The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Leadership/CISO Tradecraft®
CISO Tradecraft® artwork

Harvest Now, Decrypt Later (with Marcus Sachs) - #290

CISO Tradecraft® · 2026-06-29 · 42 min

0:00--:--

Key moments - from our scoring

Substance score

49 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft8 / 20

The episode explores the intersection of quantum computing and cryptography through a technical but accessible discussion between the host and Marcus Sachs, VP and Chief Engineer at CIS (Center for Internet Security). Sachs brings decades of government cybersecurity experience, having helped establish DHS/CISA post-September 11th and worked at NERC regulating critical infrastructure. The conversation distinguishes between symmetric cryptography (like AES), which quantum computing won't significantly threaten, and asymmetric cryptography (RSA, Elliptic Curve), which becomes vulnerable when quantum computers reach sufficient scale. The core threat isn't immediate compromise - no operational quantum computer yet exists - but rather "harvest now, decrypt later" attacks where adversaries collect encrypted traffic and blockchain transactions today, storing them for future decryption. The White House executive orders from June 2024 mandate federal agencies and critical infrastructure operators migrate to post-quantum standards including NIST FIPS 203-205 algorithms like MLK (Module-Lattice-Based Key-Encapsulation Mechanism). Business leaders need sound data retention and destruction practices, understanding that stored communications - especially TLS/SSL encrypted web traffic, blockchain wallets, and financial records - remain strategic targets.

Key takeaways

  • →Quantum computers do not currently exist at operational scales, but the "harvest now, decrypt later" threat is real and organizations should begin migrating to post-quantum cryptography standards (NIST FIPS 203-205) now before full-scale quantum capabilities emerge.
  • →AES symmetric encryption is resistant to quantum attacks due to its iterative rounds, but RSA, Elliptic Curve, and other asymmetric algorithms used in TLS/SSL handshakes are vulnerable and must be replaced with lattice-based alternatives like MLKem or Dilithium.
  • →Organizations should audit and verify data destruction practices, because encrypted data stored today (in cloud, email archives, blockchain wallets, financial records) becomes a liability when quantum decryption becomes possible, even if the immediate adversary doesn't currently possess quantum capability.
  • →The Merkel-Hellman knapsack cryptosystem was broken in 1984 by Shamir, demonstrating that entire cryptographic algorithm classes can become obsolete overnight, making preemptive migration to post-quantum standards a prudent business risk management strategy.
  • →White House executive orders require federal agencies and critical infrastructure operators to migrate immediately, making post-quantum cryptography readiness a compliance and competitive imperative for vendors and suppliers to these sectors.

Guests

Marcus Sachs

Topics in this episode

Post-quantum cryptographyRSA encryptionNIST FIPS 203-204-205 standardsMLKem (Module-Lattice Key-Encapsulation Mechanism)Dilithium digital signaturesElliptic Curve cryptographyAES (Advanced Encryption Standard)TLS/SSL encryptionDiffie-Hellman Key ExchangeHarvest Now Decrypt Later attacks

Questions this episode answers

Why should a CISO care about quantum computing if quantum computers don't exist yet?

The "harvest now, decrypt later" threat is real - adversaries can collect encrypted communications (TLS traffic, blockchain transactions, financial records) today and store them for future decryption once quantum computers become operational in several years. Data stored today remains vulnerable for decades.

Is AES encryption vulnerable to quantum computing attacks?

No, AES is resistant to quantum attacks because its 16 iterative rounds create exponential computational complexity that quantum speedup cannot overcome. The vulnerability is in asymmetric algorithms like RSA and Elliptic Curve used in key exchange protocols like TLS.

What are the new NIST post-quantum cryptography standards that organizations should adopt?

NIST FIPS 203, 204, and 205 define new algorithms including MLKem (Module-Lattice-Based Key-Encapsulation Mechanism, formerly Crystal-Kyber) for key exchange and Dilithium (formerly Crystal-Dilithium) for digital signatures, designed to resist quantum computing attacks.

What is the risk of losing old Bitcoin wallets or cryptocurrency in a quantum computing era?

Lost or abandoned cryptocurrency wallets could be cracked using future quantum computers to recover private keys, making historical blockchain transactions with enduring value (unlike bank transactions with short-term relevance) attractive targets for decryption.

How should organizations prepare for post-quantum cryptography migration?

Begin with a data retention audit to identify what data has lasting value and implement verified data destruction practices; start planning migration to post-quantum algorithms (FIPS 203-205) for TLS, digital signatures, and key exchange protocols, particularly if you're a government vendor or critical infrastructure operator.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces a handful of genuinely useful concepts - harvest-now-decrypt-later, the asymmetric/symmetric distinction in quantum vulnerability, the cryptographic bill of materials - but long stretches are consumed by tangential anecdotes (the 1986 Risk Pack project, Italian postal strike, rack-depth war stories) and basic crypto 101 that adds little for any informed CISO. The ratio of insight-minutes to filler-minutes is poor.

if I'm doing that, then what I have is an ability to capture a whole bunch of communications, store them up, and then at a future date, play them all back to my quantum computer
it's not replacing every encryption algorithm. For those who say we need to become post quantum ready, that's not RIP and replace everything. There's only a handful of things that need to be replaced

Originality

8 / 20

The episode stays largely inside the standard post-quantum narrative (go to NIST, inventory your crypto, cryptographic agility), and the Y2K analogy is well-worn in this context. A few moments - the ransomware-without-encryption pivot and the Merkle-Hellman knapsack as a historical cautionary tale of an entire algorithm class collapsing overnight - are moderately fresh but not genuinely contrarian.

