Searchable transcript of The new post-quantum cryptography executive order. Plus: What is Q-Day, really? — IBM Technology (44:12). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:01 There's a really big tsunami of stuff coming at us as cybersecurity people. If it's not frontier AI models that we've heard an awful lot about, it's also obviously AI in itself and how you actually can implement that—and implement that in a secure and a safe way. Q-Day, that's what they call the day when quantum computing capabilities will finally be able to crack the public key cryptography we rely on to secure everything from websites and email communications to digital signatures, bank accounts and blockchains.
00:35 And it might be coming faster than we think. Last week, US President Donald Trump issued a pair of quantum related executive orders, one of those securing the nation against advanced cryptographic attacks establishes a government wide mandate to accelerate the United States transition to post quantum cryptography. Welcome to Security Intelligence, IBM's weekly cybersecurity podcast.
00:56 I'm your host, Matt Kosinski, and we have a very special episode for you today, all about quantum safety. Later in the show, we'll have Suja Viswesan, VP, Security Products, and Mark Hughes, Global Managing Partner, Cybersecurity Services. Join us to talk about why we should consider Q-Day more of a process than an event, and what that means for quantum strategies.
01:14 But first, we have here Mason Molesky, who leads IBM's cyber policy strategy, which includes post-quantum cryptography. Here with me today, Mason Molesky, who leads IBM's cyber policy strategy, which includes post-quantum cryptography. Mason, thank you for joining me. Let's start with an overview. What exactly is this executive order? What's it all about?
01:40 So on Monday, President Trump signed an executive order on post-quantum cryptography, which is just the latest development in a decade long US government policy effort to address this transition from modern day encryption to new encryption that is not susceptible to attacks from quantum computers. The, this particular executive order represents the US government's transition from recognizing quantum risk to really mandating coordinated actions and efforts, you know, through establishing clear accountability, clear
02:15 timelines and enforcement, to ensure our information and data is protected. To really dive in there. You know, what does that mean? You know, it establishes first, you know, that the Office of Management and Budget, which is where the federal CIO sits, as well as the national cyber director in the White House are going to lead this the strategy representing the level of importance and coordination that's going to occur across the US government, as well as technical guidance to be coming from our National Institute of
02:48 Standards and Technology, our National Security Agency and our Cybersecurity and Infrastructure Security Agency. Second point is it creates clear accountability. It asks for agencies to appoint a lead for post-quantum cryptography migration efforts, so that the White House specifically knows who to, who to go to, who to ask questions, and who to hold accountable for these efforts across the federal government.
03:18 So can you expand on that for us? What is the EO asking organizations to do? I think probably one of the most significant things that this executive order does is it accelerates the timeline of the transition that the US government is going to be undertaking. Yeah, there's a lot of a lot of numbers out there in terms of what year people say we need to be quantum safe by where quantum computers are actually going to pose a risk to regularly breaking encryption.
03:48 And 2035 was kind of an agreed upon date generally with the US government before this new executive order accelerates that up to end of 2030 and then the 2031. And then I think, you know, and lastly, it it helps kind of set the directive of how this matters to, to others. You know, the US government's going to be updating its acquisition regulation so that government or federal contractors are required to comply as well.
04:18 And accelerates some of the processes that enable this activity. So the the crypto validation to be able to sell products, they're looking to streamline and enable this in the marketplace. Thanks for breaking that down for us. So I know that the executive order deals, you know, primarily with the functions of the US federal government, but obviously it's got broader implications, too.
04:36 Right? So the question is who should be paying attention to this executive order and why. Like you said, I you know, first and foremost, it's the federal government and the agencies. But I think that it obviously extends well beyond this, as I mentioned, you know, federal contractors are going to care about this because the acquisition regulations and what they're going to have to comply with.
05:02 But at the same time, the executive order has a has a clear focus on on the two other main stakeholders, which is international partners, meaning they want to ensure that internationally we adopt similar standards, you know, ideally leveraging the NIST standards that we've spent over a decade developing in the United States with global colleagues. And that's really to ensure that we have interoperability, that when we when we talk to someone else overseas, that that information can be understood appropriately.
05:40 And second, it's really the critical infrastructure operators and owners, that's water power, electric, financial. Many, many of these sectors are already thinking and working through this. The IT sector, telecommunications, financial sector are always kind of ahead in this because they they play in this space. But helping ensure that our water plants or our hospital systems have the ability to protect information that may never change, that is sensitive, that we want protected, is done so properly.
