Q&A: Thales’ Todd Moore On Quantum Threats, AI Risk & Crypto Agility

Thales' Todd Moore on why quantum readiness can no longer wait, how AI and quantum have become the same problem, and the launch of the quantum-safe Luna 8 HSM at Black Hat 2026.

Published on Aug 7, 2026
Joel Witts Written by Joel Witts
Q&A: Thales' Todd Moore On The Quantum Countdown, AI Risk & Crypto Agility

Quantum security was one of the defining themes of Black Hat 2026. Research from Gartner, Google, and others now points to a quantum event that could impact current cryptography around 2029 to 2030, and governments from the US to France, Singapore, and Australia are already regulating for a post-quantum future.

Cryptography underpins everything: banking, digital identity, how we interact with the internet. A cryptographically relevant quantum computer would break the public-key encryption that protects it all. Migrating to post-quantum algorithms is a multi-year program, not a switch to flip overnight.

This week, Thales has launched Luna 8, its next-generation, quantum-safe hardware security module. Todd Moore is Global VP and GM of Data Security Products at Thales, where he has led the company’s global data security business for over a decade, spanning encryption, key management, and preparing organizations for the quantum era.

We spoke to Todd live at Black Hat 2026, on the final day of the show, about why quantum has moved from tomorrow’s problem to today’s, what crypto agility really means, and what’s inside Luna 8.

You can listen to our full conversation on the Expert Insights Podcast or watch the whole interview, recorded live at Black Hat, below.

Answers have been edited for clarity and length.

You’ve been vocal that quantum has moved from being tomorrow’s problem to something security leaders need to be thinking about today. Can we kick off with why this is the year security leaders need to take quantum threats seriously, and why the risks are real today?

Sure. The research is out there and the governance is out there. It’s clear that we’ve been thinking about the advent of a quantum computer for quite some time, and the technology is catching up. Quantum technology is getting much more scalable, it’s getting much more performant, and the research shows that we could see a quantum event that impacts our current cryptography around 2029, 2030, if you listen to Gartner and Google and a few other large organizations. With regulations coming from the US government, from France recently, coming out of Singapore, Australia, a lot of governments are now being prepared for this advent and asking that companies start implementing safeguards into their systems.

And like any large rotation of algorithms that we’ve done in the past, whether it was going to AES or going from SHA-2 to SHA-3, it’s not trivial. It’s not trivial because cryptography is pervasive within our systems. It underpins everything we do: our lifestyle, our banking, how we interact with the internet. So the risks are becoming more relevant, there’s governance that says we have to start moving, and we’re starting to see industries really getting serious about it. 2029 is not that far away. Think about it, we’re almost out of 2026. You’re talking two years. So it’s now really a relevant time to start getting prepared.

And these processes take a lot of time to put in place. You can’t just flick a light switch and be a quantum-ready program.

I think that’s one of the fallacies. I talk to board-level, CISO-level folks, and some who are not in the regulated industries but in broader industries that will be impacted too, saying, well, can I just flip a switch? Can I just implement these new algorithms and it’s just going to work? And as we’ve seen in the past, it doesn’t work that way. With PQC cryptography, the new algorithms that are coming out that have been ratified by NIST and others have different key lengths, different block sizes, different latency. It’s really going to change your network and impact your infrastructure. So you can turn on these new algorithms, but if you don’t prepare your applications, prepare your infrastructure, you’re going to break stuff. It has to be a process and a plan to get prepared.

We’ve heard a lot about AI this week. How do you see the rapid adoption of AI changing the data security picture, and do you think the AI challenge and the quantum challenge are becoming linked?

Absolutely. I think it’s one of the messages here on the showroom floor, and maybe in your conversations: it’s dominated by AI. But all those agents have personalities, they’ve got credentials, they’ve got identities. They’re talking to your data, and they’re doing it using security, and that security is based on cryptography. So there’s a sheer volume and velocity around more and more cryptography being used around AI. AI is creating more data that needs to be protected.

With AI leveraging this legacy cryptography, everything is underpinned by cryptography. If AI is built on top of something that’s going to change, you’re putting your AI security at risk. So it’s got to be known, and we want to bring to the surface that AI really depends on these methods, these methods are changing, so AI needs to be part of the PQC and the quantum discussion.

Now, one of the good things, is that AI actually can be used to help. That’s what people forget. You can actually use AI to help you find where there are gaps in your systems, and you can start preparing for this quantum new world with the use of AI.

And the last point I’ll make is that when I talk to the people here on the showroom floor, everyone says: I have so much budget for AI, how do I use it? I would argue that when you talk about PQC and getting ready for quantum with some of those leaders, they’ll tell you: I have no budget for quantum. It would be great if we can find a way to convince our leaders of what we just talked about. AI security relies on quantum. Give me some of the AI budget to actually go off and do something to protect against quantum.

