Preparing for Q Day Risk, Governance, and Agility in Quantum Computing

http://Preparing%20for%20Q%20Day%20Risk,%20Governance,%20and%20Agility%20in%20Quantum%20Computing

Today, we’re diving deep into the world of quantum computing and its far-reaching implications for cybersecurity, risk, and digital resilience. Join Frank La Vigne and Candace Gillhoolley as they sit down with Chris Basener, a leading GRC advisor specializing in post-quantum cryptography. Together, they unravel the challenges organizations face in preparing for the inevitable arrival of quantum computers powerful enough to threaten today’s encryption, discuss the realities and misconceptions surrounding post-quantum cryptography, and explore practical strategies for building long-term digital resilience.

We’ll explore the urgent need for cryptographic agility, the complexities of migrating to new standards, and why every organization—from banks to manufacturers—must start planning now, despite the uncertainty around when quantum threats will fully materialize. Plus, Chris Basener shares insights on talent shortages, project management for quantum readiness, and how companies can move from awareness to action. If you’re curious about the intersection of quantum technology, cybersecurity, and strategic risk management, you won’t want to miss this conversation!

Links

Time Stamps

00:00 Quantum computing and cryptography risks

04:04 Understanding Mosca’s Theorem Basics

08:02 Quantum computing in finance

12:10 Concerns about quantum cryptography adoption

15:58 Importance of Strategic Planning

19:30 Challenges of Early Adoption

23:01 Building cyber resilience with agility

26:55 Challenges in Manufacturing Security

28:31 Importance of national security

31:49 Future risks of data security

35:30 Discussing hybrid algorithm security

41:15 Discussing cybersecurity frameworks

43:11 Securing funding through governance

48:47 Creating a post-quantum cryptography course

50:04 Post quantum cryptography course

53:42 Connecting on LinkedIn for courses

Transcript
Speaker:

It's not necessarily rocket science in terms of understanding it at

Speaker:

a practical level, but there certainly are risks involved.

Speaker:

I think perhaps another layer of complexity before we actually

Speaker:

get to the answer is unlike previous IT

Speaker:

issues such as Y2K, no one knows when

Speaker:

there'll be a cryptographically relevant quantum computer. We read

Speaker:

headlines, we know that there are companies that have quantum computers,

Speaker:

but not large enough to break current cryptography

Speaker:

using and running Shor's algorithm. So I think

Speaker:

for all those reasons and perhaps more, there certainly is confusion

Speaker:

in the industry. But to directly answer your question in context,

Speaker:

many experts believe, and I certainly concur from everything I've read, that it's not

Speaker:

really a question of if we're going to have a cryptographically relevant quantum

Speaker:

computer, but it really. It's more of a matter of when.

Speaker:

Welcome to Impact Quantum.

Speaker:

Hello and welcome back to Impact Quantum, the podcast. We explore the emerging

Speaker:

industry and field that is quantum computing. And with me

Speaker:

is the most quantum curious person I know, Candace Gooley. How's it

Speaker:

going, Candice? It's going great, really. Today is going to be fun. We could

Speaker:

barely get out of the green room to start the call. We have so much

Speaker:

to talk about. I'm very excited. Today we're going to be

Speaker:

speaking with Chris Basener and he speaks to

Speaker:

post quantum cryptography and he is called a

Speaker:

GRC advisor. Chris, thank you so much

Speaker:

for joining us today. Thank you so much for having me. It's

Speaker:

such a delight to speak with people who are enthusiastic and curious

Speaker:

and knowledgeable about future. So this is great.

Speaker:

Very cool. I think quantum

Speaker:

security aspect is the one that's going to get the headlines

Speaker:

for the foreseeable future for real reasons

Speaker:

as well as kind of hype and the good old fashioned

Speaker:

fud, right? Fear, uncertainty, doubt. So what

Speaker:

is the real risk, in your opinion about quantum

Speaker:

and having a strategic defense against quantum algorithms?

Speaker:

That's a great question and I'm glad you asked because there's so much out there

Speaker:

and I'm not a FUD fan, quite frankly, I

Speaker:

understand sort of why it's being used or

Speaker:

perhaps in my view, manipulated, but the threats are certainly

Speaker:

real. And the hard part is how do people parse hype

Speaker:

from reality when quantum is not the easiest thing to

Speaker:

understand? Now, it's not necessarily rocket science in terms

Speaker:

of understanding it at a practical level, but there

Speaker:

certainly are risks involved. I think perhaps another layer

Speaker:

of complexity before we actually get to the answer is

Speaker:

unlike previous IT issues such as Y2K,

Speaker:

no one knows when there'll be a cryptographically relevant quantum computer.

Speaker:

We read headlines, we know that there are companies that have quantum

Speaker:

computers, but not large enough to break

Speaker:

current cryptography using and running Shor's algorithm.

Speaker:

So I think for all those reasons and perhaps more, there certainly

Speaker:

is confusion in the industry. But to directly answer your question

Speaker:

in context, many experts believe,

Speaker:

and I certainly concur from everything I've read, that it's not really a question of

Speaker:

if we're going to have a cryptographically relevant quantum computer, but it really, it's

Speaker:

more of a matter of when. And you'll have experts opine it could

Speaker:be:Speaker:

people say never. But given the progress that we've seen recently,

Speaker:

that doesn't really seem to be feasible. So

Speaker:

the risk is that we know that criminals are stealing data now

Speaker:

and waiting for a quantum computer to decrypt it. The harvest now,

Speaker:

decrypt later. Risk is nothing new. Right. It's been around for

Speaker:

over a decade, it's recently gained more headline,

Speaker:

but it's certainly not a new threat. So the risks are

Speaker:

real and I think Mosca's theorem really sums it up. Well,

Speaker:

Dr. Mosca has a theorem that I'm sure you've heard of.

Speaker:

If X plus Y is greater than Z, well then that's problematic.

Speaker:

So what are those variables? X is the

Speaker:

time that data needs to be secure. That's going to vary by industry,

Speaker:

of course it's going to vary by vertical, whether it's healthcare or

Speaker:

insurance or banking or proprietary information for

Speaker:

a company. But X stands for how long do we need to keep our data

Speaker:

secure? Then the Y is how long will it

Speaker:

take our organization to transition to using post quantum

Speaker:

cryptography? And this is not our phones

Speaker:

getting the latest operating device. Transitioning to post quantum

Speaker:

cryptography, as you know, is a huge undertaking for large

Speaker:

organizations. It may take a decade for the Googles and the

Speaker:

Microsofts and the large enterprises of the world.

Speaker:

So if Y is the time that it takes to transition to use post

Speaker:

quantum cryptography, and X +Y is greater than Z, Z

Speaker:

being the time that it will take for there to be a cryptographically relevant quantum

Speaker:

computer, then you can see that we're in trouble. So the

Speaker:

risks are real and I'm glad that you're educating your

Speaker:

listeners to that. I think this past year has

Speaker:

gone from what is quantum computing, what is post quantum cryptography?