PQC was real popular before AI came along a couple of years ago. That was like the big buzzword.
in 84 AD Shamir, he's the uh, SNRS came up with an attack that basically it didn't back really out of them. It was a general solution. What meant that everybody who'd built a product, everybody who'd implemented the product, everybody had used it, suddenly realized that... there you are with no cryptographic protection

Guest Caliber

14 / 20

Marcus Sachs has legitimate, senior, operational credentials: one of three people who stood up what became CISA post-9/11, White House cybersecurity policy work, CSO at NERC (the bulk power regulator), and VP/SVP roles at Verizon and CIS. He is a genuine practitioner who has done consequential work at scale, not a circuit-riding thought-leader. The transcript itself, however, does not fully exploit that depth.

Back in the summer of 03 it was three of us that were uh, kind of ones to make startup if you will.
I was the uh, CS at nerc, that's the regulator for the bulk power system

Specificity & Evidence

10 / 20

The episode scores above average on algorithm-level specificity - naming FIPS 203/204/205, ML-KEM, CRYSTALS-Dilithium, Shor's algorithm relevance to RSA and Diffie-Hellman - but is nearly devoid of hard numbers on timelines, qubit thresholds, organisational cost, or breach impact. Practical recommendations stay at the level of 'do a crypto inventory' without named tools, vendors, or case studies.

the NIST has a federal information processing standard or FIPS 203, 204 and 205
The first one uses a module, um, Lattice Key Encapsulation Mechanism. They call it MLChem

Conversational Craft

8 / 20

The host has genuine domain knowledge - he can name Merkle-Hellman, Clifford Cocks, and FIPS standards - which lifts the conversation above a pure PR chat, but the questions are predominantly open and leading ('what else do we might want to think about?'), and there is no substantive pushback or productive disagreement at any point. The host frequently answers his own questions or hijacks the floor for extended personal anecdotes.

Many CISOs hear the word quantum and they figure, yeah, that's a problem for 2035. Is, is that dangerous way of thinking?
How should CISOs go about evaluating vendor claims?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B52%
  • Speaker A48%

Most-used words

quantum56back22cryptography18today18ahead18first17course14part14nist14crypto13computer13pull13somebody12world12algorithm12information11

Episode notes

Nation-state adversaries are vacuuming up encrypted traffic today, waiting for quantum computers to decrypt it tomorrow. This attack strategy, "Harvest Now, Decrypt Later," isn't theoretical. It's happening right now. G Mark Hardy sits down with Marcus Sachs (former White House cyber advisor, CSO of NERC, now SVP and Chief Engineer at CIS) to break down two executive orders just signed by the White House on post-quantum cryptography and what every security leader needs to do before the clock runs out. What you'll learn: Why TLS, VPNs, and PKI are your most urgent exposure The Harvest Now, Decrypt Later threat model and what it means for your data retention policies How to build a Cryptographic Bill of Materials (CBOM) What cryptographic agility means and why hard-coded crypto is a ticking time bomb Lessons from Y2K that apply directly to the quantum migration You can't name a date certain. But your adversaries are already running the clock. Links, NIST resources, and both executive orders in the show notes.

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hey, quantum, um, computing is going to be ready next year. We've been hearing that for 25 years. But the White House finally got serious about stuff this past week. I've got an expert here to talk to you all about it. Stick around. For everybody out there. So here's a little bit of the background of what's going on. We're going to discuss kind of what could be one of the huge technological advances when it gets here with regard to security. And that is the move to post quantum cryptography. So we're going to talk a little bit about cryptography. What is quantum, what is post quantum? And then what's the impact for you as a business leader? How do you communicate this information to your executives in a way that won't make their head spin, as well as what is the risk of things such as that? So first of all, kind of a quick cap on the news and I'll have these references in the show notes. Two presidential actions that were published executive orders this past week on June 22nd. And one of them addressed, uh, American quantum innovation. The other one is accelerating the migration to post quantum cryptography for high value organizations or basically important elements of the US Government. So if you're a ciso, maybe the obvious question you should be asking is now, should I care finally today, or is this still going to be somebody else's problem? It's going to be 10 years in the future and I think we've got somebody here who can be a really good expert about that. So Marcus, as I said, I've known you for a number of years, but quick little bit of your background. I don't know if you have to go all the way back to the army days, but you can mention that.

Speaker B: Yeah, sure, we can start there. Because I retired from the army about 25 years ago. So right after September 11th, uh, did a 20 year career, was going to head off to the private sector. September 11th happens and then I get a phone call from the White House wanting to know if I could come over and work for them instead of running off to the private sector. So, you know, when the White House calls, of course you say yes. And was, uh, there for a couple of years. This was, uh, started early 02. So just a couple of months after September 11th and through 02, we really were working on the national strategy to secure cyberspace. First time we'd ever done that, put together a White House strategy, um, that along with the national strategy to secure the homeland and a whole bunch of national strategies all came out about the same time. And later in spring of 03 we launched the Department of Homeland Security or DHS. The initial concept was to have a cyber capability built in, you know, that be part of it. Today we call that CISA. Back in the summer of 03 it was three of us that were uh, kind of ones to make startup if you will. Startup, startup, yeah, that's probably the best way to frame it. Had very little budget and uh, some really cool ideas and a lot of help from outside who wanted to show us how. So that's kind of how this all got started. Even back in the 90s, quantum, the term was around. We knew it was coming. It was not just a dream. There was still research being done at that point. I think our biggest fear in those days was terrorist groups. Uh, we understood nation state threats of course, but having the terrorists had just struck and we were really worried about them terrorizing the Internet. So there was a lot of time being spent on critical infrastructure protection and how to make sure the banks weren't disrupted or the power grids or the phone networks. And that's really where our big focus was back 25 or so years ago. Now of course things have changed over the years. We've gotten better at it. We understand threats better, we understand technologies better and um, we all grow up and over time, uh, you know, move on to other things. I spent some time at Verizon, uh, doing national security policy work. I was the uh, CS at nerc, that's the regulator for the bulk power system. And for the last couple of years I've been the um, VP or senior VP and chief engineer here at cis. CIS by the way, is a nonprofit. Uh, we mostly serve what we call serve the underserved. So we're all about helping small, medium sized businesses, state, local, tribal, territorial governments, those that are not uh, very well financed. Not the big companies, big corporate world, but the average sized companies and smaller ones, small organizations. And so we've done quite a bit of work, you know, thinking about it and talking about how best to secure the systems. Working close with the federal government, also working close with industry and others. So that's kind of where we stand here today in 2026.