You mentioned some of the regulations that are pushing enterprise adoption of quantum preparedness. The new US executive order on post-quantum cryptography sets hard deadlines. Do you see that as important regulation, or were enterprises already moving in that direction?

I think industries like financial, healthcare, governments, the ones that are used to regulations and compliance, are taking this seriously. A lot of large banks and governments have already said: 2029, we’re going to be ready for the advent of quantum computing, we’re going to have our quantum-safe networks. It’s the others I’m more worried about. It’s the retail, the entertainment, the manufacturing that aren’t as impacted by these regulations, or historically haven’t followed some of these compliance regulations. They may be taking this as guidance, not as law.

So I think there’s a lot of work that needs to be done from our industry to make sure we explain the value of what you can do to protect against quantum computing. The regulated industries have already started. They’re following it, the rules are there. It’s now about getting that knowledge out to a broader audience.

A lot of organizations may still be in the early stages of quantum planning. What’s the first practical step security leaders should take if they want to prepare for the post-quantum era?

A lot of organizations are going to live in this hybrid world for a while. They’re going to be working in existing cryptography and existing applications as they move to new. But I do think the first step is to try to do your best to get an inventory. Understand what applications, what systems, what infrastructure is leveraging this legacy cryptography, RSA and ECDSA, that’s going to have to change. You may not be able to inventory everything, and it doesn’t have to be exhaustive, but do that first pass of understanding where everything is at.

Then next, pick a couple of applications, some really key, core applications for you as a business, and really start testing. What does it mean to turn on these new algorithms, these new quantum-safe mechanisms, these new protocols? See what it does to your system and your applications. It’s going to be a phased approach. Like any cryptographic standard implementation, it’s going to take time. But organizations need to take a quick inventory, do an assessment around that, pick the applications that may be impacted first and hardest, and then actually do some testing and start slowly working your way through implementing safeguards for all your applications.h

You mentioned the new quantum protocols that are coming out, and I know there’s still some uncertainty around which specific algorithms and standards will end up being adopted. What’s your advice for organizations preparing when there’s still uncertainty around how the technology will evolve?

There’s this concept of crypto agility, and we didn’t talk about that just yet. You’re right, the standards are going to change. Some have not been ratified. There’s talk about going to a brand new standard versus hybrid standards, having both supported. We don’t know where that’s going to come down.

So let’s talk about crypto agility. A lot of organizations, ours and broader, talk about crypto agility just around the algorithms. And the algorithms are going to change, let’s be clear. Whatever we implement today is going to change tomorrow. So whatever you build to be quantum safe has to have the ability to upgrade as the algorithms upgrade.

But crypto agility doesn’t just mean algorithms. And I like your question, because it’s really the protocols and how folks are using those algorithms. Agility has to be around the fact that standards are going to change, and you’ve got to be prepared and have the flexibility, from a memory perspective, with more keys being generated, in how you’re going to implement those standards. Being hybrid for a while is important. We don’t have a crystal ball to anticipate everything, but there are a lot of technical constructs we can put in place from a programmability perspective to be prepared.

Let’s talk about how the Thales platform helps. Luna 8, the Luna Network HSM 8, is a next-generation hardware security module designed for enterprise environments. Can you give us an overview of what’s new with Luna 8 and how it addresses some of the risks we’ve talked about?

Thank you for bringing that up. We announced our next-generation HSM here at the show. It’s called Luna 8, and it’s quantum safe from the ground up. What does that mean? It means it’s built securely using quantum principles. All the protocols inside the box are based around quantum-safe principles, and we back up keys and information the same way. The whole ecosystem is based around quantum-safe principles.

It’s been built with a customized ASIC, a chip we developed ourselves, to accelerate this new cryptography as well as traditional cryptography. So it’s fast. It’s very performant around these new algorithms, because it’s different math, basically, and you need accelerators to be able to do this new math. It’s crypto agile, with programmable elements to move as things change, as we already talked about.

If you want to summarize it all in one spot: it’s a platform. It truly is a platform with all these different elements, where we can run multiple HSMs on the same platform. We’ve got the performance, we’ve got the multi-tenancy, we can grow as the industry grows, and it’s fully quantum safe. And for our existing customer base, it’s easy to migrate from what you have today to this new platform. As you do that testing and slowly bring different capabilities online, we help you test in those environments to bring it to production. We’re right there with you. We’re really future-proofing, I guess, is the way to say it.

In terms of the Luna 8 launch, what’s changed in the market that makes now the right time? Why launch it at Black Hat this week?

That’s a great question. We’ve been working with industry around quantum for a long time. Thales has been interested in the math and what’s happening in the quantum industry, and the advent of a quantum computer, for the last eight, ten years. We’ve been working with partners and internally with our own technologists around quantum. We knew this was going to be something that would really impact us, and with NIST coming out with the algorithms, with the regulations coming out, our customers were demanding a solution.

