LIVE · cybersecurity feed
Live wire
post-quantum cryptographyhigh

Post-quantum cryptography (PQC) migration workshop report

The UK's National Cyber Security Centre (NCSC) and Vodafone recently co-hosted a workshop on post-quantum cryptography (PQC) migration, bringing together government, industry, and academic leaders. The event highlighted the critical need for collaboration in transitioning to quantum-resistant algorithms, emphasizing that no single organization can manage this shift alone. Key themes included securing executive sponsorship by framing PQC as a business risk, ensuring supply chain readiness, and fostering transparency and cross-sector collaboration to build national resilience against future quantum computing threats.

zeroday.news · 10d ago

The National Cyber Security Centre (NCSC) and Vodafone, in collaboration with the National Cyber Advisory Board, recently hosted the inaugural UK government and industry workshop on post-quantum cryptography (PQC) migration. The December 2023 event brought together security leaders and PQC specialists from various sectors, including industry, academia, and government, to address the complex challenges of transitioning to quantum-resistant cryptographic algorithms. A central conclusion from the workshop was that no single organization can effectively manage this migration in isolation, underscoring the necessity of collaborative efforts.

The urgency for PQC migration stems from the anticipated threat posed by sufficiently powerful quantum computers, which are expected to be capable of breaking current public-key cryptography. This foundational cryptography secures modern networks and systems. The NCSC has established key milestones for PQC migration, with targets in 2028 and 2031, emphasizing the need for immediate action to avoid significant future costs and complexity. The transition is not merely a technical undertaking but a global strategic resilience imperative across all industries and governmental bodies.

While extensive guidance on PQC migration exists, the workshop highlighted that guidance alone is insufficient. Successful and secure migration requires deep collaboration among experts in cryptography, cybersecurity, and network operations, alongside individuals who understand the technical and business realities of their organizations. The workshop aimed to foster these connections, facilitate the sharing of real-world approaches and challenges, and build momentum for collective action.

Several key themes emerged from the discussions. One prominent theme was the critical importance of executive sponsorship and building a compelling business case for PQC. Participants stressed the need to frame PQC as a business risk and resilience priority, clearly articulating "why now?" and the potential consequences of delayed action. Approaches identified to engage boards included emphasizing the cost savings associated with early action, linking PQC efforts to broader organizational goals like addressing legacy systems and enhancing overall cyber resilience, and tailoring the business case to specific organizational priorities such as system availability, legal compliance, or financial impact.

Identifying a senior sponsor, such as a CTO, CIO, or CISO, who can advocate for the initiative at the board level was also deemed crucial. Leveraging peer and industry benchmarks to demonstrate what other organizations are doing can also influence board members. Furthermore, preparatory work, including engaging with the supply chain, conducting initial discovery exercises, and identifying critical assets, can strengthen the business case by making the risks and resource requests more concrete. Prioritizing the migration of systems that process the most valuable data or involve long-lived hardware dependencies was also recommended.

Developing a phased roadmap with clear timelines, targets, required investments, and necessary skills for each phase was seen as essential for setting expectations and building confidence in the actionable plan. The NCSC's guidance on PQC migration timelines offers suggestions for this planning process.

Another critical theme was supply-chain readiness. An organization's ability to achieve quantum readiness is directly dependent on its supply chain and the preparedness of its suppliers. Workshop participants underscored the importance of integrating PQC considerations into supplier security assessments and sourcing processes. Early engagement with suppliers to discuss PQC migration is vital for understanding and influencing their PQC roadmaps and for communicating specific requirements. Without supplier alignment, even well-planned migration strategies risk delays. Efficient and economical PQC migration often involves leveraging natural technology refresh cycles, which necessitates products with PQC functionality or upgrade capabilities.

post-quantum cryptographycybersecurityrisk managementcollaborationnational security
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]