Is your network ready for post-quantum cryptography? It isn't always just a software patch

Started by ArcMage14, Today at 03:03 PM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Topic: Is your network ready for post-quantum cryptography? It isn't always just a software patch   Views(Read 30 times)
Active members in this topic:
ArcMage14(1)

ArcMage14

This is aimed squarely at enterprise IT teams that is worth reading even for smaller operators. The main argument is that moving networks to post-quantum cryptography won't be as simple as swapping one algorithm for another. In some cases it could mean upgrading hardware to cope with the extra processing, memory or protocol demands that the new algorithms bring

Forrester analyst Jitin Shabadu says the pressure is highest for organisations holding sensitive data that could be exposed to harvest now, decrypt later attacks, or large stores of personal information. That threat model is the one people often forget. Traffic captured today can be stored and cracked later once capable machines exist, so data with a long shelf life is already at risk

The first hurdle is simply finding where cryptography lives across a business service path. The article points out that overlap tends to show up in the network stack, where traffic from several critical services runs through the same routers, firewalls and switches. That makes network gear a natural starting point, and another expert quoted, Gorman, calls it low-hanging fruit that gives teams a useful test and helps build trust with executives

The good news is that for a lot of equipment it will be a software patch. Systems with enough capacity and vendor support may only need configuration changes or updates. Legacy kit without headroom or support is where the hardware bill arrives

Shabadu is blunt that not everything in an enterprise will be quantum safe in the next three years. His advice is to start with the crown jewels that support the core business and expand step by step. Gorman sums it up as sizing the problem to your capacity, which is about as practical as security advice gets

For forum admins and small site owners, the lesson scales down nicely. Know which parts of your stack handle TLS and keys, check whether your hosting provider or CDN already supports hybrid post-quantum key exchange, and keep software current so you get the updates when they land. The big firms will be forced to act first, but the rest of us rely on the same libraries and will inherit their fixes


Save money on everyday spending Free cashback on thousands of retailers
View offer