Thank you very much It's not on the screen here But yes, if you have any questions, you can also text it in and if not, you can also do things. So I actually was struggling with what to name this session and I really wanted to make it something that Was impactful something that was going to be interesting to people But really I came up with this that the deadline arrives or arrived before the announcement And it's a post-quantum reality check. So what I'm going to try to give you is is 30 minutes of Little or no jargon. You do not have to be technical to understand this.
I'm not going to Soothe, you know you and say that everything is going to be all fine Oftentimes when I get in front of people and I talk about when quantum Q days is the technical term for it. When is that going to happen when quantum actually has the capacity to decrypt All of our algorithms and encryption So what I'm going to do is is I'm going to tell you with from my perspective what's happening right now And then at the very end, I'm going to give you five questions that you should ask your board of directors So to begin with this is who I am.
I'm Brian Nielsen I am the CEO of quantum core Institute and we are just a risk advisory for quantum post quantum encryption So we help organizations come up with a framework to deal with what will happen once quantum computing actually breaks all encryption So there are three things that you've all heard and all three of them are wrong The first one is is that Q day is going to happen in 2030 as recently as about Maybe six to nine months ago.
That was 2035 It's it's wrong Nobody technically knows when it's going to happen What I try to tell people is the following is is that if you went back five years ago? so we've had AI for essentially three and a half years, but if you went back five years and Asked when was AI actually going to arrive and at the same time as when is quantum going to arrive?
The answer was almost uniformly 2035 it was roughly 12 to 15 years away and everyone was going like this is great I know that this is going to be fantastic By the way, I'm already busy with doing all the cyber security that I could imagine and so I don't have to worry about this December or actually November 2023 what we did we see we saw open AI release this this product called chat GPT and Of course in the subsequent two and a half years.
We've seen change in everything we do I'm telling you this that if you want to take the most conservative approach to when Q day is going to happen base everything on 2035 If you want to try to take a more realistic one, I would start to think about maybe 2030 and if you really want to be kind of aggressive, I would even say as fast as 2028 The second lie that is all always there is the quantum computers will break all encryption It doesn't break all encryption.
It breaks 99% of all encryption And chances are the encryption that you use will be broken But with that, you know, there's a lot of things that are out there that is still available as this points out AES 256 survives with a small adjustment But all the RSA everything else that you've been Using chances are it's broken and if you're a crypto, bro you know, you really need to be panicked because that's gonna happen faster than you can even imagine and The third one is is that we still have a lot of time. NIST has come out and they're still working on it That's only partially true.
They came up with four Post quantum encryption standards that can be used each of them has a slightly different use case So all of them have been released since 2024. So two years ago They have three more that they're giving consideration to and this is just NIST You have then also the EU coming up with some alternative algorithms.
You have the UK you have Japan you have China coming up with all different standards that are going to be used but to say that it's still in process is Well, it's one of the three lies so if you came here, I mean there there's a This expression of Schrodinger's cat and you wanted to know whether it's alive or dead.
Well, you're going to be disappointed Disappointed because what really what we're going to talk about today is your data your vendors and of course your job So the real story is cryptographic obsolescence So as it says up here, the two-sentence version is quantum computers will eventually break the public Cree cryptography Protecting almost everything online the assumption underpinning the math is no longer safe to hold Indefinitely so really what I'm going to try to talk to you about today is this what actually breaks and what doesn't What is harvest now and decrypt later?
And are you even concerned about it? I'm going to talk about the four lies that organizations tell themselves and Then what is a credible plan looks like? And then I'm going to cover the ten most Impactful quantum risks that you'll see out there and then we'll end really quickly With the five questions for your Monday morning board meeting So let's talk about what breaks The things that break immediately are of course RSA Elliptic curve cryptography and the Diffie Hellman. These are these public key systems that are already out there.
They're implemented everywhere Yes, all of those are going to be broken the things that are going to be bruised but not broken, of course is a yes, you know, it's the the Quantum Algorithms that will break it are different. So for for the RSA etc. The RSA EEC That's a Shor's algorithm and then for a yes It's a Grover's algorithm. One of the things that you should be aware of is is don't be Surprised if you're looking at only the hardware part of What's happening with quantum? Quantum is actually going through a major revolution.
And if you start to think about it in terms of iterations Lifecycles and how fast they're going through these improvements you you would be going You know what? Maybe the 2035 is still realistic. What you're missing though is is the improvements on the Algorithms a Grover's algorithm and a Shah's algorithm both of them Have the ability I mean Shor's algorithm both of them have the capacity to improve dramatically and they have Shor's algorithm in 2010 required more than a million qubits to actually break encryption by 2014 that was down to about 600,000 By 2020 it was a hundred thousand qubits.
