Summer is over and so is this summer PQC series. I am glad that several people thought that these posts were helpful. Before I close things out, I want to leave you with an important final message: No matter what emerging technology comes, ALWAYS, ALWAYS, ALWAYS own your cybersecurity posture.
Most organizations are willing to start learning about what PQC but they don’t have is a clear sense of where to start. And in that gap, I’ve watched two paths that worry me.
Two paths that don’t actually solve the problem
The first path: Government agencies are putting out PQC solicitations built almost entirely around picking “the right PQC vendor.” The technical requirements usually came from the few people at that agency who understand cryptography, and the whole effort is focused on finding the vendor who checks the most boxes.
Overall, that does not get an agency very far (but, I will applaud that they at least started somewhere). A vendor is really good at selling to meet their quota but most PQC vendors do not understand your environment and are not incentivized to work through the kinks. Additionally, all PQC vendors have limitations on what they can and cannot find in your environment. Picking the right vendor was never the hard part. Understanding what cryptography is in your environment, monitoring for new and hidden cryptography, and making sure mission remains up are the hardest challenges to the PQC migration.
The second path: Large primes handed money and told to take care of the problem. I’ve talked to federal clients and PQC vendors who complained about this choice. The government spent real money to receive confusion, challenges, and expectations unmet. So, that’s not solving the PQC problem either.
I’ve watched crypto modernization efforts before, and the honest lesson from that history is that some things get better and some things get worse along the way. The best recommendation is to have a combination of the vendor, the prime integrator, and an independent consultant. Why? The partners worth keeping are the ones who solve problems as they come up without running up your budget every time something shifts, and who stay engaged with you over time.
The insurance lesson
Here’s an analogy I keep coming back to. For years, some organizations treated cyber insurance as their cybersecurity strategy: if a breach happens, we’re covered, and that’s how we “handled” the cybersecurity problem. But when you actually read the terms and conditions, insurers didn’t have to pay out if the organization hadn’t maintained basic cybersecurity practices. No ownership of their own posture meant no liability for the insurer.
PQC works the same way. You’re still liable for your own security posture. Throwing money at a contract or picking a vendor who says they can handle it, doesn’t transfer that liability, and it doesn’t make you less vulnerable. You’ve just paid for the appearance of a solution. At the end of the day, your PQC journey should be identifying your vulnerabilities that a quantum machine (or quantum plus AI) might take advantage of in the immediate future.
Recommendation – How to start the PQC Journey
These are the recommendation I have for you to start your PQC journey, sooner than later:
- Put someone on your team in charge of owning the PQC migration, with a support team around them, if you can manage it. That person, not an outside vendor, should be the insider resource (preferably in your CTO/CISO/TD/CIO’s office) who understands your environment end-to-end.
- Document your own inventory. Your own resources already have significant knowledge about your networks, infrastructure, and devices.
- Set a budget for year one. Use that number as your baseline to tell you how much, or how little, you had to work with and how far that got you. That data can be used in planning for the following years and help to formulate more realistic budgets.
- Look for a vendor and integrator to take you through the discovery process. Release solicitations with the combined role of a vendor and an integrator to discover the hidden cryptography you did not know was in your environment.
- One step people skip: talk to the vendors you already have. Ask them directly how they’re implementing PQC. What products just need an update? What is included in your existing contracts? That conversation gives you real information, and it takes work off your plate. The work your existing vendors are doing will prevent you from duplicating the work and will save you money.
- What about the consultant I mentioned before? A consultant can help you release a solicitation. They can also help you think through, if your vendor(s) and integrator are getting you closer to a secure environment, without the bias of large contracts or meeting quotas.
One more note, I’ll add from earlier in this series: it would be easier to just pick one vendor and call it done. But there’s real value in a multiple vendor approach. Different vendors will catch different aspects of your environment. No vendor will see everything, and that overlap is where you will find what one tool alone would have missed. The goal should never be to have a single clean inventory report. Your goal should be to have an accurate inventory that feeds into continuous monitoring, because your environment keeps changing after the scan ends.
The point isn’t the mandate
One last thing, from my years on the offensive side: an adversary isn’t deterred by a cybersecurity program on paper. The adversary is just looking for one vulnerability you don’t know about, and PQC doesn’t change that. Your goal has to be securing your environment, not just satisfying a mandate.
If you need help, or just have questions, reach out.
And if you’re looking for more to read on this as the series wraps, two resources I have a direct hand in:
- “Post-Quantum Leadership: Knowledge and Practical Perspectives on Post Quantum Readiness,” which I edited,
- and the PQC awareness course content I developed.
Lastly, I’ll likely be publishing an article in U.S. Cybersecurity Magazine soon, taking this conversation from inventory into planning. Today’s post was your sneak peek.
Thank you for reading this series. It’s been a good summer. The deadlines are real, the work is real, and some of it will be hard. But we will get through it, one honest step at a time.
Where MIL comes in
Owning your cybersecurity posture doesn’t mean you have to navigate PQC alone. MIL can help you take the next step with your environment, mission, and priorities in mind. Explore MIL’s quantum offerings and PQC readiness services to learn how we can support your post-quantum journey.