Speaker:

To oh, I think we need some of that.

Speaker:

That's a very good summary of the last year and Ironically, like, the

Speaker:

larger the organization, the more nurture they have.

Speaker:

And the irony part is the more likely they need

Speaker:

this type of protection. So I think it's, it's

Speaker:

interesting. I think I'm glad people are starting to take notice because

Speaker:

even if it does take 10 years, you're

Speaker:

better off getting started today. And also too like that is an issue point, like

Speaker:

Y2Q, right. Doesn't have a calendar date.

Speaker:

Y2K did. You could easily figure out

Speaker:

how much time you had. Whereas now, I don't know, maybe it's five years, maybe

Speaker:

it's 50 years. Right. Or maybe it's five months. Right.

Speaker:

We may never know when the actual first

Speaker:

ever cryptographically

Speaker:

relevant quantum computer will actually be fielded. Right. Because I would imagine

Speaker:

that when somebody does it, they're going to keep it under his wraps as long,

Speaker:

as long as they can. Exactly. And I think

Speaker:

that's an important point. I don't think we're going to have the billboards in Times

Speaker:

Square announcing that there's a cryptographically relevant quantum computer. It's

Speaker:

too easy to think if a nation state that

Speaker:

wants to create problems for their adversaries

Speaker:

would destroy them. Right. Or steal money,

Speaker:

steal national secrets. But I think it, that's

Speaker:

too, too easy of a target. I

Speaker:

think the reality will be more nuanced. I think we'll have

Speaker:

multiple Q days. Right. I think we'll,

Speaker:

I mean, it depends on who gets the first cryptographically relevant quantum computer, whether it's

Speaker:

used for good or for nefarious purposes. Right. And I

Speaker:

think if a nation that wants to cause problems,

Speaker:

wants to cause problems, they're going to do that for a while. I mean, think

Speaker:

back to World War II, when Enigma was broken. There was

Speaker:

no announcement. They kept it secret, they kept it under wraps.

Speaker:

They specifically carried out tactics

Speaker:

so that the Germans wouldn't know that it had been cracked. So I think

Speaker:

if we use history as our tutorial, the result

Speaker:

is more nuanced, as you, as you mentioned.

Speaker:

So let's just take a step back for a moment. I'm just curious to find

Speaker:

out what first sparked your interest in cybersecurity and then

Speaker:

quantum technologies. Yes, good question. So

Speaker:

in terms of quantum, having been in the governance, risk and

Speaker:

compliance space and project management space and working with

Speaker:

financial institutions, I took a pause and I looked.

Speaker:

Where are things heading? And I realized in the financial services sector

Speaker:

particularly, and other verticals as well, that the future is

Speaker:

really going to involve artificial intelligence

Speaker:

and also quantum computing. And with that post,

Speaker:

quantum cryptography, which is Not a quantum technology, but

Speaker:

they're certainly interrelated. So I realized I

Speaker:

wanted to be a front runner. I wanted to be an early adopter and I

Speaker:

wanted to help other people. Because anywhere you

Speaker:

look, people are writing that there is a talent gap in

Speaker:

the field of quantum cybersecurity and post quantum cryptography

Speaker:

and it's not getting solved quickly. People

Speaker:

are definitely working to solve it, but

Speaker:

perhaps not quickly enough, although we'll see on that point. So I took a

Speaker:

course from mit, Quantum Computing Strategy and Impact,

Speaker:

and it was a fabulous course. It helped to your point

Speaker:

earlier about cutting through what's the hype, what's the reality?

Speaker:

And it was very easy to understand and yet it was challenging. So

Speaker:

for me, it was a great professional mix. Something that would challenge me, teach

Speaker:

me, train me, and also be understandable and very

Speaker:

practical to implement. So that's what sparked my interest

Speaker:

in post quantum cryptography in terms of

Speaker:

cybersecurity. That's a good question. I've done other things

Speaker:

professionally, but I think perhaps at my core being a dad and a

Speaker:

defender, I just wanted to help defend people. And I really enjoy

Speaker:

reading regulations and drafting best policies in terms of

Speaker:

policies and procedures that will help organizations

Speaker:

and also really providing the right training. And so really that has been a

Speaker:

great niche in terms of the post quantum cryptography area because it's going to take

Speaker:

education for companies to learn. But what you train, the board of directors

Speaker:

is different than what business heads need. So

Speaker:

being able to differentiate that has been. And translate

Speaker:

regulations into practical action has been a great skill

Speaker:

set. That's a very rare skill set too. I mean,

Speaker:

I, I live in the D.C. kind of Baltimore area and

Speaker:

I've had some exposure to the policy crowd and some of

Speaker:

them get it, some of them don't. And a lot of the people who are

Speaker:

in elected

Speaker:

positions don't get it. Like, you know, they, you

Speaker:

know, whatever side of the aisle you're on is just interesting to see kind of

Speaker:

the bubble that they live in. They live in a bubble. D.C. is a bubble.

Speaker:

Right. You know, I think one thing to live

Speaker:

in a bubble and it's one thing to, to live in a bubble and not

Speaker:

realize that you're in a bubble or live in the bubble and expect that the

Speaker:

entire world is in that bubble. And yes, it's not. That's where

Speaker:

most of the problems in the world, well, not all the problems, but a lot

Speaker:

of problems stem from that. I will just. That's what I'll say. Well,

Speaker:

so what's one thing most People misunderstand, basically

Speaker:

misunderstand about post quantum cryptography.

Speaker:

That's a good question. A couple of

Speaker:

things come to mind. It's not a quantum technology, right? We expect that

Speaker:

someday there will be quantum cryptography that actually uses quantum

Speaker:

physics. And when you see post quantum cryptography, it's

Speaker:

natural to think post means it's something we'll use after there's a quantum

Speaker:

computer. But really, post quantum cryptography is

Speaker:

cryptography. Algorithms, keys, et cetera, the methods that we

Speaker:

use to keep our data safe, both from a classical

Speaker:

computer, the computers we're using currently, and also a

Speaker:

cryptographically relevant quantum computer. So

Speaker:

I think that's perhaps one thing, I think the other thing is because

Speaker:

artificial intelligence has gained such hype in the

Speaker:

boardroom amongst

Speaker:

investors that that's been sort of the shiny object. And there's nothing

Speaker:

wrong with using AI when it's done safely

Speaker:

and securely. But it's gathered so much attention that I see

Speaker:

companies that should be adopting post quantum cryptography, they should be

Speaker:

thinking about it. It's not even on their radar.

