12.6 billion dollars. Six times more than a year before, in 2025, the investments in quantum exploded.
So, more than 300 organizations worldwide are now on their way to implement quantum. And we as security experts have to ask ourselves, what does this do to security? What does this do to banking, messaging, identity, critical infrastructure? I think that was never built for this. Hello and welcome to the CISO Perspectives, your channel to find out how CISOs think, decide and lead. I'm Berthold Kerl, CEO of KuppingerCole Analysts, the research company focused on identity and cybersecurity in Europe.
And today we are actually not just remotely sitting in our offices, but we are live here in Berlin at EIC at the European Identity Cloud Conference. And it's actually our first in-person session. And I'm very happy to have you, Connie, here with me to talk about quantum. Thank you for being here and for joining us live and not via Teams.
Well, thank you very much for having me, Berthold. This is an honor to be here in the beautiful surroundings of Berlin.
Connie, to start off, before we actually go into the topics, can you introduce yourself, let people know? I think they're very curious who you are, what you do. Before we start. Yeah. Hello everyone. I'm Connie McIntosh. I'm head of security at Ericsson. I look after all sides really of security and a particular passion of mine happens to be quantum and AI. It's an emerging area, which I'm sure we're going to have a great discussion about today. Yeah. Thank you.
Connie, you recently described quantum readiness as a super urgent imperative. I already mentioned that. And these numbers actually came from a recent study from McKinsey, $12.6 billion investment in quantum. And I think at least from a commercially perspective, quantum has now crossed the tipping point.
Even so, a quantum or crypto-ready quantum computer is not yet existing. But does this investment, this tipping point now shift the story? Do CISOs now have to think of a different timeline? What do you think? Completely. Yeah. This is far more imminent than I think everybody has thought for a time. It was long said that 2030 would be the year that quantum would break.
Well, a crypto-relevant quantum computer would break our current cryptography. Google have come out saying they believe it's about 2028. So if we sit here in 2026 and we look at the timeline of how long it will take us to really move to a complete readiness for that type of breaking of all encryption in terms of our asymmetric encryption, we're already behind the timeline. All right. Okay. So I'm sure that not everyone watching this videocast is familiar with all the details. Perhaps to start off, can you describe how is now decrypt later risk? What does this really mean?
And perhaps then I have a follow-up question. Yeah, completely. So for years and years, nation state actors have already been harvesting our data. So I say we're already past harvest now decrypt later. That's gone. All that data has already been taken. The thing that we want to protect now is our future sovereign digital data. So everything in the future. But why it's still important because the data that's already been taken has a long life. So all of those secrets, all of the authentication, all types of digital signatures that can be forged have already been taken.
And so we're at the risk of now digital trust is at risk. And so this is why we have this super important mandate to move to post-quantum cryptography in terms of protecting ourselves in the future. Yeah. So now we are all already in the middle of the topic. So we have to move, you say. So how does this move look like? I think the migration to post-quantum cryptography is fundamentally different to a patch, for example. So I think cryptography is embedded everywhere in protocol certificates, firmware, hardware, utilities, stored data.
And most companies don't know because they don't have an inventory. Exactly. And this is the biggest problem. So it's not just about your own cryptography and your own assets. You have a lot of dependencies. So we have full supply chain dependencies.
I mean, you listed a whole range of hardware that has embedded cryptography that will need replacing. It can't be uploaded and changed. It's baked in. A lot of OT and IT has baked in encryption and therefore the hardware itself has to be replaced. So the dependencies don't stop there.
I mean, open source software is pretty much pervasive in organizations. It's everywhere. And so we need the whole ecosystem to move. And this is what's part of the complexity is it's not just your own organization that brings the risk. It's also all of your dependencies. And so we need to really look at how do we map and understand those dependencies, software bill of material and a cryptographic bill of material. They're critical. But then you've also got the other dependencies, your hardware, your identities.
All identities now will be targeted because any good hacker knows that the best way to use an identity is to get in because it's authenticated. And so if we then have all of our authentication certificates vulnerable, we then have an identity problem.
