Survey Reveals Slow Progress in Post-Quantum Cryptography Adoption
- Securityish
- Privacy & Personal Security
Quick Summary
The Securityish Brief
The Ponemon Institute conducted a survey on behalf of Entrust, involving 4,149 IT and security professionals. The survey revealed that 75% of respondents believe quantum computers will be able to break traditional public key encryption within five years. However, only 38% are actively preparing to adopt post-quantum cryptography (PQC). Furthermore, less than a third (32%) are creating an inventory of their cryptographic assets, which is crucial for ensuring they are crypto-agile.
Over two-thirds (68%) of the participants reported that managing cryptographic assets, such as keys and certificates, is extremely or very difficult. The top barrier to readiness for PQC is limited visibility into these assets, as noted by 41% of respondents. Greg Wetmore from Entrust emphasized that organizations are falling behind in migrating away from legacy encryption technologies, especially with the potential arrival of quantum computers capable of breaking existing schemes by 2029.
Organizations have less than three years to prioritize migration projects based on the sensitivity of the data at risk. This may involve replacing outdated applications and IT systems. The urgency is heightened by the concern that nation-states are already stealing vast amounts of encrypted data, anticipating future decryption capabilities.
More than half of the survey respondents indicated that a cyberattack involving quantum computers would significantly impact their organization or industry. Specifically, 59% expressed concerns about exposing long-term sensitive data, such as health records and trade secrets, while 58% acknowledged the risk of losing access to critical infrastructure.
Convincing business leaders to allocate resources for PQC amidst competing budget demands remains a challenge. Despite warnings from organizations like Google and advisories from the National Institute of Standards and Technology (NIST), funding is often directed toward AI tools that generate sensitive data. Some cybersecurity teams have successfully linked encryption upgrades to AI projects or embedded costs within zero-trust IT initiatives.
As quantum computing capabilities advance, the exact moment when encryption schemes can be broken, referred to as Q-Day, will likely not be formally announced. Instead, it will be inferred based on the capabilities accessible to various nations.
- Survey by Ponemon Institute found 75% expect quantum computers to break encryption in five years.
- Only 38% of organizations are preparing for post-quantum cryptography adoption.
- 68% of respondents find managing cryptographic assets extremely difficult.
- Less than a third are creating an inventory of cryptographic assets.
- Over half believe a quantum cyberattack would have a serious impact on their organization.
Key Takeaways
- Assess your organization’s current encryption methods and identify any legacy systems that need upgrading.
- Start creating an inventory of your cryptographic assets to ensure you are prepared for post-quantum cryptography.
- Engage with business leaders to discuss the importance of allocating resources for PQC initiatives.
- Monitor developments in quantum computing to stay informed about potential threats to your data security.
- Consider integrating encryption upgrades with ongoing AI projects to enhance data protection.
Key Terms & Concepts
- Post-Quantum Cryptography (PQC): In this article, PQC refers to cryptographic methods designed to secure data against the potential threats posed by quantum computing.
- Quantum Computing: Quantum computing is a type of computing that uses quantum bits to perform calculations much faster than traditional computers.
- Cryptographic Assets: Cryptographic assets include keys, certificates, and secrets that are essential for securing digital communications.
- Q-Day: Q-Day refers to the anticipated day when quantum computers can effectively break existing encryption schemes.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.