The clock, according to some estimates, is already ticking. And for Ben Volkow, the question isn't if quantum computers will crack today's encryption—it's whether enterprises will move fast enough to do something about it before that happens.
His answer comes in the form of QIZ Security, a New York-based startup that recently closed a $17 million seed round co-led by Bessemer Venture Partners and Merlin Ventures. The pitch is straightforward, if a bit unsettling: most organizations have no clear picture of where their cryptographic vulnerabilities lie, much less a plan for replacing them with quantum-resistant alternatives. QIZ wants to be the operating system for that transition—mapping encryption assets, modeling risk exposure, and orchestrating what could become one of the most complex infrastructure overhauls in modern computing.
It's a bet that the enterprise market is waking up to what cryptographers and national security officials have been warning about for years. Post-quantum cryptography, once a niche academic concern, has rapidly evolved into a compliance requirement and, for some, an operational imperative.
The funding round drew participation from Evolution Equity Partners, Qbeat Ventures, Singtel Innov8, and Qino Cyber Capital—a mix of traditional venture players and quantum-focused investors positioning themselves at what they see as an inflection point.
When Theory Becomes Mandate
The urgency driving QIZ's launch isn't purely hypothetical anymore. Recent regulatory moves have turned post-quantum cryptography from a far-off concern into something with actual deadlines attached. An Office of Management and Budget memo reportedly directed federal agencies to begin executing PQC transitions, with migration plans required within 120 days. That came on the heels of NIST's formal release of its first three quantum-resistant cryptographic standards—FIPS 203, 204, and 205—back in August 2024.
Those standards offered a technical blueprint. What they didn't provide was a roadmap for how sprawling enterprises with decades of accumulated encryption infrastructure should actually execute the shift.
And then the timelines started compressing. Microsoft, according to recent reports, moved its internal quantum-safety target to 2029, warning that cryptographically relevant quantum computers—machines powerful enough to break widely used encryption schemes—could arrive sooner than many expected. IBM's quantum roadmap similarly targets fault-tolerant systems by the end of the decade. Perhaps more troubling, the specter of "harvest now, decrypt later" attacks looms: adversaries vacuuming up encrypted data today, betting they'll eventually have the quantum horsepower to crack it open retroactively.
For regulated sectors—financial services, telecommunications, healthcare, critical infrastructure—the message is landing hard. Cryptographic assessments are starting to show up in compliance frameworks. The CNSA 2.0 guidelines, Europe's NIS2 directive, DORA financial regulations, and evolving PCI DSS standards all increasingly reference quantum readiness.
The Visibility Problem

Volkow, a serial founder whose previous ventures include Otonomo (which took the SPAC route to public markets) and Traffix (acquired by F5 Networks), frames the challenge as fundamentally one of discovery. "Enterprises cannot migrate what they cannot see," he noted—a line that sounds almost tautological until you consider the reality of most large organizations' IT estates.
Encryption isn't centrally managed. It's embedded across applications, databases, network protocols, IoT devices, third-party integrations. A single Fortune 500 company might have cryptographic assets scattered across hybrid cloud environments, legacy on-premises systems, and partner networks. QIZ's platform attempts to continuously scan those environments, build inventories of vulnerable encryption, and provide remediation workflows that prioritize where to act first.
The product includes tooling developed through a collaboration with Google Cloud, announced earlier this year, including what the company calls a "TLS PQC Enablement dashboard." It's also listed on AWS Marketplace, positioning itself as an "end-to-end operating layer" for cryptographic governance—industry jargon that essentially means: one place to see everything, plan the migration, and track progress.
Volkow is joined by Dr. Itan Barmes, who previously led Deloitte's Global Quantum Cyber Readiness capability before becoming QIZ's Chief Strategy Officer, and CTO Lenny Ridel. The founding team collectively claims over six years of hands-on PQC work, having supported more than 100 organizations in prior roles. In a market where many CISOs are still parsing what "quantum-resistant" even means, that institutional knowledge may prove valuable.
A Crowded, But Immature, Market

QIZ isn't alone in spotting the opportunity. PQShield, a UK-based competitor, raised $37 million in early 2024. QuSecure is taking a different technical approach, focusing on quantum-safe networking. Incumbent players like Palo Alto Networks have rolled out quantum-safe security applications, while certificate and key management vendors are retrofitting their platforms with PQC readiness features.
But the market remains nascent. Most enterprises are still in the awareness phase, commissioning assessments and inventory projects before committing to full-scale migrations. QIZ claims early traction with "some of the world's largest brands" in financial services, telecom, and critical infrastructure, though it hasn't publicly named customers. The company also lists an ecosystem of partners—Cisco, AWS, Google, CrowdStrike, Deloitte, EY, IBM—though the depth and formal structure of those relationships varies.
For regulated industries facing hard deadlines, there's pressure to pick a platform soon. But there's also caution: betting on the wrong cryptographic posture management vendor could mean re-doing the entire migration if the tooling doesn't scale or integrate cleanly.
What $17 Million Buys

The funding will go toward expanding the platform's capabilities and scaling go-to-market operations. QIZ is hiring, with open roles for senior sales engineers and product managers across the U.S. and Israel. For a seed-stage company, the challenge now is balancing product development—building features that handle edge cases and complex hybrid environments—with the sales motion required to land large enterprise deals.
There's also a narrative challenge. Convincing a CFO or board to fund a cryptographic overhaul requires painting a vivid picture of downside risk. "Q-Day" remains theoretical, even if timelines have tightened. Harvest-now-decrypt-later attacks are harder to quantify. The ROI case for quantum readiness is mostly defensive: you're paying now to avoid a catastrophic breach later.
But perhaps the regulatory wind is enough. If federal mandates cascade to industries with government exposure, and if European directives start triggering enforcement, the calculus shifts. Compliance has a way of unlocking budgets that abstract security risks sometimes can't.
For now, QIZ is focused on the immediate task: helping enterprises answer what should be a simple question—where is all our encryption, anyway?—and then figuring out what to do about it before the clock runs out.
