ZENTARA

Post Quantum Cryptography: A Migration Blueprint for Singapore CII Operators

Learn how Singapore CII operators can build a post quantum cryptography migration roadmap, inventory cryptographic assets, and prepare for quantum-safe security.

Muhammad Ziyad7 min read
Post Quantum Cryptography: A Migration Blueprint for Singapore CII Operators

Post Quantum Cryptography: A Migration Blueprint for Singapore CII Operators

For years, discussions about quantum computing have focused on a future threat.

One day, sufficiently powerful quantum computers may be able to break widely used public-key cryptography algorithms such as RSA and ECC that currently protect digital communications, authentication systems, and sensitive data.

For Critical Information Infrastructure (CII) operators, however, the challenge is no longer whether quantum computing will become relevant. The challenge is how to prepare for the transition before existing algorithms become a security liability. This is particularly critical for operators managing critical information infrastructure Singapore networks.

This is where post quantum cryptography (PQC) comes in. It refers to cryptographic algorithms designed to remain secure against both classical and quantum computers. While large-scale cryptographically relevant quantum computers do not yet exist, governments and cybersecurity agencies worldwide are already encouraging organisations to begin planning migration efforts.

For Singapore organisations operating critical infrastructure, the safest approach is to start building cryptographic agility now rather than waiting until migration becomes urgent.

Why Quantum Computing Matters to Cybersecurity

Most modern digital systems rely on public-key infrastructure. Standard RSA encryption and ECC cryptography are widely used for:

  • TLS certificates
  • VPN connections
  • Secure email
  • Digital signatures
  • Identity and access management
  • Software signing
  • Public key infrastructure (PKI)

These algorithms are considered secure against traditional computers. Quantum computers could change that.

Using Shor's algorithm, a sufficiently powerful quantum computer could theoretically solve the mathematical problems that underpin RSA and ECC far more efficiently than classical computers.

First proposed by mathematician Peter Shor in 1994, the algorithm demonstrated that quantum computing could potentially break widely used public-key cryptography systems that are considered secure today.

While practical quantum attacks remain a future concern, the potential impact is significant because these algorithms are deeply embedded throughout modern technology environments.

Why CII Operators Should Prepare Now

1. Sensitive data may outlive current encryption

Some information remains valuable for many years. Critical infrastructure designs, operational procedures, intellectual property, government-related information, and strategic business data may require long-term protection.

Attackers may already be collecting encrypted data today with the intention of decrypting it later when quantum capabilities mature. This risk is commonly referred to as "harvest now, decrypt later."

For organisations managing critical services, protecting long-lived data requires planning before the threat fully materialises.

2. Cryptographic migration takes time

Replacing cryptographic algorithms is rarely a simple software update. Cryptography may be embedded within applications, databases, network devices, industrial systems, certificates, authentication platforms, and third-party products.

Large environments often discover hundreds or thousands of cryptographic dependencies during migration planning. The earlier organisations start inventorying these dependencies, the easier it becomes to manage future transitions.

3. Regulators are encouraging quantum readiness

Global cybersecurity agencies have increasingly encouraged organisations to prepare for quantum-related risks.

In August 2024, the U.S. National Institute of Standards and Technology (NIST) formally released its first post-quantum cryptography standards, including ML-KEM, ML-DSA, and SLH-DSA, providing organisations with standardised quantum-resistant algorithms for future adoption.

These developments are shaping national policy for post quantum cryptography Singapore initiatives, shifting the strategic question from when to migrate to how fast operators can execute.

Building a Post Quantum Cryptography Migration Roadmap

1. Create a cryptographic inventory

The first step is understanding where cryptography is used. Many organisations have detailed asset inventories but limited visibility into cryptographic assets.

A cryptographic inventory should identify:

  • RSA implementations
  • ECC implementations
  • TLS certificates
  • VPN technologies
  • PKI infrastructure
  • Code-signing systems
  • Authentication platforms
  • Hardware security modules (HSMs)
  • Industrial control systems using cryptography

Without this visibility, migration planning becomes difficult.

2. Identify critical dependencies

Not all cryptographic systems carry the same risk. Organisations should identify which systems support critical business services, operational technology environments, customer-facing services, and sensitive information.

Prioritisation helps focus resources on systems that would have the greatest impact if cryptographic weaknesses emerged.

