Event ATP Gov exhibiting at TechNet IndoPacific 2026 Announcement 2026 CRN Solution Provider 500 Announcement Check out The BLUF Podcast today! News Learn more about UxS & C-UxS from our experts

Text graphic stating "Quantum risk is no longer theoretical. What federal security teams need to know about Delinea QuantumLock." with a padlock icon on a dark background.

Quantum computing has moved beyond theoretical research and into a strategic cybersecurity concern. While most Federal and Department of Defense (DoD) organizations are not deploying quantum systems today, they are already responsible for protecting data that must remain secure for decades.

This creates an immediate challenge: how do you protect sensitive information today against a threat that may not fully materialize for years—but could already be targeting your data?

A recent technical walkthrough from Delinea highlights key considerations around quantum computing risk, post‑quantum cryptography, and QuantumLock within Secret Server.

Traditional computing relies on bits—binary values of zero or one. Quantum computing introduces qubits, which can exist in multiple states simultaneously through a property called superposition. This enables massive parallel computation, allowing quantum systems to solve certain classes of problems exponentially faster than classical computers. For Federal agencies, the risk isn’t theoretical:

  • Sensitive data often carries 20–50 year confidentiality requirements
  • Nation‑state actors are already conducting “harvest now, decrypt later” operations
  • Encrypted data stolen today may be decrypted in the future once quantum capabilities mature

If encryption protecting data today fails within its retention period, mission assurance is compromised—regardless of when the breach occurred.


What Actually Breaks in a Quantum World

Not all cryptography is equally vulnerable to quantum computing. Most modern public‑key cryptography depends on mathematical problems that are difficult for classical computers:

  • RSA → factoring large prime numbers
  • Elliptic Curve Cryptography (ECC) → discrete logarithm problems

Quantum algorithms, such as Shor’s Algorithm, could solve these problems exponentially faster, effectively breaking these encryption methods once sufficiently advanced quantum systems exist. In contrast, symmetric encryption like AES‑256 remains resistant to quantum attacks with appropriate key sizes. This distinction is critical: The primary quantum risk lies in key exchange and key protection, not the encryption of data itself.


Post‑Quantum Cryptography and CRYSTALS‑Kyber

To address this risk, organizations are turning to post‑quantum cryptography (PQC)—algorithms designed to remain secure against both classical and quantum attacks. One of the leading approaches is lattice‑based cryptography, specifically: CRYSTALS‑Kyber

  • Part of the NIST post‑quantum cryptography standardization effort
  • Designed for Key Encapsulation Mechanisms (KEM)
  • Provides security comparable to AES‑256
  • Optimized for efficiency and performance

Kyber’s role is not to encrypt data directly, but to secure the keys that protect that data, making it a foundational component of quantum‑resilient architectures.


How QuantumLock Works in Secret Server

Delinea’s QuantumLock (formerly DoubleLock) introduces an additional layer of protection within the Secret Server platform. It is important to understand that QuantumLock does not replace vault encryption—it enhances it.

Here’s the Technical Workflow

  1. A secret is encrypted using AES‑256
  2. The AES key is protected using asymmetric key encapsulation
  3. Encapsulation methods include:
    • RSA‑2048 (legacy)
    • Kyber‑1024 (post‑quantum option)
  4. The private key required for decryption is secured by a human‑generated password, independent of Secret Server access controls

This design creates a secondary cryptographic boundary:

  • Even if an attacker compromises Secret Server
  • Even if they access the underlying database
  • They still cannot decrypt the secret without the QuantumLock password

This provides protection that is independent of identity, role‑based access control, or system compromise.


Operational Considerations: A Surgical Control, Not a Default

QuantumLock is not designed for universal use across all secrets. Enabling it introduces tradeoffs:

  • Disables automatic password rotation
  • Disables remote password changing
  • Disables heartbeat monitoring

These constraints are intentional and align with specific high‑value use cases, including:

  • Tier‑0 credentials
  • Root and break‑glass accounts
  • PKI‑related secrets
  • Long‑lived mission system credentials
  • Sensitive data elements requiring extended protection

This positions QuantumLock as a tool for strategic risk containment, rather than routine operational credential management.


Why Waiting Is Not an Option

According to NIST projections, quantum threats to public‑key cryptography could emerge between 2026 and 2030. However, the “harvest now, decrypt later” model changes the timeline:

  • Adversaries can collect encrypted data today
  • Decryption can occur years later when quantum capabilities become available
  • Current mission lifecycles already overlap this risk window

Waiting for mandates or standards to finalize may result in retroactive exposure of data that should have been protected earlier. The real challenge is not implementation—it is crypto‑agility planning.


