CyberSecurity SEE

World Quantum Readiness Day: Insights from the Industry on Transitioning from Blueprint to Implementation

World Quantum Readiness Day: Industry Perspectives on Transitioning from Blueprint to Build

Today marks World Quantum Readiness Day, showcasing significant strides in the realm of quantum security, with this year’s theme, “From Blueprint to Build.” This theme reflects the journey that the industry has taken over the past three years, during which post-quantum cryptography (PQC) has transitioned from a niche topic to a central discussion on the C-suite agenda. However, the difference between having a strategic plan and operationalizing that plan remains substantial, underscoring the ongoing challenges faced by organizations.

IT Security Guru engaged with various industry leaders from certificate authorities, network vendors, banks, standards bodies, and consultancies to gather their insights on the current landscape of quantum readiness.

Transitioning from Plan to Execution

Paul Holt, Group Vice President EMEA at DigiCert, emphasizes that moving from a blueprint to actual implementation involves more than merely outlining a strategy. It requires “developing the operational capability to change cryptography across the organization.” Despite DigiCert’s research indicating that 87% of IT and security leaders are in the planning, testing, or implementation stages of PQC initiatives, a stark disparity exists: only a small fraction has successfully deployed quantum-safe or hybrid certificates at scale, revealing the true state of the industry today.

Vince Stoffer, Field CTO at Corelight, echoes this sentiment, noting that awareness surrounding PQC has grown remarkably. The leading organizations are now actively establishing the necessary tools, personnel, and processes to implement these advancements. However, he also observes a significant maturity gap across sectors, with government agencies and financial institutions leading the way, largely due to the sensitivity and longevity of their data, which magnifies the perceived risk.

Callum Evans, Senior Solutions Architect for Cybersecurity at SHI, adds another layer to this discussion, metaphorically likening the process of discovery to “unraveling a ball of string.” He points out that organizations in heavily regulated sectors or those that support critical national infrastructure have been quicker to respond. Nonetheless, he warns that no organization has complete visibility regarding the positioning of their cryptography.

Daryl Flack, Partner at Avella Security and cybersecurity advisor to the UK Government, identifies an important distinction: the transition to quantum readiness is fundamentally an organizational issue rather than a purely technical challenge. The most advanced entities are those that have embraced executive ownership and carried out pilot programs that surface legacy dependencies and supplier gaps, facilitating real-world testing of migration processes.

Kieran B., Head of Security Engineering at Bridewell, elaborates on the practical steps organizations are taking by evaluating and validating quantum-safe cryptography within limited sectors of their operations. As candidate algorithms become standardized and implementable, teams are able to assess performance impacts while addressing their highest-risk data first.

Misunderstandings Surrounding PQC Migration

A prevailing misconception among industry experts is the assumption that migrating to PQC entails merely replacing one algorithm with another. Thomas Brunner from Sygnum Bank argues that while algorithms have largely been settled, the actual challenges reside in coordinating and governing a sprawling, hybrid estate. He warns that the risks associated with quantum threats aren’t confined to the next decade; anything requiring confidentiality over several years is already vulnerable to potential data harvesting strategies.

Tim Hudson, President of OpenSSL Corporation, reinforces this notion, suggesting that organizations should not prioritize the selection of a new algorithm as their initial step. Although OpenSSL Library 3.5 supports the finalized NIST algorithms, mere availability does not culminate in successful transitions. The most well-prepared organizations will be those who understand their dependencies profoundly, rather than rushing to deploy systems hastily.

Aparna Rayasam, CEO of Atsign, disputes the idea that the costs associated with deploying PQC are prohibitive. She claims that delaying migration could be a more significant error. While acknowledging that post-quantum algorithms may introduce computational and message-size overhead, she argues that such challenges should be viewed as engineering problems that can be addressed rather than reasons to postpone necessary migrations.

Omer Kidron, Enterprise Security Consultant at Sygnia, cautions against complacency, warning organizations not to rely on vendors to silently implement authentication upgrades as they did with browser encryption. Unlike automatic updates in browsers, certificate authorities and firmware updates require proactive organizational efforts.

Kieran B. of Bridewell articulates the misconception as a legacy technology upgrade. The challenge lies in the uncertain obsolescence timeline, suggesting that organizations must understand their exposure, prioritize remediation, and adopt a systematic approach irrespective of the buzz surrounding quantum developments.

Defining the First 90 Days

In discussing the first 90 days of transitioning to quantum readiness, several experts offered similar guidance: the objective should not be a perfect inventory but rather establishing visibility and ownership. David Mudd, Global Head of Digital Trust Assurance at BSI, presents the underlying threat as “harvest now, decrypt later,” emphasizing that organizations must gain insights into their vulnerabilities prior to prioritization efforts. He points to the necessity for robust security measures for systems with long operational lifespans, such as satellites and undersea cables, where simple patches may not suffice.