So it's vastly improving. It's being optimized Dramatically and then most recently it's estimated that it only needs 10,000 qubits Well, we already have machines that have been announced a year ago more than a year ago. So January of 2024, I mean 2025 you're starting to see that we're already at the two and three thousand qubit range So in the past 15 months has there been any improvements I'm sure there has been the question is is when is it going to arrive?
So this idea between harvest now and decrypt later everyone's going like well, you know what all of my systems are secure I know that no one's breaking into my my dad is a basis and nobody's stealing that data But what we are not really tracking really well is is are the databases in whole in mass being Stolen, you know, there's a moment of clarity where you can say to yourself. Well, it's encrypted.
So we're safe the problem is is that the Malicious or rogue agents out there that are trying to actually take advantage of this knowledge They're willing to be patient they're willing to be patient to the extent that they're saying like You're gonna let me have access to your entire database Yeah, sure It's encrypted but there will come a day when that is not then the question is is what did you need to really protect?
So if you haven't already started thinking about post quantum computing as of this moment, you're already late So what we see here again is just a little map harvest now They store until a quantum ready and then they decrypt So the truth there's three timelines that you can actually choose from And you can only choose one of these it It's it's the old argument is is which do you want to be the cheapest the fastest or the best? You can only choose one.
These are the things that you have to choose so you can choose as an example to Start dealing to this when the threat arrives, of course, that is anywhere from 5 to 15 years again Nobody knows but given our advancements in technology.
I say that it's infinitely sooner than what others are saying The second is is that you can deal with it when your data expires Well, depending on what industry and sector that you work in or your clients work in Yeah health care records have to be maintained for 25 years Financial transactions theoretically need to be seven years saved trade secrets Those are decades long. I mean you we can talk about trade secrets things like simple things like the coca-cola recipe I know that has been more than a hundred years.
In fact, you even get now a lot of different companies not Copywriting their IP because they don't want to release it at all So you have these this IP that's out there that you are going to have to try to protect for decades and again This timeline you already know or should it's sitting in your data's Classification policy in terms of how long you actually have to protect this data And the third is is that when your migration finishes you're going to be able to to do it quickly Well, the problem is is that unless you were literally a startup today?
You were gonna have a lot of legacy systems And if those like assist legacy systems take you a period of time to prepare and convert them and migrate them to a post quantum encryption methodology then You're already late because everything that is not covered is going to be exposed So cryptography is literally the only field where a deadline arrives before the announcement because of this harvest now decrypt later So when you step back and think about it you go Well, generally I don't use technology or if you don't fear technology until that after it arrives if you go back just literally a year ago when all of a sudden we started seeing you know agents being Constructed on make and and and and all of a sudden you started to see oh, this is really very clever stuff That's going on and then of course then you had open claw or clawed by when it was originally released Come out and they became orchestrators of Agents and of course they've gotten better and better and then you've come up with alternative Technologies like paperclip that will do essentially the same thing The problem is is that you didn't start thinking about them until it arrived because you didn't know what you could do with it The problem with cryptography is is that the risk is there today?
The risk is not going to go away So it's already arrived that deadline has already arrived And one of the things that I was actually speaking with Matthew here a little bit earlier is like You know, why would you not want to start working on this? You know, why would you not want to start working on this and his answer kind of it wasn't a direct answer to the question But his answer was well, there's already a million fires going on. I don't have unlimited budget I don't have unlimited people. How am I even going to start thinking about this?
So this is the four lies that organizations try to tell each other The first is is we'll deal with it when the vendors are ready Well, if you're gonna wait for then You're gonna find yourself Trying to figure out. Well, should I even be using specific vendors?
And again, one of the things that this particular conference has talked about is is the vendors just in the identity space? That is you know You can't wait for them to get there because if you start to do a migration and you don't have then the Capacity to it to take their product in and provide a secure environment for you for your data Then you're already behind The eight ball so to speak NIST is already working on it. That was one of the three lies that I mentioned to you a little earlier They've already been doing this. It's an IT problem.
I mean that is generally one of the most Recognized and and common excuses as to why you shouldn't Organizations don't want to deal with it. It's an IT problem. I'll get my see-saw to start looking at it The problem is is that this is not an IT problem. This is a governance problem the governance Comes down. Not only it comes down from the board. It comes down from regulators. It comes down from you know compliance So when you start to think about who should be responsible within your organization, it's not just the see-saw It's probably your compliance manager.
