Transcript
A (0:02)
You're listening to the Cyberwire Network powered by N2K. This exclusive N2K Pro Subscriber only episode of CISO Perspectives has been unlocked for all Cyberwire listeners through the generous support of Meter building full stack zero trust networks from the ground up. Trusted by security and network leaders everywhere, Meter delivers fast, secure by design and scalable connectivity without the frustration, friction, complexity and cost of managing an endless proliferation of vendors and tools. Meter gives your enterprise a complete networking stack, secure, wired, wireless and cellular in one integrated solution built for performance, resilience and scale. Go to meter.com CISOP today to learn more and book your demo. That's M-E T E R.com CISOP. Quantum computing isn't replacing classical computing anytime soon, with soon being defined as within the next one to three years. That said, given that most strategic planning cycles are three to five years long, it seems foolhardy not to consider quantum computing and its impacts. While everyone argues about timelines, there's one thing that's already when quantum does scale, it will break a lot of what we depend on to keep our organization secure. The problems with quantum aren't going to automatically appear out of the blue. Rather, the countdown for these concerns has already started. Think about how long your sensitive data needs to remain confidential. 5 years? 10? 20? If your data has a long shelf life, it may already be at risk. Data can be stolen today, stored cheaply, and decrypted later once quantum capabilities are strong enough. What is commonly known as harvest now, decrypt later strategy Many nation states and some larger enterprises are already behaving like this is inevitable. So what should the CISO do now to try and get ahead of this seemingly existential threat? Here are some thoughts. Start identifying your quantum vulnerable assets. Which systems use pre quantum encryption algorithms? Where are your encryption keys stored? Who owns the system? Dependencies to include third party dependencies? Focus on crypto agility. Ensure your infrastructure can swap out cryptographic algorithms without major disruption, and consider beginning the migration to post quantum cryptographic algorithms. Further, if you've hard baked today's encryption into your systems, you may have set yourself up for a painful future. Keep abreast of emerging standards. NIST has already selected several post quantum algorithms. Every vendor you rely on should have a migration roadmap, and if they don't, you should be asking why. Build awareness boards don't need to be told the physics. They do, however, need to understand that there's strategic risk and a transition timeline. Quantum computing isn't happening tomorrow, but assuming it's decades away will result in your infrastructure becoming needlessly vulnerable. CISOs are not just operators, they are strategic business leaders. It's time for us to start thinking about Quantum and moving our enterprises toward being able to better mitigate risks associated with this technology. My $0.02. Welcome back to CISO Perspectives. I'm Kim Jones and I'm thrilled that you're here for this season's journey. Throughout this season, we will be exploring some of the most pressing problems facing our industry today and discussing with experts how we can better address them. Today, we are diving into a technology that is poised to greatly impact security efforts. Quantum computing. Michael Satilli is an amazing cyber practitioner whom I've had the privilege of watching grow up within the profession. As CISO of Quantilium and a good friend, I could think of no one better to help me demystify quantum computing for this audience. I sat down with Michael to help separate truth from fiction around quantum computing and help CISOs figure out what they should be focused on now in order to prepare for this next major technological innovation. A quick note that the opinions expressed by Michael in this segment are personal and should not be interpreted as representing the opinions of Quantilium or any organization that Michael has worked for in the past. First things first. Michael, it is great to see you.
![Quantum [CISOP] - CyberWire Daily cover](/_next/image?url=https%3A%2F%2Fmegaphone.imgix.net%2Fpodcasts%2Ff9558cb0-cb06-11f0-bde7-0f479da5a13c%2Fimage%2F4576c79a6260b29daaff0ea0480913c0.png%3Fixlib%3Drails-4.3.1%26max-w%3D3000%26max-h%3D3000%26fit%3Dcrop%26auto%3Dformat%2Ccompress&w=1920&q=75)