Degree 4 · Unit 4.6
Quantum and post-quantum cryptography
Most of what protects your communications today rests on mathematical problems that classical computers find hard — factoring an enormous number into its primes, for instance. A quantum computer, once it is mature enough, solves precisely that kind of problem efficiently enough to remove the foundation altogether.
And here is the detail that tends to get overlooked: the threat is not uniform. Asymmetric encryption, which secures key exchange and digital signatures, is the part that is threatened. Symmetric encryption and hash functions need nothing more than a doubling of the key length. What this calls for, in other words, is an orderly transition rather than panic.
"Harvest now, decrypt later"
This is the point that makes the subject urgent rather than futuristic. A patient adversary can intercept your encrypted data today and simply store it, waiting for the capability that will open it years from now. If your data loses its value within a month, then no harm is done. But medical records, long-term contracts, manufacturing secrets and sovereign documents are worth as much in ten years as they are worth today.
So the working rule is this: if your data needs to stay confidential for longer than quantum computing is expected to take to mature, then you are exposed now — not at some point in the future.
Three steps that start today
1Take an inventory: where is encryption used across your systems, with which algorithm, and who holds the keys? Most organisations do not have this list at all, and it is the precondition of any transition.
GATE · LEVEL FOUR
A red-team report + a cognitive shield
Hand over two outputs: the first, the one-page report from your miniature red-team test — at least fifteen scenarios, ordered by impact, each with a proposed control and an owner to implement it. The second, a one-page cognitive defence plan: the five habits applied to your own situation, an agreed verification word, and the first-two-hours procedure for a forgery incident.
The standard of success: that at least one control from your report is actually implemented — not read and thanked for.