It's going to be the audit committee on the board of directors It's going to be the board of directors. It's going to be the entire c-suite. They need to be looking at this today and Of course, we have a roadmap the problem with just having a roadmap Is that oftentimes we create these roadmaps as a checklist for?
Yes, I'm doing this check. I have a plan. Yes. I spoke to my vendors. Yes That's theater. You're not doing anything to actually confirm that that's actually happened So this is the pattern of all four lies you start from a point of denial Because it's a future risk you choose not to do a transition and then you find yourself at that moment of clarity when all of a sudden the regulatory environment or the risk to your organization is Happening right now and the problem with that is is that if you think about it from a budgetary standpoint?
That's when it's the most Expensive to try to solve you don't have the resources. The team's not focused. You don't have a framework You don't know who's responsible and yet everyone's coming and saying it has to be resolved now so What a credible plan actually looks like is the following so there's a three-part governance Pattern that I'm going to share with you today.
I will say that if you ever go to my website There's a free we published our framework our governance framework you can download it for free Don't even have to put in an email address for it But these are three of the important things. The first thing is is you have to create an inventory of what where your exposure is Do you even know do you even know what the encryption? Methodologies that are being deployed in each of those solutions So having an inventory at least allows you to say, you know what I can now create a priority The second is is ownership.
You can't dump this on IT and the see so and and say hey This is really your problem.
No, the ownership has to actually be a named individual someone who's going to be held accountable for it so The idea is is that this is such an impactful risk That not having an individual who's personally responsible for it is is really negligent on your Organizations part if they haven't identified that and of course Then the third one is something that I talk about a lot and that is is evidence You have to have an audit trail for all of this So if your third-party vendors are saying, you know what we're PQC compliant.
We're ready for this Really can you tell me what you've actually done and show me proof? Can I verify those records and and can I see evidence of this change and can you share with me the architectural?
Changes that was required because that's going to impact my business If you're not asking your third-party vendors that question then what you've done is you've gone back to the check box Approach you actually have to have evidence of this and that's done through just simple audits So there are two tests that every organization should run this quarter The first is a crypto agility test So I'm going to kind of define what a crypto agility test is and it sounds kind of easy but it's really hard and that is is what does it take to replace your your encryption a Framework in your product with a post quantum framework That ability to exchange that that is a crypto agility test.
Is it gonna break things? Is it going to go through and create additional problems? What are the repercussions of it? And then the second is is this a vendor accountability test?
And again, this is what I just said a moment ago. What encryption algorithms do you currently have? Are they even telling you are you even asking? What is your PQC migration roadmap and timeline what is your crypto agility plan and what do you require from us to complete that migration and Will you have an officer of your organization? Sign a written statement Acknowledging and attesting to this now there's legal liability.
That's a part of that So again all of these things I Reference it down here is part of the the framework that my organization has published and that's available to you for free So what I'm going to talk about here is this the 10 quantum threat landscape So the first is of course the thing that we always talk about is this harvest now decrypt later That is it's a huge problem as you can see there are various areas where you can start to see where there's Risk involved in it.
The second is of course is the digital certificate collapse You know as we start to see this Everything that we build is based on a trust framework.
And if all of a sudden those digital certificates Fail then we have bigger problems than just having some of our data exposed Of course, there's broken authentication methods one of the things that I Came to this conference and I it's it's wonderful because all the vendors here are saying like we have this beautiful solution for you and They're talking to all of us who are consumers of their products The problem is is that even as good as all those products are our implementations are very poor Generally, it's very very hard to to to create a full trust framework and of course when any part of that breaks it becomes Difficult to actually then say, you know what you're responsible.
You're responsible. It's now all of a sudden just broken Of course, then there's the identity life cycle fragility This is important because now all of a sudden we're going to be dealing with Incompatible key sizes we're going to be talking about vendor migration and consistencies if you're Reliant on multiple vendors. How are they going through the process? How are they coming together? And when is when are those timelines going to actually work so that everything works flawlessly in the future? And of course We're not perfect Integrations are difficult.
So what happens do you have do you do when you have a failed integration?
Of course then you have the Federation trust breakage so you have one vendor who comes up and says, you know, I'm upgrading to PQC compatible signatures and Vendor two is not well this affects of course all of our protocols And it creates them more importantly failure model modes So you have signature algorithm and compatibility you have metadata trust validation failures And of course you have mixed cryptographic environment breakage So our sixth threat is long-lived credentials or the individual in visible identity debt There is so many credentials that are embedded I mean if you're thinking of yourself as as a government and all of a sudden or you're a big telecom You have satellites that have embedded within the hardware all the encryption It's not easy to go up there and swap out a board or Change some firmware that you have in there.
