The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cyber Work
Cyber Work artwork

Why Hackers Are Stealing Encrypted Data Now To Decrypt Later | David Close

Cyber Work · 2025-08-11 · 44 min

0:00--:--

David Close explores the urgent shift toward post-quantum cryptography as quantum computing advances threaten the RSA and elliptic curve algorithms securing nearly all enterprise data today. The core threat is that nation states and criminal actors are harvesting petabytes of encrypted data now, betting that fault-tolerant quantum computers will crack these algorithms within 10-15 years, making decades-old data vulnerable retroactively. This particularly threatens industries like satellite communications, financial records, and intellectual property with multi-decade security requirements. Close explains how NIST's August release of quantum-resistant algorithms (Kyber, Dilithium, Sphinx+) provides a path forward, though these algorithms have larger key and signature sizes requiring protocol rethinking. He highlights real-world adoption: Google and Cloudflare already deploy hybrid encryption (combining elliptic curve with Kyber) in production. FutureX's approach emphasizes "crypto agility" - designing systems where algorithms can be swapped without full re-architecture. For both large and small organizations, Close recommends starting with cryptographic discovery: identifying where encryption is used, classifying data by sensitivity and longevity requirements, and prioritizing migration based on risk.

Key takeaways

  • →Attackers are harvesting encrypted data now specifically to decrypt later when quantum computers become capable, creating a 10-15 year window of retroactive vulnerability for sensitive data.
  • →NIST standardized the first three quantum-resistant algorithms in August: Kyber (key exchange), Dilithium (signatures), and Sphinx+, which are already in production use by Google and Cloudflare in hybrid implementations.
  • →Crypto agility - designing systems where encryption algorithms can be swapped without full re-architecture - is critical because future quantum-resistant algorithms will eventually be broken too, requiring ongoing algorithm flexibility.
  • →Organizations must start with cryptographic discovery and data classification to identify where encryption is used, how long data needs protection, and which assets (satellites, financial records, IP) require immediate post-quantum migration.
  • →Even small and mid-sized businesses have a clear path forward starting with hybrid encryption approaches and cryptographic audits, rather than waiting for perfect quantum-safe solutions to be universally available.

Guests

David Close

Topics in this episode

Crypto agilityPost-quantum cryptographyHarvest Now Decrypt Later attacksNIST post-quantum standardizationQuantum computing threat to RSA and elliptic curveKyber algorithmDilithium algorithmSphinx+ algorithmHardware Security Modules (HSM)Hybrid encryption

Questions this episode answers

Why should companies worry about quantum computing if quantum computers won't be powerful enough to break current encryption for 10-15 years?

Nation states and criminal actors are harvesting encrypted data now with the intention to decrypt it once quantum computers become fault-tolerant, making today's encrypted data vulnerable decades into the future. Satellites, financial records, and intellectual property that must remain secure for 10+ years are at particular risk.

What are the new quantum-resistant algorithms NIST standardized and are they ready for production?

NIST released three quantum-resistant algorithms last August: Kyber (for key exchange), Dilithium (for digital signatures), and Sphinx+. Organizations including Google and Cloudflare are already deploying these in production, typically in hybrid models combining them with elliptic curve encryption.

What is crypto agility and why does it matter for post-quantum cryptography?

Crypto agility refers to designing systems where encryption algorithms can be rapidly swapped without requiring complete re-architecture of code and hardware. It matters because post-quantum algorithms will eventually be broken too, so organizations need to plan for ongoing algorithm transitions rather than assuming one fix will last indefinitely.

What is the first step small and mid-sized businesses should take to prepare for post-quantum threats?

Cryptographic discovery is the starting point: identify all places where encryption is used, classify data by sensitivity and how long it needs to remain secure, and prioritize migration based on risk level of specific assets or data categories.

How do hybrid encryption approaches work and what advantage do they provide?

Hybrid encryption combines two algorithms, such as elliptic curve plus Kyber, maintaining smaller key sizes while ensuring that if one algorithm is broken, the data remains protected by the other, providing redundancy against unexpected cryptographic weaknesses.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C56%
  • Speaker B32%
  • Speaker A12%

Most-used words

algorithms47cryptography42quantum41cryptographic28data28futurex21today20industry18space18cybersecurity17security16different15career13systems13future12post12

Episode notes

Get your FREE Cybersecurity Salary Guide: David Close, Chief Solutions Architect at Futurex, discusses the reality facing our digital world: quantum computing will soon break the encryption protecting everything from mobile banking to satellite communications. But here's the twist - hackers aren't waiting. They're harvesting encrypted data now, betting that quantum computers will eventually crack today's "unbreakable" codes in a strategy called "harvest now, decrypt later." David explains how NIST's new post-quantum cryptography standards are already being deployed by companies like Google and CloudFlare, why crypto agility is essential for future-proofing your security infrastructure, and how you can break into the exciting field of cryptography - even without a PhD in mathematics.