3. Assess third-party exposure

Many cryptographic dependencies sit outside direct organisational control. Cloud providers, telecommunications providers, software vendors, managed service providers, and industrial technology suppliers may all use cryptography within their products and services.

Organisations should engage vendors to understand their post-quantum roadmaps and expected migration timelines.

4. Evaluate cryptographic agility

Cryptographic agility refers to the ability to replace one algorithm with another without major disruption. Systems that hard-code cryptographic algorithms are often difficult to upgrade.

Evaluating agility helps determine whether conducting a preliminary POC migration or launching a full-scale architectural overhaul is required.

Adopting Quantum-Resistant Algorithms

1. Understand the NIST standards

NIST's PQC standards provide a foundation for future migration efforts. These algorithms are designed to resist attacks from both classical and quantum computers. Organisations do not necessarily need to replace all legacy cryptography immediately, but they should understand how these standards align with future technology roadmaps.

  • ML-KEM for key establishment
  • ML-DSA for digital signatures
  • SLH-DSA for specific signature use cases

2. Use hybrid approaches where appropriate

Many organisations are expected to adopt hybrid cryptographic models during the transition period. A hybrid approach combines traditional algorithms with post-quantum algorithms, providing protection against both current and future threats.

This allows organisations to gradually introduce quantum-resistant capabilities while maintaining compatibility with existing systems.

3. Prioritise new deployments

New systems often provide the easiest opportunity to improve quantum readiness. Rather than building infrastructure that depends entirely on legacy cryptography, organisations can evaluate whether new projects support cryptographic agility and future PQC adoption.

This reduces the amount of future remediation work required.

Special Considerations for CII and OT Environments

1. Legacy systems may be difficult to upgrade

Critical infrastructure environments often include systems with long operational lifecycles. Industrial control systems, SCADA environments, operational technology platforms, and specialised hardware may remain in service for many years.

Some of these systems may not support modern cryptographic standards without significant upgrades or replacement. Migration planning should therefore begin well before quantum-resistant cryptography becomes a mandatory requirement.

2. Safety and availability remain priorities

Security changes in operational environments require careful testing. A cryptographic upgrade that affects system availability could create operational risks. CII operators should evaluate quantum-readiness initiatives alongside existing safety, reliability, and business continuity requirements.

3. Third-party dependencies may drive timelines

Many operational technologies depend on vendor support. Migration schedules may therefore depend on vendor product roadmaps, firmware updates, and hardware refresh cycles. Organisations should identify these dependencies early to avoid unexpected delays later.

Common Post Quantum Migration Mistakes

1. Waiting for quantum computers to arrive

One of the most common mistakes is assuming migration can begin after quantum threats become immediate. By that point, many organisations may still be trying to identify where vulnerable cryptography exists.

Migration programmes often take years rather than months.

2. Treating PQC as a cryptography project

Post quantum migration affects architecture, infrastructure, applications, procurement, vendor management, and governance. Success requires coordination across multiple business and technical functions.

3. Ignoring third-party systems

An organisation may successfully migrate internal systems while remaining dependent on vendors using vulnerable cryptography. Vendor readiness should therefore be part of every migration programme.

4. Failing to build cryptographic agility

Future cryptographic transitions are likely. Organisations should use this opportunity to build architectures that can adapt to future algorithm changes rather than creating new long-term dependencies.

From Quantum Awareness to Quantum Readiness

Post quantum cryptography is no longer purely a research topic. It is becoming a long-term cybersecurity planning challenge for organisations that depend on secure digital infrastructure.

For Singapore CII operators, the most important step is not deploying quantum-resistant cryptography everywhere immediately. It is understanding where cryptography exists, identifying critical dependencies, engaging technology providers, and building a realistic migration roadmap.

Organisations that begin planning now will have greater flexibility, lower migration risk, and more time to adapt as standards and technologies continue to evolve.

Zentara helps organisations strengthen their cybersecurity posture through cybersecurity consulting, VAPT, and Managed SOC services. These capabilities can help organisations identify security dependencies, assess cryptographic exposure, and build practical roadmaps for future resilience.

Talk to our experts now.

More like this, monthly.

What our teams are seeing in Indonesian threat activity and regulatory movement — written by the people running the SOC.

We use your address to send what you asked for and nothing else. No list is sold or shared. Privacy policy.

Have a security question this raised?

Our engineers answer directly — no qualification call first.