06:22 And so the executive order calls for that in both ways. Calls for Department of State and others to work internationally with their partners and allies. And it calls on the, you know, Cybersecurity and Infrastructure Security Agency, as well as the sector risk management agencies like Health and Human Services to work with their respective sectors to help enable and support this this major transition for critical infrastructure.
06:47 Now, I always like to close out segments on the show with the so what right. The immediate kind of concrete takeaways for our listeners. So Mason, what's the so what here. You know, what do we start doing. Where do we go. First, let's start with why this matters at all. What what we're already seeing is bad actors look to gather encrypted data. It's often called, you know, collect now, decrypt later.
07:15 Collect now harvest. Harvest now. Decrypt later. That's a very clear indication that, you know, these adversarial actors understand that they can collect sensitive information that'll have a lifespan whenever a quantum computer is regularly available, and then they can decrypt it then. And that's, that's not just government secrets. It is government secrets, but it you know, that extends to, like I said, health care information that will never change about you, about you.
07:45 It extends to financial information. And so we are seeing that actively as a risk. It's not all information. We don't think everything needs to move. A takeout menu is is going to change. And the life of that is not not something that needs to be protected. But we we do want to ensure that we're taking this risk based approach to protect the information we need.
08:05 For, for a long time, and then, you know, part of why this matters as well is we've we've this is not the first encryption transition we've been through. Encryption goes back to the Roman days. You know, the Caesar cipher, very simple encryption. It was physically where we would take information, they would encrypt it that way. It's it's meaningless information in transit, physically on horseback or in person.
08:34 And they would decrypt it with that trusted party at the end. It works the same way. It's just with our laptops now. But that transitions then, as well as transitions now, over the last 50 years with computers, have taken years and years and years. We still haven't fully completed past encryption transitions. So even if we think a quantum computer will won't be available until 2040, it could easily take that long until something is available and the timelines of when quantum computers that may risk this could become
09:07 available are as soon as this decade possibly, which means we could potentially already be behind or starting to put information at risk. So given these risks, what do you recommend organizations start doing today? The good news is we you know, the US government has been doing this work. The the the world has undertaken a very collaborative effort to create these new post-quantum encryption standards.
09:38 And those standards have are out. And now you know what's happening. Industry has taken those. IBM has helped create those standards. So it may have a jump start, but now we are commercializing those into products and to solutions, that first secure the the products that we sell, because most, most organizations are just going to buy, they're not going to be doing this work themselves.
10:08 So they they want to ensure that they are buying products that are quantum safe. And second, we're developing products and services that help organizations understand what they have, what risk they have, and how they can make this, this, this successful transition. Finally, just to put a fine point on this, you know, we we have a very clear kind of perspective that we talk with, with governments.
10:34 And the US government's not the only one doing this, you know, a dozen or so governments worldwide updated post-quantum cryptography policies last year, another dozen or so created new ones. We're seeing sector guidance already start to come out. So collectively, the world is kind of moving towards ensuring the security. But but our, our, you know, as governments think about this, our guidance to them is clear.
11:04 It's it comes in three phases. It's make sure that we plan, make sure that we act, make sure that we motivate. Planning means we have to as governments as nations work to get roadmaps, get readiness together, integrate PQC into existing national cybersecurity strategies, doing the big, weighty, process heavy things, getting the budget aligned to ensure that we can do this successfully.
11:38 It means ensuring that we prioritize. Like I said before, not all information is the same value, the same sensitivity over the same lifetime. So understanding what you have, how sensitive it is, how valuable it is over time is what matters and prioritizing where you need to do this. This is kind of where the the executive order really steps up. It says we are not just going to to plan and to talk about doing this.
12:06 We actually want tangible action. It calls for pilots, specific like pilots. That's next year. Quick, quick action to have lessons learned to actually migrate. You know, the EO sets forward clear migration deadlines, 20, 30, 20, 31. And from those things, it's it's clear to say, like we need to replicate and grow those examples. So that's part of what the support to critical infrastructure will be.
12:38 Is a power plant pretty, pretty important? The data may be less sensitive, so it may happen slightly later, but it'll it'll have lessons learned from across the government sector. And finally it's it's really about motivating, not just us, US government, federal agencies to act. It's about ensuring that all organizations, critical infrastructure, all their private organizations worldwide are educated enough to to know what they should be thinking about, what they need to know, what they don't need to know, and what to
13:12 do, how to take action, what tools and resources are out there and available. Thank you, Mason, for hopping on with us today. Switching gears now, here is a prerecorded conversation with Suja and Mark Hughes. Hence the change in wardrobe and location that our video viewers will pick up on. I want to dive right in up top and just ask if you can outline for our listeners, what exactly are the concerns when it comes to quantum computing and security?