Full transcript

44 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Today on um, Cyberwork is all about cryptography. As quantum computing moves towards reality, attackers are beginning to take a harvest now decrypt later approach to hacking and theft, betting that advances in computing technology will eventually allow them access to today's very strong cryptographic algorithms, which nevertheless would be no match for quantum computing enabled decryption. Is this 10 years down the road? Later, a lot of hackers have chosen to play the long game. And to find out what the cryptography innovators of today can do to create the next generation of quantum built cryptographic algorithms and how you can get into this work yourself, please tune in to this week's episode of cyberwork. The IT and cybersecurity job market is thriving. The Bureau of Labor Statistics predicts 377,500 new IT jobs annually. You need skill and hustle to obtain, uh, these jobs of course. But the good news is that cybersecurity professionals can look forward to extremely competitive salaries. That's why InfoSec has leveraged 20 years of industry experience drawing from multiple sources to give you Cyberwork listeners an analysis of the most popular and top paying industry certifications. You can use IT to navigate your way to a good paying cybersecurity career. So to get your free copy of our Cybersecurity Salary Guide ebook, just click the link in the description below. It's right there near the top, just below me.

Speaker B: You can't miss it.

Speaker A: Click the link in the description and download our free Cybersecurity Salary Guide ebook. Your cybersecurity journey starts here. Now let's get the show started. Welcome to this week's episode of the Cyber Work Podcast. I'm your host Chris Sanko. My guests are a cross section of cybersecurity industry thought leaders and our goal is to help you learn about cybersecurity trends and how those trends affect the work of InfoSec professionals as well as leave you with some tips and advice for breaking in or breaking or moving up the ladder in the cybersecurity industry. Um, my guest today, David Close is chief Solutions Architect at FutureX and he leads the strategic vision and innovation uh, of advanced cryptographic and key management Solutions. With over 16 years at Futrix, he has driven global expansion through visionary leadership and deep expertise in enterprise security architecture. Under his guidance, the Solution Architects team has evolved to meet the demands of international projects, uh, scaling up to deliver success globally. David's forward thinking approach and meticulous planning have been critical in implementing cutting edge cryptographic infrastructures trusted by Fortune 100 companies his initiatives have bolstered Future X's ability to provide top tier security solutions and set new standards in compliance and operational excellence. As a respected figure in the cryptographic community, David's influence extends beyond architecture to encompass the management of FutureX's project product roadmap, ensuring alignment with evolving security needs. He holds a Bachelor of Science in computer engineering from St. Mary's University, San Antonio, Texas and is certified to audit cryptographic infrastructure across industries. His interdisciplinary experience enables him to deliver innovative solutions, seamlessly blending business requirements with technical demands.

Speaker B: Uh, so as you can imagine from uh, that bio, I would be remiss if I didn't talk to someone about uh, who's an expert in cryptography, about cryptography. And that's what we're going to do today. We're going to talk really high level cryptography stuff, stuff post quantum, uh, and what that's going to mean for the entire affair.

Speaker A: So David, thank you for joining me today and welcome to Cyber work.

Speaker C: Hi Chris, it's nice to meet you and uh, that was a mouthful but I appreciate you going to my background.

Speaker A: My pleasure.

Speaker B: Yeah, well strap in because I have

Speaker A: a lot to ask you about your background here.

Speaker B: Uh, so yeah, I want to first of course always ask our guests about your early years. I'm guessing from the sort of like tech intensive person you are now that you've been sort of a tech fan since you were a kid.

Speaker A: What was the initial spark that got

Speaker B: you excited about computers and security?

Speaker C: Yeah, I've always been into tech. Growing up I was one of those kids who took apart electronics just to see how they worked. Um, I'm sure I broke more than I fixed. But the curiosity is what got me started. Um, in college I studied computer engineering and I found myself really drawn to embedded firmware development, which is low level programming that interacts um, directly with hardware. So that was the initial spark and it felt real hands on. Uh, from there I moved into the cryptographic system space, specifically devices called HSMs, hardware security modules, which is what FutureX manufactures. These are hardware based cryptographic subsystems and that's what really launched me into the cybersecurity space.

Speaker B: Yeah, I was going to say because uh, normally my second question to our guests is I go through their LinkedIn profile and say how did you get to where you are now? Because a lot of times they start here and then they zooch over here and then they take a turn, get some, you know, whatever. Uh, but you know, as you basically said you got a Bachelor of Science, computer engineering from St. Mary's University and then immediately founded or joined FutureX as

Speaker A: a chief solutions Architect and haven't looked back.

Speaker B: So uh, yeah, talk more about this.

Speaker A: You've been here for 17 years. What is your role as Chief solutions Architect all about? And is it true the company's been around for 40 years?

