Author transcript
Hello and welcome to UC today. I'm Kristian McCann and today we're exploring one of the most pressing and underestimated threats facing enterprise security in the notsodistant future and that is the race to quantum proof our data before it's too late. Uh the prospect of a workable quantum computer is no longer science fiction. And when the moment arrives, the cryptography world relies on to protect our sensitive data currently could be rendered obsolete. But that threat doesn't start then. It starts now because obviously there's threats that we will get into. Um, if you're responsible for IT security or technology strategy, then stay with us because I'm joined by Chris Harris, a mere technical director for data and application security at Tales to unpack the quantum threat and what businesses need to do to prepare. So Chris, thanks for joining me today. No problem. Nice to be here. Right. So, as I mentioned in the introduction, Chris, um, you know, Quantum's been talked about for many years, but it really seems to be kind of, uh, picking up intensity, uh, with some of these, uh, companies and, um, you know, security firms really talking about it a lot more in depth. Um, I was wondering, can you tell us what's made this a more urgent conversation? Now, it's it's really the fact that we've moved from something that people saw as an if to something that people now understand is a when. And that is really a completely different business conversation to be having if you're you're a business looking to uh to protect yourself. Um and really what's caused that is several things have happened. So, uh, major governments have published quantum strategies. They've published guidelines that organizations should be following. Um, here in the UK, the NCSC have uh set out some timelines for organizations to create inventories to secure their high priority systems and then then to secure their their whole systems. And other countries have done the same. Those guidelines are out there now. um the the standards bodies have done their work as well. So if you've read anything about quantum over the past uh past few years, you'll have heard about the NIST. Um it was a competition initially where they were looking for algorithms that were going to be postquantum safe. Uh that's concluded. The algorithms have been reviewed, they've been standardized, they've been released, and really that's led vendors to implement some of these things into their technology. Uh, and so now organizations can get commercial products, they can upgrade their software so that they have the ability to become quantum safe. Um and and so the the change really isn't in the quantum computer in itself, although that that's accelerated. Um certainly developments are are increasing uh the pace. Uh it's that we now know what the replacement cryptography looks like, which is really the change from before. You know, five years ago it was wait and see and today the advice has moved to you really need to start doing something about it. Excellent. Well, you you mentioned wait and see, Chris. Perhaps there's some people who are listening to think, well, you know, we can wait and see. You know, quantum isn't a real threat right now. But, um, why is there still a lingering concern about quantum data security even before, you know, we have this operational quantum computer? It's a funny one. Um, but when you think about it, it kind of makes sense. uh and that's that attackers don't need to break encrypted data today. They just need to steal that encrypted data today and then if it has value in 5 years or seven years or 10 years they can decrypt it once these quantum technologies and quantum computers come along. Now, if if you watch the same kind of films that I watch, you know, you kind of think of long long live data, you know, what could that be? And you think about spies and, you know, covert cells in in different countries. And and for sure, you know, that is sensitive data that that that needs to have a long life. But it's it's quite mundane things as well. You know, it's things like medical records, it's intellectual property, it's uh defense information, it's government information, it's research for universities or uh pharmaceutical companies. You know, all of this information is information that has a value which is is very long. Um organizations really focus a lot on and rightfully so on protecting attacks that happen today. Um, so they're they're interested in protecting their networks, their systems from from things that are happening right now, things that are going to happen tomorrow. And really quantum is making us think about those kind of future secrets. Um, it's it's not just when data is moving, it's when data's been stored. And I am sure that information has been taken today even though they don't know what it is because it's encrypted with technology that's still valid. It's still protecting that information. But at some point in the future, somebody is going to have the ability to troll through that information uh to see what it was that they captured. And some of it won't be any use. Some of it will be pretty dull. I'm sure if anybody wants to see what's going on in my WhatsApp conversations, they're more than welcome to. They're not that interesting. Um, but some of it will be very valid data um, which impacts people and impacts organizations. And so that's why it's really important to start thinking today about how you protect that information because it's like it's like a burglar stealing a safe and knowing that a master key is going to be made in the future. They just need to sit and wait. Okay. Well, you mentioned uh obviously it's a very scary prospect that you've uh you raised even before the advent of quantum computing, but you've also mentioned a couple of sectors. You know, you mentioned uh university, uh companies of intellectual property, uh military. I was wondering um which sectors do you think are the most exposed of this uh quantum threat if indeed um it's happening soon or even even kind of initial attacks right now where they're where they're perhaps doing this kind of steal now decrypt later. It it ties in with you know the kinds of information that that is long lived. So, you know, governments will be definitely a target. Um, and certainly more exposed defense organizations. We have financial organizations, um, communication companies, you know, uh, people that protect information when people are communicating, you know, like we're talking or like you communicate with anybody. Um, you know, all kinds of information gets shared. there's cloud providers, uh the pharmaceuticals, and really that's kind of the first group of organizations who who really should be doing something about it and many of them are. I mean, you know, I don't want to scare anybody and and suggest that this has come out of nowhere. You know, this has been something that's been on the radar for a long time, but the pace is definitely growing. Um but you you can definitely broaden that out. Um if you think about things like VPNs, many organizations use VPN technology. Uh digital certificates or all organization use digital certificates in some way. Um identity systems if you think about source code, code signing. So when you install an application, when you download an application, it's signed. You know where it's come from. You know that it's come from a trusted source. uh if you can fraudulently create signatures, you can create software that people will start installing and that will be another way into an organization to to get malware out there. Uh it's, you know, APIs that that organizations have that that provide connectivity to other organizations and