13:43 What is the risk of Q-Day? Mark, you want to start us off? The main issue is you teed up up front is that the quantum computing capability that we're going to have is going to essentially be able to run an algorithm, which we've known about for some years, called Shor's Algorithm, which essentially unravels for the better description, the PKI encryption algorithm.
14:03 And what that means is that, therefore, a lot of the stuff that we rely on today in terms of encryption is going to become vulnerable, and therefore we have to do something about it. So the so-called Q-Day, which is a bit misleading because it's not a day, it's actually going to be a process. But the point is that the quantum computing capability that's now emerging is going to essentially undermine the encryption, a lot of the encryption, asymmetric encryption that we rely upon today.
14:29 Absolutely. And I'm glad you gesture towards the fact that Q-Day is kind of maybe more of a process than just the day, because I do want to dig into that with you folks. Both. You wrote a great article about this. But before we do, Suja, I just wanted to, you know, ask for your kind of top line overview. Anything to add to to to what Mark said up there for us about the risks of quantum, to cybersecurity.
14:47 I mean, just like everything else, right? Today, the AI wave. Because of that, the identities are exploding, and then we need to be ahead of it. And when you are taking care of it, you might as well take care of the post-quantum thing as well. As Mark pointed out, it is not a point in time like Y2K. After that, after everything gets better, it comes in waves, not in shocks.
15:12 So we have to be prepared for that. That is why we are talking about it today, even though you can say it's five years and it's anybody's guess at this point. As you point, Google is having a date, IBM has a date, government has a date. So that's all fine. But it's a journey. So are we getting prepared for that? And, you know, I it does come at a time, like you said, we're also dealing with this AI and how it's changing security.
15:36 And it just it feels like a lot. You know, there are cybersecurity professionals have a lot to be thinking about. Mark, does it complicate things that we've got AI and quantum both like together like like how does that play out for us? Of course not that it makes a lot more interesting though. Yeah. I mean, look, I think Suja would agree with me. There's a really big tsunami of stuff coming at us as cybersecurity people.
16:01 At the moment, if it's not frontier AI models that we've heard an awful lot about, it's also obviously AI in itself and how you actually can implement that—and implement that in a secure and a safe way in most organizations. Suja talked about the identities that come with that. A lot of organizations are really struggling with how to get the best out of AI because they can't work out, work out yet how to implement it securely, with the right levels of access.
16:24 And then of course, you've got quantum alongside there as well. So there's a lot. But, Matt, the good news is that within all of that, there's a few foundational principles that we work at with cybersecurity. And a lot of those foundational things don't change. But the one thing that does change is we've got to speed up, because a lot of the quantum, an impending quantum revolution.
16:44 And also what we're seeing with AI means that we've got to do a lot of the things that we know how to do. We've got to do them a lot quicker. I'm glad you also, you referenced the foundational stuff because I do want to come back to that. But, you know, we've kind of set up the scene here for folks, but I really want to dive into what I think is kind of the crux of the conversation today.
17:01 And it is this idea that Q-Day is not really a when it's a process, right? Back in April, you folks published a coauthored article that kind of gave your take on this matter. Here's a quote from that. Unlike Y2K, there won't be a single moment when everything breaks at once. Rather, quantum risk will be realized over time, spanning multiple years as different cryptographic systems become vulnerable at different times.
17:25 That was really fascinating to me because I've been hearing for years about Q-Day as like a specific moment. Right? And this is like, no, it's an unfolding process in time. We're dealing with it already. Suja, could you elaborate a bit for us on what it means to view Q-Day as something that happens over time rather than a sudden event. Since we wrote, our thinking hasn't changed.
17:41 I believe Mark and I agree. As I said, this comes in waves because when we think about cryptography, right, which is the encryption, this is invisible scaffolding, if you will, for the modern software. So when the quantum computer doesn't break just encryption, it breaks a lot of our assumptions that we have had for years on this one. And because of that, it's the hardware.
18:10 It is your credentials. It's your PKI that Mark was talking about. So everything needs to change. And so this is not just a technology problem. It's the people the process. So the biggest bottleneck is execution. Mark, Matt, we know about the data in general stays for ten years. Financial institutions, they say they keep the data for ten years, something that is today 2026.
