Home › Blog

The Scott G PQC Playbook

1. The Quantum Problem in Plain English

Quantum computing uses quantum bits that can exist in multiple states at once. That parallelism lets certain algorithms especially Shor’s factor large numbers exponentially faster than classical computers. RSA, Diffie-Hellman, and Elliptic-Curve Cryptography rely on factoring or discrete logarithms being hard. Once they’re not, your keys might as well be printed on a t-shirt.

The threat isn’t “the day quantum arrives.” It’s today’s data being captured and stored for tomorrow’s decryption. This “harvest-now, decrypt-later” model means any data requiring confidentiality beyond five years is already at risk.

2. Mission Statement

Build quantum resilience before the adversary’s decryption window opens. That means transitioning all vulnerable crypto to quantum-safe primitives, using hybrid schemes as an interim bridge.

3. Core Phases of the PQC Transition

Phase 1 Discovery & Inventory

  • Objective: Map every instance where cryptography is used, at rest, in transit, and in code.

  • Tools: Crypto inventory scanners, TLS fingerprinting, SAST/DAST for hard-coded keys, dependency mapping.

  • Deliverable: Crypto Bill of Materials (CBOM) listing algorithms, key sizes, certs, lifetimes, libraries, vendors.

Phase 2 Risk Classification

  • Rank systems by data sensitivity, encryption longevity, and exposure surface.

  • Example matrix:

  • High risk: healthcare, government archives, M&A files (15+ year secrecy).

  • Medium: enterprise backups, HR data.

  • Low: short-lived web sessions.

Phase 3 Hybridisation Strategy

  • Combine classical + PQC algorithms for key exchange and signatures. e.g. X25519 + Kyber; Ed25519 + Dilithium.

  • Update TLS 1.3, IPsec, SSH configs to support hybrid key establishment.

  • Maintain algorithm agility - your stack should allow future swaps without rebuilds.

Phase 4 Re-Encryption Pipeline

  • Develop automated pipelines to re-encrypt archives and long-term stores.

  • Use hybrid PQC/classical first; move to pure PQC once standards stabilise (NIST FIPS 203–205).

  • Track throughput (TB per week) and data class coverage.

Phase 5 Continuous Assurance

  • Monitor algorithm usage and lifecycle.

  • Integrate PQC metrics into GRC dashboards.

  • Schedule cryptographic health checks in CI/CD pipelines.

4. Governance & Policy

  • Establish a Crypto Steward role bridging security, architecture, and compliance.

  • Embed PQC requirements into supplier contracts: roadmap dates, algorithm agility, test plans.

Report metrics quarterly to the board in business language: risk reduction %, re-encryption velocity, vendor readiness.

5. The Risk Register

Risk Description Mitigation

  • Harvest-Now Decrypt-Later

  • Encrypted data exfiltrated today will be decryptable later.

  • Prioritise long-lived data for early re-encryption.

  • Vendor Stagnation Some suppliers lack PQC roadmaps.

  • Contractual mandates + exit criteria.

Implementation Flaws

  • New crypto introduces side-channel risks.

  • Use vetted libs (Open Quantum Safe, BoringSSL PQC branches).

  • Performance Degradation

  • Lattice maths adds latency and key bloat.

  • Benchmark, cache, adjust MTUs.

Governance Blind Spot

  • No one owns crypto inventory.

  • Assign Crypto Steward + board-level reporting.

  • Legacy Hardware

  • IoT and embedded devices can’t upgrade.

  • Gateways + proxy encryption layers.

  • False Sense of Security

  • “Quantum safe” labels without proof.

  • Third-party testing + certification (FIPS, CNSA 2.0).

6. Technical Recommendations

Algorithms (NIST finalists):

  • Key Encapsulation: Kyber (KEM)

  • Signatures: Dilithium or Falcon for performance; SPHINCS+ for conservative fallback.

  • Hashing: SHA-3 family (KMAC, SHAKE).

  • Libraries: liboqs, OpenSSL 3 PQ branch, AWS libcrypto pqc.

Hybrid Patterns:

  • TLS: X25519 + Kyber768 (KEMTLS draft).

  • VPN: IKEv2 hybrid key exchange.

  • Storage: AES-GCM keys protected by Kyber KEK hierarchies.

7. Operational Metrics Dashboard

  • Assets Profiled (%).

  • Critical Flows Quantum-Sensitive (%).

  • TB Re-Encrypted per Week.

  • Vendors with Signed Roadmap (#).

  • Median Key Lifetime (days).

  • PQC-Verified Flows (%).

  • PQC Coverage Across Environments (Cloud / On-Prem / Edge).

8. Cultural Guidance

  • Rebrand PQC as Trust Resilience, not Crypto Upkeep. Executives fund trust, not maths.

  • Reward Visibility. Crypto projects die in silence. Publish metrics and milestones.

  • Train for Algorithm Agility. Make crypto upgrades a routine discipline like patching.

  • Use Humour to Educate. Fear sells budget once; understanding keeps it.  Jokes are of course welcome.

9. The Seven Stages of PQC Adoption

  • Denial – “Quantum’s decades away.”

  • Anger – “Why did no vendor warn us?”

  • Bargaining – “Let’s just rotate RSA keys faster.”

  • Depression – “Every API call uses TLS 1.2.”

  • Acceptance – “Fine, we’ll test Kyber.”

  • Evangelism – “Hybrid crypto is actually elegant.”

  • Smugness – “Our entropy’s post-quantum, yours isn’t.”

10. Closing Reflections

Quantum computing won’t appear with a press release. It will appear quietly, when an adversary decrypts something they were never supposed to see.

By then, it’s too late to migrate.

PQC isn’t a project; it’s a generational refactor of trust... one we either start now, or inherit as forensics later.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing