Thales article

The role of HSMs in digital transformation

Digital transformation depends on cryptographic trust

As organisations modernise applications, move workloads to the cloud, adopt AI, connect more devices and digitise customer services, they rely more heavily on cryptographic keys. Those keys encrypt data, verify identities, sign code, protect certificates, secure transactions and preserve trust between systems.

This makes key protection a strategic issue. When keys are exposed, misused or difficult to govern, the impact can reach beyond the security team. It can affect regulatory readiness, operational resilience, customer trust, cloud strategy and the ability to adopt new technologies securely.

Hardware security modules, or HSMs, help organisations establish a stronger foundation by generating, protecting, storing and using cryptographic keys inside a secure, tamper-resistant hardware environment. This creates a hardware root of trust for the applications, identities, data, devices and transactions that digital transformation depends on.

Key points

  • Digital transformation expands the number of applications, identities, devices, certificates, transactions and data flows that depend on cryptographic trust.
  • HSMs provide a hardware root of trust by protecting cryptographic keys inside a secure, tamper-resistant boundary.
  • Post-quantum cryptography makes crypto agility a near-term requirement. The 2026 Thales Data Threat Report found that 59% of organisations are prototyping and evaluating PQC algorithms, while 61% cite harvest now, decrypt later as their top quantum concern.
  • Cloud adoption increases the need for key ownership and control. The same report found that 53% of organisations report cloud providers control encryption keys for more than half of applications.
  • HSM strategy can help CISOs connect technical cryptographic risk to board-level priorities such as resilience, sovereignty, AI readiness, compliance and long-term digital trust.

Digital transformation creates more places where trust must be proven

Digital transformation is often measured by speed, scale, automation and customer experience. But every new digital initiative also creates more places where trust must be established and maintained.

A cloud migration depends on encryption and key control. A customer application depends on TLS certificates and secure identities. A software delivery pipeline depends on code signing. A connected device ecosystem depends on device identity. A digital asset platform depends on private key protection. An AI initiative depends on the confidentiality and integrity of data, models and supporting systems.

This is why cryptography has become foundational to the modern enterprise. As organisations depend on cryptographic keys to secure communications, authenticate machines, protect software integrity, safeguard payment systems and support digital assets, the infrastructure used to protect cryptographic operations becomes more important.

For CISOs, this creates a practical business conversation. Boards will want to know whether the organisation can move to the cloud without losing control of sensitive keys, adopt AI without exposing critical data, maintain sovereignty, meet regulatory expectations and prepare for quantum-enabled threats.

What an HSM does in a modern enterprise

An HSM is a secure hardware device that generates, protects, stores and uses cryptographic keys. It serves as a hardware root of trust for sensitive cryptographic operations.

That secure boundary matters, because keys are high-value assets. They protect customer data, payment systems, certificate authorities, software updates, databases, digital identities and regulated workloads. When keys are stored or used only in software, they may be more exposed to malware, privilege abuse, memory scraping, misconfiguration, insider threats and other compromise paths.

An HSM reduces that exposure by keeping sensitive key material inside hardened hardware. Sensitive operations can be performed without exposing the keys outside the HSM boundary, giving organisations stronger assurance that critical cryptographic processes are protected, controlled and auditable.

HSMs have long supported high-assurance use cases such as PKI, payment security, code signing, TLS, database encryption and compliance-driven encryption. Today, they also support trust-sensitive operations across cloud, hybrid and multicloud environments, including digital identity, software supply chain security, cloud key control, AI systems, connected devices, digital assets and post-quantum readiness.

Post-quantum readiness raises the stakes

Post-quantum cryptography has moved from a future consideration to a current planning priority. Quantum computers could eventually break some of the primary public-key cryptographic algorithms used today. Attackers may capture encrypted data now and attempt to decrypt it later when quantum capabilities mature. This is commonly known as harvest now, decrypt later.

PQC migration will affect more than traditional encryption algorithms. It will touch enterprise key management, public key infrastructure, code signing, certificate lifecycle management, blockchain, software supply chain integrity, application security and the broader ecosystems that depend on digital trust.

This is where HSM strategy becomes important. Organisations need HSMs that can protect today’s keys and support tomorrow’s cryptographic requirements. For HSMs, crypto agility means the ability to introduce, update and transition algorithms, keys and policies securely without disrupting applications, integrations or operations. PQC readiness is not simply an algorithm checkbox. It requires architecture, governance, operational planning, interoperability and trust infrastructure that can adapt.