18:39 Today's data needs to at least last until 2036. If you think about health care data, it needs to be held on for the lifetime of a person. So these are all important data which are encrypted and kept. How do we make sure that they are safe? How do we prevent them from harvest now and decrypt later? Because the bad actors are already taking this data today to decrypt later?
19:05 How do we stop that? That is why it's a journey, because you need to be starting on the journey because first, we don't even know. We cannot fix things that we don't know because cryptography is something that we will put on and don't worry about for a year or two years. And then they will take a look at it. Today we need to be looking at it and make sure that our hardware, software, our third party vendor software that you are having, all of them are ready for this new world.
19:33 And it's a good thing that it's a process because you have time to work through it almost. Right? Like, yes, there are issues that we're starting to deal with already, but we can start thinking about them as we move along. Mark, anything to add there in terms of, you know, how our thinking changes when we see Q-Day as a process? Yeah. Massively important what Suja was saying.
19:51 It really is pervasive and it's not an area in cryptography that was absolutely essential. Because the one thing about cryptography more broadly, when when things don't work, when certificates don't work, whatever, everything stops, things can't handshake properly. And so it's a it's a really important area, but one which we have got pretty well working well and we have had over many, many years.
20:14 The thing now though, is as we enter this, this period, we really now have to start rethinking the way we approach this in a way in which we necessarily haven't done had to do for some time. So of course, that that demands, as you were saying, a different approach which pervades right across many different parts of the whole IT ecosystem. So there's a lot of little pieces of the of the issue, essentially that ecosystem that I was talking about that need to be addressed, that really it starts with understanding what's
20:44 out there. And as you said, you can't you can't deal with something that you don't know about. And so just getting to that discovery point is a pretty important step in all of this, which actually is not to do with anything complex around algorithms or anything. We can get to that later. It's actually just starting about, well, what have you got already and what do you know about today?
21:04 And once you can get to that point, then you can begin to work out, well, how are you going to prioritize and how you're going to manage it over that, that time period? Yeah, I like that framing a lot because I think especially we talk about quantum, it can feel like a radical break from what's out there. Right. Like it can feel like something that's totally different than what we're used to.
21:21 But you a couple times now, Mark have gestured towards like, look, it starts with understanding what you already have, what's in place and applying some fundamental principles just to a new kind of realm. And in this way, I see again that parallel between quantum and AI, where like, it can feel so different from what we've seen before, but a lot of what we know can still be transferred over to this area.
21:42 It's just about okay, the terrain has changed. So how do we implement things the right way? And I want to ask too, because like I said, this, this idea of Q-Day as a process was new to me and it was very clarifying. I would love to get your take on how the rest of the industry talks about this. Do you think the kind of tenor of our Q-Day conversations is it on the right track?
22:03 Are we sensational? Are we not sensational enough? And Suja, I'll ask you first, do you feel like we've got the right conversation out there, or do you worry that we need to change the framing? How do you feel about it? Look, from and I when I think about last year to this year, I do see people are taking it much more seriously. Today we have we see about 30% of the industry have started on this journey.
22:28 Okay. I'm not saying they are in there, at least started on a journey. They started at least in the strategize and discovery phase, right? So they are at least beginning in that which shows especially because of regulations and also the finance and the health care industry and telecom industry are the in the forefront of it because it matters for the critical infrastructure to be ready for this quantum era.
22:54 So I do see that the conversation has started, but we are only at 30% and we are in the first two stages. I'd love to shift gears now to talking about the the so what? Right. The point of this show is to to offer people kind of, you know, pragmatic, concrete takeaways, right? So let's start with talking about what does it mean for us that we are at the beginning of the kind of Q-Day process, thinking about this stuff?
23:17 Where do we get started? And Mark, I want to ask you, especially because earlier you had mentioned, you know, some of the foundational stuff of cybersecurity still applies here. And I was wondering if you could start maybe let's talk about that first. First. What's the foundational stuff that still applies to a kind of post-quantum world? Can you walk us through that?
23:34 Yeah. First things first is actually just realizing that there is an impending issue coming up. And Suja was saying 30% of organizations really needs to be a lot more than that, because, as you said, right at the beginning, regardless of when the day is, if it's 29 or whatever, when we know that the capability will exist, won't necessarily be immediately accessible for everyone to get to, but the capability will exist to undermine current asymmetric encryption.