Chad Thunberg, CISO at Yubico, backs this urgency with compelling statistics, revealing that “69 percent of organizations have no plan in place for post-quantum cryptography.” He argues that the critical timeline isn’t linked to the emergence of quantum computers but rather how long it would take large enterprises to conduct comprehensive migrations across varied infrastructures.

Kieran B. emphasizes that the discovery phase must precede any strategic initiative. Given that cryptographic assets are frequently poorly documented, the first three months should entail a combination of actively scanning code repositories and TLS-exposed systems, in tandem with leveraging organizational knowledge and passive detection tools to establish an asset inventory efficiently.

The Necessity of Ecosystem Collaboration

It has become abundantly clear that no organization can transition to quantum readiness alone. Paulina Gomez, Director of Portfolio Marketing at Ciena, notes that the industry is shifting its focus from merely assessing risk to proactively embedding quantum-safe protections within networks. While many service providers are still in early evaluation stages, her firm’s research indicates that over half are either launching or expect to roll out quantum-safe encryption services within the next year.

Paul Savill, SVP and Global Practice Leader at Kyndryl Cyber Resilience and Connectivity, bluntly states that "no company is truly quantum-safe unless its ecosystem is quantum-safe." He emphasizes that the challenge extends beyond a technology update; it fundamentally underpins digital trust across countless interactions that occur daily.

Frank de Jong, Quantum Safe Network Lead at Orange Business, advocates for World Quantum Readiness Day to serve as “a prompt for action,” emphasizing the extensive duration required for foundational work. He contends that organizations must prioritize identifying and securing their most sensitive, long-lived data rather than attempting to protect all assets simultaneously.

Simone Giacomelli, founder and CEO of Prem AI, highlights the risks associated with relying on third-party AI vendors, cautioning that “quantum hackers could be harvesting your data at this very moment.” His apprehension centers around the burgeoning AI landscape, where businesses utilizing third-party resources may lack the visibility needed to determine if their providers are quantum-resilient.

Navigating Standards and Regulations

Several contributors elucidated the current state of standards, noting that while the core NIST algorithms (ML-KEM for key exchange and ML-DSA and SLH-DSA for signatures) are established and ready for implementation, uncertainties linger around higher-level protocols and legacy vendor support. Notably, the withdrawal of a previously promising signature candidate due to a structural weakness reminds stakeholders that algorithm choice should be embedded within configuration and policy rather than hard-coded into applications.

Regulatory frameworks significantly impact organizational strategies. In the United States, Executive Order 14412 has transformed post-quantum readiness into a compliance requirement, pushing sensitive federal systems toward a transition deadline of 2030 for encryption and 2031 for authentication. Countries like the UK, Germany, France, Singapore, Japan, and Australia are similarly advancing with phased milestones extending through 2035, necessitating multinational organizations to navigate overlapping obligations.

Kieran B. of Bridewell emphasizes the importance of regulations: in a fast-paced technological landscape dominated by rapid advancements like AI, emerging threats such as quantum risk might often be deprioritized unless legal mandates enforce budget allocations for proactive measures.

Emphasizing Crypto-Agility

A recurrent theme among industry experts is that achieving a “done” status in quantum readiness is a misleading concept. Simon Pamplin, CTO of Certes, articulates that the industry has progressed past the point where merely having a roadmap is sufficient. “We are past the point where just having a plan for quantum is enough,” he asserts, noting that sensitive data continues to evolve concurrently with the development of inventories and migration plans, reinforcing the urgency of implementing protective measures directly tied to the data itself.

Jonathan Nguyen-Duy, CTO at Arqit, argues that waiting for the arrival of “Q-day” is not a viable business strategy. The goal should not center on completing a one-off migration project with a definitive end date, but rather on cultivating a lasting state of crypto-agility—an ongoing capacity to evolve cryptographic standards in response to changing threats and business demands.

Kieran B. proposes a framework for grading organizational progress toward this goal. He suggests that a “good” organization utilizes cryptographic standards impervious to known attacks, including quantum. A “better” organization knows precisely where each standard is implemented and how long the data requires protection. The “best” organization exhibits total crypto-agility, understanding the time required for transitioning away from current standards should they fail to withstand future attacks. The concept of “done” becomes irrelevant as organizations strive for continual adaptation.

The overarching message resonates across various responses: the ultimate objective transcends a mere migration to a finite set of algorithms. True success lies in achieving crypto-agility—the ability to locate, understand, and adapt cryptographic standards throughout the organization without undergoing another prolonged scramble when standards evolve. Given the consensus among experts on the existing execution gaps, this dynamic adaptability is likely the real litmus test of whether organizations can transition from “Blueprint to Build.”

Source link

Exit mobile version