confusion around it, but handle attacks, right? Harvest now, decrypt later, right? We hear about this in terms of post-quantum where hackers will grab all your data and then they'll be able to unencrypt it a couple of years from now. Do you see that as a legitimate threat in the market? Is that more of a scare tactic? What are your thoughts on that?

Michael Jordan:

Personally, I don't see it as a scare tactic. Given the organizations that I see that are concerned about that, this isn't originating from IT vendors. This is originating from governments. And they're not worried about some teenage kid with a laptop, they're worried about state-sponsored actors with deep pockets where they have the means to harvest massive amounts of encrypted data with the view that at some point in the future, they will also have access to the technology that would allow them to essentially determine the cryptographic keys that were used and therefore decrypt the data. And when you think about The other important aspect of that is if it's data that has, you know, a five minute shelf life, then, you know, there's there's not really much risk there. Right. Where we're concerned is, you know, data that has, you know, lifecycle that's measured in years and in decades, because even that data, if it's encrypted today, is still of value and still of use in years from now. And that's really that's really where, you know, the concern is. And when you look at, you know, different geos and you look at, you know, even organizations where they've established more aggressive timelines for migrating to PQC, one of the significant drivers for that is the Harvest Now Decrypt Later with the view of the sooner we get migrated to PQC, the less be at risk for harvest now, decrypt later, even if the technology doesn't come to fruition, you know, in the next, you know, five years, for example.

Matt Kimball: 

So it's interesting because, yeah, it brings that kind of, it brings that sense of urgency back in and that maybe that point on the horizon is a little bit closer than we realize, because this isn't just about, you know, when you're able to, when a hacker or a bad actor is able to decrypt, it's about, you know, access to the data.

Michael Jordan: 

It also reinforces the point I was making earlier about doing your, you know, your discovery and inventory and planning, you know, sooner rather than later, because one of the things I think we can do as an industry to sort of help mitigate the harvest now decrypt later is make sure we're using the strongest technology available to us today, you know, where we can. And in the process of doing that discovery and inventory, more than likely organizations are going to discover places where they have technical debt, where they're using weaker algorithms than they realized they were using. And those weaker algorithms will be susceptible sooner than the stronger algorithm. So as we do that inventory, then you can kind of say, oh, We have risk above and beyond PQC. We have some technical debt that we need to address. And addressing that makes them less susceptible to the harvest now, decrypt later types of attacks.

Matt Kimball: 

So that's a good point. And it's a good segue into my next question, which is, so I'm an enterprise CISO or CIO. I've got, say, 5,000 servers, 10,000 servers in my data center. Is there a way, as I go about, I go through my inventory process, I kind of, I get a good kind of snapshot of, you know, where my infrastructure is today. Is there, is there kind of some measurement use you would recommend or some kind of way you would recommend for organizations to prioritize, hey, Go get, you know, go correct this first and then that, or here's your greatest vulnerabilities with these servers. Obviously the, you know, the least protected, but is there other kind of, you know, things that IT leaders should be thinking about?

Michael Jordan: 

So where I think the industry is going, my recommendation, and also where I think the industry is going here is, Again, doing that invent discovery and inventory. And as, as part of that discovery inventory that there's, there's going to be a bunch of metadata that you'll need to capture and, you know, collect in there and, you know, including dependencies, internal and external dependencies, including the asset that's being, what is the asset that's being protected? What's the application that we're protecting here? And once you have that inventory, then you can look at, okay, what happens what's the impact to our business if this asset is able to be compromised? And from there, you can do a risk-based prioritization of knowing that it might take longer than you expect. If you can have a risk-based prioritization of what you want to change, then as you go through and do this migration, you're changing the most critical assets first and doing it that. That's how I would do it if I were running an IT organization.

Matt Kimball: 

Sure. Protect your most critical assets first and move out from there. Obviously, Broadcom plays a big role in this space, but I'm curious from your perspective. You've been in industry for quite some time. You're super experienced in all of this. Do you, you know, I hear more and more from folks I talk to that this, you know, post-quantum and security in general, it's part of a bigger, broader resilience conversation, right? Are you hearing this and kind of, you know, do you see protection as, I don't want to say just one, cause it kind of minimizes it, but you know, an element of that larger, you know, kind of resilience strategy?

Michael Jordan: 

I think that's a really interesting question in the context of, um, what we're in the midst of right now as an industry with all of the frontier AI models, right? I think we're in a new era here. And when we look at frontier AI models, and when we look at quantum computing, those are two technologies that are disrupting forces in the cybersecurity space. And they're basically tools that threat actors can add to their arsenal to mount attacks. You can use a quantum computer to break cryptography, or you can use these AI models to you know, identify vulnerable systems or misconfigured systems or, you know, vulnerable code and, you know, use it to mount attacks. And they underscore the heightened need for vigilance, for sure. But they also kind of, as you suggest, highlight the need that we really need, you know, to make sure that we're not losing sight of this idea of cyber resilience, that yes, we need to do everything we can to counter these attacks and make sure, you know, and protect against them. But we also have to have the mindset of, you know, What do we do if one of these, you know, attacks is successful right and and be prepared to detect it so you know how do you know you know how do you know when such a attack has occurred, respond to it. ultimately be able to recover from that. And that takes a lot of preparation and coordination, you know, across an organization, right? And so, absolutely, you know, we hear about that all the time.

Matt Kimball: 

I hear a lot of, it's funny because talking with enterprise, again, talking with enterprise leaders, one of the things I hear a lot is, you know, we have designed to not even introduce the if, right? But we prepare for when. Because if you don't, you're going to be at your most vulnerable in that game. I think this is one of those topics we could talk about for hours. But thank you for joining us. Sure. And I hope you invite me back. I'd love to have further conversations with you. Well, be careful what you wish for, because I might be calling you. frequently. But I really, we really do appreciate you joining us for this cybersecurity spotlight. And for listen, for those are that are watching this, please don't forget to hit subscribe, follow us on social media and check out all of the great content we have from the six five summit at six five media.com backslash summit, and we will see you next time.

Speaker

Michael Jordan
Distinguished Engineer
Broadcom

Michael Jordan is an IBM Distinguished Engineer for IBM Z and LinuxONE Security. He is responsible for driving the security strategy and leading innovation in the areas of system security and data security for the IBM Z and LinuxONE platforms. Mr. Jordan joined IBM in 1989 and has over 31 years of IBM Z experience, including 27 years of research and development experience and 4 years in a client-facing role leading complex and large-scale IBM Z projects.

Michael Jordan
Distinguished Engineer