23:55 So that that is not far away. And when you think about the complexity of the interwoven nature of hardware software and how interoperability happens between different organizations, unpicking that to discover where those cryptographic artifacts are and then doing something about it is pretty urgent. And so what the so the starting thing is actually organizations have got to realize this needs to be addressed.
24:21 And this is not a you know, we just do it once and that's it. We can talk a bit more about that later on. But the reality is this is a process that starts with really getting and digging deep into something that perhaps organizations haven't had to do for some time. So it's an awareness point to start with, and that really has to be driven from really a pretty high level within an organization, because there's so many different pieces of the ecosystem that needs to be touched, and also the flow down
24:46 interoperability that has to happen in their supply chains. If you think about the average enterprise, you know there's a lot to think about. So the first thing is literally just getting the awareness to say, hey, we've got to get off to this and start addressing it. And then really is the next biggest step in this journey is, as you've probably realized already, Matt, Suja and I alluded to is, how do you discover what you've got?
25:08 Because you can't deal with stuff that you don't know. If you don't know it's there. So that discovery exercise, where are these cryptographic artifacts? Who am I working with? What are they doing in terms of. Because if they start doing some changes and then the organization that you're in hasn't done those changes, then obviously that could cause you some trouble in terms of interoperability.
25:27 Now's the time to think through that when we've got time. I'm afraid to do that and leave that much longer. If you're in a pressured situation where others are changing around you and you haven't got on with it soon enough, and go on at least with a decent amount of discovery at this stage, you could find yourself in a lot of trouble. So really, now is the time to get going and to get going with that, that discovery exercise.
25:51 Absolutely. And you brought up something there that I didn't really think about at all. And it feels like a major, you know, a miss for me, which is that like, this is also a supply chain issue, right? Like, like you said, even if maybe you're addressing some of the cryptography in your own systems nowadays, nobody's making like software in a vacuum.
26:10 We're using, you know, open source libraries or code that other people have written. We're pulling it all together. So you could have your whole, you know, fiefdom can be all set up. But if somebody's got got something, you know, if they haven't touched it in theirs, that can be a huge issue. Suja, any thoughts there on like, you know, discovery like Mark said, is huge, especially in this supply chain that we have built is very complex of our supply chain.
26:33 Any thoughts on on how we actually discover these things? What do we do? That's why this is not a project project. It's a transformation, right? The first one is you strategize, right? Okay. Because this is hardware, software, network, all of these. And like you said, it's a supply chain. All your your vendors. When are they going to be ready. So this is if your vendor is not planning to be ready then you have to have alternate.
26:57 That means it's a migration project. So that is why the strategizing is very, very important. Then assessing like we Mark talked about, the discovery part of it, then you figure out how you're going to modernize it. When you modernize, this is a transformation product. You have to govern and make sure that it doesn't waver from where it is. And then you remediate when the day comes.
27:17 When the algorithms are available, you are ready to be agile and remediate. And the cycle continues, right? This is not it's a five step, but this five step keeps going. It's in a circle, right? You strategize, assess, modernize, govern, remediate and then it keeps going. And the biggest thing for us the strategizing is we you talked about supply chain.
27:38 If you are doing a hardware refresh today right. You don't do it every year. You want to make sure that they are quantum ready so that you don't have to be spending money unnecessarily. That is why we are starting today. Same thing. The certificate lifecycle is changing. It used to be a year, then it became 200, now it's becoming 100. Then it is reducing it.
28:00 Think about how are you going to make sure that they are quantum ready that way. Because you can use some of these to accelerate your path and be ready for the new world. Because look, this is not a question of whether a company is going to do it or not. This is about like who's going to start first, because that is what that person is going to have the advantage.
28:21 Because if you do it last minute, it's going to be very, very expensive. Very, very expensive. Yeah, it's going to be very, very expensive. And also I could see, you know, you talk about like you have to work with your vendors. Right. And if you have a vendor who isn't thinking about this or you are a vendor is not thinking about this, you could lose some trust from from customers, right?
28:40 Like if you're not starting to think about this and they come to you and they say, hey, what are you doing for post-quantum cryptography? And they're like, nothing that people are going to start looking elsewhere. You know, and you mentioned Suja, you know, modernization, right? Once you've actually looked at everything and you've kind of inventoried, you figured out who you're working with, you're getting started, you want to do some modernization.