Speaker C: Yeah, the company FutureX has been around for 40 years and I've been lucky enough to be with them for I guess the last 17 years of those. Just uh, yeah, but I didn't join as the Chief solutions architect. Um, that's where I ended up. Uh, but I started doing embedded development for our next generation HSM platform at the time. So FutureX builds cryptographic infrastructure that includes HSMs, key, uh, managers, PKI systems, tokenization systems, the whole stack. And so my role today is a mix of strategy, architecture and standards work. I represent us on various standards bodies and I help and oversee with our product and service roadmap, um, particularly around new areas like post quantum cryptography which um, hopefully we get to spend some time on most definitely. And I also work with customers uh, in designing their systems in a secure um, in a secure way. And Again I represent FutureX on multiple different bodies, um, that dictate how crypto is actually implemented. Um, so it's a role that's both technical and outward facing as well. And I love the balance of both.

Speaker B: Yeah, yeah. Okay. So uh, what aspects of the technical. I mean I'm assuming that you have to be staying on top of different aspects of cryptography as the person who's um, studying or examining what needs to be done to implement a solution rather than someone who is uh, I don't know, working in the trenches so to speak. So what aspects of cryptography and cryptographic solutions are you learning about at this moment?

Speaker C: So Futurax, uh, we are much more into the practical application of cryptography. There are a lot of academic research firms and cryptographers that go into developing the algorithms that are implemented. But, but at FutureX we implement those algorithms in a practical way. Cryptography is used everywhere in almost all enterprises and how they actually get implemented is something that people don't realize is a very um, involved uh, uh, strategy. And so we help with um, taking protocols and algorithms that have been approved and standardized in the industry and look at how they're actually implemented inside organizations so they can actually take advantage of them.

Speaker A: Okay.

Speaker B: Now I guess just as a brief, I don't know if history lesson is right, but sort of your view of it, uh, I think when people think of Cybersecurity, uh, and so forth. Going back 40 years to think of some of these things. We talk about sort of modern pen testing kind of happening in the early 2000s and certain aspects of what are sort of standard practice cybersecurity now happening in kind of the mid 2000s or early 2000s. What was cryptographic, you know, what was FutureX, uh, doing in, I guess it would be the 1980s. Uh, and how has that changed in the past 40 years?

Speaker C: Yeah, so I mentioned earlier that FutureX, uh, is a manufacturer of hardware security modules. HSMs were originally developed for cryptography in the payment space. So in the 80s when online transaction processing was becoming big, um, a device was invented called the HSM that would handle all of the cryptographic operations around payments. And that's when we originally started um, getting into encrypting data that was used for settlement, online transaction processing, issuance of, of card material, encrypting pins and cardholder data and all of that. And the technology grew to be used in general purpose enterprise settings for everything from databases, PKI, encrypting, email, you name it. HSMs are involved uh, somewhere. So we grew outside of just the payment Space and our HSMs, um, today are used all over the world and pretty much any vertical that you can name. But the origin of it was in the payment space. If you think about it, securing payment information, um, that is tied to money is always important. Um, then um, it expanded from there.

Speaker B: When you left St. Mary's with your computer, uh, engineering degree and you joined FutureX, uh, in this space, the payment space and the cryptographic space, were you already very deeply invested in cryptography or did you have to become invested in cryptography by joining Future X? Was it, what was, what was the chicken and egg situation here? Did you, were you already interested in this and you said I have to get myself into Futurix or did Future X come along and you're like okay, now it's time to start hitting the books about this stuff.

Speaker C: Yeah, so I did have some experience with cryptographic algorithms and practical applications for cryptography just from my academic career. But my goal when I started with FutureX was actually uh, doing embedded Linux development. Um, and FutureX was perfect for that because they made cryptographic modules and hardware that executed it. So I was really in my comfort zone there. But um, I didn't come with a, uh, deep background in cryptography, but what I did have was a strong curiosity and a desire uh, to, to learn. Uh, and what I found pretty quickly was that I landed in exactly the right vehicle, uh, to grow my career. I think that sometimes people underestimate early on how important it is to find the right environment that aligns with your interest and pushes you technically and it gives you the room to evolve. And for me, FutureX was that place. So uh, it challenged me honestly to understand cryptography at a very fundamental level, um, including how keys are generated, stored and exchanged and why all of that matters in securing digital, uh, payments and digital data in this new world.

Speaker B: Did you have a particular, uh, mentor or supervisor there that was really sort of influential in helping you get up to speed that quickly, or were you kind of left to, uh, self study your way into, um, mastery?

Speaker C: I think the culture at Future X is very unique in that we have very, very talented engineers, very talented cryptographers, and uh, different individuals that manage our products. So I would say my mentor as a whole was all of the different, um, talents that we had at Future X. And it really helped skyrocket my career and helped me get involved in projects that I could have never, um, even dreamed that I would be involved with.