That's going to allow you to actually migrate to a PQC If you're in any of the infrastructure things waterworks, you know, I look at that as probably one of the biggest Social risks. I mean we can live with power going down, but we can't live without water So I look at it and say these are huge huge risks And of course service and API credentials some of these things have decade-long Lives, you know, when was the last time you even upgraded some of those certificates?
So category 7 is machine Identity explosion and when we think about that That's what this conference has been very interesting about so we used to talk about and in my keynote on Tuesday I talked about McKinsey and McKinsey has 25,000 employees human employees and they had no 40,000 human employees and they deployed 25,000 AI agents and of course That is expected in the next 12 months to be a one-to-one So they'll go from 25,000 agents to 40,000 agents, but really the proliferation of agents is is much much higher than that Especially with you know organizations.
I mean, I've read that EY as an example is Encouraging all of their consultants to actually start to create agents.
Well two problems one is is there's no accountability There's no identity and people are letting these things loose On the organization and use all of a sudden are going from a situation where you're thinking Well, it used to be one-to-one one human to one agent now We're ten to one or a hundred to one or a thousand to one the ability for Proliferation is is massive So then there's also the issue of Vendor dependency risk and so it's the question is is what kind of algorithmic support are you going to get? What are you going to do on?
Migration timelines and of course, there's the dependency map that happens when you're trying to coordinate all of these people Threat number nine is is recovery pathways and account to take over risk as we start to go through this migration process That's really the most vulnerable time for each of our organizations Because as we go through that things even even the idea of having hybrid encryption Policies in place or deployments what you're going to end up doing with a hybrid is is that you're going from today's?
Encryption standard to this hybrid standard and then you're going to have to repeat it again when you go to a pure Post-quantum encryption standard, so you're basically doubling your work as you start to go through this and threat category number 10 is governance blindness blindness So what boards here is quantum is far away and I'll patch it later But the reality is the identity structure Has already happened at the changes that are there are at risk and it's going to take literally somewhere between 5 to 15 years for big organizations to actually migrate everything within their organization So that governance Failure is not ignorance.
It's a category error So the idea behind it is is that treating long-term? a lead time infrastructure as a Patchable software is the root cause of what is called quantum unpreparedness So again, here are the questions that boards are sometimes asking wrong. The first one is is when will quantum computers break our encryption? That's the wrong question. The right question is how does PQC transition pressure?
destabilize identity trust and right Identity trust right now even before quantum arrives so that idea of identity infrastructure has long has again a long replacement cycle and the winter to the window to act Deliberately is already of course narrowing or actually expired So here's the five questions I want to leave you with that your board you should be asking your board The very first one is is who's going to be responsible for this?
That's a big question who is going to put their career on the line to be responsible for that organization's risk management of quantum The second is is and again, this was one of the three items that I mentioned at the beginning Creating an inventory coverage. Do you even know what products you use that you either have internally or? Third-party vendors. Do you have that information? Do you know what critical systems they support? Do you know what is their encryption methodology that they currently use?
Do they do you know if there's a question as to when do they have a roadmap or a migration plan in place? The third one is is a parallel thing and that is is on vendor commitments, you know You know really you need to be saying to yourself Which vendors do I really need to rely on because if I have vendors who are unwilling to do a migration? Or in the timeline that is necessary for our organization Then what you're doing is you're saying to yourself. I don't need this vendor This vendor is not going to come with the right Support for the organization again.
So these are the questions who's the named owner? What is our inventory coverage? What are our vendor commitments? And then here's an important thing data shelf life versus migration path again Some data has more value and a longer term life cycle than other data So you have to then once you've created that inventory coverage You need to then say to yourself.
Well, what's the most important and I need to now migrate to the next step And I need to now migrate based on that priority. And of course, then the last one is a board visibility You know, the the question here is is when did the board last receive a quantum readiness update? Chances are never And if the answer is never that's a governance gap Not a technology gap So i'm going to leave you with this.
So the deadline has already started q day is not the deadline Your data shelf life is the deadline your migration timeline is the deadline Your vendor silence is the deadline and the deadline arrived before the announcement again quantum advantage arrives unevenly quantum risk takes asymmetric Risks arrives asymmetrically and readiness is a choice. Thank you