Secure communications enabled by cryptography underpin everything digital society relies upon. But the advent of quantum computing poses a very real risk to those defenses – specifically vulnerable asymmetric cryptography.

As such proactive quantum migration is now becoming an urgent priority. According to the most recent study by the Global Risk Institute, the probability of a quantum breakthrough by 2034 is estimated to be between 19%-34%.1 That represents an unacceptably high risk.

Industry, government, standards bodies and academia are already working together to introduce quantum-resistant cryptography to ensure businesses and organisations are ready.

Tommy Charles, HP’s Chief Cryptographer and a Distinguished Technologist in the HP Security Lab, discussed this important topic with CIO in the first of a two-part webcast: Securing your organisation from the quantum threat: What you need to know. Charles likens the potential consequences of a quantum break to cryptography, as enabling attackers to enter through the front door undetected.

“Authorities are really taking this threat seriously and instigating big change in what’s a permitted use of cryptography because they see this as something that has to be acted on,” he says.

“It affects potentially any digital system” and requires “all these different participants in the security and technology community to make changes and adopt protection.”

“At HP we’ve been looking at this problem and identified the foundations of our PCs and printers needed to be upgraded to protect against the quantum threat.”

The CIOs’ strategy for quantum protection

Any organisation that cares about the security of its data or access systems needs to take action now. For CIOs this means considering a number of key areas as part of their strategy for quantum protection.

The first step is to have a plan, says Charles. “You should prepare by understanding what the impact on you may be initially and you should identify if you have any particular priorities,” he says. “You should engage suppliers and vendors if you rely on them for protection and you should act to put protections in place.”

The key is to remember this isn’t something organisations have to tackle alone. “There are guides and help is available. HP has written some blogs on what to do, as have authorities,” he adds. Some priorities may require immediate action, while others could be incorporated into system refreshes, where quantum resistance is provided as a default.

“Because a change over several years is required to get full protection in place, introducing protections at sensible times is a good way of managing that programme and making progress on it as part of [the device] lifecycle.” Whatever risk management approach IT leaders decide to take, the message is clear: “Have a strategy and give it some thought,” says Charles.

For more information on this topic watch the full webcast here. And to find out more on how to prepare watch part-two here.


1 Quantum Threat Timeline Report 2024 – Global Risk Institute


Share
Share