Speaker B: Well, we're going to talk about some stuff that I think our listeners would give anything to be involved with. Uh, we have a lot of students and a lot of entry level people who are, um, chopping their careers trying to figure out where they want to go first, where they want to go next. Uh, and you know, obviously cryptography, uh, is not one we get on the show very often because it's uh, not done by a whole lot of people. But, uh, I want to start out with, uh, one of the more unusual aspects of this discussion. Uh, one of the first things that jumped out at me was the phrase post quantum cryptography initiatives. Uh, so you note that enterprises will be forced to start preparing for threats from quantum computing enabled threat actors in a timetable that's maybe not some years down the road, but within the next few years. Whatever the distinction is there. So to start with, uh, David, could you catch us up on the state

Speaker A: of quantum computing at the moment and

Speaker B: why you think the gains being made will be weaponized sooner rather than later?

Speaker C: Yeah, I think one of the key things to understand about quantum computing and quantum cryptography, um, is that it fundamentally changes the math behind our current encryption. So algorithms that we use today, things like RSA and elliptic curve, they rely on problems that classic computers struggle with, uh, like factoring large numbers or solving discrete logarithms. But with quantum compute computing architectures, the architecture is completely different and they're very well suited to, to solve these problems in a fraction of the time. So essentially quantum computers break the algorithms that we rely on heavily today. Things like mobile banking and online banking, um, transaction processing, securing data between one entity and another, health care records, everything in our lives rely on these algorithms. So today, right now, quantum machines aren't, aren't powerful enough to break these uh, these algorithms, they're, they're noisy, they're in their infancy, they're, they're limited in scale. Um, companies though, uh, like IBM M and Google, they're very focused on rapidly increasing something called qubit counts, uh, which is, is really what the um, essence and the foundation of quantum computing is, is, is about, but estimates. They're suggesting that we might have fault tolerant quantum computers capable of breaking RSA 2048 bit, um, encryption within 10 to 15 years and possibly sooner. No one really knows right now.

Speaker B: Right? Yeah, now, uh, I don't know, maybe our listeners already know this, maybe I'm asking this for myself, but I think someone will want to know this. But like can you talk about, you know, when we talk about, you know, encrypt your data, you know, if you have a, you know, a vpn, you've got encryption, you know, no one's going to get through there, no one's going to be able to commit a man in the middle. Can you talk about like what is actually happening in terms of what can um, you know, what can realistically be done by a hacker with a more standard computer versus what the sort of like higher order sort of computing functions involved with like a quantum computer is that would actually be able to break something as sort of staggeringly complex as even a basic, you know, cryptographic algorithm.

Speaker C: Yeah, so I think your question is around, you know I mentioned quantum computers are still a number of years off, so why worry about it today? Yeah, because class can't be. Computers can't break these, these algorithms. The, the issue that we have and the, the, the urgency that we have is around the fact that the industry as a whole know, they know quantum computers are coming. And because of that nation states and just bad actors are preparing for that, that deployment. And they're doing it in a way where um, they're harvesting data now, encrypted data and storing large quantities of it, terabytes, petabytes of data with the intention that once quantum computers get to a place where they can decrypt this data, um, they have the data ready to decrypt. Because of that, there are organizations that have data that need to stay Encrypted and stay private for much more than 10 or 15 years. They're now deploying these algorithms. Um, initiative for looking at new algorithms uh, that are resistant to quantum attacks started in 2017. NIST issued their competition where they started looking for submissions of algorithms that were not susceptible to known quantum attacks. They just released last August, um, and ratified the first three algorithms that um, were resistant. Um, Dilithium, Kyber and uh, Sphinx plus were the first three. The problem with these algorithms is um, they have a much bigger key size and the digital signatures that they create are much bigger than RSA or elliptic curve, uh, signatures and keys and so on. All of the different protocols that we use today that utilize these algorithms are having to be rethought and re engineered, things like tls. So if you go to a website that has HTTPs, that protocol that's used to encrypt that data is having to be re looked at in order to support these new algorithms. So a lot of companies are looking at hybrid algorithms where they utilize something like Elliptic Curve plus Kyber in order to secure data. So that gives you kind of the best of both worlds. It prevents um, the issue that we have of larger uh, signatures and key sizes, um, but also if elliptic curve is broken you still can rely on Kyber. So gives you the best of both worlds. A lot of organizations have started deploying that type of hybrid encryption approach with um, web traffic. Google, um, and Cloudflare, they did a great case study and actually implemented it in a real life scenario. You're probably using it today and don't even know it. Yeah, I don't know much. It was very successful.

Speaker B: Okay, now I want to go back to sort of steal now encrypt or you know, decrypt, uh, later. Uh, because like a comparison that it made me think of was all the people, you know, maybe they're still doing it, but people who would uh, freeze their body when they were about to die with the idea that you know, science will get better X number of years down the road and whatever they're dying of now, they'll be able to revive. I mean realistically, like what, what, what level of gamble are people who are stealing these petabytes, uh, of data, you know, with the idea that 15 years down the road Quantum is going to be you know, riding to the rescue. And also like is that 15 year old data still going to be of

Speaker A: any use to anyone?