So yeah, it's something everyone will have to really work together in the ecosystem to fix. You mentioned it's a tremendous supply chain challenge, I call it. So there are dependencies on chipset providers, software components, customers, and they are all at different levels. What do you think is the weakest or the blindest spot, the weakest point at this point?
Yeah, maturity is a major problem here. So what we'll see is the large organizations really moving quickly into post-quantum cryptography. And then we'll see a quantum divide in terms of the digital divide between those who have moved to quantum cryptography and those who have not. And now the problem with the supply chain is a lot of your dependencies are the small to medium organizations that are in your manufacturing supply chains and software supply chains and other hardware supply chains who will not be there.
So when you talk about what is the resilience and security posture of your organization, it's only as good as your weakest link. So we then have the challenge of the small to medium organizations we are dependent on for our supply chain not being ready, not being there, and therefore delivering not secure quantum-ready hardware software. And so that is where I see regulatory really comes in because Europe is in a unique position where you have a lot of mandates. You've got NIST2, CRA, DORA, all really supporting the quantum uplift.
And I think that's where we really need to ensure that the ecosystem you have, your sovereign ecosystem, really operates under those same principles. So you basically think that is more helpful than it just creating noise or a theater?
Yeah, okay. So regulations in themselves, I think Europe has probably the most amount of regulations across the board. When I'm talking about quantum, I think they're very helpful. I think they do a multitude of things in terms of awareness. I think you can see that Europe takes this seriously through the QCI infrastructure, the quantum infrastructure that's being built both terrestrially and to satellite. And I think that's a really good thing to have for your critical infrastructure because it's then layered defense. You're not just relying on quantum cryptography, which is purely math.
You're actually relying on quantum physics, which is a way to have a layered defense because any interruption of quantum physics, meaning the no-cloning theorem and the Heisenberg principle, you cannot break that because then you're automatically notified. You know something has happened. So I think that Europe is really using and leveraging regulation to build the infrastructure and the awareness to migrate to post-quantum cryptography, which is going to see Europe in a really leading position. And I really like it.
Of course, there is opportunity for it to become theater. And how that happens is by people just ticking a box to get compliance. They're not actually doing all the necessary steps. One thing to mention is that normally regulation is not very fast, so it's quite slow.
Now, when you look at, for example, NIST has finalized the PQC standard in 2024. Now, with all the developing going on, and we just mentioned the tremendous money which is going into that development, isn't quantum too fast for regulation?
Yeah, look, I think the standards are ahead, which is great. We need those standards like NIST and ISO, and we're now seeing the ITU and ETSI really building in the hardware specifications which are required. And I do think that we are far more leading in standards than in regulation. But you in Europe have uniquely already the post-quantum roadmaps, as well as your NIST 2, which is really driving that. But what I also love is the supply chain focus, because it's an ecosystem.
So you can't have one organization safe and the rest of your supply chain not, because as we all know, supply chain is a massive target. It's a soft, you know, sort of the soft point where attackers use. And so I think the standards are moving faster than regulation, and I think that's appropriate. I think that's where you want to be. You want to have the standards and you want to be implementing those. But I think the other thing is when we talk about cryptography, that's maths. It's just hard math. And hard math at some point is going to break again. So crypto is going to break.
Even quantum cryptography, quantum and AI together, let's say, will power smart, you know, sort of technology development where that will break as well. So we need to be crypto agile in terms of replacing crypto frequently, but also in the ability to refresh it quickly if that change happens. So you will not come on a point where you say, we are done and now let's go.
Sadly, but the good thing for us in security is it keeps us in a job. You know, we'll always have work. The hackers don't sleep and they're always looking for opportunities. And cryptography is, you know, it's our digital trust for the entire nations and certainly critical infrastructure is getting very high focus globally around this. So you work at Ericsson, which is part of the telecommunication ecosystem. And I think you have even a unique challenge because you not only have to protect your own company of crypto, etc.,
but you are also an infrastructure provider, critical infrastructure, even for thousands of clients. So how do you deal with that challenge? Yeah.
