I have spent most of my career in rooms where cryptography was the thing nobody wanted to discuss. Too mathematical for the risk conversation. Too foundational for the architecture conversation. Too invisible for the board conversation. Everyone assumed someone else understood it. Usually, nobody did.
That era is ending. The CISOs who see it first are quietly rewriting their own job descriptions.
How cryptography left the appendix
For most of the last two decades, a CISO's daily reality was operational. Alerts. Incidents. Phishing. Patch cadence. Third-party risk. Compliance audits. Cryptography sat in the background as an assumption. TLS worked. Certificates renewed. HSMs stored keys. If nothing was on fire, cryptography was not on the agenda.
Two forces broke that assumption almost at the same time.
The first is post-quantum migration. NIST's finalized PQC standards in August 2024 turned "someday we'll need to swap algorithms" into a live, multi-year enterprise transformation with a deadline no one can name precisely. Every crypto dependency you have. TLS libraries. Code-signing pipelines. PKI. VPNs. HSMs. Embedded firmware. Third-party vendor stacks. All of it is now on a migration path. That is not a specialist concern. That is a top-line architectural program.
The second is agentic AI. Autonomous agents now generate, consume, sign, and verify cryptographic material at machine speed. API tokens. Ephemeral certificates. Code signatures. Model provenance attestations. Tool-use credentials. Most organizations have no policy for this because the pattern did not exist eighteen months ago. The volume of cryptographic events per day in a modern enterprise has quietly gone up an order of magnitude. Governance has not.
Between these two forces, cryptography has moved from background assumption to the largest, longest, and least-understood architectural risk on the CISO's desk. The role is being rewritten in real time, whether the org chart acknowledges it or not.
What actually changes about the CISO's day
I have been asked more than once whether this is real transformation or just a reframing. Honest answer: some of both. But the parts that are real are the parts that matter most.
What is genuinely new:
- You now own an inventory problem you did not have before. A Cryptographic Bill of Materials is not optional. It is the artifact the board will eventually ask to see. It will take longer than you expect.
- You now own a vendor timeline problem. Every third-party dependency has a PQC roadmap. The ones without are the ones that will strand you. Your TPRM program has a new column.
- You now own AI-generated cryptographic material. Which agents can mint tokens? Which can sign artifacts on your behalf? What is the audit trail? Rare questions in 2023. Unavoidable now.
- You now own the crypto-agility architectural conversation. Not "should we be agile." The specific engineering practices that make swapping algorithms a configuration change instead of a rewrite.
The things that stay familiar are the leadership rhythms. Board reporting. Budget defense. Incident response. Retention. Culture. What changes is what you are reporting on. The slide called "encryption program," if it existed at all, is now the anchor tenant of the enterprise architecture roadmap.
Y2K. The useful comparison and the misleading one.
Every senior security leader I know has reached for the Y2K analogy at some point in the last two years. It is useful. But only if you notice where it breaks.
Useful. Y2K, like PQC, was a foundational-layer replacement problem that spanned every system in the enterprise, every vendor, and every embedded device. It required inventory before remediation. It succeeded because it was treated as a leadership program with executive sponsorship, dedicated funding, and defined governance. Not as an IT project.
Misleading. Y2K had a hard deadline. Midnight, January 1, 2000. Everyone knew the date. That gave the entire industry a coordination point. Budget cycles, vendor timelines, board attention, and public accountability all rallied to it.
PQC has none of that. The deadline is soft, contested, and moving. It might be 2032. It might be 2035. In a bad scenario, earlier. And critically, the failure mode is silent. When quantum arrives, no dashboard turns red. There is no "the systems went down at midnight." There is only the slow, invisible realization that the data you stored ten years ago has been readable for six months.
This is harder than Y2K. Not easier. Same leadership discipline. Much more patience.
Agentic AI is the accelerant
The PQC conversation on its own would justify treating cryptography as a top-tier CISO priority. Agentic AI turns it from a priority into an existential architectural question.
Look at what has already changed in most enterprises over the last eighteen months. Autonomous agents request short-lived credentials. Produce signed artifacts. Verify inputs from other agents. Increasingly manage secrets themselves. Every one of those operations is a cryptographic event. Every one needs a policy. Every one needs an audit trail. Most have none.
Meanwhile, the PQC migration that is already complicated to reason about with a slow human release cycle becomes vastly harder when the systems in question are agents that can regenerate their own tokens and renegotiate their own cipher suites with no human in the loop.
The CISOs who will succeed here are not the ones who "add AI governance" to their existing program. They are the ones who see that cryptographic policy and AI policy are converging into the same policy. And who reorganize accordingly.
The reorganization no one wants to talk about
The uncomfortable implication of everything above is structural. The traditional CISO org chart. SOC on one side. GRC on the other. AppSec somewhere in the middle. Cryptography as a footnote in the PKI team. It is not organized for what is coming.
Some organizations will respond by creating a formal Chief Cryptographic Officer or Head of Cryptographic Transformation role, reporting to the CISO. That is a defensible choice, especially in regulated industries.
Others will keep the title and reshape the role. This is where I expect most enterprises to land. The CISO of 2027 will spend a materially larger share of their week on cryptographic strategy, algorithm lifecycle policy, and AI governance than they did in 2023. And a proportionally smaller share on the operational cadence they were promoted for excelling at.
That is a hard leadership pivot. It requires letting go of the parts of the role that made you a CISO in order to grow into the parts that will keep you one.
A challenge, then, for anyone reading this in the CISO seat. Pull up your last four board decks. Count the slides that discussed cryptographic posture, PQC readiness, agentic AI credential governance, or the maturity of your cryptographic inventory. Zero? The transformation has not started. One? It has barely begun. The board conversation is a lagging indicator of the internal one. Both need to change in the next four quarters.
The job description is being rewritten. The only question is whether you get to write it, or inherit it.
Lekshmy Sankar, PhD