Speaker C: Um, I think it really depends on the industry. So we work, I mentioned earlier with a lot of different verticals if you think of something like a satellite that is launched, uh, into orbit, these satellites have a much longer lifespan than 10 or 15 years.

Speaker A: Sure.

Speaker B: Okay.

Speaker C: And attackers are just waiting for, uh, quantum computers that are fast enough and fault tolerant enough in order to decrypt this traffic or make fake signatures that allow them to change the software running on these satellites. So it's a very real, um, problem that exists today and it's really dependent on the industry. Things like, um, your financial records, they will need to be secured 10 or 15 years from now. Um, but other data, a text message to your wife maybe that's not as important. So there are verticals and there are use cases where that 10 to 15 year mark is a problem. Um, I think unlike the freezing your body and getting ready to, you know, find a cure for whatever you have in the future, the difference there is the data that they're harvesting that doesn't decay. Right. But the algorithms that secure it, they do decay. And there's no question that the algorithms that we have now will, uh, be broken.

Speaker B: Okay.

Speaker C: The challenge that a lot of our customers and partners that we work with, uh, face is just because we're moving to new algorithms with post quantum cryptography and we're implementing these, that doesn't really solve the problem because at some point in the future, post quantum algorithms will also be broken. So where future X really helps, um, the industry is looking at ways to implement something called crypto agility. Designing systems where algorithms can be changed very quickly without having to re architect all of your solutions, all of your code and hardware that implement these algorithms.

Speaker B: Yeah, that makes sense. Obviously every story of cybersecurity is a story of, ah, escalating arms race between the hackers and the defenders. And okay, now we have more of this. Now we have more of this and it keeps going back and forth. That makes sense. Um, now if for the companies that have already had this encrypted data harvested and you know, is this like a 15 year ticking time bomb where they're just, they're waiting for the inevitable to happen, like what, what can they do in the meantime with, with the data that's already been stolen, or is that just sort of a horse is out of the barn, nothing to be done about it now kind of thing?

Speaker C: Yeah, I think what organizations are doing now is looking, they're looking at algorithms that solve this problem. I mentioned, um, nist, the competition, and last August they, they publish new algorithms that are quantum, ah, resistant. Um, and organizations are deploying those today. There are a Lot of systems and hardware and architecture and protocols that need to be updated. Organizations are indexing where they use cryptography in their industry or in, uh, their company. And they're classifying this data. How important is this data? How long does it need to stay secure? Um, what's the risk level involved? And once all of this is indexed, then they can then prioritize from a project standpoint what needs to be addressed first. Again, text messages to your wife may not need to be the priority there, but satellites, absolutely. Or even intellectual property that you're managing. And it's really the value of your company that is going to still need to be secured in 10 years.

Speaker B: Yeah. And 15 years from now we're all going to know what the 11 herbs and spices were, in case I just know it. Okay. Anyway, sorry about that, uh, onward here. So, um, I want to talk, uh, as you said, about the scale of it and obviously the scale of what's valuable and what's not. I think there's also something to be said about scale in terms of the size of the target. I mean we know now that everyone's a target, even small medium businesses are a target. And we hear things like, you know, state cities and municipalities saying, oh, they wouldn't hack us, we're too small, or you know, what would they get from us or things like that. So, uh, you know, it's hard to know what to do if you're one of these small medium businesses and you hear these kind of apocalyptic tech warnings. So, uh, where do you see post quantum encryption and defense progressing in the coming years, uh, from like a scalable perspective towards sort of smaller targets like that? Is there certain things they should be doing now to make themselves safer?

Speaker C: Yeah, you know, I think for small and mid sized businesses and even larger enterprise, it can feel overwhelming. Um, I mean the good news is there is clear, there's a clear path forward. Um, first, as I mentioned, we've already seen real adoption of quantum safe algorithms. Kyber for key exchange and dilithium for signatures being standardized by NIST and large organizations like what I mentioned earlier with Google and Cloudflare, they're already using these in production in hybrid models. Uh, so for any enterprise big to small, the most basic starting point is cryptographic discovery. Knowing where you use cryptography, you need to know where encryption is used in your environment. And that is everything from tls, so data in motion, uh, to file and storage, uh, data at rest, and then prioritize those systems. So nist, when they published these new algorithms in Addition to publishing algorithms, they also published guidance on a roadmap for how to implement these algorithms. And there was a very big focus on um, inventorying where you use cryptography because it's not uncommon for a large organization or even a small organization to have hundreds of different applications that all use cryptographic libraries. They use encryption to secure data and oftentimes they may have some one off developer that looked online for some method to encrypt data and implemented something off sourceforge or something like that. So knowing where you implemented cryptography is important and then focusing on crypto agility, where you can change the algorithms that you use every day, um, very quickly. So um, also making sure your vendors like, like us are, are have a roadmap for supporting uh, new algorithms and are very focused on that because at the end of the day you rely pretty heavily on vendors to uh, for your cybersecurity infrastructure and that includes encryption and cryptography. So there needs to be uh, views there to make sure they have a roadmap to help you secure this data.

