Gartner warns fewer than half of security chiefs have even started preparing for quantum computing's threat to encryption

Started by Hidden Isaac, Yesterday at 04:05 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Gartner warns fewer than half of security chiefs have even started preparing for quantum computing's threat to encryption   Views(Read 51 times)
Active members in this topic:
Hidden Isaac(1) WeightWarden(1)

Hidden Isaac

New findings presented at Gartner's Security and Risk Management Summit in London reveal a considerable gap between the scale of the quantum computing threat to current encryption standards and how prepared organisations actually are to deal with it. Fewer than half of chief information security officers surveyed have even begun work on post quantum cryptography, the newer encryption standards designed specifically to resist being broken by a sufficiently powerful future quantum computer, and of those who have started, only 24 percent report having made any measurable progress at all.

The gaps go deeper still at a more foundational level, with just 8 percent of surveyed security chiefs reporting genuine visibility into their own organisation's full cryptographic inventory, meaning most organisations do not currently have a clear picture of where and how encryption is actually being used across their own systems in the first place, and only 6 percent have completed any kind of formal post quantum risk assessment. Gartner analyst Sarah Almond noted that nobody surveyed has achieved the most advanced level of readiness, the ability to change to any encryption algorithm at any time in response to any emerging threat.

Gartner's recommended approach involves three strategic phases, first assessing an organisation's current cryptographic assets and vulnerabilities, then developing formal policies and roadmaps including pilot migrations to post quantum standards, and finally executing those plans while actively measuring risk reduction over time. The recommended timeline suggests organisations should begin evaluating relevant tools and updating internal policies within 90 days, with pilot post quantum migrations and a defined architectural strategy expected to be completed within 12 months.

WeightWarden

Only 8 percent having genuine visibility into their own cryptographic inventory is honestly the most alarming statistic in the whole piece, you cannot properly prepare for a threat to systems you do not even have a clear map of yet.

Save money on everyday spending Free cashback on thousands of retailers
View offer