¿Necesita mi empresa migrar a cifrado post-cuántico ya?Does my business need to migrate to post-quantum encryption now?
No hace falta migrarlo todo de golpe. Pero sí hace falta responder cuatro preguntas para saber si ya estás expuesto, aunque el ordenador cuántico todavía no exista.
You don't need to migrate everything at once. But you do need to answer four questions to know if you're already exposed — even though the quantum computer doesn't exist yet.
Es la pregunta que más nos hacen los responsables de seguridad que oyen hablar de criptografía post-cuántica por primera vez: "¿esto es para dentro de diez años o ya nos afecta?" La respuesta correcta no es un titular alarmista ni un "todavía no toca" cómodo. Es un árbol de decisión con cuatro preguntas.
Pregunta 1: ¿guardas datos que deben seguir siendo confidenciales dentro de 5-10 años?
Contratos, propiedad intelectual, historiales clínicos, datos de clientes con obligación de confidencialidad larga. Si la respuesta es sí, ya estás expuesto — aunque el ordenador cuántico capaz de romper el cifrado actual todavía no exista. Un atacante puede robar hoy esos datos cifrados y guardarlos esperando el día en que pueda descifrarlos. Es el ataque conocido como "harvest now, decrypt later", y no depende de cuándo llegue la máquina, sino de cuánto tiempo debe seguir siendo secreto lo que guardas hoy.
Pregunta 2: ¿tu sector es defensa, salud, finanzas, infraestructura crítica — o proveedor de alguno?
Son los sectores donde el coste de una filtración retrasada es más alto y donde reguladores y clientes empiezan a exigir explícitamente resiliencia criptográfica a futuro. Si tu empresa es proveedora de alguno de estos sectores, la presión te llega igual, solo que por contrato en vez de por ley.
Pregunta 3: ¿tienes obligaciones NIS2 o vas a tenerlas?
La resiliencia criptográfica está empezando a formar parte de lo que un auditor NIS2 puede pedir ver, junto con cifrado de datos en reposo y en tránsito con criterio de futuro. No es (todavía) una obligación explícita de usar algoritmos post-cuánticos, pero sí es exactamente el tipo de pregunta que un auditor exigente empieza a hacer.
Pregunta 4: ¿cuánto tardarías en migrar toda tu infraestructura si empezaras hoy?
La migración completa de una organización grande puede tardar años — por eso NIST animó a empezar cuanto antes tras publicar sus estándares post-cuánticos en 2024. Cuanto más tarde una empresa en empezar, menos margen tiene si el calendario se acelera.
La recomendación pragmática: no migres todo de golpe
No hace falta rehacer de un día para otro toda la infraestructura de la empresa. El punto de partida lógico, de menor fricción y mayor impacto, es empezar por lo que más tiempo debe permanecer confidencial: backups, documentos legales y archivo. Es el dato de mayor vida útil, el más expuesto a "harvest now, decrypt later", y migrarlo no obliga a tocar aplicaciones ni redes.
Es exactamente por ahí por donde permite empezar TitanVault: backups y documentos firmados con criptografía post-cuántica desde el primer día, sin tener que rehacer toda la infraestructura de la empresa de golpe.
Preguntas frecuentes
¿Necesito migrar ya si el ordenador cuántico todavía no existe?
Si guardas datos que deben seguir siendo confidenciales dentro de 5-10 años, sí. El riesgo no depende de cuándo exista la máquina, sino de cuánto tiempo debe seguir siendo secreto lo que guardas hoy.
¿Por dónde empieza una empresa que no tiene recursos para migrarlo todo?
Por backups, archivo documental y documentos firmados o legales — el punto de menor fricción y mayor impacto.
¿Qué sectores tienen más prioridad para migrar?
Defensa, salud, finanzas e infraestructura crítica, y cualquier proveedor de estos sectores, además de empresas sujetas a NIS2.
It's the question we hear most from security leads encountering post-quantum cryptography for the first time: "is this a ten-years-out problem or does it affect us already?" The right answer isn't an alarmist headline or a comfortable "not yet." It's a decision tree with four questions.
Question 1: do you store data that must stay confidential 5-10 years from now?
Contracts, intellectual property, medical records, customer data under long confidentiality obligations. If yes, you're already exposed — even though a quantum computer capable of breaking today's encryption doesn't exist yet. An attacker can steal your encrypted data today and hold onto it until they can decrypt it. This is the "harvest now, decrypt later" attack, and it doesn't depend on when the machine arrives, only on how long what you store today must stay secret.
Question 2: is your sector defense, healthcare, finance, critical infrastructure — or a supplier to one?
These are the sectors where the cost of a delayed breach is highest, and where regulators and customers are starting to explicitly demand future-proof cryptographic resilience. If you supply one of these sectors, the pressure reaches you too, just via contract instead of law.
Question 3: do you have NIS2 obligations, or will you soon?
Cryptographic resilience is starting to be something a NIS2 auditor can ask to see, alongside encryption of data at rest and in transit with a future-proofing criterion. It's not (yet) an explicit requirement to use post-quantum algorithms, but it's exactly the kind of question a thorough auditor is starting to ask.
Question 4: how long would it take to migrate your whole infrastructure if you started today?
Full migration for a large organization can take years — that's why NIST urged organizations to start as soon as possible after publishing its post-quantum standards in 2024. The later a company starts, the less margin it has if the timeline accelerates.
The pragmatic recommendation: don't migrate everything at once
You don't need to rebuild the whole company's infrastructure overnight. The logical, lowest-friction, highest-impact starting point is what must stay confidential the longest: backups, legal documents and archives. It's the longest-lived data, the most exposed to "harvest now, decrypt later," and migrating it doesn't require touching applications or networks.
That's exactly where TitanVault lets you start: backups and signed documents with post-quantum cryptography from day one, without having to rebuild your entire infrastructure at once.
FAQ
Do I need to migrate now if the quantum computer doesn't exist yet?
If you store data that must stay confidential 5-10 years from now, yes. The risk doesn't depend on when the machine arrives, only on how long your data must stay secret.
Where should a resource-constrained company start?
Backups, document archives and signed or legal documents — the lowest-friction, highest-impact starting point.
Which sectors are the highest priority?
Defense, healthcare, finance and critical infrastructure, and any supplier to these sectors, plus companies subject to NIS2.