Speaker A: Yeah, I have to imagine that if

Speaker B: you're a, you know, a vendor that's, you know, mostly using, you know, retail and taking payment and, and so forth, like you're pretty much setting and forgetting your uh, you know, your sort of Shopify store or your payment software or whatever. So I suppose it probably behooves you to be asking the people who are doing the, you know, encrypted services for you, what exactly do you need to know from me? Or what can we do to make this better? Is that probably true?

Speaker C: That is very true. A lot of these more sensitive use cases are regulated by uh, bodies that define what algorithms can be used and how long these algorithms can be used and what key sizes you have and all of these different nuances. I would say all of these regulatory bodies are focused on these new post quantum algorithms and how they are, um, implemented in each individual industry. And that could include, you mentioned payments. That is true for payments. But many other regulatory bodies as well are focused on this. Everything from telecommunications to just different government regulatory bodies are very focused on this.

Speaker B: Yeah. Now um, I want to move on to the sort of career aspects of these things because again as I said, we are people who want, you know, people who are just starting to sort of lower the bar to entry if you're, if this is something you're interested in. Uh, so I want to get your advice on how you kind of keep up to speed on the advances in cryptographic technology or maybe it's FutureX who's doing the good writing or research on this topic right now? Who would you recommend our listeners be following each week to see sort of what's, what's happening in the space?

Speaker C: Yes, I mentioned NIST earlier and I would say NIST is probably the most active in terms of relevant um, papers that come out and guidance on how to implement this. But there are a lot of other bodies to follow as well. Um, the PKI forum. PKI is what is used to uh, secure identities, everything from websites to IoT devices. Um, they have had many uh, different forums and conferences where they have guest speakers come in and look at it. Um, there was one last year in Austin, Texas, um, and there was an individual named Scott, uh, Aronson that came in, um, out of the University of Texas. He is a great individual to follow. He's one of the leading voices in quantum computing and he does an excellent job of really breaking down complex concepts, um, in a way that's both technical and uh, deep and accessible. Um, beyond that, uh, I really like blogs and publications from pq Shield is a good one to follow and the Open Quantum Safe Project. Um, they both do a good job covering the practical side of implementing post quantum cryptography. Um, what works today, uh, what to watch out for and, and how to start experimenting in real environments. It's a fast moving space but honestly just carving out an hour to a week to stay current on these sources can make a huge difference and having uh, you stay ahead of the curve.

Speaker B: Yeah, that's great. That's a goldmine. That's exactly what I was hoping for. Thank you. So, um, turning to the type of work that someone just getting started in the space would do, I've heard from past guests and you can maybe corroborate that there's really kind of only a handful of brainiacs in the world that are really doing the sort of top, top level like creating these quantum grade crypto algorithms and solutions. But there's plenty of jobs in and around cryptography like implementation as you do or tool building or security engineering or architecture or grc.

Speaker A: Can you talk about the type of

Speaker B: work that people who are really into learning cryptography can get?

Speaker C: Uh, absolutely. And I think, you know what, if you are a mathematician and you have the wherewithal to look at, uh, the fundamentals of how cryptographic algorithms work and want to develop those algorithms, M. That is a great space to be in and there is a need for that in the industry, but you don't need to be able to invent the next algorithm to work in this space. There's a massive demand for people who can implement test scale, uh, uh, cryptography securely. Um, that includes software engineers, uh, working on secure libraries, uh, DevOps, folks integrating crypto into CICD pipelines, and security architects that are building out key management systems. Um, in our industry we're very focused on HSMs, which, the presence of HSMs in the industry have grown immensely m over the last 10 years, 15 years. But uh, operational aspects of HSMs are a very niche skill set and having people that know what an HSM is or how they're implemented is very unique and is great for job security. But that's just one example. Cryptography is used in so many different ways and everything from architects to operational, um, implementers need to be uh, filled. There's positions that need to be filled out there.

Speaker A: Yeah.

Speaker B: Okay. So um, again turning back to very, very beginners or people who are still students. Um, you know, uh, this is always the hardest question, but where, where do you get the experience to get your start? You know, what would, what would you say to someone who has no experience, has learned the space? How do you stand out your resume? You know, are there certain projects you can do around cryptography that sort of shows your, your acumen? Uh, what would you recommend, what would, what would look, what would look appealing to you on an entry level person's resume or experiences?

Speaker C: I think mainly interest in cryptography is the biggest, the biggest thing they're following, um, industry publications, how the industry is changing, being familiar with how to use cryptographic tools and libraries, things like Open ssl, the Microsoft libraries, Java libraries. There's so many out there, it's a very intrinsic space. Um, but typically when you're looking at a career in cryptography, it's typically joined with something else.

Speaker A: Right?

