Quantum computing could unlock the protective encryption that keeps confidential electronic information secure. However, when it comes to security, CIOs and CSOs already have a lot to think about. That can make knowing how and where to start planning for the era of quantum computing feel like a daunting task. Fortunately, there are strategies IT leaders can take to prioritise quantum-resistant migrations and get in front of the threat.

Tommy Charles, HP Chief Cryptographer and a Distinguished Technologist in the HP Security Lab, discussed a number of these key tactics in the second part of the CIO webcast: Securing your organisation from the quantum threat: How to prepare.

“There will be urgent security priorities competing with this one,” says Charles. “So, what I’d really recommend is taking a risk management approach and integrating with existing systems and processes you have for managing cyber risks.”

One important point is the distinction between the quantum threat to cryptography and a standard zero-day security vulnerability, for example. “It’s not quite the same thing as having a patch that needs to be applied, it needs to be a more involved programme of identifying where [vulnerable] cryptography is being used and instigating a programme of change.”

Steps to stay ahead

Start by looking at the critical data and systems your organisation has and make an assessment as to how urgent the threat is. Asymmetric cryptography is prevalent in most systems and is particularly vulnerable to the quantum threat.

“At HP we did our own prioritisation exercise. And we identified the security foundations in the hardware of our PCs and printers are a priority for migration because these platforms are in the field for a long time.” The very nature of hardware means it can’t be upgraded at a later point – which is why HP started releasing quantum-resistant products now. It also identified the quantum threat as especially problematic for critical industries and large organisations – another driver for HP’s upgrade, says Charles.

Securing hardware and firmware is a crucial first step in creating a foundation for a broader migration. This is the protective foundation for every device. Without it, attackers could install malware at the most privileged layer and compromise the entire device, he says. “By making these devices quantum resistant now, you are creating a quantum-resistant upgrade path throughout their lifetime.”

It’s also a good idea to think about whether your vendor has a good track record for security and can provide the types of features and capabilities required, he adds.

“At HP we look at the threats which are going to matter to our customers, and we act to get ahead and put the protection in place.” Failing to act would have represented an “unacceptable risk” considering the multiple millions of HP devices used by customers.

“It was very important that we got this protection into our hardware, into our products and into the field so they are protected and those organisations that prioritise this protection, can get quantum resistance established.”

Watch the full webcast here. And to find out more about HP’s approach to security, including everything you need to know about endpoint threat landscape click here.

Share
Share