The Role of Integration in Quantum Readiness

Adopting post‑quantum cryptography is not simply a technology decision—it is an architectural one. Organizations must determine:

  • Which secrets require long‑term quantum protection
  • How to design tiered protection models
  • Where post‑quantum controls fit within Zero Trust architectures
  • How to align with DoD, FedRAMP, and NIST guidance

This is where experienced integrators play a critical role. ATPGov supports agencies by:

    • Identifying high‑impact use cases for post‑quantum protection
    • Designing architectures that balance security and operational continuity
    • Integrating platforms like Delinea Secret Server into enterprise environments
  • Ensuring crypto‑agility strategies do not introduce unintended mission risk

Quantum readiness is not achieved by enabling a feature—it requires deliberate design decisions across the enterprise.

The phrase "the bottom line..." in bright blue futuristic text, with a Cisco Hypershield-inspired shield symbol replacing the letter "o.

The BLUF

Quantum risk is not defined by when quantum computers arrive—it is defined by how long your data must remain secure.
  • Quantum computing threatens public‑key cryptography, not symmetric encryption
  • “Harvest now, decrypt later” makes this a current risk, not a future concern
  • CRYSTALS‑Kyber provides a NIST‑aligned post‑quantum solution for key protection
  • Delinea QuantumLock adds a secondary cryptographic boundary that survives system compromise
  • It is best suited for long‑term, high‑impact Federal secrets
  • Agencies must prioritize crypto‑agility and integration strategy, not just algorithm awareness

The image shows the word "Delinea" in bold, dark blue letters on a white background, representing Delinea QuantumLock—a solution at the forefront of Federal Security and Quantum Risk protection.

If your organization is responsible for protecting information that still matters in a quantum‑capable future, your timeline for action has already begun.

Synopsis


This episode distills Delinea’s walkthrough on quantum computing risk, post-quantum cryptography, and the Quantum Lock feature in Secret Server. It explains how quantum computers and Shor’s algorithm threaten public-key cryptography like RSA and ECC, enabling “harvest now, decrypt later” against data requiring 20–50 years of confidentiality, while symmetric encryption like AES-256 is more resilient. It highlights NIST-aligned post-quantum approaches such as lattice-based CRYSTALIS-Kyber (Kyber 1024) for key encapsulation. Quantum Lock adds an extra layer: secrets are encrypted with AES-256, the AES key is wrapped with RSA 2048 or Kyber 1024, and decryption requires a human password even if Secret Server is compromised; it is intended for tier-zero, static, long-term high-impact secrets and disables rotation/heartbeat features.

  • 00:00 Why Quantum Risk Matters
  • 01:07 Quantum Basics Explained
  • 01:55 What Quantum Breaks
  • 02:36 Post Quantum Crypto Kyber
  • 03:09 Quantum Lock In Secret Server
  • 03:57 Operational Constraints Use Cases
  • 04:34 Why Act Before 2030
  • 05:05 Bottom Line Takeaways
  • 05:41 Integration Strategy And Support
  • 06:20 Closing And Contact

This episode is brought to you by ATP Gov. Visit us online at www.atpgov.com or follow us on LinkedIn.

Transcript

[00:00:00] Welcome to The Bottom Line Up Front, the podcast that cuts through the noise to deliver distilled insights from today’s most important technical webinars, presentations, and demonstrations. Designed for federal and military IT leaders, each episode breaks down complex technologies into mission-ready takeaways so you get the key points fast.

Whether it’s cybersecurity, cloud architecture, or emerging defense technologies, we highlight what matters most and how trusted integrators like ATPGov can help implement and operationalize these solutions across your agency or command. No fluff, no filler, just the bottom line up front. Quantum computing has officially crossed from science research into strategic risk.

And while most federal and DOD security teams aren’t deploying quantum systems tomorrow, they’re already responsible for data that must remain secure for decades. Today on the Bottom Line Up Front, we’re distilling a technical walkthrough from Delinea on quantum computing risk, post-quantum cryptography, and [00:01:00] quantum lock inside of Secret Server, what it actually does, where it fits, and why waiting may already be the wrong move.

All right, so let’s level set. Traditional computing processes bits as zeros and ones. Quantum computing introduces qubits, which can exist as both zeros and ones simultaneously using what’s called superpositioning. This allows for parallelized computation at scale, which is why quantum systems fundamentally threaten modern cryptography.

And for federal agencies, this isn’t theoretical. Classified and controlled data often has a 20 to 50-year confidentiality requirement, and nation state adversaries are already executing harvest now and decrypt later operations. And data stolen today may not be decrypted until quantum systems mature, but that still fails mission assurance.

Because if encryption fails in 10 years and you’re storing that data for 30, that’s actually a problem today. So let’s talk about what actually breaks in a quantum world. Most public key cryptography in use [00:02:00] today relies on math that is hard for classical computers. Let’s just say RSA uses factoring of large prime numbers while ECC is designed for discrete logarithms.