Speaker A: Well, got it. So at CIS, I'm thinking critical controls that sound like the right thing, uh, that most people would associate with cis. They inherited that from sand be the sans 20 critical controls. And if you to the cis 20 controls. And they dropped the 20 because uh, we're now down to 18.

Speaker B: There's just so many. Right.

Speaker A: And it's the idea is you didn't want to lock yourself down into something like that. So that's great. And again, appreciate all the service that you have done for our nation and also for, uh, the industries out there, because it's smart people and dedicated people like you that really help make a difference. So, again, thank you. So let's get into a little bit about crypto and quantum. Now, I am a guy who used to write crypto contests for a lot of hacker conferences. You go to defcon, and for years Shmookon did a number of those crypto contests. But the thing was, they weren't the type of crypto contests where you needed to have a Cray computer. Or today you just go ahead and you submit everything up to AI. But rather, they were things that people could puzzle through in their own brain. So when we talk about cryptography, we're often thinking about zeros and ones and how do we go ahead and scramble that. And, uh, I'd written a whole bunch of crypto contests for hacker conferences. Defcon, shmoocon, things such as that. And these are classical problems, not things that you'd upload to the cloud or you'd solve on a Cray computer back when those things were the like. But you'd sit down with pen and pencil and figure stuff out. Kind of like around World War II. Well, we've moved forward with everything being digitized. And so what's happened is we've had symmetric cryptography for years. I have a key, you have a key. I encrypt, you decrypt. And that part's easy. But of course, the problem was how do I get my key to you? And if there's an enemy in between that could intercept that particular courier. And then we Fast forward to 1976, and with Diffie Marty Hellman, they come up and they say, hey, we've come up with this concept of asymmetric cryptography where I create a pair of keys that have some mathematical relation where I can encrypt something with this key, but it only decrypts with that one and vice versa. So think of it, for example, that I have a mailbox in apartment building. I can open up my mail, put my mail in and close it with the key. The mailman comes in, opens the other side, takes the mail out, delivers it, puts a new up, um, and back and forth. And the idea is one goes in, the other goes out, but you can't go ahead and move it that way.

Speaker B: So you probably know that concept was thought of in the 1950s and was deeply classified for about 20 years.

Speaker A: Yeah, I think Clifford Cox had some stuff, and there's another. Some really smart people that it was

Speaker B: rediscovered in the early 70s and published by researchers. And then the Katz out of the back at that point. You can't keep that a secret once it's been published.

Speaker A: So you get to be famous when you publish first.

Speaker B: That's right.

Speaker A: And so anyway, what happens then is that traditional cryptography, we now have this symmetric and asymmetric. Well, you fast forward to today, and pretty much we'll use the pair because asymmetric cryptography is very computationally intensive. If I want to go ahead and go to a website that I've never talked to before and the enemy's listening in, I need to do a key exchange. And so I use this asymmetric cryptography to go ahead and trade it in 56 bits of information. What's ones and zeros? That's a symmetric key. And once I've exchanged it, I throw over to that and off I go, high speed. Now that sounds pretty cool. And so what? Uh, who cares? Well, here's the interesting thing, is that in the past, we have said that the ability to try to break this asymmetric cryptography has been out of reach. That is to say, too much computational effort. We look at something like Rivest, Shamir, Enneidelman, or RSA, as people know about it, not to be confused with the rsac, the conference. And what it involves is factoring very large number into two primes. So you take a giant prime number, another giant prime number, multiply the two together, and if I give you the product, what are the prime factors? I don't know. 2, 3, 5, 7, 11, 13, 17, 19. It takes you a long time until you get to the, you know, gigantic number. That's the first stop. And so as a result, it works pretty well. Well, the thought was, is that when you get into quantum cryptography, which I'm not going to explain in its entirety because we'd really have to get into the physics. But think about it this way. Under normal computers, a bit has a state of 0 or 1. That's it. You're off, you're on 1, 0. In, out. In quantum computers, you have the quantum bits or qubits, which have quantum entanglement. You have two things that Einstein described as spooky action at a distance that allows you to basically have things that are 0 or 1 at the same time. It's a little bit like Schrodinger's computer. You don't know the answer until you reach in and you pull out the response. Well, the concept would be, in very, very layman's terms, that I could represent all possible answers at the same time using this quantum computer. And if I have a way to reach in and pull out just the right value, I got the needle in the haystack and I win. What do you win? Well, what you now win is the ability to go ahead and decrypt that key exchange that took place to swap out that 256bit AES key. Well, so what? Who cares? Well, the thought is, if I'm doing that, then what I have is an ability to capture a whole bunch of communications, store them up, and then at a future date, play them all back to my quantum computer. Now, maybe by then 99% of the stuff is no good. Maybe 99.9. But if you could have 0.1% of all the, let's say, bitcoin transactions, could you make some money on that? Could you make money on financials? What if you're a government agency and you're looking at their defense departments or special stuff? There's a lot that we can do here. So that's kind of set up. There is the initial battle problem, so to speak, for a conversation.

Speaker B: Yeah. And just, um, with quantum computers, oftentimes people think of them as it's just a faster version of a standard computer. Well, maybe, but not really. Uh, the world around us is a quantum world. You know, quantum physics surrounds us. We're just, in the last few decades, we're beginning to understand it. The quantum computer does real good at simulating in classic space what quantum space looks like. So it, it is using quantum physics, but it can also let you zero in on part of the quantum world, the quantum physics that you're looking for. Then simulate the environment that you need in order to do these really cool math calculations. And so it's kind of a neat abstraction, almost like the Matrix.

