Deloitte and Daiwa Outline Practical Framework for Enterprise Post-Quantum Migration
Security specialists advocate for incremental testing and asset prioritization over comprehensive upfront cryptographic audits.

As corporate IT departments begin preparing for the post-quantum cryptography (PQC) transition, cybersecurity experts recommend treating the initiative as a staged organizational migration rather than an abstract physics problem. According to industry leaders speaking at DigiCert Inc.’s World Quantum Readiness Day event, approaching PQC adoption through standard project management practices helps eliminate technical uncertainty and keeps implementations on track.
In an interview broadcast by SiliconANGLE’s streaming studio theCUBE, representatives from Deloitte Touche Tohmatsu Ltd., Daiwa Institute of Research Ltd., and DigiCert detailed methods to manage the scale of quantum migration without stalling operations. Colin Soutar, managing director at Deloitte, noted that basic mitigation procedures are well understood, even if navigating internal governance, software lifecycles, and budgets introduces organizational complexity.
To evaluate the real-world performance impact of quantum-resistant algorithms, Daiwa Institute of Research conducted a proof-of-concept trial within a development environment built for Daiwa Securities' online trading infrastructure. Sadaaki Yamazaki, senior security specialist in Daiwa's Digital Solution R&D Department, explained that his team deployed a post-quantum-enabled load balancer to assess Transport Layer Security (TLS) performance under realistic traffic conditions.
Daiwa's benchmark testing revealed that the average TLS handshake latency rose by approximately 1.2 milliseconds. While Yamazaki characterized this performance impact as minimal inside high-bandwidth data centers, he warned that PQC algorithms increase both total packet counts and payload sizes. Consequently, organizations running infrastructure across wireless connections or bandwidth-constrained networks must independently test performance inside their own environments.
Technical readiness across cryptographic functions remains uneven. Standardized benchmarks from the National Institute of Standards and Technology, such as Federal Information Processing Standard 203, establish algorithms like ML-KEM for key establishment. Hybrid key exchange methods, including X25519MLKEM768, are already entering commercial platforms to mitigate "harvest now, decrypt later" tactics, wherein threat actors store encrypted traffic today to decipher it once quantum systems mature.
Conversely, digital signatures and broader public key infrastructure (PKI) transitions present more complex integration requirements. PKI environments span digital certificates, identity management, code signing, application programming interfaces, virtual private networks, and cloud resources managed across disparate teams. Yamazaki emphasized that substituting an individual algorithm is technically straightfoward, whereas locating where cryptography resides and coordinating cross-departmental governance represents the primary hurdle.
Navigating that scope requires clear operational prioritization. Soutar noted that Deloitte advises companies against attempting an exhaustive cryptographic discovery before taking initial action. Instead, he recommended focusing early discovery efforts on an organization's most critical assets and high-priority systems, allowing teams to demonstrate early progress while incrementally expanding coverage across the broader enterprise network.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.