Cloud and AI make key control harder to manage

Cloud adoption has changed where data lives and who controls the keys that protect it. Many organisations now operate across on-premises systems, private clouds, public clouds, SaaS platforms and multiple cloud providers. This gives teams flexibility, but it can also fragment key management.

If teams cannot centrally govern encryption keys, prove control or apply consistent policies, they may struggle to meet security, sovereignty and compliance requirements. HSMs help by creating, managing and storing keys within a hardware root of trust. With BYOK, HYOK and double key encryption, organisations can keep keys separate from data, use consistent controls across clouds, reduce lock-in and retain the flexibility to migrate or repatriate workloads.

AI adds another layer of urgency. As AI models, pipelines and agents gain access to more enterprise data, organisations need stronger controls over confidentiality, integrity, authentication and authorisation. HSMs do not replace data discovery, classification, access governance, application security, model protection, monitoring or policy controls. But they can strengthen the cryptographic foundation AI systems rely on by protecting keys used to secure sensitive data, safeguard model assets and preserve trusted interactions across AI-enabled workflows.

HSMs help secure the technologies driving transformation

Digital transformation is not one initiative. It often includes the technologies behind cloud migration, AI, IoT, 5G, software modernisation, digital assets and new data-driven services. These initiatives differ, but many depend on the same principle: high-value keys and cryptographic operations need strong protection.

Digital asset ecosystems rely on trusted cryptographic operations to secure wallets, custody platforms, tokenisation services, blockchain infrastructure and transaction signing. If private keys are exposed or misused, the impact can be immediate and difficult to reverse.

IoT environments depend on secure device identity and trusted communication. As endpoint devices multiply, organisations need a reliable way to authenticate devices, protect communications and maintain data integrity. 5G and mobile environments add scale and new entry points, increasing the importance of strong entropy, device identity protection and rigorous authentication controls.

Established cryptographic systems remain just as important. PKI protects certificates and digital identities. Code signing protects software integrity. TLS secures communications. Database encryption protects sensitive records. HSMs help protect the private keys behind these systems, while giving organisations stronger auditability, separation of duties and lifecycle control.

What a future-ready HSM strategy should include

A future-ready HSM strategy should protect today’s keys, while helping the organisation adapt to new business, technology and cryptographic requirements. Security leaders should evaluate whether their HSM approach provides:

  • A hardware root of trust where keys are generated, stored and used inside a secure boundary.
  • Crypto agility and PQC readiness to support algorithm transition and a path towards standardised post-quantum algorithms.
  • Deployment flexibility across on-premises, cloud, hybrid and multicloud environments.
  • Governance and operational control through strong authentication, role separation, audit logging, centralised management and policy controls.
  • Integration breadth across cloud platforms, PKI, certificate authorities, code signing systems, databases, application encryption, digital signing and enterprise key management.
  • Resilience and scale for high availability, backup, restore, disaster recovery, performance and operational support.

This is why HSM selection should be treated as a strategic infrastructure decision, not a narrow product comparison.

Where Thales Luna HSMs fit

Once organisations understand the role of HSMs in digital transformation, the next question is what kind of HSM architecture can support both today’s workloads and tomorrow’s cryptographic requirements.

Thales Luna HSMs provide a hardware root of trust for critical applications, data, identities, transactions and infrastructure. Organisations use Luna HSMs for established use cases such as PKI, code signing, TLS and database encryption, as well as emerging technology use cases such as cloud key control, digital assets, IoT, 5G, AI and post-quantum readiness.

Luna HSMs also support the operational side of digital trust, including centralised management, strong authentication, role separation, flexible deployment options and broad integration with third party applications. For hybrid and multicloud environments, Luna HSMs help organisations maintain key ownership and control, while performing cryptographic operations in the HSM.

For organisations preparing for PQC, Luna HSMs support the broader goal of crypto agility: protecting sensitive data, keys, preparing for algorithm transition and helping teams build a cryptographic foundation that can evolve with new requirements. For CISOs, that makes HSM strategy more than a technical control. It becomes part of the broader conversation about resilience, innovation, sovereignty and long-term digital trust.

Related Articles

No Result Found