Speaker A: Yeah, it's not something that fits under your desk either. This is going to be running pretty close to absolute zero.

Speaker B: Very large. Right. And we don't have one that works yet. We have quantum computers, IBMs got them, but, but there's still a lot of uncertainty and you got a lot of error correction that has to be done. And so to get down to the, the number of qubits, the actual size that we need, we still have a few more years of work to go here. In fact, we'll get to these executive orders in A few minutes. That's part of what's driving this is it's like, let's quit talking about these quantum computers. Let's actually build one. You know, get, get out of the theory and let, let, let's get going and make this happen.

Speaker A: Yeah. So when we think about what we had talked about, about different types of algorithms, if you're using Diffie Hellman Key Exchange, that's potentially vulnerable. RSA potentially vulnerable. Elliptic curve, potentially vulnerable because they depend upon math problems like factoring integers or discrete logarithms. And all possible solutions can exist at once. Now, the important thing to remember is, remember we're going to exchange with all that Fancy overhead to 256 bit AES key, AES, the advanced encryption Standard, which was an update to the Digital encryption standard, or DEA. The digital encryption algorithm, which first was published in 1977, is not vulnerable. Well, why, how could, how could an algorithm for 1977 resist quantum computing? Because it's ITER. You've got 16 different rounds. And so it's possible you could go ahead and say, I'm going to build something that's going to solve one round. So I have one computer, but then I've got a billion billion outputs. Well, now I need a billion billion computers to do round two and then a billion billion to the billionth and then it just goes insane. And so it doesn't work. And so the idea being is that it's about the public key infrastructure. It's not replacing every encryption algorithm. For those who say we need to become post quantum ready, that's not RIP and replace everything. There's only a handful of things that need to be replaced and things such as that. So let me do one last thing in terms of where people can look at. If you're really a crypto geek and you want to look at it, uh, the NIST has a federal information processing standard or FIPS 203, 204 and 205. You can go find them@the NIST.gov website. But the first one uses a module, um, Lattice Key Encapsulation Mechanism. They call it MLChem. That's as far as I'm going to get in terms of how it works.

Speaker B: Say that twice.

Speaker A: Exactly. It used to be Crystal Kyber, but they came up with an abbreviation. I like the other one, uh, the digital signature of them was known as crystals. Dilithium.

Speaker B: Hmm.

Speaker A: Hm. I wonder what inspired that one.

Speaker B: Where'd that come from?

Speaker A: Right, yeah. And that's gonna replace your digital signature which is kind of the emergency algorithm. It's based upon a different approach just in case um, these lattice based approaches crack open. Because one of the interesting things is you go back and you look at history. I remember I was taking a course from Dr. Lance Hoffman at George Washington University back in 1980 and we're looking at cryptosystems and things like that. And what had happened was, is that some of the early crypto systems, public key crypto systems, were based on different classes of math. And Ralph Merkel and Marty Hellman came up in 1978 something they called the Merkel Hellman knapsack cryptosystem. Which not to get into the details but what was important is in 84 AD Shamir, he's the uh, SNRS came up with an attack that basically it didn't back really out of them. It was a general solution. What meant that everybody who'd built a product, everybody who'd implemented the product, everybody had used it, suddenly realized that as Warren Buffett said, when the tide goes out, there you are with no cryptographic protection. So sometimes entire classes of algorithms vanish overnight in terms of a solution for mathematics. And this is kind of what we're talking about. This has been kind of a slow roll with regard to the death of regular quantum or non quantum, but why these executive orders came out in the first place. So let's talk a little bit about, you know, what's, what's going on with these EOs and stuff like that.

Speaker B: Yeah. And I think real quick before we leave, just.

Speaker A: Okay, sure.

Speaker B: The audience understands there is a big difference between asymmetric and symmetric algorithms and quantum computing as we're describing it, you know, this ability to create this, this environment, this simulation is a bigger threat to the um, public private key pair style of asymmetric encryption. So we're not saying that all of this stuff gets thrown away. We have to recognize there's a new threat here. And it's because math typically is hard. We typically try and find one way algorithms, you know, one way through. And it's just so hard to come backwards. But in a quantum world, there's new math, there's new algorithms, there's new fun ways we can kind of bend the quantum physics of the world around us. Symmetric encryption on the other hand, it's kind of like industrial style. You can just make it bigger and more rounds and more of it. And uh, as you're saying, it's not so much throwing quantum at it, but all that being said, somebody might figure out a Way also with symmetric, you know, this is one of these things in cryptography. We say that the algorithm has not been broken yet. You know, there's no such thing as a perfect algorithm yet. And who knows what could happen, you know, so just as soon as we think we're safe and we can come out of the woods and all the, all the bears are gone, here comes another bear. So, you know, stay tuned folks. It's, it's not over till it's over.

Speaker A: Yeah, I think one of my latest bit of fun here, oldest documents in my crypto library is from January of 77. Coming up on 50 years for the digital encryption algorithm. And although everybody has found ways to brute force, that is try all two to the 56 combinations, nobody's found a back door. So that's right, those people writing code 50 years ago knew what they were

Speaker B: doing and nobody's found one yet.

Speaker A: Yet. And of course that's, that's the challenge. So how about this question here? Many CISOs hear the word quantum and they figure, yeah, that's a problem for 2035. Is, is that dangerous way of thinking?

Speaker B: I think, yeah, maybe. So we have to take a deep breath. Is this a problem I need to worry about this afternoon? Does somebody have a quantum computer and they're able to, you know, go in, let. Uh, one more thing to step back on. Uh, we haven't really mentioned this. The, the backbone of the web today is ssl tls. Nothing works. Uh, transactions, whether you're in the HTTPs world, like the little lock there in your web browser, whether you're using TLS for transport, for email, even down to currency exchanges, airline flight, traffic control, I mean it is everywhere. That is a huge vulnerability if we get to this point. Because guess what TLS depends on. Yeah.

