CIOs must take post quantum cryptography seriously today or risk future peril

Glowing digital shield blocking streams of code and malware attacks
A glowing digital shield protecting against hacking attacks in cyberspace

Quantum computing is an exciting new venture to the world of computing. It brings new opportunities…but also new risks. As I referenced in my post about IBM Think, quantum is a lot closer than many think.

While some enterprises, such as Cleveland Clinic, are already starting to embrace quantum, all enterprises need to consider one aspect of their cybersecurity posture that is impacted by quantum.

This action needs to be taken today, not when starting to engage quantum.

Post-Quantum Cryptography

One misconception to address right up front is that quantum computing is not a faster version of classic computing. Quantum computing solves very different types of problems than the classic computing solutions that we are familiar with today.

The issue facing enterprises today is PQC or Post-Quantum Cryptography. Classic computing and quantum computing use different types of computational algorithms. Today, cryptography algorithms are based on the capabilities of classic computing. Unfortunately, those algorithms can be broken using quantum computing.

One option is to move to algorithms used by quantum. Another option is to use algorithms that are beyond both classic and quantum computing. Essentially making it increasingly more difficult to decrypt encrypted data.

PQC is a critical topic for enterprises today as much of their critical data is currently encrypted using algorithms on classic computers. As quantum becomes more readily available, those algorithms are at risk of the cryptography being broken.

The urgency to act is now

For some time now, nation states and bad actors have been amassing encrypted enterprise data from data breaches. While they cannot decrypt the data today using classic computers, the purpose is to keep it until they can decrypt the data using quantum computers. Google said that by 2029 quantum will start breaking algorithms.

The first step is to get educated on PQC and fully understand your risk profile. Where are you most vulnerable and least vulnerable? How do you stack-rank your profile?

One aspect to consider is that data has a half-life. For the different classifications of data, calculate the half-life and factor that into your profile.

The second step is to formulate a gameplan to address. There are newer algorithms available today that can prepare organizations for the upcoming risks. One unfortunate thing to consider is that not all solutions in-market today are ready to support PQC. So, even if you have a gameplan, you may not be able to fully execute it in the way you would like. This is changing over time, but something to be aware of.

Lastly, a best practice is constant re-evaluation of your security posture. If you’re not already considering that confidential data may be in the hands of your adversary, consider the worst-case scenario and what actions you would take to put yourself in a better position.

As always, preparation is key when it comes to cybersecurity. PQC just furthers the need for preparation today.


Discover more from AVOA

Subscribe to get the latest posts sent to your email.

Discover more from AVOA

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from AVOA

Subscribe now to keep reading and get access to the full archive.

Continue reading