Maryanne Baines is a preeminent authority in cloud technology, renowned for her clinical approach to evaluating complex tech stacks and their real-world applications across various industrial sectors. With a background that spans the evolution of distributed computing and enterprise architecture, she has become a leading voice for organizations navigating the treacherous waters of digital transformation and emerging cyber threats. Her insights are particularly vital as businesses grapple with the terrifying reality of quantum computing and the slow collapse of traditional perimeter-based security models. Today, she shares her strategic vision on why the future of cybersecurity must be data-centric rather than infrastructure-bound, offering a roadmap for channel partners and enterprise leaders alike.
This discussion delves into the systemic failures of traditional network security and the urgent need to move toward a model where protection follows the data itself, regardless of its location in hybrid clouds or AI pipelines. We explore the nuanced difference between a simple cryptographic transition and a total security transformation, while highlighting the immediate danger of the “harvest now, decrypt later” strategy employed by modern attackers. Finally, the conversation examines how managed service providers can pivot from selling mere tools to delivering high-value business resilience through the implementation of crypto agility.
For decades, we have been told to secure the network and verify identities, but you suggest that this infrastructure-heavy focus is becoming a liability. How has the rise of hybrid clouds and AI pipelines fundamentally broken this traditional security model?
The old way of thinking—securing the perimeter, locking down the network, and controlling access—was perfectly logical when our data stayed inside a four-walled data center, but those walls have effectively vanished. Today, data is a living, moving entity that flows through hybrid cloud environments, SaaS platforms, and increasingly complex AI pipelines that most organizations don’t fully own or control. We are seeing a massive shift where data moves through partner ecosystems and edge infrastructure, yet many security teams still operate under the illusion that if they guard the “building,” the contents are safe. This assumption is falling apart because attackers have stopped trying to kick down the front door with brute force; instead, they are using legitimate credentials to simply walk through the lobby. When they gain access, they find that the data inside is completely usable and exposed because we focused all our energy on the gate and none on the prize itself. We need to stop treating the network as the ultimate control point and realize that in a highly distributed world, the only thing we can truly control is the usability of the data itself, no matter where it happens to be traveling.
Many organizations see the quantum threat as a distant technical hurdle that just requires a quick software update, but you argue it is actually a structural crisis. Why is transitioning to quantum-resistant algorithms such a massive operational challenge?
There is a common misconception that quantum readiness is just a standard cryptographic refresh cycle, like swapping out an old battery for a new one, but that couldn’t be further from the truth. Quantum doesn’t just challenge our algorithms; it exposes the messy, tangled web of how cryptography has been haphazardly embedded into applications, devices, and cloud environments over the last thirty years. In most large enterprises, there isn’t a single person who has a 100% complete inventory of where their encryption actually lives, making a “simple” replacement almost impossible. We have to distinguish between a “transition,” which is just swapping an algorithm within an existing, aging architecture, and a “transformation,” which involves rethinking the entire security lifecycle. This isn’t just about the technology; it’s about the massive operational weight of updating thousands of interconnected systems without breaking them. The organizations that are actually making progress are the ones moving away from these rigid, embedded models and toward a structure that allows for fluid management of their entire cryptographic footprint.
The phrase “harvest now, decrypt later” sounds like something out of a science fiction novel, yet you describe it as a present-day reality. What should organizations holding sensitive data with a long lifespan be doing right now to mitigate this?
The “harvest now, decrypt later” model is perhaps the most chilling aspect of the quantum threat because it means the breach is happening today, even if the damage isn’t felt for another decade. Attackers are currently vacuuming up massive amounts of encrypted data—healthcare records, intellectual property, and government secrets—with the full intention of holding onto it until a quantum computer is powerful enough to crack it. If your data has a shelf life of ten or twenty years, like a patient’s medical history or a proprietary chemical formula, then you are already at risk today, not in some distant future. The question is no longer about the specific date a cryptographically relevant quantum computer arrives, but whether the data we are generating this morning will still be a liability when that day comes. Organizations cannot afford to wait for a perfect modernization project that might take years; they need to start applying data-centric protections immediately so that even if the information is intercepted now, it remains a useless pile of bits for whoever is holding it in the future. It’s about shifting the risk calculation from “can we stop the theft” to “can we make the stolen goods worthless.”