28:59 And that makes me think about, you know, post-quantum cryptography or quantum cryptography, which is I think when we talk about Q-Day, that's the kind of the top line thing that comes up a lot, which is like, you got to get that post-quantum cryptography. What exactly is that, though? Mark, could you give us a kind of overview of what's the difference between cryptography and PKI, post-quantum cryptography?
29:18 What makes those things different? It's a great question. So look at the National Institute of Standards and Technology ran around a competition a few years ago to, to really, to to for organizations to actually develop new cryptography and that can't be unraveled by quantum computing to the best of our knowledge. And that's important because this will come back to our notion of what we call crypto agility, because in the future we've seen we see cryptography being not so static as as quantum computing capabilities
29:47 continue to to emerge and become more powerful, then we see that the cryptographic approach is going to have to change as that happens. But for today, and as we see a quantum, quantum computing capability being available, the approaches that there have been a number of algorithms that have been developed, there are four and IBM, IBM has been at the absolute forefront of developing those, those post-quantum resistant algorithms.
30:13 And so what we mean by post-quantum cryptography is there's algorithms exist. Now here's the catch. And the catch is that of course the quantum compute capability means that the algorithms have to be more sophisticated, because they have to be able to withstand the now this new compute capability that's going to emerge, because obviously that's very different from what we have today.
30:33 So they are more complicated, they are potentially bigger and they have different characteristics. So this is not a one for one swap. So at the moment we have four post-quantum resistant algorithms. In the future there could be more. And the way in which we deploy those and we think about how we deploy them. And most importantly, during this transition period where organizations are in this transformation, they're going to have to make some choices about which is the most appropriate and necessary algorithm to deploy
31:01 in different scenarios. So that's really why there is a shift from what was a fairly static environment to now, this environment where there are some choices based upon the complexity of the cryptographic algorithms that are post-quantum resistant and that will continue to emerge and develop, we think, in the future as well. Yeah. It's like Suja said, right.
31:23 This is a cycle that doesn't stop. You might reach a kind of a moment of crypto safety or post-quantum safety, and then that might change again. And you might need another algorithm or another way of implementing it. PQC is necessary, but it's not sufficient. Crypto agility is the endgame, right? Are you agile? Because we are used to having an encryption and forgetting about it, right?
31:45 Because we are safe. Now you need to be agile and will be able to change as these algorithms mature, as things mature. Are you able to be agile to take in? That means your protocols need to be upgraded. Your systems need it's a hardware, software. Everything needs to be thought about and upgraded so you can be agile. This is a serious thing. This is a real transformation and a transformation, not just in terms of we've got to do this big project now.
32:10 This is a transformation to how you operate. And in many respects, when we think about how AI is impacting our IT stack here, that that is also a transformation in how we're operating as well. And that's where I think many organizations that Suja and I talk to. Yeah, I've got to start with thinking about it in that way, real transformation and ground up.
32:29 How do we think differently now and get to a state of crypto agility? And that's different, as I was saying from today. So it's this notion of we've got to think much more dynamically, be much more prepared to think we have to reopen, revisit as new things emerge. And that, I think, is going to be a theme not just in the post-quantum cryptography space, but if you think about it just in terms of what quantum computing is going to offer for us in the first place, right?
32:53 Today we've got some ideas what they'll be able to do, but in the future, I think that will impact on the whole IT stack as well. So there's this notion that we are now much more in this way of being able to think about it, much less static, much more dynamic and changing rapidly. Yeah. It reminds me, you know, again, I didn't see these parallels before I started talking to you folks for this, this, you know, episode.
33:13 But it's almost like we're developing a similar kind of. And you can tell me if I'm wrong here, but it's almost like we're developing a similar kind of agility with AI in terms of like, how the new models keep coming out and you kind of have like, you can't just sit and wait for, you know, like, okay, this, you know, Mistral's preview is the model to end all models.
33:29 Oops. No, it's not right. Like and I feel like that's what we're saying about kind of quantum computing and quantum cryptography. Right. Is that like it's not going to be a thing where we find the one thing that we sit on for the next 20, 30 years, right? It's going to be developing that agility. And we've said this term a few times now, crypto agility.
33:46 And it might be useful to just kind of define it explicitly for our listeners. Suja, do you have like a definition of crypto agility? What does that mean to you? Crypto agility is the ability to change your cryptography as easily as a software upgrade, right. You're updating your software today. That is not how it happens. It takes it's a huge transformation journey.
