Is Quantum-Resistant Cryptography something we need to implement immediately?
I keep reading about "Store Now, Decrypt Later" attacks where hackers steal encrypted data today, waiting for quantum computers to become powerful enough to break it. Should mid-sized companies be looking at Post-Quantum Cryptography (PQC) standards now, or is this still a problem for the distant future and national governments?
2024-11-05 in Cyber Security by Karen White
| 7248 Views
All answers to this question.
It’s better to be early than late. Start by mapping out where all your encrypted data lives so you know what needs updating first when the time comes.
Answered 2024-11-06 by Patricia Moore
-
Good point, Patricia. Knowing your "Data Inventory" is the first step in any security upgrade. You can't protect (or re-encrypt) what you don't know you have.
Commented 2024-11-07 by Mary Collins
While we aren't quite at "Q-Day" yet, the "Store Now, Decrypt Later" threat is very real for data with a long shelf life, like medical records or trade secrets. If your data needs to remain secret for 10+ years, you should be evaluating PQC today. NIST has already released the first set of standardized algorithms like CRYSTALS-Kyber. You don't necessarily need to overhaul everything tomorrow, but you should start a "Crypto-Agility" audit. This means ensuring your systems are modular enough to swap out old RSA or ECC algorithms for newer, quantum-resistant ones without a total rebuild.
Answered 2024-11-09 by Mary Collins
Are you managing your own internal PKI infrastructure, or are you relying on cloud providers like AWS or Google to handle your encryption standards?
Answered 2024-11-12 by William Davis
-
William, that’s the key question. If Karen is on the cloud, most major providers are already rolling out hybrid post-quantum TLS. This means the cloud handles the heavy lifting. However, for internal legacy systems, the responsibility falls on the IT team. My advice is to prioritize the migration of your external-facing gateways first, as those are the most vulnerable to bulk data harvesting by sophisticated actors preparing for the quantum era.
Commented 2024-11-15 by Christopher Lee
Write a Comment
Your email address will not be published. Required fields are marked (*)

