Quantum computing · Cryptography · Security leadership
Quantum Computing for Security Leaders:
Without the Panic
Quantum computing is something security leaders need to consider in their planning, but there is no need to panic.
The central issue is straightforward: a sufficiently capable quantum computer could undermine public-key systems in widespread use today, including RSA and elliptic-curve cryptography. This does not mean that current security will fail overnight. It means organisations need enough time to plan, test, budget and manage the transition to new cryptography before it becomes an emergency.
What Is Actually at Risk?
Not all encryption faces the same level or type of risk. Public-key methods used for key exchange and digital signatures are the main systems that will need to be replaced or migrated.
Symmetric encryption and hash functions are affected differently. Their treatment is more likely to involve appropriate key lengths, output sizes and algorithm choices than the kind of wholesale replacement required for RSA or elliptic-curve systems.
The Long-Term Confidentiality Problem
The most immediate concern for many organisations is sensitive information that must remain confidential for years. An adversary could collect encrypted data now and retain it until technology capable of decrypting it becomes available later. This is commonly described as “harvest now, decrypt later.”
The longer the information must remain protected, the earlier its owners need to understand where vulnerable cryptography is being used.
Questions Security Leaders Should Ask
A useful discussion starts with practical questions:
- Where are we using RSA, DSA, DH, ECDH, ECDSA or EdDSA?
- Which information must remain confidential for five, ten or twenty years?
- Which suppliers manage cryptographic systems or services on our behalf?
- Which systems will be difficult to update with new algorithms?
- Which certificates, keys, tokens, protocols and libraries are not yet being tracked?
Most organisations will not have every answer immediately, and that is understandable. Discovering and managing cryptography is an ongoing discipline rather than a one-time meeting. At heart, it is an asset-management challenge with significant security implications.
Start with One Cryptographic Inventory
A sensible first step is to build a cryptographic inventory for one manageable group of applications. Record:
- Protocols in use
- Certificates
- Cryptographic algorithms
- Key lengths
- Libraries and dependencies
- The sensitivity of the data
- How long the data must be retained
- The person or team that owns the system
Do not wait for perfect tools or complete organisation-wide visibility before beginning. A limited, well-understood inventory can reveal gaps, clarify ownership and create a repeatable method for the next group of systems.
From Panic to a Managed Programme
Quantum readiness is not a single product purchase. It is a managed transition involving discovery, prioritisation, supplier conversations, testing, funding and the ability to change cryptographic algorithms without redesigning every system around them.
Security leaders do not need to predict the exact arrival date of a cryptographically relevant quantum computer. They need to understand which data and systems have the longest exposure window, then begin reducing that risk in a measured way.
“What is the biggest hurdle for your organisation: limited knowledge, incomplete inventories, supplier dependencies or budget constraints?”Read the original article on LinkedIn ↗
Pass it on
Share this article
Use your phone's share menu for apps such as Instagram, or choose one of the direct options below.