34:07 We want to be in a place that you just, hey, I'm able to update it like I update a software. So because the cryptography, as Mark was pointing out, will be changing and evolving and vulnerable, new vulnerabilities will emerge and then the threats will shift. So that's what it is. So for me, it's about can you upgrade it just like you do a software upgrade.
34:28 You just put it in the night in your phone or something. Upgrade and you'd upgrade it instead of having to go do this massive transformation. So the transformation map is saying the transformation is about getting to a state where you can do that, not just about where you've worked out which are the best new bits of cryptographic artifacts to replace the ones that you've got today.
34:47 So you've got to think about it in that way. And what I, what I would also add is when talking to too many clients, as Suja and I do, is when you think about that whole environment, that whole changing nature that does make people suddenly lots of times I feel pretty uncomfortable, actually, because it's like, so this is not a one and done. This is not I can do this and then I'm done.
35:08 No, no, no, this is going to be an ongoing, as we said, crypto agile approach as is as are now many other things in the IT environment. And that that it's, you know, there's this notion that it's okay, a few things will happen, it'll be disruptive, and then everything will settle down, and then we can just go back to how we used to be. Now that's not how it's going to be now.
35:27 And some people are really excited about that. You can probably tell that Suja and I are very excited about that. But some others, you know, find that a bit, a bit bit hard to deal with and understandably so because it's like constant change. And that presents challenges. But it presents an opportunity as well. And it's overwhelming. So I know I made it simple saying that, hey, it should be as easy.
35:46 So what can you do? So first thing is, when you're architecting, make sure that you're designing into the architecture. Right. And the second one is knowing I think, Mark, you had mentioned knowing where your cryptography lays your certificates, algorithms, keys. Where where do they live. That's where discovering and knowing that becomes visibility becomes very important.
36:06 And then decoupling this cryptography from your application so that it's not been built in your application. And your this is you talked about the model example. So this is something that you reach out and then get it when you need it. Then automating the lifecycle. Right. If a certificate is expiring, you are not finding out later and their systems are down.
36:23 You are automating this and building into the system. And establishing clean governance so that when changes are systematic and you are not doing reactively. So when you do that in a in that fashion, it becomes much easier. That is why it's a transformation journey that each one of our enterprises, including us, IBM, has scanned thousands of repos, millions of lines of code building the cryptographic bill of materials.
36:48 So we understand we are in the same journey, just like we are a vendor. We are also in our own journey and we are learning from it. And then we are able to share it with our clients. Yeah. I, you know, what's really cool to me here is that I walked into this conversation thinking the transformation was just from cryptography to post-quantum cryptography.
37:07 But it is so much more than that. And I can see now, you know, why you would say this is exciting? Because there is something really cool about this idea of like, what if your cryptography was as agile as a software update, right? What if you didn't have to commit to an algorithm for decades? You could use it when it was the strongest and when you needed to change it out, you could change it out.
37:24 That's exciting. I feel kind of energized by that, almost. I do. So we're starting to run low on time here. And there's two more things I just want to ask you folks about real quick. The first is we spent a lot of time here talking about kind of quantum computing as a big cybersecurity risk. But I also am kind of wondering if quantum computing might have some benefits for us too, like, you know, and again, not to hit the parallels too hard, but I think about AI, right?
37:55 We talk about it as a cybersecurity risk a lot, but we also talk about it as a major cybersecurity boon. Mark, any thoughts on like, will quantum also be good for us in some ways? What do you think? Yeah, I mean, trust security to come along and spoil the party as as is often the case, but I try not to consider and I really try not to. It's, it's it's it's it's only one sliver of what quantum is going to bring us, and everyone wants to talk about it, and they should talk about it because as we said, it's urgent that we
38:21 need to address it. But it is only one thing, which is that in the space where quantum is going to bring us this unbelievable ability to, to, to perform very complex algorithmic, algorithmic, algorithmic tasks. Right? That's one of the big use cases that quantum is going to bring us. If that one bit in there, which is the ability to run the algorithm that's going to defeat some of our existing asymmetric encryption, that's the only thing really, which we have here, which is the security focus downside of it.
38:51 There are so many upsides. If you just go beyond the well, start with that algorithmic capability, which is going to exist now, there are so many things that, you know, clients are already working with us on. Think about complex financial ways of trading and transactions. You know, there's there's complex algorithmic solutions that quantum is going to bring us that we can't do at the moment, even if the compute capabilities as good as they are, quantum is going to really change that.