Speaker:

And I'm concerned that people will think I'm a doom

Speaker:

and gloom guy when I'm really an optimist at heart. But when you look

Speaker:

at the data, the talent shortages, when you look at the data of when will

Speaker:

we likely have a cryptographically relevant quantum computer and you see the

Speaker:

time that it will take to transition, even considering a hybrid transition, right.

Speaker:

Using what we currently have alongside of post quantum cryptography,

Speaker:

companies are going to be in real trouble. And I wish that weren't the case

Speaker:

I mentioned earlier. I don't like the fear, uncertainty and doubt, but the

Speaker:

reality is there is a talent shortage. The reality is it is

Speaker:

coming, whether people like it or not. I can say gravity doesn't exist, but if

Speaker:

I jump, I'm coming. And

Speaker:

it's concerning because with the talent shortage, we

Speaker:

only have so many hours in the day. Right. I think there are companies that

Speaker:

are going to realize they need to do something, perhaps too late,

Speaker:

they're going to want help and the

Speaker:

employees, the consultants that know how to do it are going to be

Speaker:

too busy and are just going to have to say, I'm sorry, I'd love to

Speaker:

help you. If you contacted me three years ago,

Speaker:

we'd be on board. But I just physically can. I need to sleep.

Speaker:

Right, Right.

Speaker:

Interesting. What do you think

Speaker:

we go from here? Like, I mean, what, what, what would be your advice

Speaker:

to not just organizations, but

Speaker:

I think from the individual contributors point of view, right? Like

Speaker:

someone's Getting out of school. Right. And they may have a degree in computer science.

Speaker:

Right. And because, you know, four years ago when they started their education,

Speaker:

that was the, that was the path, the glory and riches.

Speaker:

However, you know, obviously I don't think that the

Speaker:

era of the software developer is over. I think we're in that,

Speaker:

I think we're in a honeymoon phase where AI could do all, AI could do

Speaker:

no wrong. I think there will be kind of a, a snap

Speaker:

back to reality. But the job market looks dismal for comp

Speaker:

sci majors. What would be your advice to someone who

Speaker:

is in that space right now?

Speaker:

That's a good question. Well, I really think learning

Speaker:

some of the technical aspects of quantum computing, learning how to

Speaker:

code and IBM have some fabulous resources that are free

Speaker:

on their website. And if,

Speaker:

I think if one learns that, there's definitely a niche for them

Speaker:

and it may not be the niche that they imagined. But I think you're spot

Speaker:

on in terms of this being a honeymoon phase. I don't think

Speaker:

AI is going to take everyone's job. It's certainly

Speaker:

replacing some people. But it's often said, and although I'm

Speaker:

concerned people might think it's a bit cliche, I think AI isn't coming after

Speaker:

everyone's job, but it's certainly going to take jobs for people that don't learn how

Speaker:

to implement AI into their own workflows or use it.

Speaker:

So AI is like anything else, it's a tool, it can be used to help

Speaker:

people. If it doesn't have the right guardrails, it can cause problems. We all know

Speaker:

that that's not new. But I think to your point, if people can

Speaker:

learn some of these quantum computing technologies and learn how to

Speaker:

implement post quantum cryptography, there's definitely going to be a need.

Speaker:

I'm also an all candor seeing sort of a gap between people like

Speaker:

me who want to be early adopters and help people get started.

Speaker:

Sometimes companies are hesitant to actually get started.

Speaker:

Right. And with all the hype and the misinformation

Speaker:

out there, some people are thinking, oh, we need to, we need to do an

Speaker:

inventory first. Well, yes, you have to have a cryptographic inventory. You can't

Speaker:

migrate what you don't know. But if you don't have the right people in place,

Speaker:

if you don't have the right governance in place, if you don't have the right

Speaker:

policies and procedures to drive your corporate objectives,

Speaker:

what's your inventory going to do? Right. What if you don't have the right people

Speaker:

that know what to do? And what if your inventory is incomplete? We found in

Speaker:

large organizations, sometimes it takes some years to uncover all the

Speaker:

cryptography because it's in everything. It's in software, it's in hardware, it's in

Speaker:

libraries, it's everywhere.

Speaker:

So I think taking a step back from the

Speaker:

hype and not panicking to your question earlier about what do people do,

Speaker:

but thinking strategically, how do I incorporate this into what I

Speaker:

do, into something that I love doing to really help

Speaker:

organizations, people, companies move forward in a way that's

Speaker:

secure? There are some great possibilities out there. It

Speaker:

might not happen as quickly as one hopes, thinks or dreams, but

Speaker:

the opportunities are definitely going to be there. If you read data for projections

Speaker:

from market share, it's definitely going to be there. And

Speaker:

then the early adopters have a strategic advantage. Right. And I think in New

Speaker:

York at least, I'm seeing the large banks assemble teams. JP

Speaker:

Morgan Chase has been very vocal about having a team to help with this.

Speaker:

And there are other banks as well. It's not a, that's not a paid advertisement.

Speaker:

It's just an observation. But I think, but some banks have been. I think you're

Speaker:

right. Some banks have been more aggressive about it than others. That's a fair blanket

Speaker:

statement. Absolutely. But then the problem comes in. If you have smaller

Speaker:

banks that don't have the bandwidth or the budget or the

Speaker:

knowledge to know what to do, what happens then? When they're

Speaker:

communicating with larger banks, the chain is only as strong as the weakest link. So

Speaker:

I mean, that's something that the bank for International Settlements is working on.

Speaker:

So there's some bright minds working on the issue.

Speaker:

That's an interesting point too. Right. Because I think one of the things said there,

Speaker:

I think governance is really kind of key here, right? I mean, arguably

Speaker:

and I, in a perfect world, in an ivory tower, speaking of

Speaker:

bubbles, every organization

Speaker:

over a certain size, particularly in regulated industries, industries, already

Speaker:

ought to have an inventory of their crypto graphic systems,

Speaker:

right? They really should have that already anyway, whether or not

Speaker:

Quantum is in the picture on the horizon over the. They should have that

Speaker:

anyway, right? Because that's just good governance. But you're right, good governance

Speaker:

is rare. Rarer than it should be.

Speaker:

Correct. And to your point earlier, there have been some great industry

Speaker:

leaders that have said, take these no regret moves. Right? Make sure

Speaker:

your cryptographic inventory is up to date. It may not be up to date. Okay.

Speaker:

It may not be perfect. None of us are perfect, none of our organizations are

Speaker:

perfect. But make sure it's up to date. And then I

Speaker:

think the other trouble is that some marketers are promising or

Speaker:

over promising, right? They're selling snake oil. You know, our tool will catch all

Speaker:

your cryptography. Well, anyone who's been in the field

Speaker:

long enough knows that there's no one tool that's going to grab all your

Speaker:

cryptography, right? You need, you're going to need

Speaker:

a set of tools, right? You're going to need a toolbox, not just one tool

Speaker:

to grab all of that. So it's good to have these

Speaker:

deeper conversations because online you'll see splashes

Speaker:

do this or that, as if it's a one size fits all

Speaker:

or a silver bullet. So it's good to have these

Speaker:

conversations. So how do you balance

Speaker:

innovation and risk when advising

Speaker:

organizations on quantum readiness?