Speaker C: You're a software developer, maybe implementing solutions around cryptography or using cryptography. Or maybe you're an auditor that wants to go in and get involved in helping organizations look at their deficiencies and helping solve those. So um, not only being interested in the cryptography, the underlying cryptography that's used, but also the, the actual core requirements. Uh, being a developer who is very interested in cryptography is something that would be appealing to Future X, um, and many other organizations out there.

Speaker B: Okay, that's great. That's, that's, that's excellent. VICE and it also, it makes it sound like um, you know, something, you know, it's, it's a little different than say something like digital forensics or pen testing. Where it's like that's the major. Whereas like the cryptography is kind of the minor. Like you add it to another major thing that you'll be doing and you can kind of like it's like an add on or something in certain ways. Unless you're like I said, you're really like in the heart of darkness.

Speaker C: Absolutely.

Speaker B: So speaking of that, I mean we talked a little bit about the future here. Uh, if and when the dust settles after you know, quantum computing really starts to break some of these algorithms. Where do you see, what do you see the landscape looking like in 15 years? Do you see sort of like quant counter quantum encryption sort of taking up the slack? What does the battle look like in the meantime do you think?

Speaker C: Well I think if you look at five years from now I think most enterprise systems will be running some form of either hybrid cryptography or just vanilla um, post quantum safe algorithms. Um and this is where classical and so hybrid is where classical uh, uh and post quantum algorithms are used side by side. We mentioned the use case earlier with tls. I think PQC support will be built into TLS stacks by this time. Uh, mobile operating system and cloud APIs. Um, it'll be part of a standard cryptographic toolkits that are used today. I think if we look 15, 10, 15 years out, I expect most high security systems will already have moved away from algorithms that are used today. Things like RSA and elliptic curve. Um, that's actually not just speculation. That's direction from NIST and, and actively guiding the industry. They've made it clear that ah, cryptographic community needs to begin phasing out RSA and elliptic curve algorithms in favor of quantum resistant standards. Um and those standards are already mostly adopted and they're adopting new standards as we speak. But um, by that point we'll have robust vendor support already. Um, we'll have mature tooling so libraries like I mentioned, open ssl, that will be the standard and um, they'll already now be operational experience uh running PQC applications today. Um, organizations are really craving experience with people that know something about post quantum cryptography and that knowledge can really help advance your career very quickly where 15 years down the line that will be the only option if you want to be in the cryptographic space space.

Speaker B: Okay, uh, now at the risk of unleashing my inner cynic, I know I've certainly talked to enough people about things like CMMC or um, uh, other sort of federal government things where there's a directive in three years we need to go, uh, completely zero trust or whatever. NIST says we need to phase out RSA and elliptic curve. Uh, is there an or else attached to that or is it going to be sort of on the, uh, on the good behavior of people who are using these algorithms. Do you think that there's going to be a stick with this carrot here?

Speaker C: In many deployments of cryptographic systems, um, there are requirements and certification that these cryptographic systems have to go through. I'll give you two examples. Um, we mentioned the payment space earlier. There's an organization, um, called pci, um, which governs the security around encrypting cardholder data and PINs and online payments. Um, I sit on the board of advisors, uh, for pci. And so in order to implement, uh, cryptography in PCI environments, you have to adhere to their, um, recommendations, uh, and actually be audited against those by third party auditors. Um, HSMs with feature X manufacturers are certified under PCI and adhere to their guidelines. So once PCI says no more RSA 2048bit keys, we have to adhere to that. And there's a stick there if I want to be able to run payment transactions.

Speaker B: Got it.

Speaker C: The second is, um, in Federal Systems, um, NIST does have a certification under FIPS. Um, so the current, uh, certification is FIPS 143. And they have different levels, level one, two, three and four. And uh, level three certifies hardware cryptographic systems like HSMS. And in order to um, uh, get audited and have a certified FIPS device, uh, you have to adhere to what algorithms are supported. So there are a lot of regulatory bodies that do have sticks, um, to enforce what algorithms use.

Speaker B: Okay. Yeah. So the biggest stick of all is basically do you want to accept payments or not use our new system or

Speaker C: do you want to sell products?

Speaker B: That's what I mean. Yeah, exactly. Do you want money for your products, yes or no? Yeah. No one's going to be sending cash in the mail anymore. So. Yeah.

Speaker A: So as we bring this episode to

Speaker B: the close, uh, David, and thank you for taking the time to explain all of this to us and especially to me, because I don't understand it at all. But I understand it better now.

Speaker A: But let me ask you a basic question. Uh, what's the best piece of a

Speaker B: career or life advice you ever received?

