Information security has always had to keep pace with technology, but the next wave of change, from AI agents and autonomous systems to quantum computing, is arriving faster and touching more of the business at once. InfoSec is no longer a layer added around new technology. It is what determines whether customers, partners and regulators can trust that technology at all.
Protecting tomorrow, today, means making specific decisions now about problems that will fully arrive later: encryption that quantum computers could eventually break, software agents that act with their own credentials, and interconnected devices and algorithms that no perimeter can contain. The organizations that start early will make these transitions as planned upgrades. Those that wait will make them as emergencies.
Beyond firewalls and passwords
Next-generation InfoSec is built on three ideas rather than a network boundary. Data integrity means knowing that information and models have not been tampered with. Identity assurance means knowing, with high confidence, which person, device or piece of software is making each request. Resilience means being able to keep operating and recover quickly when, not if, something is compromised.
Zero trust architecture puts these ideas into practice: no user or system is trusted because of where it sits on the network, every access request is verified, and privileges are kept to a minimum. CISA’s Zero Trust Maturity Model organizes the work into five pillars: identity, devices, networks, applications and workloads, and data. For most organizations, identity is the right place to start, because it is where attackers now focus.
Quantum computing: start the cryptography transition now
A sufficiently powerful quantum computer could break the public-key cryptography, such as RSA and elliptic curve, that protects most internet traffic, digital signatures and stored data. No such machine exists yet, and estimates of when one might vary widely. The risk is still immediate for some data because of “harvest now, decrypt later”: adversaries can capture encrypted data today and decrypt it once the capability exists. Information that must stay confidential for ten years or more is already exposed to that risk.
The standards are ready. In August 2024, NIST published its first three post-quantum cryptography standards: FIPS 203 (ML-KEM) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. In March 2025 it selected HQC as an additional backup algorithm. NIST’s draft transition guidance, IR 8547, proposes deprecating today’s widely used public-key algorithms after 2030 and disallowing them after 2035. We cover the background in Quantum Computing vs. Cryptography.
AI agents and autonomous systems: a new kind of identity
AI-driven automation is shifting from tools that suggest to agents that act: reading email, querying databases, calling APIs and changing records on a user’s behalf. Each agent is effectively a new identity with access to company systems, and it can be manipulated in ways people cannot, for example through prompt injection hidden in a document or web page it reads.
InfoSec for agents applies familiar principles to an unfamiliar actor. Give each agent its own identity rather than borrowing a person’s credentials. Grant the narrowest permissions that let it do its job. Require human approval for high-impact actions such as payments or data deletion. Log what agents do so their actions can be reviewed. And treat any content an agent reads from outside as untrusted input. Our article on AI agent security goes deeper.
AI also strengthens defense. Machine learning powers much of today’s threat detection, identity analytics and email security, and it lets small security teams cover far more ground. The same governance applies: understand what data these tools use and how their decisions can be explained.
When everything is interconnected, integrity becomes the priority
In an environment where devices, applications and algorithms all feed one another, the most damaging attacks may not steal data at all. They may quietly alter it: a manipulated sensor reading that drives an automated decision, a poisoned dataset that skews a model, or a compromised software update that every customer installs. Confidentiality has dominated security thinking for decades; integrity deserves equal weight now.
Practical integrity controls already exist. Sign software, firmware and model artifacts, and verify signatures before deployment. Track where training data comes from and who can change it. Keep software bills of materials for the products you build and ask vendors for theirs. Monitor critical data flows for unexpected changes, not just unexpected access. These measures also make incident investigations faster, because they establish what the system looked like before something went wrong.
A roadmap for future-ready InfoSec
These changes can be tackled in parallel with ordinary security work if they are broken into concrete steps:
- Build a cryptographic inventory. Identify where public-key cryptography is used: VPNs, TLS certificates, code signing, databases, backups and vendor products.
- Prioritize long-lived sensitive data. Records that must stay confidential for years, such as health, legal, financial and intellectual property, are first in line for quantum-resistant protection.
- Design for crypto agility. Favor systems and vendors that can swap algorithms through configuration rather than rebuilds, and ask vendors for their post-quantum roadmaps.
- Inventory non-human identities. List service accounts, API keys, integrations and AI agents, assign owners, and remove what is unused.
- Advance zero trust in stages. Start with phishing-resistant MFA and conditional access, then device health, segmentation and data-level controls.
- Invest in resilience. Maintain tested, isolated backups and rehearse incident response so recovery does not depend on everything going right.
The trade-off is budget and attention spent on risks that may feel distant. The counterargument is timing: cryptographic migrations have historically taken many years, and the organizations that finish first will be the ones that start with an inventory today.
Frequently asked questions
Do small and mid-sized businesses need to worry about quantum computing?
Most will get post-quantum protection through updates from their software and cloud vendors. The practical steps are to know where sensitive long-lived data sits, keep systems updated, and ask key vendors about their post-quantum plans.
What is crypto agility?
The ability to change cryptographic algorithms without redesigning systems. It lets an organization move to post-quantum standards, or respond to a newly broken algorithm, quickly and at lower cost.
How should we secure AI agents?
Give each agent its own identity with least-privilege access, require human approval for high-impact actions, log all activity, and treat external content the agent processes as untrusted.
Protecting tomorrow, starting today
Delana Technologies helps organizations plan post-quantum migrations, secure AI agents and non-human identities, and advance zero trust, mapped to the frameworks in our cybersecurity compliance services. Call 239.414.5126 or contact us.
Sources: NIST FIPS 203, 204 and 205 (August 2024); NIST selection of HQC (March 2025); NIST IR 8547 initial public draft, “Transition to Post-Quantum Cryptography Standards” (November 2024); CISA Zero Trust Maturity Model version 2.0 (2023).
