Delinea’s announcement of quantum-safe encryption for privileged account security makes it the first PAM vendor to explicitly address the post-quantum cryptography threat — and it raises a question that every organisation managing privileged access should be asking: what happens to your vaulted credentials when quantum computing breaks current encryption standards?
The threat is real but often misunderstood. Quantum computers capable of breaking RSA and ECC encryption don’t exist yet at scale, but the “harvest now, decrypt later” attack pattern means that encrypted credentials stolen today could be decrypted years from now. For privileged accounts — where credentials often remain unchanged for years and grant access to crown jewel systems — this creates a long-term exposure that traditional PAM encryption doesn’t address.
Delinea’s quantum-safe encryption approach involves upgrading the cryptographic algorithms used to protect credentials within its Secret Server platform to NIST-approved post-quantum cryptography standards. This means that even if an attacker extracts encrypted credential data from a compromised PAM deployment, the encryption will remain resistant to quantum decryption attempts.
For the PAM market, this is a meaningful differentiator. Most PAM vendors are focused on near-term threats — credential theft, insider abuse, lateral movement — and have not yet addressed the quantum threat to credential security. Delinea’s move signals that post-quantum readiness is becoming a PAM evaluation criterion, not just a future concern.
The practical implication for organisations is that PAM platform selection should now include quantum-readiness assessments. While the quantum threat may not materialise for 5-10 years, the credentials being vaulted today will likely still be in use when it does. Organisations should ask their PAM vendors about their post-quantum roadmap and evaluate whether current encryption standards will remain adequate for the lifetime of their vaulted credentials.
For CISOs, Delinea’s announcement is a wake-up call. Privileged access management is a long-term investment, and the cryptographic foundations of that investment need to be future-proofed. Quantum-safe encryption in PAM is not yet a standard requirement, but it will be — and organisations that prepare now will avoid a painful migration later.