Speaker A: You do the four way handshake and then you go ahead and exchange the key and up you go.

Speaker B: Yeah, exactly. Yeah. So there's a threat there, of course, but as far as we know, nobody can crack it today. Can they crack it in the future? Of course. So we have to then begin to think about, all right, well, what has value right now that next week has virtually no value? You know, transactions, probably. If, you know, if I'm doing a bank transaction today, 10 years from now, maybe somebody can crack it. Okay, so what I can see that you 50 bucks. But, but if I, if I'm using, um, uh, a bitcoin style, you know, blockchain transactions, and let's say I lose my wallet, I mean, how many of us have lost our Early Bitcoin wallets we don't have.

Speaker A: That's why we're still working at this age.

Speaker B: Could we start, you know, cracking some of those lost wallets? Well, yeah. Okay. So transactions of that sense probably have a lot of value. So we just have to be, you know, mature about whether this is a true threat to us today in terms of what we're doing, or can the threat come hit us a few years down the road? And so, yes, if you've got enough storage capability, you can be vacuuming up just tons of information today and worry about deeping it or cracking it later. And I think this is what all of us have to worry about is what are we creating? What's that? Digital exhaust, as some people like to call it. That could be stored and could be looked at later. And are we inadvertently storing things? It's not that the adversary has to go and store it. You know, we're throwing all kind of stuff up in the cloud. You know, we're just storing and storing and storing. And so maybe we're storing all the things we don't want anybody to look at so that somebody can steal it from us. Not steal it from us now, but steal it from us later by gaining access to these storage sites so then they can use their quantum M machines to go backwards and decrypted. It's a very strange world.

Speaker A: Yeah. And if you think about the history of that, that, of course, information, we think of it as an asset, but it also can be a liability. Look at the tobacco companies and the tremendous amount of fines that they were charged when all the documents that they said shred, get rid of were basically placed in boxes, put in warehouses. The boxes were marked shred. And they found them 15 years later when they went through and under discovery. It's like, well, all your docs are belong to us. And so what you want to think about is that when you purge something, get rid of it all. And a lot of things.

Speaker B: Right. And all it takes is one employee to decide takes it upon themselves. No, I want to keep my personal copy.

Speaker A: The pack rat who has all the PST folders and things like that. Exactly.

Speaker B: Yep, yep. And there they are. And again, it's not that the adversary is stealing the traffic today. They can steal it from you tomorrow if you've been keeping it. So this is like a best practice. You got to have good, solid data retention principles in place. And data, you know, um, getting rid of it. You know, data destruction is the word I'm looking for. That's Audited and verified that in fact, it is gone now. Uh, that doesn't stop. That's a different problem from somebody stealing it from you today and them storing it on your behalf. Okay, maybe that's not a bad thing either, because then if you have a data loss, you need to go do data recovery while your adversary has a backup copy.

Speaker A: Isn't that kind of how Randy Ransomware was supposed to work?

Speaker B: Right, exactly how ransomware works. Exactly.

Speaker A: Correct.

Speaker B: Yeah. And you bring up another interesting question there. Could an adversary now, uh, take a flip on ransomware, come in, gain access? You never get ransomed. They're just pulling the data down quietly.

Speaker A: And we've seen that the next generation ransomware, where it doesn't even involve encryption. See, the original ransomware is great because there was no exfiltration required, no data storage. You didn't have to go ahead and steal cloud space to get keep all this stuff. You just basically said, look, I'm encrypting it in place and all you need to get from me is 256 bits. And that's it keeps your communications bill low. But you're right.

Speaker B: If you had your own quantum computer, then you could decrypt the criminal group's ransomware key and decrypt your stuff, and

Speaker A: you're back to use it, theoretically speaking, of course. So, yeah, this does become a little bit of an interesting stuff. So, as you'd mentioned before that we're not today really worried about quantum or even in the first generation.

Speaker B: Well, we're worried about it, but. But could somebody attack me today with a quantum computer?

Speaker A: Yeah.

Speaker B: The answer is no, unless they hit

Speaker A: you over the head or they put you in there and froze you, kind of like in carbonite. But if you think about it, the types of algorithms we're worried about, so the things that are vulnerable would be, as you said, tls, um, Virtual Private Networks, uh, Public Key Infrastructure, and anything that involves a digital signature. But as we said before, AES or even like secure hash algorithms, those are fine. So let's imagine that someone out here is a Fortune 500 Chief Information Security Officer going, okay, you got my attention, Mark. And Mark, where do I begin? What do I do? How do I get started?

Speaker B: Well, I think the first thing, and this, you could look right back at nist. You know, what's step number one in the NIST framework? It's know what you have, right? So in this context, what algorithms are you using? What crypto do you have? What is protecting your information? Are you still using DES or triple des? Or have you moved to AES, uh, or gone beyond that? Uh, are you looking at what NIST is already making available to you for inside of TLS and other implementations of encryption? Are you using the most up to date algorithms? Because if you don't know what algorithms you have, if you're just trusting the vendors or you're trusting some kid who's implemented, okay, you're already behind the power, um, at that point. So we've got to start thinking about an inventory of what do we have, you know, and again, this is step number one in a NIST framework. It's something we should all be doing. But most people tend to focus on, you know, assets, as in physical things like the computers that I have or the software that I have. So even like a, um, crypto bill of materials, you know what, itemize it, what do I have on hand that is right where I would start.

Speaker A: And that is excellent because I've been talking about a, uh, You've talked about SBoM software Bill of materials and the push for that, but really a cbom, the equipment bill of materials. How do you get that? What is embedded from your vendors? Vendors, vendors, library, this public library, this pull from GitHub, what's in it and is anybody really keeping track of it or do we have some critical dependencies in there that are going to bite us? Um, so once again, so we can do a cryptographic inventory and things such as that. What else do we might want to think about doing as we.