Speaker:

Good question. Well,

Speaker:

we know from history that the early adopters can gain a strategic

Speaker:

advantage, right? And I think it's about having

Speaker:

the right people in the right room and having those

Speaker:

conversations because different organizations will have

Speaker:

different risk appetites, right? So what is their organization's

Speaker:

risk appetite for innovation? And some people

Speaker:

prefer not to be on the front, front line, right? They don't want to be

Speaker:

the ones catching the risk bullets. They want to be, you know, second or third

Speaker:

in line, which may be appropriate for the organization. So you're right,

Speaker:

there's definitely a risk because some of the early

Speaker:

adopters for post quantum cryptography, they've

Speaker:

learned some hard lessons, but I give them kudos for being brave

Speaker:

to be at the forefront. For example, some

Speaker:

organizations are finding that when they implement post

Speaker:

quantum cryptographic algorithms, the performance is slower than

Speaker:

they anticipated. It's one thing to grab a paper and pen, although people don't calculate

Speaker:

that way anymore, but essentially do the math, right? When we

Speaker:

implement these algorithms, it's going to impact the latency in our system by

Speaker:

X factor. But then they're finding when they actually

Speaker:

implement it, it takes longer.

Speaker:

What skills do you think aspiring quantum engineers

Speaker:

should develop? First?

Speaker:

Good question. My expertise is really in the governance, risk and compliance,

Speaker:

not engineering. But there definitely is a need for the

Speaker:

engineers. Learning how to code in quick sit

Speaker:

or learning how to implement these algorithms

Speaker:

is definitely important. And although

Speaker:

it's slightly tangential to your question, I think that really brings up another

Speaker:

point that enterprises are going to need a great

Speaker:

team, right? They're going to need a project manager that knows how

Speaker:

to lead a group and ask the right questions and get the right people in

Speaker:

the room. They're going to need the engineers that can actually

Speaker:

do the implementation and coding. They're going to need business leaders that

Speaker:

understand what they're doing. It's really going to take a quantum village to raise this

Speaker:

post quantum cryptography baby. But there are some

Speaker:

great resources out there in terms of learning, and

Speaker:

there's no shortage of companies that are trying to also add into that

Speaker:

space. Okay, how real

Speaker:

is Harvest Now, Decrypt later, and who

Speaker:

should be the most worried?

Speaker:

Good question. Well, it really boils down to risk

Speaker:

analysis, right? How long does a company need to keep their data safe

Speaker:

if. If they don't have data that needs to be secure? Once

Speaker:

a cryptographically relevant quantum computer arrives, then

Speaker:

as they say in Brooklyn, forget about it, right? I

Speaker:

don't think that's applicable to too many companies. But the point is

Speaker:

it's really a risk analysis. So it

Speaker:

Harvest Now, Decrypt later is gaining headlines, as we spoke of earlier. But it's not

Speaker:

a new concept, right? It's been. The concept has been around

Speaker:

for at least a decade. Well, we

Speaker:

all know that years ago that Internet traffic was routed

Speaker:

out of the US into foreign countries, right?

Speaker:

Publicly, I'm not sure that we've gotten a hard answer on what happened, but I

Speaker:

think it's reasonable to presume that data

Speaker:

was harvested there and they're waiting to decrypt it with a cryptographically

Speaker:

relevant quantum computer. So the threat is real.

Speaker:

It's happening now. And we know through ransomware

Speaker:

that people's data is being stolen, companies

Speaker:

are having breaches. So the real issue is not

Speaker:

what are we doing about it. The issue is how are we going to be

Speaker:

resilient, right? I mean, years and years ago the idea was what do we do

Speaker:

if we're breached? And that's so outdated that if companies aren't

Speaker:

thinking, what is our response plan when we are breached, right?

Speaker:

If they're not building that cyber resilience in, they're going to be toast. Right? The

Speaker:

same is true with quantum cryptography. The issue is not, okay, what is

Speaker:

FIPS 203, the and 204 and 205, the post quantum

Speaker:

cryptography algorithms? How do we get them into our system? Well, that's great

Speaker:

getting them into your system, but the real idea, the real strength is

Speaker:

going to come in cryptographic agility, the ability to swap out

Speaker:

algorithms. Because when we look at the NIST standards, we're

Speaker:

confident in them now based on what we know. But we also don't

Speaker:

know when there'll be a cryptographically relevant quantum computer. We don't

Speaker:

know if someone has developed an algorithm that will be able to reverse

Speaker:

engineer and breach those

Speaker:

cryptographic algorithms. So the idea is that we

Speaker:

can swap algorithms quickly without stopping, without the rip and

Speaker:

replace, without tearing out all of our equipment and putting in new equipment. The idea

Speaker:

is to be able to swap algorithms quickly without a lot of

Speaker:

downtime, et cetera, which is no easy task. But

Speaker:

to the point about cyber resilience, cryptographic resilience is also

Speaker:

an important topic because breaches are going to happen.

Speaker:

And that sort of fades into a question you had earlier.

Speaker:

What are some misconceptions post? Quantum cryptography isn't going to mean people

Speaker:

can't be hacked. It's not going to mean that people can't be

Speaker:

breached. It's not a silver bullet. It won't protect them from everything.

Speaker:

It's a layer of protection. But segmented works and good

Speaker:

cybersecurity practices are also still going to be important.

Speaker:

So there's a lot at stake here, but glad you're

Speaker:

educating viewers and asking good questions. That's how we, that's how we

Speaker:

progress. Right. That's how we learn. And it helps us learn, too. I mean, honestly,

Speaker:

I think we get more out of this than,

Speaker:

than you would think. I mean, I certainly,

Speaker:

it certainly does help you stop and think. Okay. I think you're, I

Speaker:

think, kind of taking a step back. You're right. This is not just a technical

Speaker:

problem, this is a process problem. Right. I'll use the G word

Speaker:

again. Right. It's a governance problem too. Right. And these are all things that,

Speaker:

honestly, having worked in data and data database systems

Speaker:

that they're supposed to have governance on, even then the governance is

Speaker:

perfect and it doesn't have to be perfect. I just think that

Speaker:

you have to embrace the imperfection and work around it. Right. And

Speaker:

be resilient to the imperfection. Right. Because there's no. I've never

Speaker:

seen a perfect governance system. Right. I've worked in.

Speaker:

You can look me up on LinkedIn, you can figure out where I worked. Right.

Speaker:

There are companies that I've noticed that have had their data act

Speaker:

together better than others. But whenever I,

Speaker:

you know, think about it, it's like, well, you know, there's things they could have

Speaker:

done better too, right? Like, it's, it's just, it's an ongoing process.

Speaker:

It's not a one and done. It's not a. It's more like infinity and

Speaker:

done. Right. Because you're never really done well. And this

Speaker:

isn't mainly an as I'm listening and I'm thinking about it, this isn't

Speaker:

mainly an enterprise issue. I'M sure the

Speaker:

mid sized companies are also going to be at risk. Absolutely.

Speaker:

Okay. And when you think about what industries,

Speaker:

you know, have the smallest margin for delay,

Speaker:

you know, what do you think? For example, what industries have the smallest

Speaker:

margin for delay for their strategic readiness?

Speaker:

Good question. Well, if you think about manufacturing, right, you think about

Speaker:

what would happen to their business with downtime,

Speaker:

could be catastrophic. You think of large companies

Speaker:

and also those environments are really, really tough too because in

Speaker:

manufacturing you have all these IoT devices, they don't have

Speaker:

a lot of memory, so protecting them is not the easiest thing in the world,

Speaker:

but it carries real risk. So I've had

Speaker:

conversations with folks in those space and it's not an

Speaker:

easy solution because think about it, downtime at a large manufacturing

Speaker:

facility, that could be an expensive event, right?

Speaker:

There are solutions for that. There are mitigating controls

Speaker:

and there are efforts to

Speaker:

make post quantum cryptography algorithms such that they work

Speaker:

with those IoT devices that have smaller bandwidth, smaller

Speaker:

memory, etc. But also think about

Speaker:

banking, what would happen to. That's what I was initially thinking, you know,

Speaker:

banking and healthcare. And then you came out with manufacturing and it just kind

Speaker:

of blew my mind for a moment because I'm like, wait a minute, that might

Speaker:

be more important. It's staggering.

Speaker:

It's all important. But yeah, I know what you mean. And plus, you know, the

Speaker:

old joke is, you know The S in IoT stands for security, right?

Speaker:

Because those things are never really built, have never really been.

Speaker:

I'm sure I'll get a comment on this. But security

Speaker:

is not really a top priority historically in the IoT space.

Speaker:

That's a really good point. And I think

Speaker:

to add to that too, we think about financial impact in business because

Speaker:

we all have to work, right? We all want to eat, we all have bills

Speaker:

to pay. But it's also important, I think, to think about

Speaker:

national security. I was having this conversation with a colleague recently

Speaker:

through InfraGard and he said, this

Speaker:

really is existential, isn't it? And I said, I'm not an alarmist. I don't

Speaker:

want to sound like one, but you're absolutely right. Because when we think about national

Speaker:

security, I mean, why have many governments said

Speaker:

this is a firm priority? Because it's a national security

Speaker:

issue, right? So again, the goal isn't

Speaker:

panic. I don't want anyone to panic. You know, nothing's likely going to happen

Speaker:

today or tomorrow. And as we know, acting out of panic

Speaker:

doesn't often lead to good results. But if companies

Speaker:

take where they're at and they get the right people in place and they

Speaker:

plan, they will make progress. And to your point, that was well said,

Speaker:

Frank. None of this is going to be perfect, right? But

Speaker:

by taking steps in the right direction, by educating,

Speaker:

by putting the right governance in place, by beginning

Speaker:

to update their inventory, planning a migration, test

Speaker:

piloting that, building resilience, they're going to make progress.

Speaker:

Right? So progress, not

Speaker:

panic. I like that. That's a good way to put

Speaker:

it. That's a. There's a title episode right there.

Speaker:

Go ahead. No, it's true. I. We hear. I'm like, oh, that's a good cold

Speaker:

open. I'm like, there's the title. So

Speaker:

what does Quantum risk look like from a board level

Speaker:

perspective? Good question. So from a

Speaker:

board, there are several risks, right? There's the risk of doing

Speaker:

nothing. As we mentioned several times,

Speaker:

early adopters often gain a strategic advantage. I think One reason

Speaker:

that JPMorgan Chase has been so vocal is when

Speaker:

the average user starts to think,

Speaker:

oh, I, I see the risk now. And it doesn't even have to be real

Speaker:

risk, right? It could be perceived risk. In our TikTok Instagram age,

Speaker:

you know, someone puts out a video that goes viral and even if

Speaker:

it's not 100% accurate, people are going to start to think, huh,

Speaker:

is my data secure? Are my finances secure? They're going to start to make decisions

Speaker:

based on what they see in marketing.

Speaker:

So the risk is doing nothing. The risk is

Speaker:

strategic. And I think down the road we're

Speaker:

also going to see litigation for that. I mean, in the US

Speaker:

there's, and it obviously depends on jurisdiction. This is to

Speaker:

educate, not giving anyone legal advice. But we

Speaker:

see how boards of directors now are being held accountable for decisions.

Speaker:

And I think at some point there's going to be litigation that

Speaker:

will say, okay, the risk of quantum computing was

Speaker:

known enough that board ABC Inc.

Speaker:

Should have known better and should have done something right. Doesn't necessarily mean that

Speaker:

they did everything. But I think we're getting to a point now

Speaker:

where the risks are well known and well communicated

Speaker:

enough that board of directors that knows that and just puts their

Speaker:

head in this proverbial sand. I think there's going to be a

Speaker:

liability issue there down the road. But again,

Speaker:

some countries, some companies, some cultures are better at looking forward than now.

Speaker:

I think in some ways we've become such a

Speaker:

culture that's so wrapped up in the moment that I think

Speaker:

some people are having a hard time seeing this is something that,

Speaker:

yes, the worst risk is probably down the road, but with harvest now,

Speaker:

decrypt later, the risk is now, your data can be stolen now,

Speaker:

but you have to think ahead far enough to plan for that and to

Speaker:

mitigate against that. It's not just about getting my

Speaker:

paycheck on Friday. It's about what you want the legacy of your enterprise to

Speaker:

be. Because to the point earlier, I really think that there

Speaker:

are going to be some organizations that

Speaker:

don't do anything and they're going to be wiped out. But the early

Speaker:

adopters, the people that really adopted and

Speaker:

developed quantum computing technology and implemented the post quantum

Speaker:

cryptography, they're gonna, they're gonna be the ones growing.

Speaker:

So it's not easily solved, but it's also not

Speaker:

neurosurgery. Right. So

Speaker:

it's not the easiest thing, but not the hardest thing also too, I think, you

Speaker:

know, I think that insurance

Speaker:

companies are going to have a large impact on this. Right. And not just criminal

Speaker:

life. I'm not a lawyer, I'm not a, you know, but, but you know, I've

Speaker:

seen, I, I've seen what

Speaker:

happens post a breach and then pre. A breach. Right.