If attackers are now logging in with legitimate credentials and moving laterally through trusted systems, how does a data-centric approach change the outcome of a breach?
When an attacker successfully hijacks a set of trusted credentials, they essentially become an “insider,” and traditional infrastructure defenses like firewalls or identity checks often stop being effective. Once they are inside the network, they can move horizontally, exploring SaaS platforms and edge locations to find the most valuable information assets. A data-centric approach changes the game because the security is baked into the data itself, meaning the protection travels with the information regardless of who is processing it or which cloud provider is hosting it. If an attacker gains access to a database or intercepts a data flow, they find that the information remains encrypted and unusable because the security policy is tied to the data, not the system it resides in. This creates a safety net where, even if your infrastructure fails or a partner’s network is compromised, your core business intelligence remains shielded and unreadable. It turns a potentially catastrophic, headline-grabbing breach into a minor security incident where no usable data was actually lost.
You’ve mentioned “crypto agility” as a strategic requirement for modern business. Can you explain what this means in practice and why it’s more than just a technical preference?
Crypto agility is the ability of an organization to pivot and update its cryptographic protections as standards evolve without having to tear down and rebuild its entire infrastructure every single time. In the past, encryption was often hard-coded into applications, making it incredibly expensive and disruptive to change, but we no longer have the luxury of those multi-year migration cycles. As quantum threats loom and new regulations emerge, being “agile” means you have the management layer in place to swap out algorithms or update policies across a multi-cloud environment in a matter of days, not years. Without this agility, a business becomes trapped in a perpetual state of technical debt, constantly falling behind the latest threats and spending millions on emergency patches. It is a strategic requirement because it guarantees business resilience; it ensures that your security can keep pace with the speed of innovation in both AI and quantum computing. In short, it is the difference between an organization that can adapt to the future and one that is destined to be disrupted by it.
For channel partners like MSPs and resellers, the shift toward quantum readiness and data-centric security seems like a massive hurdle, but you see it as an opportunity. How should they be changing their sales conversations?
The opportunity for channel partners right now is to stop being “tool vendors” and start being “outcome architects” for their clients. Customers are increasingly overwhelmed by the sheer number of security products they have to manage, and they are starting to realize that more tools don’t necessarily mean less risk. Channel partners should be steering the conversation away from infrastructure specs and toward broader business resilience, asking their clients what happens to their most sensitive data if a breach occurs today. By focusing on data-centric security, MSPs and systems integrators can offer a solution that works within a client’s existing, messy environment rather than demanding a total, budget-busting overhaul. This allows partners to differentiate themselves in a crowded market by solving the structural problems of quantum risk and cloud complexity that keep CEOs awake at night. Ultimately, the partners who can help a business navigate this transformation will move from being a line-item expense to a vital strategic ally.
What is your forecast for the future of data protection as we move deeper into this decade?
I believe we are rapidly approaching a tipping point where the number of security tools a business runs will become a completely irrelevant metric. In the very near future, the only question that will matter to boards of directors and regulators is whether the data remains usable if it falls into the wrong hands. We are going to see a mass migration away from the “castle-and-moat” mentality as organizations realize that their data is scattered across too many environments to ever truly “lock down” the perimeter. Quantum computing will be the catalyst that finally forces the industry to embrace crypto agility as a standard operational procedure, making security a dynamic, living part of the data lifecycle rather than a static wall. My advice for anyone in this space is to stop trying to protect the pipes and start focusing on protecting the water flowing through them. If you can ensure that your data is self-protecting and resilient, you won’t have to fear the next evolution of the threat landscape; you’ll be ready for it.