Speaker B: Yeah, well, yeah, definitely, of course, the identification. What do you own, the assets that you have. But then what are you dependent on? What software do you have? What vendors are you buying from? If I'm using, um, many people use Microsoft, uh, Office or Office365 and you're in Azure or you're in uh, the Google Cloud or you're in AWS or whatever. Okay, so you're dependent on a third party vendor at that point. What are they using, what protections have they put in place? Um, for email, there's still a few people out there that use pgp. God bless you. Um, that's really cool, but very hard to implement on a corporate level. Uh, others use S mime. Again, God bless you. It's very strong, it's great. But boy, is it a pain in the rear to implement and to scale.

Speaker A: Right. And it reminds me of a talk I gave at Infosec World in the year 2000. It was called PK. I don't think so. And all to do with the difficulty of the Infrastructure as exactly as you refer. And here we are quarter century later and it's still the problem.

Speaker B: Well, and to Microsoft's credit, they launched Purview a few years ago, so they're now trying to build all this in. But what confidence do you have that Purview is using the latest, you know, post quantum cryptography that's recommended by nist. I would trust that Microsoft is. But you can see where I'm going here. You are now dependent on a third party. Unless you're rolling your own. And I really don't recommend that you roll your own. Um, you've got to understand what you have and you got to understand who you're depending on, who else is out there, what are your vendors doing? What are your vendors putting plans for the future?

Speaker A: Mhm. So if I'm going ahead and I say I want to evaluate a vendor claim. Okay, and I'm saying, okay, vendor says this or whatever. How should CISOs go about evaluating vendor claims?

Speaker B: Yeah, there's a lot of help for you already. The government has provided a number of guides. I keep pointing to nist. There's some really, really good, uh, things online. Perhaps we'd be able to um, uh, provide those uh, links or URLs to where people can go to. But that's where I would start. I definitely. We're not going to roll our own, uh, we're not going to develop our own set of checklists here. Go to nist. Even for those of us here at CIS where we're really good at cranking out best practices and so forth, if you look on our website and you start looking for post quantum cryptography, we just say go to nist.

Speaker A: Yeah, go directly to nist. Do not pass code.

Speaker B: Exactly. That's the place to go. And by the way, they're open. So if you're an expert at this or if you want to learn more, there's working groups you can get involved in. It's not like it's a bunch of monks, you know, with hoods on. They're just cranking out stuff. You have no idea where it's coming from. These working groups are open and you can get involved. So there is a wealth, um, of information, I hate to say it, there's YouTube videos even that tell you what to do.

Speaker A: Well, hey, we're on one right now. There's one right here.

Speaker B: Exactly. So I think the best thing CISOs do, if you're not familiar at all with quantum computing and post quantum cryptography, start getting educated on it. Go watch Some videos, you know, read a couple of these guides at least understand the words and understand what the hype is. Uh, PQC was real popular before AI came along a couple of years ago. That was like the big buzzword. And it came, you know, about the same time we're worried about, um, blockchain and cloud computing and zero trust. I mean, everybody was kind of looking at it as a buzzword. But this is a real problem. It is a, it's physics based and it's sort of cool in a way. It's, it's mathy and geeky, but it is a, it's a real threat and it is something that our adversaries are working on. And you know, there's even friendlies that are working on it. So definitely start with educating yourself. If you don't know the terms, learn the terms, and then take it from there.

Speaker A: Makes good sense. Now, one term or phrase I've heard of is something called cryptographic agility. If, if someone is encouraged that you should have this thing, you know, does it come in a box? What is cryptographic agility? What does it mean we can do?

Speaker B: Well, if you're, if you develop software, if you're a coding shop, you know, if you're not just buying off the shelf, buying Microsoft or Adobe or something, but you're rolling your own, uh, there's two ways that developers like to play with cryptography. Some of them will just include, you know, in their software, uh, modules of cryptography that are already publicly available. And we just point to it and put, pull it in. It's a nice modular approach. So as technology changes, I can just pull out something that's all, put in something that's new. Others tend to hard code it. You don't want to go down that road, you know, you don't want to make things just part of the source. That, that, that, that's not agility. And so when we talk about cryptographic agility, we want to think modular, think about things expiring and getting out of date. I just pull it out, put something new and off we go.

Speaker A: Yeah, I remember one of my very first commercial programming projects I did. It was back, I don't know, 1986. It was a tool called Risk Pack. And I took over the code base from somebody else who had pretty much hard coded all the IO, every question, thing like that. And I said, you guys want to do a Spanish version? Now I have to go rewrite every line of code. Why don't you just go ahead and have a whole Text file and instead of saying enter your name, just you know, select row 12, select row 19. So we do the same sort of a thing is that now you can go ahead and swap out this particular file and then you just went from English to Spanish. I went from this algorithm to that algorithm and it works pretty well.

Speaker B: And that's how we should think. And that's not just for Quantum. It's just in general we should be much more modular, much more agile when it comes to being able to pull out something old, put something new in and everything else could stay put.

Speaker A: Mhm. Let's kind of migrate over now to the executive order. So the two of them that came out on 22 June, securing the nation against advanced cryptographic attacks and ushering in the next frontier of quantum innovation. It's kind of great to see that level of technical information, particularly with some good signal M. You know, figure of merit here. It's, it's a pretty good stuff coming out of the White House. And so let's talk a little bit about that if you've had a chance to look at it. And we've got the links at the bottom here in our notes. Um, but what are we thinking about here? What are your thoughts?