Speaker:

And I, I can't imagine all of that is

Speaker:

organically driven. I get the sense that a lot of that is driven by insurance.

Speaker:

Right. So I suspect that that's going to play a role too. Right.

Speaker:

Like they're going to say, like, hey, if you don't, you're in this, this is

Speaker:

your risk assessment. And if we want us to continue to insure you, you have

Speaker:

to execute policies A, B and C, right? Absolutely. I

Speaker:

can easily see that being a thing. I think you're, you're spot on.

Speaker:

I, I haven't read anything about it. And that's not to say that it hasn't

Speaker:

been written about, but I have had those conversations with people

Speaker:

and I think that's definitely foreseeable.

Speaker:

I think you're spot on. I think there will be a point where they say,

Speaker:

look, you're not insured against this. We're not going to pay out

Speaker:

for something you could have done, knew that you should

Speaker:

have done, etc.

Speaker:

Interesting. Are there some kind of like

Speaker:

hybrid cryptographic models

Speaker:

that companies could start to look at

Speaker:

to be more technically prepared?

Speaker:

Absolutely. I think at least in this country,

Speaker:

in the U.S. by this country, I mean us. But there are regulations

Speaker:

around the world that differ and there's advice that differs. But

Speaker:

absolutely. I think the current recommendation is to take a hybrid approach.

Speaker:

Right. And take post quantum

Speaker:

cryptography and blend it in with what's currently used.

Speaker:

Because the thinking is if we use a hybrid and a

Speaker:

logic in the architecture, and this is important, Then

Speaker:

if one of those systems is broken, the other one is still there.

Speaker:

So using sort of a dual encryption system

Speaker:

of wrapping one around the other. And again, I'm trying

Speaker:

to keep it simple enough for everyone to understand, not too complicated.

Speaker:

And that's also the struggle sometimes in communicating this. You want to make it

Speaker:

understandable, but you don't want to water down the content. But

Speaker:

so yes to your question, a hybrid approach is important. But here's the problem, though.

Speaker:

If a hybrid or architecture is used, if a hacker

Speaker:

or cyber criminal gets into the system, they can. It would be

Speaker:

possible for them, I think, to manipulate such that

Speaker:

the weaker algorithm is used if it's hybrid

Speaker:

or if it's one or the other. But if it's a hybrid and

Speaker:

if both are used, if one is broken, the thinking is, okay, well, if one

Speaker:

is broken, then the other one should hold. But again,

Speaker:

we don't know where. I think there are many organizations, many people doing their best

Speaker:

to solve this problem. I think in retrospect, we're going to look back

Speaker:

and say, oh, we should have done X, Y and Z,

Speaker:

but, you know, it's too easy to play Monday morning quarterback. Right?

Speaker:

But yes, hybrid. Hybrid approach is definitely important. And that's also what makes

Speaker:

this a different project than others. I designed a course

Speaker:

to train project managers how to succeed on post quantum cryptography migrations.

Speaker:

And these migrations are going to take a long time. And the

Speaker:

end goal is not even, okay, we have post quantum cryptography.

Speaker:

It's that we have this agility, this ability to swap algorithms. And

Speaker:

in the meanwhile, we're going to start with what we have. We're going to add

Speaker:

post quantum cryptography in the mix. And in the end, we'll probably

Speaker:

have only post quantum cryptography. And at some point down the road, we'll have quantum

Speaker:

cryptography. So it's really different from a project management

Speaker:

standpoint than most IT projects. Right? This is not going

Speaker:

from Windows 10 to 11 or A1 and done.

Speaker:

You know, like you said, it's infinity and done, infinity and never done. I like

Speaker:

that. That's very quotable, by the way. Oh, thank you.

Speaker:

So there are some nuances to this, that when we look at

Speaker:

lessons learned from projects that have been worked on already, we can

Speaker:

learn from other people's mistakes. And that's the beauty of being human and

Speaker:

being wise. Right? We can learn from other people's mistakes. We don't have to make

Speaker:

them all ourselves. We can make Our own, but we can learn from other

Speaker:

people's. So is

Speaker:

quantum preparedness the next Y2K

Speaker:

level coordination problem, but

Speaker:

slower and more complex to kind of

Speaker:

understand and deal with? That's definitely

Speaker:

correct. I definitely think it's slower and, and more complex for

Speaker:

reasons that we talked about earlier. But you know, people are definitely

Speaker:

thinking about this from a vendor perspective. Right. Because another lesson learned,

Speaker:

and by lessons learned, I mean projects that I've been involved with, things that I've

Speaker:

read. One issue, one bottleneck is

Speaker:

going to be vendor readiness, right? There's. If you look at the enterprise environment

Speaker:

today, even mid size enterprises, there's so many

Speaker:

third party vendors, right? So one of the bottlenecks very well

Speaker:

could be, okay, our enterprise is secure,

Speaker:

but what about the third party vendors? We know from countless stories of

Speaker:

breaches that that's often where it happens. And it's not a fingerprint. H

Speaker:

Vac vendor, I think is what caused Target a lot of

Speaker:

agitation and stress. You're exactly correct.

Speaker:

So I've developed a quantum readiness questionnaire for

Speaker:

vendors. It's not applicable to

Speaker:

every industry in the sense that it's a, you know, a plug and play. But

Speaker:

the idea is I developed a core set of questions for

Speaker:

enterprises to start to think about and build their own

Speaker:

vendor readiness questionnaire. Because there are some things you should ask. Right.

Speaker:

If the vendor doesn't have a migration roadmap to post

Speaker:

quantum cryptography, they're not doing it anytime soon.

Speaker:

Right. If they, if they don't have executives that are on

Speaker:

committees that are working on these standards worldwide,

Speaker:

they may be less educated than someone else. I mean, I

Speaker:

serve on several international organizations that are working on this

Speaker:

issue. I work with the PKI

Speaker:

Consortium, CSA Cloud Security alliance, their

Speaker:

PQC working group. So

Speaker:

I think by having experts that are working on these things, they'll

Speaker:

be ahead. And then there are other practical questions to think about as

Speaker:

well. Okay, if, if your third party is building their

Speaker:

roadmap, are they requiring their suppliers to do it as well? I

Speaker:

mean it comes to fourth party, fifth party risk as well. So I mean

Speaker:

essentially it's good third party management. But Frank, to your point earlier, not all.

Speaker:

There's no perfect governance, there's no perfect third party risk management program.

Speaker:

But it's certainly important because that is going to be

Speaker:

certainly an issue. So can, can a company,

Speaker:

can a company even become.

