Navy Cyber Expert: Post-Quantum Cryptography is Backbone of Zero Trust
The two technologies are converging as War Department officials increasingly prioritize building systems for a quantum era.
Zero trust architectures remain effective if the cryptography underlying identity, authentication and communications can withstand future quantum computers, according to cybersecurity expert Steve Defibaugh.
Defibaugh, who previously served as command information security officer at Naval Installations Command and as deputy CISO within the Naval Sea Systems Command’s Cyber Engineering and Digital Transformation Directorate, framed the relationship between the two strategies during a July 16 webinar.
“Zero trust answers who or what should be trusted right now,” Defibaugh said. “[Post-quantum cryptography] answers the question: Can the cryptographic mechanisms used to establish that trust survive a quantum-capable adversary?”
Defibaugh explained that quantum computers could eventually solve certain mathematical problems far faster than classical computers, creating a future risk for today’s public-key encryption standards. While quantum systems are limited by significant technical challenges like temperature sensitivity, he said agencies should begin preparing now for their long-term cybersecurity implications.
“Quantum computing can’t replace classic computing at this point in time,” Defibaugh said. “These things are better together rather than separate.”
Defibaugh warned that traditional perimeter-based security and static encryption could become obsolete as quantum capability matures. That threat carries particular weight for the Defense Department given how long some fielded combat systems remain in service.
“There are fielded combat systems that exist not in the matter of years, but in the matter of decades,” he said, arguing that PQC resistance protects long-lived acquisition, logistics and weapons systems data against future exposure.
Zero trust, a reigning priority for DOW, depends heavily on cryptography to perform identity authentication, secure public key infrastructure and digital certificates, issue access tokens and encrypt data and communications through transport layer security. If quantum computing eventually breaks popular cryptography standards, many of the mechanisms zero trust depends on become vulnerable.
He also highlighted ICAM’s reliance on PKI credentials and digital certificates for authentication, arguing that zero trust combined with PQC points toward a “quantum-safe ICAM” future. Without PQC, he said, the identity pillar underpinning zero trust “starts to crumble.”
Notably, Defibaugh framed quantum technology as more than a threat. He said quantum computing can also strengthen capabilities such as user and entity behavior analytics, cyber situational awareness and automation orchestration, even as those same systems require quantum-safe cryptographic protections.
“An interesting observation from the DOW ZT design process guide is that quantum technology is not only a threat — they also enhance certain capabilities that we have,” Defibaugh said, citing the guide’s finding that quantum computing can strengthen behavioral analytics and cyber awareness capabilities while simultaneously requiring quantum-safe cryptographic protections.
How Agencies Should Prepare
Defibaugh urged agencies to adopt a quantum-ready zero trust architecture that incorporates PQC and quantum key distribution into modernization requirements, training and program management planning. He recommended prioritizing legacy and operational technology systems for PQC integration based on cyber protection condition status or their relevance to mission operational plans, cautioning that system owners may present biased assessments of priority tied to funding interests.
He also emphasized the human and organizational aspect of the transition, arguing that shared language between IT and operational communities can accelerate adoption.
Defibaugh encouraged engaging directly with resource sponsors to secure funding for PQC integration, describing his own recurring efforts to make that case within the Navy’s budget process.
“We have to actually, as cyber professionals, provide them real and cogent reasons” to drive investment, he said, adding that doing so offers the clearest path toward the objectives shared by both zero trust and PQC efforts: protecting mission systems, identities and data from increasingly sophisticated adversaries.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots