CyberSecurity SEE

Boosting Cryptographic Agility Across the Enterprise

Boosting Cryptographic Agility Across the Enterprise

Encryption & Key Management,
Security Operations

A Risk-Based Approach Can Turn an Overwhelming Migration Into a Workable Plan

Boosting Cryptographic Agility Across the Enterprise

Organizations today face significant challenges in identifying the various cryptographic elements embedded within their infrastructure. Most are not adequately prepared to replace these cryptographic components without disrupting vital applications or infrastructure. This crucial transition—especially towards post-quantum cryptography—can take years to solidify, underlining the urgency for Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) to begin proactive measures before pressing deadlines necessitate hasty, suboptimal decisions.

See Also: How Data-Centric Security Enables the Agentic Enterprise

Francis Gorman, who leads the Security and Resilience Center of Excellence at Bank of Ireland, emphasizes the importance of understanding an organization’s digital landscape as an initial step. This comprehension involves identifying and categorizing certificates, hard-coded credentials, and cryptographic libraries that exist within applications, code repositories, and overarching infrastructure.

The urgency surrounding these preparations is magnified by a dwindling migration timeline. The National Institute of Standards and Technology (NIST) has ratified its first set of post-quantum cryptography (PQC) standards, urging organizations to adopt these changes immediately. Quantum-vulnerable algorithms are slated for future removal by 2035, with high-risk systems anticipated to transition even sooner. In a significant move, Google has announced its own target of 2029 for a complete transition to quantum-resilient standards, citing marked advancements in quantum technology, error correction, and factoring research.

The interplay of these regulatory developments, extended migration periods, and the emerging threat posed by adversaries who may be collecting encrypted data now for future decryption is accelerating the need for businesses to reevaluate and expedite their encryption strategies.

Jitin Shabadu, an analyst at Forrester, comments that organizations have historically approached encryption as a binary condition, treating it merely as a checklist item. Unfortunately, this lack of preparedness for transitioning between different algorithms leaves many businesses vulnerable.

The immediate threat posed by PQC sets the stage for a broader necessity: organizations must cultivate a framework for cryptographic agility that can address ongoing and future challenges. Andrew Gault, CEO of software-defined networking company ZeroTier, articulates this sentiment, advocating for the development of an adaptable framework that allows organizations to efficiently assess and adjust their cryptographic strategies over time.

You Can’t Protect What You Can’t See

The journey to greater cryptographic resilience begins with a thorough inventory of existing cryptographic resources. Gorman urges caution in this process, advocating against the urge to attempt an all-encompassing review in one fell swoop. He points out that indiscriminately scanning an organization’s environment could generate a daunting list of vulnerabilities without prioritizing actionable insights.

He suggests a strategic focus, commencing with a bounded problem tied to a clear business deadline. Identifying public certificates is an ideal starting point, especially as the lifespans of these certificates shrink, which can complicate renewal processes. Organizations should begin by assessing who owns these certificates and whether they should remain publicly accessible, setting the stage for automation, orchestration, and validation needed for secure replacements.

“Build the muscle memory,” Gorman encourages, underlining the need for organizations to establish robust processes early, which can later be applied when adopting quantum-resistant certificates and algorithms.

An effective inventory goes beyond a mere list, capturing essential details like the asset name, protocol used, cipher suite, and business data supported by the cryptography. Shabadu echoes this sentiment, asserting that organizations must recognize they cannot protect or remediate assets that are invisible to them.

Prioritize Business Exposure

Once a comprehensive inventory is established, the next step is prioritization. Gorman recommends that organizations begin with systems integral to generating revenue or critical business operations. Within these services, leaders must identify which data requires long-term protection, including particularly sensitive information susceptible to future decryption attempts.

Creating a prioritization checklist, ranking data and cryptographic measures based on sensitivity and business importance, can significantly clarify the organization’s focus areas. The assessment of encrypted communications is also vital; the potential risks associated with mundane interactions should be weighed against the exposure of financial or personally identifiable information.

“Size the problem to your capacity,” Gorman advises, discouraging attempts to tackle everything at once.

Build the Capacity to Change Safely

Experts caution that achieving cryptographic agility should not equate to an immediate overhaul of all algorithms in use. Critical processes necessitate thorough testing, appropriate approvals, and rollback protocols. Gorman highlights the need for a governance framework that integrates automation and organizational process dynamics, which will empower companies to adapt their cryptographic strategies proportionate to risk.

Creating a competent team is essential for this endeavor; architects, engineers, program managers, and various stakeholders must collaborate to drive this effort. External specialists may offer support, but Gorman assertively states that internal competencies should be maintained to ensure sustainable, responsive change.

Your Vendors Must Also Be Agile

In evaluating technology vendors, organizations should scrutinize how swiftly vendors can adapt to evolving encryption standards and guidelines. To maintain compliance, Gault recommends incorporating Service Level Agreements (SLAs) emphasizing crypto agility into procurement processes. CIOs must press vendors on their timelines for deploying updates in the wake of changing standards.

Shabadu further adds that no single vendor should be categorized as a one-stop solution for all cryptographic needs. Comprehensive capabilities across various domains—including cryptographic discovery, network monitoring, and micro-segmentation—are vital for establishing a well-rounded strategy.

Establishing measurable outcomes will also aid organizations in setting tangible goals; for instance, the aim of managing 80% of public certificates seamlessly by 2029 can guide strategic efforts. Shabadu notes that organizations should also consider the time required for implementing cryptographic changes, emphasizing the significance of efficiency in addition to diversity in supported algorithms.

Together, inventories and well-defined targets can illuminate the scope and financial implications of establishing a robust crypto-agility framework. Gault underscores the importance of this foundation, suggesting a careful budgeting process to facilitate a phased implementation approach over one to three years. Relying solely on speculative timelines regarding the advent of quantum computing could jeopardize an organization’s readiness; therefore, Gault’s counsel to CIOs and CISOs is unequivocal: begin the transition yesterday.

Source link

Exit mobile version