And look, I think for all critical infrastructure manufacturers, hardware, software, any sort of service delivery, you have a unique position as in you need to harden your own enterprise. And then you have also the regulatory bodies that you have to adhere to both on your own internal side, but then you also have to adhere for the customers. So we are global, much like many large organizations. And so that the standards, standards are fairly standard, sorry, but the regulations vary country to country.
And so we have to make sure that when we build, we build to the highest standard and deliver, and that's going to be which is the hardest regulation. And I think if we use GDPR as one, it's the toughest privacy standard. And so when you build to the toughest, then you'll comply and you'll comply to all. But this is one area I think all companies that supply critical infrastructure or work in critical infrastructure have is that, you know, we have to look at it from a perspective of the customer and not just our own internal enterprise.
So post-quantum is or has been so far a topic for security experts mainly. To what extent has this topic also arrived on board level already? I would say probably very limited anywhere. And I think the challenge for us as security professionals is that we, it's our job to be able to articulate that risk. And let's take it even a step further back is most organizations are yet to do that risk analysis.
So, you know, if you don't start with your bill of materials, your dependencies, your supply chain, you know, you have to be able to quantify the risk to be able to articulate it as an enterprise risk. Because if you say it's a security risk, that's not going to get a lot of traction. But your risks are really our enterprise risk. You're risking, you know, the digital trust of all your data, of all your connectivity, and really you're going to risk your confidentiality, your integrity, your authentication.
And so what you need to be able to do is to map that out, quantify it to say this is the cost if we don't do it. Also, this is the cost if we do do it, because you're going to need budget, right? You're going to need to get money from the board or at least the executive. And so you do have to be able to quantify that. In terms of getting budget, does the fact help that now so many money goes into, so much money goes into that quantum ecosystem so that it may even create board level attention and that may even help you to ask for money to protect you from that danger?
Indeed, it's a support factor, definitely. You need to be able to, you know, have a whole lot of data points to show why this is relevant as well as who's investing, where they're investing.
I think, you know, nation states understand this. So at the government level at nation states, China has been investing in this heavily and has the world's largest QKD network. And certainly, you know, if you look at the US, they have put it in their national security strategy that quantum is a really important focus area. And really, it's going to be where, you know, the next theaters of war are played out because whoever gets the first, you know, quantum relevant crypto computer, whoever can break encryption first is going to be winning the war.
So in order to getting quantum ready, post-quantum ready, it is a leadership challenge. So you have to, we already talked about the communication with the board, you have to take your people with you. The business has a say, technology plays a role. So where to start?
Yeah, absolutely. And I think you hit the nail on the head. It's complex and it's hard. It's a hard, it's not a small program of work and it requires so many layers of stakeholder engagement, you know, from the board to your executive, to every business unit who's involved.
I mean, you've got to bring sourcing on board. You've got to get this into your sourcing contracts so that you're onboarding suppliers who are on the same journey, that you're not, you know, creating weak links in your ecosystem. But then internally, you've got, you know, you've got your government relations. You've got to be able to show government that you are on that journey, on the roadmap, if not very quickly, you know, by 2030 have already migrated. I think it's an ecosystem that's not simple. It's got stakeholders internally and externally.
And I think the biggest challenge is your internal stakeholders, because it's not just a security problem. It is a business problem. It requires, you know, engagement across the board. Yeah. And I think that the difficulty is it doesn't hurt now. It may hurt at some point, but that is always very difficult to articulate, right?
Well, I think how you address that is you articulate in terms of how long it is going to take you to achieve. And if we start today, we're still too late. We're too late. So if you haven't started looking at your cryptographic assets and mapping them, the time it will take to get there, if 2028 is correct in terms of, you know, Google's assessment, then we are really behind schedule. So... So perhaps as a tip to the audience, if someone has not yet started, what should he do tomorrow?
Tomorrow, you are going to start a target team and you're going to get a team together to do all of your cryptographic assessments. Look at where do we have it. Look for shadow IT and OT. I think you have so many dependencies that you're not aware of. I think when people start to look at the crypto bill of materials, it is fairly surprising. Like if you think about the whole ecosystem you operate, where you have, you know, public keys is almost everywhere. And it's going to be a challenge. You must start with the inventory and mapping your dependencies.