Speaker B: Yeah, I think it's good. It's timely, of course, the White House and having worked there, it's a bit of a challenge to come up with something technical as a guideline in an executive order or presidential decision directive or anything. Those are very big strategic muscle movements. So I would never expect an EO to have, you know, paragraphs talking about Shor's algorithm. It would not be in an eo. I mean it could be, but you don't want to put that in there. So the first one that came out in a nutshell just says let's quit talking about it and let's build a scientifically viable quantum machine, one that can actually do these things that we want to do. Uh, set a one year deadline or you know, one year date to actually make this happen. I think it can be done. We've got the technology in place. We just need the motivation to make it work. It'll certainly, you know, this isn't just the government doing it. It's a, it's a government executive order. But vendors are going to be important. You know, there's a lot of hardware companies, software companies and others that can be engaged here. So this does tend to be a bit of a stimulation stimulus in the tech community and it's a good national goal. Now we're not saying build a quantum computer that can crack all these algorithms. They're saying make a scientifically viable. It's the first step. Get off the drawing board, get off the theory, and let's actually build one.

Speaker A: That's the first one you got. I was listening to the press conference in the car a couple of days ago. I guess it was on last, uh, Monday, and the President was talking about this, and then they had the Q and A. And of course, Q and A went to other types of events that are currently being challenged at the White House. But it was interesting that the president himself talking about pushing this stuff. So that's the first step. That's the first order. Says we need to go ahead and build a better approach. Uh, we're gonna need a bigger boat for one.

Speaker B: Build one? Yeah, and build a whole bunch of them. Just build one?

Speaker A: Yeah, that's all. They just. Everybody lines up for it. But what about the other eo? Because this, if you will, could be used on the offensive side. The second one, if you will, is tasking different entities more on the defensive side.

Speaker B: Yes, absolutely. Well, and, um, while you might think of the first one is offensive, it's really, let's build one. That's. That works.

Speaker A: Yeah. Scientists, for good or for bad, we can do. What you do with it is up to you.

Speaker B: Yeah, that's the next step. That being said, uh, we've got a lot of vulnerable systems and we've been identifying. Again, first step in NIST is what exactly is the critical of the critical? What are the things we need to go out and identify? And that's what we're doing pretty much talking about in round two here in the second EO is trying to identify this stuff that the government runs and that others that is truly critical, that might. Might be a target of a quantum computer. The ones we need to worry about post quantum cryptography. Where. What is it? Where are they? What's going on? Um, that's kind of what the second one's getting into. But again, it's not prescriptive. It doesn't describe what this is. There's no technology in there. There's no math, there's no science. It's using old words, you know, that go back, as I was mentioning, 25 years ago. Post September 11, we did a lot of strategies trying to identify what is critical infrastructure. What are they? We call the cikrs, if you remember that, the critical infrastructure and key resources. Yeah, this is extenuating. Just extending that now into this, this quantum world of Determining what parts of our infrastructure do we need to pay attention to what's important to us. So that's kind of where it's taking us. I think that we've got a lot of. We've done this before with ix. We've done it before with other new technologies in terms of identifying where we need to happen. So there's a lot of lessons we can pull from that. Um, but also there's uh, a lot of mistakes we can make. And so we're going to learn over the next year or two as we go through this.

Speaker A: Right? And there's some longer term, some five year planning goals, Secretary of Commerce, Secretary of Energy, Director of National Science foundation, uh, Administrator of NASA and prioritizing research, development, testing and evaluation of apps and things like that. And then some, some shorter term things within four months, 120 days, sec. War, Sec. Commerce, Sec. Energy, things like that. Develop a plan. So it's, there's a lot in there and it's typical, uh, when you look at White House policy is that you don't say everybody go do this. Rather what you're going to do is say, okay, you're in charge of this chunk. You do this this, you do that. So if I look, for example, back in my old military days, if we had something that came from the Secretary of Defense or Secretary of the Navy, he didn't say, go ahead and push this button or pull that rope, but he would say, okay, this four star, you go develop all this, this four star, you go do all this. And then everything flows from that. And there's an accountability and some deadlines that come back.

Speaker B: So, you know, it's also important to note in that second executive order, there's a tie to cybersecurity. It's like a thread that runs through it. So this isn't just encryption, but it's also the broader notion of risk and risk management and all the things that we think about in cybersecurity. So I think the big takeaway here is if you haven't read the executive orders, you ought to go read it. Goes back to what I was talking about. If you're not familiar with Quantum Get Smart on it. Um, this ought to be just in your library, your weekend reading. Take a look at it and take 10 minutes to read through it. Uh, and even if you're not a policy wonk, you're not really big into what happens in Washington. Still worth reading because there's some good nuggets in there and maybe even some takeaways. If you're managing a large organization, large infrastructure. Is there something in that eo, uh, that you might even want to do inside your own organization that takes a look at the structure of our organization. What part of us sort of looks like DoD? What part of us, or do, what part of us sort of looks like dhs, what part part of us sort of looks like nist? And should my own parts of my company or my organization start leaning into and thinking about becoming post quantum ready the same way that the federal government's doing so I would take that away if you're not a policy person or a federal person, just, just regular, uh, industry.

Speaker A: And that's an excellent point because we can take a lead from a very large complex organization like the federal government and I don't think any of us have to run something quite that big. And as a result we can look at and say, is it an overkill? Uh, maybe for us today, but maybe long term, no. As we take a look at being able to counter some of the cybersecurity threats, and as you mentioned, there's a paragraph in there for the director of the FBI to coordinate with Sec. State, Sec. War, Commerce, everybody else about cybersecurity threats and things such as that, we, uh, need to get hot on this. Uh, as you had said, start out by identifying what's in there, do an inventory of my existing crypto, then go ahead and if you will, develop your own cryptographic bill of materials so you can go to your vendors, go to your third party contractors, do to your own developers for the libraries that they pulled from GitHub or anything else like that, and say, hey, what do you got in here? And let's catalog that and keep track of it and then be able to go ahead and have that cryptographic agility to be able to go ahead and say, all right, I'm going to make this such that I could pull this algorithm out, drop this algorithm in there. I could do that at a future date and then start actually, well doing it because the clock is running. As long as we're continuing to use ciphers like TLS 1.2 and earlier. Ability to go ahead and crack things is potentially there. Somebody's recording a whole bunch of this information. Reminds me of the time I used to do active duty over in Italy and um, is reservist. And sometimes I wonder, like, how does this get the company, everybody's going on strike or things like that. I think they've changed their culture a little bit. But this is many years ago and I remember One time where I guess the postal service went on strike for an extended period of time. They resolved the strike. They had so much backlog mail, they literally could never deliver it with the people they had. So they auctioned it off. And there's TV shows today where you people buy the rights to whatever is in a storage locker. You open the lock and then whatever's in there is yours. Well, bag of mail. If somebody had a thousand lira note in there for their granddaughter, for their birthday, well, it's yours now. But somebody wrote a check to pay their gas bill. It's probably not fungible, not worthy, but

