Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

PwC’s global survey points to two distinct readiness problems: organizations are pursuing AI-enabled cyber defenses while reporting shortages of knowledge and skills, and many have not begun preparing for quantum-resistant security. The findings describe executives’ reports of their organizations—not tested security controls or a prediction of when quantum computers could threaten today’s cryptography.

What PwC’s survey says about enterprise readiness

PwC’s 2026 Global Digital Trust Insights survey page, dated October 1, 2025, reports responses from 3,887 business and technology executives in 72 countries. Responses were collected from May through July 2025. The “2026” label is the report edition; the findings reflect that 2025 survey period.

On quantum-resistant security, respondents described their organizations’ progress as follows:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported stage Share of respondents Source and qualification
Had not considered or started implementing measures 49% PwC, 2026 Global Digital Trust Insights, published October 1, 2025; survey conducted May–July 2025
Piloting or testing measures 29% PwC, 2026 Global Digital Trust Insights, published October 1, 2025; survey conducted May–July 2025
Had moved beyond piloting measures 22% PwC, 2026 Global Digital Trust Insights, published October 1, 2025; survey conducted May–July 2025

These are self-reported organizational stages, not an audit of whether deployments work, how much of an organization is covered, or whether its systems are secure. PwC says respondents cited limited understanding of post-quantum risks, limited internal resources, and competing demands as reasons some organizations had not acted.

AI-enabled cyber defense is a separate readiness challenge

PwC describes knowledge and skills gaps as leading obstacles to applying AI in cyber defense. At the same time, threat hunting ranks among the top priorities for security leaders planning AI-enabled cyber capabilities. That combination suggests organizations are interested in using AI to help identify threats but may lack the expertise to choose, govern, and operate those capabilities well.

The survey reports priorities and barriers; it does not demonstrate that AI tools improve security outcomes in every organization. Investment therefore needs to include staff capability and responsible-use governance, not just technology. PwC’s Middle East findings also stress embedding governance rather than relying on disconnected tools.

Middle East findings provide regional context

PwC’s Middle East figures are a regional view, not a substitute for the global survey. The reported quantum-readiness stages use different labels, so the figures should not be treated as perfectly equivalent categories.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported measure Middle East Global comparison Source and scope
Progressed in implementing quantum-resistant security 27% 22% had moved beyond piloting PwC Middle East, 2026 Global Digital Trust Insights regional findings; PwC global survey, May–July 2025
Piloting or testing quantum-resistant security 27% 29% were piloting or testing PwC Middle East, 2026 Global Digital Trust Insights regional findings; PwC global survey, May–July 2025
Cited lack of knowledge as a barrier to applying AI in cyber defense 53% 50% PwC Middle East, 2026 Global Digital Trust Insights regional findings
Planned to implement responsible AI practices in the next 12 months 30% 23% PwC Middle East, 2026 Global Digital Trust Insights regional findings

The reported regional comparisons show differences in respondents’ readiness and plans; they do not establish why those differences exist or prove that one region’s controls are more effective.

Why quantum-resistant security matters before a quantum computer exists

The concern is that future advances in quantum computing could threaten some public-key cryptographic systems used to protect confidentiality, authenticate parties, issue certificates, and create digital signatures. That does not mean quantum computers have already broken deployed encryption, nor that all encryption is equally vulnerable. Symmetric encryption and other controls are distinct from the public-key systems central to post-quantum migration.

PwC’s February 11, 2025 guidance highlights “harvest now, decrypt later”: an attacker could collect encrypted information now and try to decrypt it in the future if suitable quantum capabilities become available. This makes the issue relevant to sensitive information that must remain confidential for a long time, even though PwC’s survey describes quantum computing as not an immediate cyber threat. The reviewed PwC material does not establish when a cryptographically relevant quantum computer will be available.

A practical sequence for enterprise preparation

PwC’s post-quantum guidance recommends treating readiness as a program across technology, people, processes, and oversight—not as a single product purchase. Organizations can adapt the following sequence to their own risk and operating environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Assess exposure. Discover and inventory cryptographic assets, algorithms, protocols, and keys across the organization. Map them to critical services and sensitive data, identify vulnerable implementations, and assess the business impact if protected information were exposed. Include previously intercepted data whose confidentiality still matters.
  2. Plan the migration. Set security goals and a roadmap covering people, processes, and technology. Include third-party dependencies and legacy systems; update procurement rules, vendor selection criteria, and contract management so external products and services can support the transition.
  3. Transform in phases. Prioritize systems by risk and business criticality. Test candidate post-quantum cryptography in controlled environments for security, performance, and interoperability before broad deployment. Train operators and security staff as systems and procedures change.
  4. Provide oversight. Assign a clear owner, define reporting, and track progress across business units and suppliers. For large, distributed organizations, PwC suggests a dedicated project-management function to coordinate the work.

For AI-enabled defenses, the parallel practical step is to pair capability investment with training and responsible-use governance. PwC’s survey identifies threat hunting as a priority, but organizational readiness depends on whether staff can evaluate and operate tools within clear controls.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to judge your organization’s readiness

PwC’s survey percentages offer broad context, not a score for any individual company. A useful internal review should look beyond whether a project has started and test whether the organization can carry it through:

  • Stage: Has work not started, is it piloting or testing, or has it moved beyond pilots?
  • Visibility: Can teams identify cryptographic assets and the systems, suppliers, and services that depend on them?
  • Data risk: Which information is sensitive, and how long must it remain confidential?
  • Operational readiness: Are skills, ownership, third-party coverage, procurement, and migration planning in place?
  • AI governance: Are AI-enabled security uses controlled and integrated with staff responsibilities and existing security processes?

Those questions turn a broad survey comparison into a practical view of exposure and execution capacity, without treating reported adoption as proof of effective protection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.