Of course, you're not going to do everything at once. You need to know what are the critical things you're going to protect. So start with protecting critical assets, systems, and we need a project yesterday if you haven't started. So please get some funding or a target team and retro, start retroactively looking and the migration must occur. Thank you for your advice. While I have you here, so we normally do at the end of the main questions a so-called quickfire round. So I will ask you some questions and I'm asking for short, tenuous answers. So the first one is hybrid crypto.
So old and new in parallel. Is this smart or is this just buying time? It's necessary. It is absolutely necessary because you don't know the impact that post-quantum cryptography is going to have on your network. You don't know the longer keys, how much, you know, extra load that's going to put. You also don't know if it's going to break something, you know, especially when you're talking across the entire ecosystem. So hybrid is going to be necessary to start in any way. Yeah. Okay. So you mentioned the Google forecast already, but crypto ready quantum computers, what do you think?
When will they be around 2030, 2035 or later? Sooner. I will say 2028 is very realistic. What I will also say is that I think a nation state could already have one. And if they don't, it will happen in the next year. All right. Okay. And we won't know about it because, you know, many defense theorists agree that that is a more dangerous weapon than a nuclear weapon because of the lack of attribution. If they do have one, you won't know about it and the things that you can do and, you know, everybody's not going to tell you if they have one.
So I do think it's far more imminent than 2030 or 2035. Quantum security. What is the most overrated discussion point in that context? Harvest now, decrypt later. If it's gone, it's too late. It's already gone. And I think that's what everyone focuses on. And I think even, you know, the risks that are going to occur once that happened, if, you know, you think about AI, so you think about mythos and what it can do now. And then you think about what can mythos powered or any of the LLMs, because they're all quite capable of doing the same thing.
What is that powered with quantum computing power going to do? And that is where I think we need to be talking, because I think we understand that we need to replace cryptography, but I think we need to understand the threat landscape coming from the power of quantum compute with AI. You already talked about the board. So if you had one minute, what would you want them to understand? I would want them to understand that this basically will expose us to data breaches, which will expose us to potential regulatory fines and shareholder impact.
I think you, if you're on publicly listed, your share price gets impacted because it'll put you in the news. I mean, our worst nightmare, I think, for any security person is having a breach and being in the news. That's what we all want. And so I think if I could have one minute, that would be what I would articulate to understand the risk. Yeah. What advice do you have for someone who wants to start a cybersecurity career today? I would say do it. I love security. I think it's one of the most exciting areas to be in. No two days are the same.
You will never know what's coming in when you wake up. If you don't get something overnight, you will not know what's going to happen that day. So it's exciting. I would say you're in the best position you can be. There are so many programs and support and mentoring available now that I really wish I had, you know, when I started my career. So I would encourage absolutely as an amazing career path. Yeah. Do you have a recommendation what resource or book someone should read today? I would say things move so quickly that often by the time a book is published, it's out of date.
So I would say, you know, stay up to date with podcasts. You know, the internet is your friend. Yeah.
You know, latest news is always the best news. For in terms of your, whether you're, if it's a career, then, you know, you've probably got a lot of stuff going on. But if you're looking for resources, there are many, many on the internet.
I mean, I love the Black Hills Security Podcast. It's my favorite weekly one. All right. Yes. Very good.
Thank you, Connie, for that. So the takeaway of this little interview is Quantum's commercial tipping point is here. And according to you, we are already too late. If you haven't started. If you haven't started to combat the threat.
Well, if you haven't started to, yeah, definitely look at your inventory because that is the first point. Start inventorying your cryptography, understand what needs replacing, map it out. It's going to take, they say a full, full rollout will be five to 10 years. It's quite some time. You'll need patience. A lot of patience.
Connie, thank you again for making the time and having this very interesting discussion on this very hot topic. Thanks to everyone watching this series. We'll be back soon with our next episode of the CISO's Perspective, which is about how CISOs think, how they decide and how they lead. And the next one will also be live from EIC. So please watch out and stay resilient.