Speaker B: you know, there's um, there's a lot of analogies back to Y2K. For those of us who went through that drill A little over 25 years ago, the, um, that was a date certain. You know, we knew the, the two digit date field thing. This thing with quantum, there is no date certain. We, we just know we're going to get there, but we can't tell you if it's next year, 10 years from now, 15 years from now. But that being said, we did a lot in the run up to Y2K about changing our infrastructure, making it more resilient. And it began with the inventory. What do you have that's, that might be Y2K vulnerable? Uh, where are the connection points? What software do you have? Same kind of mindset. And people were really pooh, pooh in Y2K after it was over. Well, that was not a problem. You know, that was a bullet we didn't have to dodge. No elevator stop. Well, behind the scenes, there was a lot of things that quit working because of Y2K. In fact, even a few years later, we still saw mismatches, software that had vulnerabilities inside of it. So while the world didn't end, we learned a lot. And I think some of those lessons Maybe we've forgotten 25 years later, we're going to have to kind of relearn in this, this new get ready for the Quantum era. Um, but it's a good refresher just, you know, for any leader, any ciso, anybody out there, to always just think about change. Because change happens. How well am I prepared for it? How much do I know about what I have to manage? How flexible am I? How well can I adapt? I love this concept of modularity. You know, if I've got something that's getting old, instead of ripping and replacing the whole thing, you just take out the part that's getting old. You put in the Part that's new, uh, way back in my military career we used to practice this with the standard 19 inch rack, you know that you plug things into. Those things have been around since the 70s and they still work today, you know, 50 years later. The same physical rack is what we're using to put, put blinky lights into.

Speaker A: And that's going to be your width, but make sure you get the correct depth. Because I uh, had a client that they put in all the network stuff and it turned out they were an AV company and they put in AV racks and they weren't long enough to hold the UPS's. They weren't long. And like seriously.

Speaker B: But you think about it, rather than a custom built rack that's 18.2 inches wide, you know it's 19 inches is the freaking standard, right? Yeah. And, and all the stuff that's in there blinking, you just pull it out and put the new blinky light. You don't have to replace the entire rack is what I'm getting at. Power systems are very standard in terms of the cabling, the amperage. I mean and this is how we have to think in terms of, you know, what can we leave? That's sort of standard. It's timeless, will always be there. Everything else is modular. Pull it out, put it in, pull it out as, as new technologies come along. And this Quantum thing is no different but it requires good sisos. Need to understand that, kind of have that, that instinct that says in uh, order to be really, really agile and we have to do that. Then I have to think about how do I take the one thing out and put in something new without disturbing anything else and uh, without making my customers unhappy. And oh my goodness, that's the worst thing to get into is I'm sorry we have to turn this off for the next year.

Speaker A: Please do not adjust your set and don't go to anybody else. Yeah, well, I think with that we can probably get pretty close to wrap up point here. So mark any last thoughts or you think we're at a good break point here.

Speaker B: Again, Quantum is for real. There is some myth around it of course, but, but take it upon yourself to learn. Do that this weekend. Go watch some videos. If you're not familiar with it, get smart on be conversational about it. Don't be afraid of it either. And, and yeah, if you got some interest in it, get involved. I mean again it's an open process. NIST would love to have and so would others and write about it and uh, then encourage others to get smart on what's going on.

Speaker A: Sounds great. Well, thank you very much, Mark Sachs, for being part of our program at CISO Tradecraft. Those of you who are watching or listening, thanks you for being part of our audience. I hope you learned something useful today. Like we try every week to give you information that'll help you in your career and also in your mentoring and helping other people in their careers. If it had been of value to us, give us a like or thumbs up. Not because we're grade grubbing, but it improves our rankings and helps other people find it so they can improve their CISO Tradecraft as well. Until next time, learn a little bit about crypto, learn a little bit about Quantum, and well, stay safe out there.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Episode 128: Post Quantum CryptographyThe Azure Security Podcast · on Elliptic Curve cryptography87 / 100
  • When the Hacker Changes a One to a ZeroAuto Supply Chain Champions · on Post-quantum cryptography86 / 100
  • Lead-Lag Live | Christopher Gannatti, WisdomTree - The Quantum Computing Investment Case | WQTM ETFLead-Lag Live · on RSA encryption83 / 100
  • The Future of Tech - Key Themes for 2026 and BeyondThe B2B Podcast · on Post-quantum cryptography82 / 100
  • Is encryption enough to protect our data?Technology Now · on Post-quantum cryptography81 / 100
  • Auditing in the Age of AI: Risks, Rewards, and Practical StepsSpeaking of Risk and Audit · on Post-quantum cryptography80 / 100

More from CISO Tradecraft®

All episodes →
  • #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)
  • #288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)
  • #287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer)
  • #286 - AI-Native Security (with Nishant Doshi & Saro Subbiah)
  • #285 - Passwordless Authentication (with Nishant Kaushik)
Explore the best B2B Leadership podcasts →
All CISO Tradecraft® episodes →