At CISOPlatform Summit 2024, cryptographer and author Bruce Schneier was asked where post-quantum cryptography actually stands. In conversation with Bikash Barai, Co-founder, FireCompass and CISO Platform, his answer moved the problem away from the place most security programs are looking. The algorithms are in decent shape, he said. The ability to change them is not.
The math is ahead of the physics. Schneier pointed to the international competition NIST is running in the United States for quantum-resistant public key algorithms, and said that on that front the industry is doing really well. He was explicit about the uncertainty on the other side of the equation: we will not know until there is a working quantum computer, and even then it is unclear whether the attack algorithms are practical. They are not exponential, he noted, but nobody knows what the linear and geometric terms turn out to be. He described himself as pretty optimistic that we get through this.
The real issue is crypto agility. This was his central point. The products, the services and the uses of cryptography need to be agile, able to swap algorithms in and out. His argument for why that matters is broader than quantum: if a system is agile, it can absorb a quantum computer, or a development in classical cryptography, or anything else that breaks what is currently deployed. Agility is the control that covers the threat you have not named yet.
The industry's track record on swapping algorithms is poor. Schneier was blunt that we are not very good at crypto agility, and that we were terrible at it a couple of decades ago when the industry had to replace DES with AES, and MD5 with SHA, then SHA-1, then SHA-256. His hope is that we are getting better. He named this as the important thing to remember from the whole discussion.
Why this matters for CISOs
Most post-quantum planning currently on CISO desks is algorithm selection: which standard to adopt, on what timeline. Schneier's framing says that work is largely being handled for you, and that the part you own is architectural. The question you can act on this quarter is not which algorithm, but whether your systems, your vendors and your embedded estate can be made to change algorithms at all, and how long that would take. That is a cryptographic inventory and a procurement requirement, and both are decisions a security leader controls today.
It also reframes the business case. Agility is not a bet on when quantum computers arrive. It is insurance against every future cryptographic break, which is a far easier argument to take to a board than a timeline nobody can defend.
One question for the community
Pick the single system in your environment where swapping a cryptographic algorithm would be hardest. Is it a vendor product you cannot modify, an embedded or OT fleet, code your own teams own, or your certificate infrastructure? How long would that swap realistically take, and what has actually worked when you have tried it?
Join the CISO Platform community
CISO Platform is a peer community of security leaders who work these problems out together. If you are wrestling with cryptographic inventory, vendor agility requirements or post-quantum sequencing, bring it to the group. Join the CISO Platform community and add your experience to this discussion.
The full fireside chat with Bruce Schneier is available on CISO Platform.

Comments