Episode Details

Back to Episodes
Cryptographic Agility: The Only Defense Against Quantum

Cryptographic Agility: The Only Defense Against Quantum

Season 2 Published 1 month, 3 weeks ago
Description
Most discussions about quantum computing focus on a single question:When will quantum computers break encryption?The better question is this:How quickly can your organization replace encryption when it happens?Because the organizations that survive the quantum transition won't necessarily be the ones that adopt the newest algorithms first. They'll be the organizations that can change algorithms without rebuilding their infrastructure.In this episode, we explore the growing reality of post-quantum cryptography, the harvest-now-decrypt-later threat, Microsoft's evolving quantum-safe roadmap, and why cryptographic agility is becoming one of the most important architectural disciplines in enterprise security.We examine the technologies, standards, governance models, and operational practices required to prepare Microsoft 365, Azure, Active Directory, Entra ID, Azure Key Vault, VPN infrastructure, certificate services, and enterprise applications for a future where today's cryptography can no longer be trusted.If your organization expects data to remain confidential beyond 2030, this episode explains why preparation can no longer wait.
THE HARVEST-NOW, DECRYPT-LATER THREAT

Many organizations assume quantum risk begins when a quantum computer arrives.In reality, the risk started years ago.Adversaries can capture encrypted traffic today and store it indefinitely. Once cryptographically relevant quantum computers emerge, that archived data can potentially be decrypted retroactively.We explore:
  • Harvest-now, decrypt-later attacks
  • Long-term confidentiality risks
  • Why encryption can fail years after data is stolen
  • The impact on healthcare, finance, government, and intellectual property
  • How retention periods influence quantum risk
For organizations protecting data with multi-decade value, the threat already exists.
UNDERSTANDING QUANTUM COMPUTING

Quantum computing is often misunderstood.It's not simply a faster computer.Quantum systems use entirely different computational models built around qubits, superposition, interference, and entanglement.This episode explains:
  • Physical versus logical qubits
  • Error correction challenges
  • Shor's Algorithm
  • Grover's Algorithm
  • Why quantum computers threaten public-key cryptography
  • Why symmetric encryption remains more resilient
Understanding the technology helps separate realistic risk from sensational headlines.
THE GLOBAL QUANTUM TIMELINE

Nobody knows exactly when Q-Day will arrive.What matters is that governments, vendors, and standards organizations are already planning for it.We discuss:
  • NIST standardization efforts
  • IBM quantum roadmaps
  • Google Quantum AI milestones
  • Quantinuum and IonQ developments
  • Government transition mandates
  • Expert forecasts for cryptographically relevant quantum computers
The conversation is no longer about if organizations need to prepare.It's about whether they can prepare in time.
THE COLLAPSE OF RSA AND ECC

Modern digital trust depends on public-key cryptography.The internet, cloud computing, software updates, identity systems, VPNs, and certificates all rely on mathematical assumptions that quantum computers threaten to break.We examine:
  • RSA
  • Elliptic Curve Cryptography (ECC)
  • Diffie-Hellman key exchange
  • Digital signatures
  • PKI infrastructures
  • Identity systems
When these foundations fail, the impact extends far beyond encryption.
THE NEW GENERATION OF POST-QUANTUM ALGORITHMS

The replacement algorithms already exist.After years of evaluation, NIST selected a new generation of post-quantum standards designed to resist both classical and quantum attacks.This episode explores:
  • ML-KEM (formerly CRYSTALS-Kyber)
  • ML-DSA (formerly CRYSTALS-Dilithium
Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us