39:16 We think about the whole area around natural sciences and the natural world, how we can emulate the natural world, and especially in the life sciences and medical applications of thinking about how we can really use quantum computing to unfold proteins and give us the ability to actually target, for example, treatment schedules and medicines designed specifically for individuals really based upon the understanding how the quantum is going to bring us to be able to actually unlock some of the, those processes that we
39:42 haven't been able to in the natural world. So there are many, even just at this beginning point of quantum computing, we can already see some clear use cases that are going to bring us some fabulous capabilities. And of course, in security as well. So some of those things apply in terms of being able to now process complex algorithms, manage data, do sensing in a way in which we can't get anywhere near at the moment.
40:07 You know, that quantum capability is going to give us that as well and give us the ability to respond and react much more quickly. So lots and lots of different applications, which are really exciting and which are already people are beginning to talk about. The one thing I would say actually, is that because everyone's so fixated on AI and AI deployment, that they're sort of forgetting that this huge revolution with all the benefits that will come from it is, is coming to us, and we really need to start thinking about
40:31 it because there's endless capability and opportunity. I think for me, the healthcare, right, the amount of the compute, the research that we can do and then solve a lot of like these niche 1 in 1,000,000, somebody is suffering. And because of that, we don't have enough compute to do research and figure it out can be unlocked with the quantum computers.
40:54 Look, we put the quantum computers on the cloud ten years back. We have quite a million people already using it and published 6000 plus research papers. And it's really, really exciting to see. This is this is another era, just like what we saw with AI and everything else that's emerging. And this is going to be really, really good. Yes. With everything, we had to be ready for that.
41:15 Then we have the time to get ready for the day so we can get there. But what we will see on the other side is really, really exciting. And personally for me, it is on the medical field because and we see a lot of partners who are putting, putting our quantum computers in their labs to go and start experimenting on. One is in the research side of the world, education and also in healthcare.
41:37 So I'm really excited about that. Absolutely. And yeah, you know, I, I just had to step back for a second. Something you had mentioned there, Mark? I do, I kind of agree with you that like AI gets a lot of the headlines right now. But like quantum has been making these quiet leaps in the background and really reaching levels that like just a few years ago, I'm not sure that we could have even imagined.
41:51 And so, like, I think some really exciting things are on the horizon. And I agree with you, Suja. You know, looking at those real world applications of like, think about medicine, what could change there? But to close us out today, folks, I always like to end the show on kind of the a practical note, right? So let's imagine somebody sitting there listening to this episode.
42:12 They're saying, this all sounds amazing. What do I actually do right now? Like, how do I get started? What's the first kind of steps I take? Mark, I'll ask you first your thoughts on like if you're an organization today, where do you get started on this? Get a conversation going immediately at the highest level in the organization to say that this is coming and we need to address in a transformational way how we think about cryptography and then start deploying tools, start discovering where you have crypto
42:40 cryptographic artifacts across the organization to then get that cryptographic bill of materials, and then you'll have a chance of being able to then think about what the strategy needs to be and the mitigation options to you, as algorithms that are available now can be deployed or other mitigating strategies. So have a conversation, get going with discovery straight away.
42:58 Strategize and discovery. That is the biggest thing that you can start with. A few things. The non-human identities, which used to be like 20 to 1 with human identity, is now 50. And and when I, when I was looking up before this meeting, it was 109 or something like that. So it is exponentially increasing. That's number one. So when these things are already increasing, it's important to get started.
43:21 For me, the enterprises that are going to win are not the one that's moved fast. That's the one that starts early. Folks, that does it for today's episode. Thank you so much to Mason and Suja and Mark. Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode.
43:39 Stay safe out there and if you have questions, comments, or concerns about Q-Day and the quantum future, drop them in the YouTube comments. We'd love to hear from you. And don't forget to check out our latest bonus episode with Ryan and Schutz. We talk all about patch management and why we need to actually ditch it for a new approach he calls Exposure Management that's available on all the usual audio platforms right now.
Q-Day is not a single day; it is an unfolding process over multiple years as quantum computers gradually make different asymmetric cryptographic systems vulnerable.
Unlike Y2K, there won't be a single moment when everything breaks at once.
Crypto agility is the ability to change your cryptography as easily as a software upgrade.
You can't deal with stuff that you don't know.
Produces the Security Intelligence podcast, helped create post-quantum cryptography standards, and is commercializing related products and services.
00:52