The Scott G PQC Playbook
1. The Quantum Problem in Plain English
Quantum computing uses quantum bits that can exist in multiple states at once. That parallelism lets certain algorithms especially Shor’s factor large numbers exponentially faster than classical computers. RSA, Diffie-Hellman, and Elliptic-Curve Cryptography rely on factoring or discrete logarithms being hard. Once they’re not, your keys might as well be printed on a t-shirt.
The threat isn’t “the day quantum arrives.” It’s today’s data being captured and stored for tomorrow’s decryption. This “harvest-now, decrypt-later” model means any data requiring confidentiality beyond five years is already at risk.
2. Mission Statement
Build quantum resilience before the adversary’s decryption window opens. That means transitioning all vulnerable crypto to quantum-safe primitives, using hybrid schemes as an interim bridge.
3. Core Phases of the PQC Transition
Phase 1 Discovery & Inventory
Objective: Map every instance where cryptography is used, at rest, in transit, and in code.
Tools: Crypto inventory scanners, TLS fingerprinting, SAST/DAST for hard-coded keys, dependency mapping.
Deliverable: Crypto Bill of Materials (CBOM) listing algorithms, key sizes, certs, lifetimes, libraries, vendors.
Phase 2 Risk Classification
Rank systems by data sensitivity, encryption longevity, and exposure surface.
Example matrix:
High risk: healthcare, government archives, M&A files (15+ year secrecy).
Medium: enterprise backups, HR data.
Low: short-lived web sessions.
Phase 3 Hybridisation Strategy
Combine classical + PQC algorithms for key exchange and signatures. e.g. X25519 + Kyber; Ed25519 + Dilithium.
Update TLS 1.3, IPsec, SSH configs to support hybrid key establishment.
Maintain algorithm agility - your stack should allow future swaps without rebuilds.
Phase 4 Re-Encryption Pipeline
Develop automated pipelines to re-encrypt archives and long-term stores.
Use hybrid PQC/classical first; move to pure PQC once standards stabilise (NIST FIPS 203–205).
Track throughput (TB per week) and data class coverage.
Phase 5 Continuous Assurance
Monitor algorithm usage and lifecycle.
Integrate PQC metrics into GRC dashboards.
Schedule cryptographic health checks in CI/CD pipelines.
4. Governance & Policy
Establish a Crypto Steward role bridging security, architecture, and compliance.
Embed PQC requirements into supplier contracts: roadmap dates, algorithm agility, test plans.
Report metrics quarterly to the board in business language: risk reduction %, re-encryption velocity, vendor readiness.
5. The Risk Register
Risk Description Mitigation
Harvest-Now Decrypt-Later
Encrypted data exfiltrated today will be decryptable later.
Prioritise long-lived data for early re-encryption.
Vendor Stagnation Some suppliers lack PQC roadmaps.
Contractual mandates + exit criteria.
Implementation Flaws
New crypto introduces side-channel risks.
Use vetted libs (Open Quantum Safe, BoringSSL PQC branches).
Performance Degradation
Lattice maths adds latency and key bloat.
Benchmark, cache, adjust MTUs.
Governance Blind Spot
No one owns crypto inventory.
Assign Crypto Steward + board-level reporting.
Legacy Hardware
IoT and embedded devices can’t upgrade.
Gateways + proxy encryption layers.
False Sense of Security
“Quantum safe” labels without proof.
Third-party testing + certification (FIPS, CNSA 2.0).
6. Technical Recommendations
Algorithms (NIST finalists):
Key Encapsulation: Kyber (KEM)
Signatures: Dilithium or Falcon for performance; SPHINCS+ for conservative fallback.
Hashing: SHA-3 family (KMAC, SHAKE).
Libraries: liboqs, OpenSSL 3 PQ branch, AWS libcrypto pqc.
Hybrid Patterns:
TLS: X25519 + Kyber768 (KEMTLS draft).
VPN: IKEv2 hybrid key exchange.
Storage: AES-GCM keys protected by Kyber KEK hierarchies.
7. Operational Metrics Dashboard
Assets Profiled (%).
Critical Flows Quantum-Sensitive (%).
TB Re-Encrypted per Week.
Vendors with Signed Roadmap (#).
Median Key Lifetime (days).
PQC-Verified Flows (%).
PQC Coverage Across Environments (Cloud / On-Prem / Edge).
8. Cultural Guidance
Rebrand PQC as Trust Resilience, not Crypto Upkeep. Executives fund trust, not maths.
Reward Visibility. Crypto projects die in silence. Publish metrics and milestones.
Train for Algorithm Agility. Make crypto upgrades a routine discipline like patching.
Use Humour to Educate. Fear sells budget once; understanding keeps it. Jokes are of course welcome.
9. The Seven Stages of PQC Adoption
Denial – “Quantum’s decades away.”
Anger – “Why did no vendor warn us?”
Bargaining – “Let’s just rotate RSA keys faster.”
Depression – “Every API call uses TLS 1.2.”
Acceptance – “Fine, we’ll test Kyber.”
Evangelism – “Hybrid crypto is actually elegant.”
Smugness – “Our entropy’s post-quantum, yours isn’t.”
10. Closing Reflections
Quantum computing won’t appear with a press release. It will appear quietly, when an adversary decrypts something they were never supposed to see.
By then, it’s too late to migrate.
PQC isn’t a project; it’s a generational refactor of trust... one we either start now, or inherit as forensics later.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·