HomeMalware & ThreatsAdvocating to the Board for Post-Quantum Preparedness

Advocating to the Board for Post-Quantum Preparedness

Published on

spot_img

Framing Quantum Risk for Business Exposure, Timelines, and Strategic Investment

As organizations prepare for the impending advances in quantum computing, Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) are finding themselves in a position where they must garner support from their boards for crucial cryptography projects. However, a significant piece of advice has emerged: quantum physics should not be the focal point of these discussions.

Francis Gorman, the head of the Security and Resilience Center of Excellence at Bank of Ireland, emphasizes that bombarding board members with scientific terminology—such as entanglement, quantum gates, and qubits—will likely lead to confusion rather than clarity. “If you approach the board with complex physics jargon, you risk losing their interest entirely, making them feel as if they’re watching an episode of Star Trek instead of discussing critical business strategies,” Gorman warns. Instead, the priority should be on ensuring that board members understand the vulnerabilities associated with essential business services and data, as well as the timelines and costs involved in mitigating these risks.

Monique Shivanandan—a board member at Token and a former group CISO at HSBC—shares this perspective. In conversations regarding both quantum computing and artificial intelligence, she conveys that boards do not need to grasp every technical detail but should trust their senior executives to assess risks effectively. “The board’s primary concern is the overall strategy and the potential risks to the business, not the intricate workings of how these systems are developed,” she says.

Translating Quantum Risks into Business Risks

To efficiently communicate the threats posed by quantum computing, Gorman suggests starting discussions by outlining the organization’s tasks and the necessary security measures to ensure their success. He highlights the importance of confidentiality, integrity, availability, and non-repudiation, all of which are fundamentally reliant on cryptography.

Following this, CIOs should identify the sensitive data tied to each service and recognize the timeframe in which this data needs protection. For example, sensitive information such as biometric data or financial records may retain their value for decades, thereby exposing organizations to modern risks, including "harvest now, decrypt later" breaches. This method underscores the potential danger of adversaries collecting encrypted data today, only to decrypt it when they possess the necessary quantum computing capabilities in the future.

Analysts, such as Jitin Shabadu from Forrester, emphasize that the risks extend beyond financial institutions and government sectors. For instance, he notes that healthcare research data, particularly work related to valuable molecules, maintains its worth over time—making it an attractive target for future breaches. “Illustrating the vulnerabilities of your organization to these threats resonates strongly with boards,” Shabadu argues, especially with recent advancements in quantum research from tech giants like Google, Cloudflare, and Microsoft solidifying this discussion.

The Uncertainty of Quantum Advancements

CIOs are tasked with making board members aware that predicting the specific onset of "Q-Day"—the day when quantum computers could potentially break current encryption—remains an uncertainty. However, Gorman reassures that the timeline for strategic investments doesn’t require a precise date. “While we cannot pinpoint when a quantum computer will be inherently dangerous, what we can analyze are the advancements being made in this field and the financial resources being allocated,” he states. He reminds stakeholders that there is a considerable lead time needed for organizations to prepare for these potential threats.

The U.S. National Institute of Standards and Technology advocates for early adoption of post-quantum standards, suggesting organizations start implementing these protocols to protect sensitive data before vulnerable algorithms are phased out by 2035. Similar timelines have been recognized by companies like Google and Cloudflare, who have announced their targets for migration.

Andrew Gault, the CEO of networking firm ZeroTier, acknowledges a significant shift in conversations surrounding quantum readiness. “In the past, some investors questioned the relevance of preparing for quantum threats. Today, there is widespread acknowledgment of its importance,” he notes. Yet, Gault also observes a lag in action, stating that many organizations still have not initiated the necessary changes. “Those who have not begun this process should have started two years ago. Ideally, start yesterday,” he remarks.

Seeking Incremental Funding Approaches

Instead of requesting an all-encompassing budget for enterprise-wide migration, CIOs are advised to seek initial funding focused specifically on understanding the organization’s exposure to quantum threats and devising a structured plan of action. Gorman stresses the importance of this phased approach, encouraging requests centered around research and assessment over blanket capital requests.

Organizational leaders should seek support for an 18-month discovery phase aimed at pinpointing vulnerable encryption, essential services, sensitive data, third-party dependencies, and systems that cannot be updated. Gorman further recommends combining this funding request with a demonstration of quick, visible results, such as initiating a hybrid configuration change on external endpoints, which can provide immediate feedback and foster trust with the executives.

By framing the initial budget as essential for understanding and planning, instead of vague, unlimited outlay for an ambiguous future threat, CIOs can make compelling arguments for gaining board approval. Simultaneously, they must prepare the board for potentially substantial capital commitments in the years to come, acknowledging that leading companies may allocate up to $100 million over the next decade for quantum readiness initiatives.

Demonstrating a Sense of Urgency

Gorman prepares CIOs for board queries concerning costs and timelines, reiterating the imperative of beginning preparations without delay. He cautions that deferring action not only raises costs but may lead to a scenario where catching up becomes exponentially more daunting. “Procrastination can lead to tripled expenses; immediate action is crucial,” he asserts.

To effectively measure progress, organizations should employ metrics related to critical service assessments, identification of unsupported systems, and overall preparedness for cryptographic changes. Gorman suggests specific, outcome-oriented goals, like “80% of public certificates managed end-to-end by 2029,” ensuring that aims commensurate with exposure and risks.

Finally, building internal capabilities is essential. Rather than outsourcing every aspect of the transition, Gorman underscores the need for organizations to develop in-house expertise. “Establishing internal competencies enables resilience and a proactive stance on security matters,” he concludes, driving home the point that addressing quantum risks is integral to overall business strategy—not merely a technological issue.

As boards weigh the necessity of initiating quantum readiness preparations amidst uncertain timelines, Gorman assures them that the investments made now will yield benefits, regardless of when the quantum tipping point arrives. “None of this investment is wasted,” he affirms, reinforcing the need for proactive, thoughtful action in facing the era of quantum computing.

Source link

Latest articles

Telegram Account Linking ASOS Rogue Notification to Gaming Trading

ASOS Breach Investigation: Insights from Group-IB and Industry Experts Recent revelations from Group-IB, shared exclusively...

Power BI Phishing Campaign Distributes Malicious ScreenConnect Clients

Attackers Exploit Microsoft Power BI for Phishing Campaign Recent research from Huntress has revealed alarming...

Encrypted Instructions Manipulate Copilot CLI to Reveal Developer Secrets

New Security Vulnerability Discovered in GitHub Copilot CLI: Sensitive Data at Risk Recent studies conducted...

More like this

Telegram Account Linking ASOS Rogue Notification to Gaming Trading

ASOS Breach Investigation: Insights from Group-IB and Industry Experts Recent revelations from Group-IB, shared exclusively...

Power BI Phishing Campaign Distributes Malicious ScreenConnect Clients

Attackers Exploit Microsoft Power BI for Phishing Campaign Recent research from Huntress has revealed alarming...