Speaker:

I just kind of think of a company, can a company become quantum safe if

Speaker:

the vendors aren't. Absolutely. And that's definitely

Speaker:

a risk. That's something that's being looked at now. And the

Speaker:

importance I think here, if we talk about governance and project management

Speaker:

is to make sure when we're working with vendors that it's

Speaker:

in our SLAs, it's in our service level agreements, it's in our

Speaker:

contracts that they are building quantum

Speaker:

preparedness, that they are starting to integrate post quantum

Speaker:

cryptographic algorithms. And that has to be in contracts. Right.

Speaker:

It can't just be, you know, I, I pinky promise

Speaker:

or you know, they told me they were so I believe

Speaker:

them. There has to be some,

Speaker:

some teeth to the words, right? That's exactly something

Speaker:

to back up the thing. So you mentioned standards bodies. I know like

Speaker:

there's ISO, there's Six Sigma. Is there, is there something kind of

Speaker:

in the works about this? Like you know, you

Speaker:

can get some kind of certification saying that you and your supply chain are quantum

Speaker:

safe or quantum ready or I would imagine the

Speaker:

wording around that would be very

Speaker:

challenging. But I mean, is there something like, I mean, I

Speaker:

would imagine something like this is in the works. Yes, you're absolutely

Speaker:

correct. There are different companies that have put out

Speaker:

frameworks, whether it's a maturity model,

Speaker:

you know, the idea of just getting started to more mature. Like if we think

Speaker:

about the NIST cyber security framework

Speaker:

maturity levels, there are organizations that have adapted that

Speaker:

there are definitely frameworks out there. And

Speaker:

I think a lesson learned is there's no necessarily one right

Speaker:

framework, but there's really the best match for your organization. So

Speaker:

to your point, there are frameworks that are, that have been developed, there

Speaker:

are others in the works. The ISO,

Speaker:

I think ISO is going to come up with a standard. Currently

Speaker:

when we look at the ISO standards, there are definitely standards and

Speaker:

guidance when it comes to cryptography, but there's no mandate from ISO

Speaker:

saying, you know, you have to use post quantum cryptography. But the same is true

Speaker:

with hipaa, right? There's no requirement for HIPAA to use post quantum

Speaker:

cryptography. They require cryptography.

Speaker:

And at some point, again I think this is going to get muddled with.

Speaker:

Okay, your standard essentially says use best practices, but you weren't using

Speaker:

post quantum cryptography. Right. You technically

Speaker:

click the compliance box but you miss the bigger security picture. But

Speaker:

I do think that some of these other frameworks,

Speaker:

standards, etc are going to be requiring it in the near future.

Speaker:

So the best organizations are one that can look into the future,

Speaker:

not a crystal ball. But just look at trends, where are things headed

Speaker:

and start to adapt ahead of time. So

Speaker:

more coming, I'm sure. So how do you help

Speaker:

teams move from awareness of quantum risk to a

Speaker:

funded timeline driven

Speaker:

executive execution plan.

Speaker:

The funded perhaps might be the hardest point, but

Speaker:

I love the practical question. So

Speaker:

as you mentioned, going from aware could mean

Speaker:

educating your staff, right? So I think to get

Speaker:

a fully funded program, it's good to, to have a plan in place, right?

Speaker:

Boards don't want to fund something they don't understand. And if they don't

Speaker:

understand how that impacts their enterprise, then they're less likely

Speaker:

to fund it. And to Frank's point earlier about the importance of governance, I think

Speaker:

something many people miss in governance is governance

Speaker:

does, does not exist for the sake of governance, right? We don't have

Speaker:

rules for the sake of rules. We don't have security for the sake of security.

Speaker:

We have security to keep an enterprise safe, to accomplish their

Speaker:

enterprise goals. And one thing I love about working in

Speaker:

the governance risk and compliance space is when you look at

Speaker:

governance within a corporation, if they're creating new

Speaker:

policies and procedures that don't align with their corporate mission, that don't align

Speaker:

with their current governance, then it's time to raise a hand and have a conversation.

Speaker:

Or if they have a new initiative, this isn't really well aligned. The issue is

Speaker:

alignment. So I think if a board of directors

Speaker:

understands the risk at a level that they understand, that is

Speaker:

you're in banking. If you don't do this, we're not going to be around.

Speaker:

And they see the flip side, hey, if we're early adopters and

Speaker:

this is communicated through our marketing team, we're going to gain market share through

Speaker:

this. So let's invest. We're not

Speaker:

throwing money for the sake of throwing money. We're investing. And then also

Speaker:

thinking about, okay, what are the line items that we can take out once we've

Speaker:

implemented post quantum cryptography, once we've migrated

Speaker:

and secured our system in that respect, are there other things we can cut out?

Speaker:

Just having an adult conversation about, okay, we need to do

Speaker:

this, it's being, it's going to be mandated in

Speaker:

some verticals. How do we do it in such a way that it

Speaker:

helps us achieve our goals through security, strategic

Speaker:

advantage, et cetera. And then I think they're more likely to say yes.

Speaker:

That's a good way to put it. I

Speaker:

think so. I'm just, my mind

Speaker:

is like blown. I'm loving it. There's a lot, there's a lot to unpack

Speaker:

here, right? It's not just a simple, I mean, not to go back to

Speaker:

Y2K, but with Y2K, that that was simple either.

Speaker:

But you knew what the problem was.

Speaker:

You knew when it was going to be a problem. Right.

Speaker:

There were definitely things

Speaker:

here that are not quite so clear cut.

Speaker:

Right. Obviously we don't know when this is going to be a

Speaker:

thing. Also, to your point, there's

Speaker:

multiple ways to solve this. With Y2K, it

Speaker:

was do some kind of adjust how you stored the

Speaker:

year and do windowing and things like that and

Speaker:

migrate off the old COBOL systems. Right. But

Speaker:

this is not quite so simple.

Speaker:

Right. There's a lot more nuance. Right. There's

Speaker:

arguably more moving parts,

Speaker:

but Chris is offering real tools. Absolutely. I think

Speaker:

that's the value here. Right. I think panic is the wrong

Speaker:

answer. You know, sensible preparedness seems like the right answer. And

Speaker:

that's the tools that you're offering. Is that a good elevator pitch?

Speaker:

Absolutely. Well said. I really wanted just

Speaker:

you to talk for a moment even more about the project management

Speaker:

course that you created. It just really, I found that to be

Speaker:

incredibly interesting because it was kind of like attacking the problem from a

Speaker:

different angle entirely. Can you tell us a little bit more about

Speaker:

why you created it, what you're hoping it's going to accomplish?

