← All writing

Cutting Through the Noise

Quantum has a timeline. Your migration doesn't.

The quantum-and-encryption headlines swing between "years away, relax" and "harvest now, decrypt later, panic." Both are postures. Neither is a plan.

The real risk isn't a code-breaking quantum computer arriving next year. It's simpler and already here: data stolen today can be stored and decrypted later, once the capability exists. Anything with a long confidentiality shelf life is therefore exposed now, not in some future decade. The threat is genuine, and the standards designed to resist it already exist.

Here's where the noise misleads. The hype argues about the date of the threat. The work has nothing to do with that date. The work is knowing where your cryptography actually lives, in which protocols, libraries, certificates, appliances, and third-party products you don't control, and whether you could change any of it without a multi-year excavation. Most organisations can't answer the first half of that, let alone the second.

So post-quantum readiness isn't a product you buy. It's crypto-agility, the plain ability to find and swap the algorithms you depend on, which you either designed for or you didn't. The migration is inventory and plumbing, not a purchase order.

The useful questions have nothing to do with qubits. Where does our cryptography live, and do we have an actual inventory rather than a guess. What do we hold that stays sensitive long enough for harvest-now to matter. How much of it sits inside vendor products we can't modify. If one primitive had to be replaced, how long would that honestly take.

You cannot schedule the arrival of quantum computing, and you don't need to. You can schedule finding out where your crypto lives and whether you could move it. Only one of those is inside your control, and it's the one nobody's selling you.

Related

Written by Mandeep Singh. More at the writing index or get in touch.