Speaker C: That's a good question. I would say the best piece of advice that I ever got, um, related to my career path was it's important to find the right vehicle for your career and doing it early. Um, I've been with FutureX for 17 years and there's a reason for that. Um, it's easy to get caught up in titles or flashy job descriptions, but the reality is your growth depends so much on whether you're in the right environment. Um, the right vehicle is a place that not only aligns with your interests, but it also challenges you and supports you and gives you a platform to evolve. Uh, one thing that I love about Future X is just the encryption is used everywhere in the industry. Futurax is involved in pretty much any vertical that you can think of. Whether it's telecommunications, payment, government use cases, you name it, we're in it. That really interests me and I thrive on learning and FutureX requires me to learn something new every day. Um, that's my interest. But other people have different interests. So I would say the best advice I ever got was find the right vehicle, whatever that is, earlier in your career, early in your career, and it will make you a more happy person and more, um, you will find a long career path if you can find that, that vehicle.

Speaker B: Great. Yeah, couldn't agree more. So, uh, just for fun and because I'm always curious, is there anything you've been currently reading or listening to or watching or playing that you would want to tell uh, us about that you're excited about?

Speaker C: Wow, um, I just finished reading the Age of AI um by Eric Schmidt and Henry Kissinger.

Speaker A: Um,

Speaker C: it's an interesting take on how the emerging technologies like AI and Quantum will reshape national security and policy, which we're very heavily in. Um, I also listen, I guess to Darknet, uh, diaries that's full of real world cybersecurity stories that are uh, educational I guess. Um, what else for fun? I've been watching the Peripheral. That's a sci fi, uh, that gets weirdly close to what the future might actually feel like.

Speaker B: Yeah, I was going to say it's always good to hear, uh, which ones are actually hitting the vibe and which ones are still using phasers and teleporters and things like that. So that sounds great.

Speaker A: So, uh, all right, well one last

Speaker B: request here, one last question.

Speaker A: Tell our listeners where to find out

Speaker B: more about David close and or futurex online.

Speaker C: Yeah, I mean the best place is, uh, futurex.com we have webinars, white papers, lots of educational content on cryptographic infrastructures and post quantum readiness. Um, you can also find me on LinkedIn, David Close at, uh, FutureX. Um, then I think those would probably be the best resources.

Speaker A: Great.

Speaker B: Yeah, look up David. Uh, all our listeners. I hope you'll, uh, get in touch there.

Speaker A: So, David Close, thank you for your insights.

Speaker B: This was such a fun conversation.

Speaker C: Yeah, thank you for having me. I really enjoyed our discussion.

Speaker A: Great. Uh, this has been another episode of the Cyber Work Podcast. Thank you for watching and listening. If you have any topics you'd like us to cover or guests you'd like to see on the show, drop them in the comments, make use of our YouTube community tab, or let us know by commenting on our TikTok channel. Uh, before we go, please check out infosecinstitute.com free for a wealth of free and exclusive things for Cyber Work listeners, you can check out our free Cybersecurity Talent Development Playbook, which has in depth training plans and strategies for the 12 most common security roles including Soc Analyst, Pen Tester, Cloud Security Engineer, Information Risk Analyst, Privacy Manager, Secure Coder, ICS Professional, and more.

Speaker B: Or take a look at our Cybersecurity

Speaker A: Salary Guide for the latest data on popular certifications and their related roles, as well as the average salaries for those roles. We've also got Security awareness posters, search study ebooks, and you can sign up for 100 plus free courses in a

Speaker B: free month of our InfoSec Skills platform.

Speaker A: You can learn incident response, forensic, Security

Speaker B: architecture, all of that.

Speaker A: So one more time, that's infosecinstitute.com free and one last time, thank you to David Close and FutureX. And thank you for watching and listening. This is Chris Anko signing off. Until next time, make sure to learn something new every day.

Speaker B: Thanks.

Speaker A: Keep one step ahead of the story and don't forget to have a little

Speaker B: fun along the way.

Speaker A: Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Prioritization Problem: Securing AI While Preparing for Post-QuantumThe Identity Thread by Entrust · on Post-quantum cryptography86 / 100
  • Securing Singapore: The CSA Quantum Safe Migration FrameworkShielded · on Harvest Now Decrypt Later attacks83 / 100
  • Is encryption enough to protect our data?Technology Now · on Post-quantum cryptography81 / 100
  • Max Levchin - Building Affirm, PayPal, and Why He Only Starts Network BusinessesFintech Leaders · on Post-quantum cryptography79 / 100
  • Not Caring About Code Signing is a Billion Dollar Mistake ft. Stefan WenigTrust.ID Talk · on Crypto agility77 / 100
  • Cyber News: Iranian Hacker, Quantum Ransomware and Rogue AIThe Audit · on Post-quantum cryptography75 / 100

More from Cyber Work

All episodes →
  • From stealing servers to saving lives: Working in red teaming | Jim Broome69 / 100
  • Working in ransomware response, investigation and recovery | John Price
  • From security audits to privacy consulting: Building a GRC practice | Will Sweeney
  • From "dead-end job" to CEO: Building an IT consulting business | John Hansman
  • From FBI Cyber Agent to Police Tech Innovator | Andre McGregor
Explore the best B2B Engineering & DevTools podcasts →
All Cyber Work episodes →