to customers. And so really, you kind of end up with with every organization being impacted by this. Um but really it's it's about prioritization. Um it it's it's funny that you know ideal in cryptography it's kind of what we do but very few organizations think of them as think of themselves as a cryptography company. Um but really every business that conducts business digitally is at heart a crypto company. Uh it just doesn't doesn't serve you very well when you go to the board you know and you start talking about crypto and quantum and cubits. uh you're much better off talking about risk and you know this this is a real risk. Okay. Well, it is as you mentioned it is a real risk and maybe someone listening to this would be um definitely keen to move to uh mitigate the risk or manage the risk. So what would you say they should be doing to prepare now and what does that preparation involve? I think the good news is that the path has become clearer. um it's become a lot lot more obvious what organizations can do and there's a lot better support and tools for them to to be able to do that. Uh that the starting point is really that most organizations don't know where cryptography exists. I I was looking around the room that I'm standing in my office uh at home today thinking you know well it's it's you know your standard home office. Where's where's crypto? But then I'm looking up at the the ceiling and I've got, you know, a connected smoke alarm so I know if my house is on fire when I'm outside. That's got a certificate in it that's communicating with a cloud service. I've got a printer that's cloud connected I think so that they can sell me ink to be honest. But you know that connects to a cloud service and it's sat on my home network. And so discovery is really important. You know at an enterprise scale then obviously that's much wider. It's about the certificates, the databases, the applications, the cloud connectivity, the APIs. You you've got to see what you've got that uses crypto. And then the next step is to do something of an inventory to find out how that crypto works. Um, you know, what what form it takes. So, what algorithms do you use, what key lengths they are, what does it communicate with, what certificates have you got? Because only really once you've got that picture of where the crypto is and how it's being used and and whether some of it's okay or or not okay or needs looking at uh can you then move on to prioritizing which is really your next step. You need to figure out what needs to be replaced first. Um quantum protection postquantum cryptography is one of these funny things where where doing a little bit of it is better than doing nothing. You don't have to be completely quantum safe or not quantum safe. You know, there's definitely a prioritization, an order in which you should approach these things. And so, you should be looking for these long-term secrets, this information that needs to be protected for a long ter the long term uh and start there. And then once you kind of move through that, you can start looking at more mundane systems within your organization where uh the impact would be less or the information is very short-lived. then you can you can really kind of wait until until that kind of technology exists. Um but certainly you can't migrate what you can't see. So you need to find it and then start testing. You know begin some tests on postquantum to make sure that it it works in your environment that you're comfortable using it and that you can create a kind of repeatable process for all those pockets within your organization where you're going to need to do something. Okay. Well, that was a great sort of uh basis for, you know, what you should really be looking at for um quantum securing um your enterprise and its different um arteries. But I was wondering, you gave us some good examples, but um what does a migration to post quantum involve beyond just knowing right what needs to go first and what's most important? Uh how long does it take and what are the kind of challenges that you imagine many organizations might see? Well, for sure the challenge is is, you know, as I've said, most organizations genuinely don't know where cryptography is used within their organization. Certainly, they don't know everywhere that it's used. Um, the second challenge is really probably dependencies. Uh, if you think about an organization, you know, there will be very few organizations where everything that they use is something that they've created themselves. And it's really only those things you create yourself that you've got the ability to update, to change, to to, you know, figure out how you're going to address this this quantum threat. The other, I don't know, 80% or whatever an organization has belongs to software vendors. It's software that you've purchased. It's hardware that you've purchased. It's software as a service, cloud services that you use. And it's those vendors and those partners that are going to need to do the work. And so for you as an organization, you need to start working with those partners. You need to start asking them the questions, the difficult questions about, you know, how are you protecting this? Are you protecting it? What's your postquantum road map? So that you can start crossing some things off your list in your inventory so that you can, you know, end up in a situation where you feel comfortable. Um, it's it's a little bit like I don't know when they replace lead pl in plumbing. You know, all the pipes in old cities used to be lead and uh obviously that's not very good for you and so they need to replace them. They can't turn the water off, replace all the pipes and then turn it back on. It's it's a process which is bit by bit, little by little. And very much that's the approach here. It's about identifying something that needs to be changed, thinking about how you're going to change it, changing it, and then moving on to the next part of of what really is a big map, an infrastructure or an architecture diagram. Yeah, absolutely. And it being such a big map, um maybe some people might think, well, where where should I even start first? Um for companies wanting to get ahead and start to prepare now, what would you say is the uh the biggest single piece of advice you could give them?
you need to begin understanding where your cryptography lives because everything else depends on that. Um I I'd say that trust is much harder to rebuild than cryptography is. So uh that that's something to be aware of and I would say that this is an opportunity for organizations. Um again when you read about quantum you you might see the phrase crypto agility is one that we use a lot and that means that what you want to replace this with is not something else which is fixed and then some number of years down the line we're going to go through this all over again when somebody needs to change the algorithm to a longer key length or a different algorithm. You need to put something in place which is configurable and updatable so that in the future it doesn't require this whole discovery journey and re-engineering effort. It just requires configuration changes. It requires small updates. You know what you've got and uh and then you can very quickly be yeah crypto agile. And so that would really be my best advice. Okay. Well, that's good good piece of advice to end it on. Thank you for joining us today, Chris. No problem at all. Thank you. And thank you to the audience for watching. If you've enjoyed this, as always, don't forget to like, comment, and subscribe to stay in touch with more great videos like this. I'm Christian from UC Today, and until next time, we'll see you then. [music]
[music]