Post-quantum security deadlines force leaders to protect existing infrastructure

The post-quantum security transition is emerging as one of the most pressing challenges facing enterprise and government infrastructure, as “harvest now, decrypt later” attacks — in which adversaries steal encrypted data today to unlock once quantum computers mature — move from theory to active concern.

Estimates for when quantum machines become a credible threat have steadily compressed from mid-century toward the end of this decade, and regulators are responding. In June, a U.S. executive order set new federal post-quantum deadlines for the most sensitive systems. Yet the underlying issue is not quantum-specific, according to José R. Rosas-Bustos (pictured), chief executive officer of EigenQ Inc.

“The fact is that this is not a quantum problem. This is a crypto agility problem,” Rosas-Bustos said. “This is a problem that we have been facing as an industry for a long time. If we had already implemented countermeasures for crypto agility in the past, we would not be facing the issues that we’re facing today.”

Rosas-Bustos spoke with Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed post-quantum security readiness, crypto agility and how leaders can protect existing infrastructure investments while preparing for a quantum future. (* Disclosure below.)