Speaker:

Absolutely, please. Well, I, I love project management,

Speaker:

right. Because we can all think back and look at projects that on paper

Speaker:

shouldn't have succeeded, but the right project manager was involved, so it

Speaker:

crossed the finish line. And I just,

Speaker:

I enjoy working with people, I love coaching, I enjoy encouraging people and

Speaker:

I enjoying taking actionable steps with a plan that can

Speaker:

help achieve those goals. Right. Because a hope without a plan is,

Speaker:

you know, just hope, not a goal. So

Speaker:

when I started learning more about post quantum cryptography

Speaker:

and I looked at project management standards, I thought project managers

Speaker:

can be really great at adapting. Right.

Speaker:

And I noticed a gap between what post quantum cryptography migrations are

Speaker:

going to require and what's currently taught in most project

Speaker:

management circles. So I thought, okay,

Speaker:

and everyone has different expertise, right? So I thought, I want

Speaker:

to help close this gap between what's going to be required on

Speaker:

a post quantum cryptography migration. So I thought, okay, they're going to have to

Speaker:

look at risk differently because unlike

Speaker:

longer term projects, the risk is evolving so fast.

Speaker:

With quantum, you know, it seems like almost every day there's a new

Speaker:

headline, you know, Company X made this advancement,

Speaker:

but I think later that's going to go quiet. Right. When things get closer,

Speaker:

if some of these computing technologies are close to

Speaker:

national security, I don't know that we're going to know. I think things might go

Speaker:

Quiet. And so to get

Speaker:

back to the question, I realized there was a gap and I wanted to close

Speaker:

it. So I created a course that's a 12 week course

Speaker:

and it's designed to teach project managers what is post quantum

Speaker:

cryptography, how do we implement it,

Speaker:

how do we use the phased approach and how do we use a hybrid project

Speaker:

management approach? Because when you look at project management, a traditional waterfall approach,

Speaker:

okay, let's plan everything ahead. That's great if you're building a bridge, that's great

Speaker:

if you're building a house. But when you're working with something where the

Speaker:

technology can change and is changing so quickly,

Speaker:

that doesn't really work. And then

Speaker:

combining frameworks from project management and technology together

Speaker:

to think about, okay, we can't just start throwing

Speaker:

code at something as far as developing the right algorithms and keys

Speaker:

to be safe against a cryptographically relevant quantum computer.

Speaker:

We need a phased approach. Okay, we need to design,

Speaker:

then we need to build, then we need to test and we need to implement,

Speaker:

then we need to validate. So taking, taking security and

Speaker:

project management, putting them together and if they were to have a baby,

Speaker:

that's what the goal of this course is. How do project managers in

Speaker:

a secure way lead post quantum cryptography

Speaker:

migration projects? Now, there are other, other professionals

Speaker:

working on the issue. Dr. Greg Skulmoski out of Australia has put together

Speaker:

some great books on project management and post quantum cryptography that I've

Speaker:

read. And he's a great person by the way too. I, I've spoken with him

Speaker:

and so there are other professionals working

Speaker:

on it. But to your point, it's such

Speaker:

a complex issue, it's not okay, I'm going to read this

Speaker:

little article and then I'm going to be ready. So I

Speaker:

developed this course to happen over 12 weeks and I'm

Speaker:

in the first cohort now. And I

Speaker:

think it's really going to help because when we look at other companies

Speaker:

like Santander and we look at literature from the bank

Speaker:

for International Settlements, we can learn lessons of what's

Speaker:

been difficult for other post quantum cryptography migrations. And if we learn

Speaker:

that now, before we start, we're going to be ahead of that

Speaker:

proverbial curve. So it's been really

Speaker:

fun, I've enjoyed it and

Speaker:

I think it's definitely going to help prepare

Speaker:

people. And I, there's been some interest too. Yeah, I

Speaker:

presented in February to the Project

Speaker:

management institute on projectmanagement.com. you know, it was an hour

Speaker:

overview and you can't get anything that depth, in depth in an hour.

Speaker:

But it was a stepping stone. So there is interest in

Speaker:

the topic, which is exciting and it'll be exciting

Speaker:

to, to see wins from this. Right. It'll be great to see companies

Speaker:

that have migrated and when we look at big breaches,

Speaker:

sometimes cryptography is the culprit. Right. So we, we can't

Speaker:

say, oh, post quantum cryptography would have stopped every breach. That's just not

Speaker:

realistic or true. It doesn't even make sense. Right.

Speaker:

So my goal is not to over promise but to be realistic.

Speaker:

But when we do look at breaches, there's one in particular

Speaker:

that I can think of. It turned out the cryptography was so

Speaker:

outdated anyway.

Speaker:

Well, usually with cryptography it's usually key management is always the issue.

Speaker:

Right? That's definitely an issue. And also size, you know,

Speaker:

with a quantum computer, it's not that every piece of cryptography

Speaker:

is going to be ruined. Mostly asymmetric

Speaker:

cryptography is going considered vulnerable by

Speaker:

Shor's algorithm. But Grover's algorithm is considered to

Speaker:

weaken symmetric cryptography, but not totally break it. So some of

Speaker:

that can be managed by increasing, increasing the size.

Speaker:

So it's not a one size fits all approach. And then when we look at

Speaker:

the FIP standards, the Federal Information Processing Standards

Speaker:

for 203, 204 and 205, the Post Quantum

Speaker:

cryptography standards, there are different levels, if you will, of strength

Speaker:

for these keys. And some are most appropriate for national secrets, some are most

Speaker:

appropriate for things that don't need to be as secret. So

Speaker:

there are some nuances here that, that one can glean that

Speaker:

to really make a difference in their organization.

Speaker:

I mean everything you're saying, you're clearly about building

Speaker:

long term digital resilience. Absolutely.

Speaker:

And that to me that's kind of the

Speaker:

summation of like what you're working towards and

Speaker:

what you're trying to get the message out about. I think

Speaker:

that's brilliant. I love it. This has been

Speaker:

fantastic. I think that's a great place to stop. We can go on

Speaker:

for another hour, but we'll be respectful of your time. So where can folks

Speaker:

find out more about you and what you're up to and sign up for

Speaker:

this course? Sure. So I'm happy to have folks reach out to me

Speaker:

on LinkedIn. I created a group that's free to join

Speaker:

specifically for project managers or folks similarly situated to learn about

Speaker:

post quantum cryptography. So if they reach out to me on LinkedIn, I'm

Speaker:

happy to connect and provide more information.

Speaker:

The next cohort will start in April for the course

Speaker:

but if folks connect with me on LinkedIn and

Speaker:

I'm happy to send my email, give them an overview and if it's the right

Speaker:

fit, talk about that. And make sure you tell them

Speaker:

that Frank and Candace sent you. Absolutely.

Speaker:

This has been fantastic. I've really enjoyed this conversation. Thank you.

Speaker:

Me too. I learned quite a bit. Passionate about learning and

Speaker:

interested and curious and knowledgeable. And that's just

Speaker:

a fantastic mix. Awesome. Thank you.

Leave a Reply

Your email address will not be published. Required fields are marked *