Quantum computing changes the game. Algorithms like Shor’s can solve these exponentially faster, effectively invalidating RSA and ECC once sufficiently large quantum systems exist. Symmetric encryption, like AES 256 on the other hand, remains largely resistant to quantum attacks as long as key sizes are sufficient.

So the real attack surface is the key exchange and key protection, not the bulk data encryption. So let’s enter the post-quantum cryptography world. Post-quantum or quantum safe cryptography is designed around math problems that are hard for both classical and quantum computers. One of the most mature and widely adopted families is lattice-based cryptography, which is where Crystalus Kyber comes into the conversation.

Kyber is part of the NIST post-quantum cryptography standardization effort, and it provides security roughly equivalent to [00:03:00] AES 256. It is designed specifically for key encapsulation mechanisms, or KEM. In other words, it protects the keys that protect everything else. Quantum Lock, formerly known as Double Lock, is an additional cryptographic control layer inside of Secret Server, and it works like this: A secret is encrypted using AES 256, which is fast, resilient, and scalable, and the AES key is protected using an asymmetric key encapsulation, and that key encapsulation uses RSA 2048 for legacy Double Lock operations, and also Kyber 1024, which is the post-quantum option.

The private key used for decryption is protected by a human-generated password, not just Secret Server’s permissions. That means even if Secret Server is compromised, and even if an attacker has access to Secret Server’s database, they still cannot decrypt the secret without the Quantum Lock password.

This is security orthogonal to identity, roles-based access control, and system compromise. But I do want to note that Quantum Lock is not a universal [00:04:00] switch. You have to apply it surgically, and there are some important constraints. Enabling Quantum Lock disables password rotation within Secret Server, no remote password changing, and no heartbeat monitoring.

This is absolutely intentional and aligns with federal use cases such as tier zero credentials, root and break glass accounts, PKI related secrets, long-term protected data elements, and mission systems with static credentials by design. This makes Quantum Lock less about day-to-day IT ops and more about strategic risk containment So let’s talk a little bit more about why this matters now and not later.

And that’s because NIST estimates quantum threats to public key encryption should materialize as early as 2026 all the way through 2030. But what harvest now, decrypt later really means is you don’t need a quantum computer to exploit the risk, you just need access to encrypted data today. And that attack window already overlaps with current mission life cycles, and waiting for mandates may violate existing data protection policies retroactively.[00:05:00]

The long pull here isn’t implementation, it’s crypto agility planning. So what’s the bottom line up front? Quantum computing threatens key exchange, not symmetric encryption. Harvest now, decrypt later means waiting is already risky. Kyber 1024 and NIST aligned post quantum KEM is built specifically for this type of problem, and Delinea’s Quantum Lock provides out of band secret protection that survives system compromise.

It’s ideal for long-term, high impact federal secrets, not rotating operational credentials. Agencies need this integration strategy now, and not just algorithmic awareness, because quantum risk isn’t about the future, it’s about the duration of impact. And our role in this space is all about helping agencies identify which secrets actually require post quantum protection, designing tiered secret protection models that preserve operational continuity, integrating systems like Delinea’s Secret Server with Quantum Lock into zero trust architectures, and aligning quantum safe adoption with DoD, FedRAMP, [00:06:00] and NIST roadmaps.

This also means that we are ensuring crypto agility doesn’t create new mission risk. With all that said, you have to realize that Quantum Lock isn’t just a checkbox, it’s a design decision for your enterprise. So if you’re protecting data that must still be secure when Quantum becomes operational, remember, your timeline is already closing.

Be sure to reach out to atpgov today at www.atpgov.com or email info@atpgov.com or check us out on social media on LinkedIn. Thanks for listening, and be sure to subscribe to the Bottom Line Up Front wherever you get your podcasts. And stay tuned for more distilled insights from the front lines of tech and national security.

So until next time, stay secure, stay mission ready

About this Podcast

The Bottom Line Up Front, is ATP Gov’s podcast that cuts through the noise to deliver distilled insights from today’s most important technical webinars, presentations and demonstrations designed for federal and military IT leaders. Each episode breaks down complex technologies into mission ready takeaways, so you get the key points.

Fast.

Whether it’s cybersecurity, cloud, architecture, or emerging defense technologies, we highlight what matters most and how trusted integrators like ATP Gov can help implement and operationalize these solutions across your agency or command.

No fluff. No filler, just the bottom line up front.


Black rectangle featuring a white Apple Podcasts logo and the text "Listen on Apple," highlighting episodes about Cisco Hypershield. Green rectangular button with the Spotify logo, featuring the text "Listen on Spotify" in white—perfect for sharing Cisco Hypershield playlists. Red button with a white play icon and text that reads "Listen on YouTube," featuring content about Cisco Hypershield.