So really, we were working to have something in market now to help meet what was originally the 2030, 2031, 2032 timeframe. That’s accelerated, and it’s actually worked out well for us, because we’re at an inflection point in our market with these fears that a quantum computer could be available in 2029. So why launch now? Well, it’s ready now, which is good news. We’ve tested it, we’re excited, and we felt Black Hat was the right platform. Given this technical audience, and how many people around here care about cryptography, we wanted to launch it here.

I want to circle back on future-proofing. We’ve talked about crypto agility, and Luna 8 enables crypto agility. Why is that so important to have in the platform you’ve launched?

It’s what we spoke about before. We know for a fact, period, that the algorithms we have today will change going forward. New algorithms will be built, algorithms will be modified, protocols will change. Having the ability, with the platform, to keep up with the technology and the changes that occur gives our customers and our community the ability to not be stuck with one solution that isn’t performant or doesn’t really support their needs. For us, future-proofing means giving our customers the capability to really keep up with the industry and the technology as things evolve over the next couple of years.

How does Luna 8 fit into the broader enterprise post-quantum strategy? Is it simply a hardware upgrade, or does it represent a different way of thinking about cryptographic infrastructure?

That’s an interesting question. HSMs are pervasive. Every day we all use HSMs, whether we know it or not. Digital banking, using physical cards to open doors, using our credit cards. It’s pervasive in what we do today. So I think the use cases for HSMs are relatively the same. They’re still out there, they need to be met, and more use cases are emerging.

Do I think something has fundamentally changed? Not necessarily. I think HSM use cases will remain. We just want those use cases to remain secure and stay secure. But we do know for a fact that with AI, there are going to be more identities, more non-human identities, more interaction. We talked about the sheer volume of data going up and going all over the place. So HSMs have to grow. It’s really a scalability thing.

Maybe that’s how I’ll answer your question. With previous versions of HSMs, we were working in a world where the use cases were pretty fixed, and it was very clear what we needed to do. With the volume and the speed of the world now, we need HSMs that can scale. Luna 8 has been built with scalability in mind. We’re able to do the crypto agile piece, but we also have enough processing and memory and other resources to help you scale as the world scales around you.

Thales is a global security company, far beyond just the cyber side. Do you think the scale Thales has as a company gives you a unique position to help organizations handle the quantum era challenge?

That’s a great question, and I think so. Our industry touches a lot of different types of verticals, including defense. And defense is very curious about what’s going to happen with quantum. The quantum technology we’re developing with Luna 8 isn’t just for our existing customers. Thales is a customer too. The quantum technologies we’re building are actually being used within all of Thales.

I think the way the quantum world is emerging, there are a lot of companies out there, a lot of ecosystem, a lot of partnerships happening. It’s interesting how many technologies complement each other in this space. We’re not sure exactly when a quantum computer will arrive, and the technology is still changing, but we’re seeing a lot of relationships being built between organizations and companies to help address problems. Thales is embracing that, and given our global reach and all the different industries we touch, we’re going to continue to build out those partnerships and use the technology internally. So yes, I think it gives us an advantage. I hope so. I think so.

Taking a step back as we come to a close: if we were to come back to Black Hat and have another conversation in two or three years, which would bring us to 2029, what do you think will have changed about the way organizations are thinking about post-quantum security?

We’ll see in the next couple of years, if the researchers are correct, that we’re going to get closer to a crypto-relevant quantum computer. I think in two or three years you’re going to see more budget being allocated, and you’re going to see organizations outside of finance, government, the regulated industries, really starting to make motions.

And you’re right, here at Black Hat, AI, identity, and quantum are being talked about, but AI is obviously on every booth and in every conversation. I think you’re going to see a lot more sessions and a lot more conversation around quantum, with people sharing ideas. Because just like anything in our industry, there’s not going to be a silver bullet. There’s not going to be a magical platform that pops up that everyone just implements across the world. There are going to be lessons learned and best practices. So in three years here at Black Hat, I see a lot more sessions around people sharing: this is how I’ve done it, this is how you may want to do it. It’s going to be a much more top-of-mind topic in a few years.

Todd, this has been a fantastic conversation. My final question: for someone watching this, if they were to take away just two or three things from this conversation to act on today, what should they be?

First and foremost, if you haven’t thought about getting prepared for a quantum world, do something. Don’t wait. There’s no downside to starting now. That could be a simple visibility exercise, a crypto inventory. It could be a simple risk assessment, looking at applications. Pick one priority application and start understanding how it would be impacted if a quantum computer popped up.

The second takeaway is: watch the hype. There’s not going to be a one-all, end-all solution. There’s not going to be a magic tool. Someone that tells you they have a solution for post-quantum today that isn’t crypto agile, both in the algorithms and in the protocols, is not telling you all the truth. So make sure you’re working with vendors that give you the scalability to allow you to grow as the industry changes.

And my third takeaway is: think about how AI can help you in solving this journey. If you can tie together AI and getting prepared, the first two things we spoke about, I think that’s going to help get management buy-in to actually start preparing for this new world.

Learn more about Thales

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.