Member Contribution - Weekly CISO Podcast Pick
This Week's Pick by David B. Cross (CISO, Atlassian)
Series curated by the CISO Platform community, sharing practical security leadership resources recommended by experienced CISOs and senior practitioners.
Security This Week: Quantum is the Answer. What's the Question?
David's recommendation this week is episode 192 of Security This Week, a discussion on quantum technology and the cybersecurity planning questions it creates for organizations. The episode is framed around breach-driven security learning and then moves into the larger leadership issue: how should teams prepare for a future where today's cryptography may not be enough?
For CISOs, the value is practical. Quantum risk is not only a future engineering problem. It affects long-lived confidential data, vendor roadmaps, certificate and key management, regulatory expectations, and how quickly an organization can change cryptographic controls when standards and products mature.
Source: Security This Week episode 192 - Quantum is the Answer. What's the Question?
Focus: post-quantum readiness, crypto agility, long-lived data, vendor planning, executive risk framing
Why this matters to CISOs
- Quantum readiness is a security program issue, not a narrow cryptography project. It reaches identity, TLS, VPNs, code signing, data protection, third-party services, and procurement.
- The "harvest now, decrypt later" problem changes prioritization. Data that must remain confidential for many years should be assessed before near-term systems with short-lived secrets.
- Boards and executives need a measured risk narrative. The right message is not panic, but visible preparation: inventory, prioritization, vendor accountability, testing, and staged migration.
- Crypto agility is the control that buys time. Teams that can rotate algorithms, keys, certificates, and protocols with less disruption will be better positioned when migration windows tighten.
Copy-paste takeaways for your team
- Create a cryptographic asset inventory that covers public-key algorithms, certificates, key exchange, code signing, SSH keys, and sensitive integrations.
- Classify sensitive datasets by confidentiality lifetime so long-lived data receives earlier migration planning.
- Ask critical vendors for their post-quantum cryptography roadmap, supported standards, hybrid-mode plans, and test environment availability.
- Add post-quantum readiness to architecture review for identity, network access, secrets management, data storage, and customer-facing platforms.
- Treat migration as a staged program: discover, prioritize, test, pilot, migrate, verify, and keep the inventory current.
Standout ideas
- The most exposed assets may not be the most visible ones. Long-retention records, archived traffic, legal data, regulated data, and high-value intellectual property need separate attention.
- Post-quantum planning is also a dependency-management exercise. Many organizations will move only as fast as their vendors, protocols, appliances, and managed services allow.
- A good executive plan separates today's action from future uncertainty. Start with inventory and agility now, then adapt the migration path as standards and implementations mature.
- Quantum risk can be used to improve current hygiene: certificate lifecycle discipline, key ownership, algorithm visibility, and stronger change-management paths.
Try this in the next 7 days
- Pick one high-value application and map where it uses public-key cryptography.
- Ask the data owner which records in that workflow must stay confidential for more than five years.
- Review whether the application can support algorithm changes without a major redesign.
- Send one post-quantum readiness question to the vendor or internal platform owner responsible for the application.
- Document one practical blocker, such as an unsupported protocol, hard-coded algorithm, unmanaged certificate, or unclear ownership path.
About David B. Cross
David B. Cross is CISO at Atlassian and a long-time CISO Platform community member. His weekly picks highlight practical conversations that help security leaders sharpen judgment, improve team execution, and stay current on emerging risk.
Share this with your team
Use this pick to start a focused conversation with architecture, infrastructure, identity, risk, and procurement teams about post-quantum readiness.

Comments