Shielded · 2026-08-24 · 39 min
Key moments - from our scoring
Substance score
63 / 100
Five dimensions, 20 points each
Singapore's Cybersecurity Agency has released practical guidance to help critical infrastructure and enterprise organizations prepare for the quantum computing threat to current cryptographic systems. Radhi Koch explains how the CSA positions quantum-safe migration not as an esoteric technical challenge, but as an operational one - reframing the threat (quantum), solution (cryptographic replacement), and implementation challenge (operational processes already familiar to IT teams). The agency published two companion resources in October 2024: the Quantum Safe Migration Handbook, which provides step-by-step guidance on identifying crown jewels, prioritizing systems, and implementing no-regrets moves; and the Quantum Readiness Index (QRI), a self-assessment questionnaire that helps organizations understand their current maturity level and identify next steps. Koch emphasizes that quantum-safe migration involves standard IT processes: inventory management, asset mapping, crypto discovery, risk assessment, and technology refresh planning. The guidance covers five domains - risk assessment, governance, technology, training and capability, and external engagement - designed to integrate quantum-safe work into existing organizational cybersecurity and business processes rather than treating it as a separate initiative.
The QRI is a self-assessment questionnaire released by Singapore's CSA that helps organizations understand their current quantum-safe maturity level and identify the specific actions needed to progress to the next level, serving as a conversation starter with senior management and a companion to the Quantum Safe Migration Handbook.
The five domains are risk assessment (identifying crown jewels and quantum risks), governance (establishing accountability and alignment with business objectives), technology (selecting appropriate quantum-safe cryptographic solutions), training and capability (building organizational skills), and external engagement (working with vendors and stakeholders).
Cryptography is pervasive across systems - used in TLS, key exchange, digital signatures, smart cards, and credit cards - but often invisible to organizations; discovering where public-key cryptography exists, in what context, and whether it's critical becomes a massive undertaking that must be completed within tight timelines.
The CSA reframes the challenge as operational rather than technical: the threat is quantum computing, the solution is cryptographic replacement, and the implementation involves standard IT processes like asset management, inventory maintenance, and system updates that most organizations already perform.
No-regrets moves are immediate first steps organizations can take toward quantum-safe migration that provide security benefits regardless of when quantum computers become a practical threat, such as implementing TLS 1.3, updating configurations, and beginning crypto inventory work.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode provides useful frameworks for approaching quantum-safe migration (threat vs. solution vs. operational challenge; five domains: risk assessment, governance, technology, training, external engagement), but much of the substance is repeated explanation of these concepts rather than novel insights. The guest articulates the operational nature of the challenge well, but rarely ventures into unexpected territory or specific technical trade-offs that would surprise a informed operator.
The threat is quantum, the solution is cryptographic, and the challenge is operational.
these are actually standard foundational, um, processes that I think as a Korea Games would somewhat
The framing of quantum-safe migration as a standard IT asset management problem is sensible but not novel - the episode largely recycles existing industry consensus (NIST standards, timeline alignment with US/EU, the need for vendor engagement). The five-domain structure is useful for organizations but represents conventional cybersecurity practice applied to a known problem, not fresh or contrarian thinking.
we have been a national cybersecurity agency
these are actually standard foundational, um, processes
Radhi Koch is a credible practitioner with relevant background (mathematics degree, cryptography master's, mobile security startup experience, product certification role at CSA) and holds a genuine policy-making position as technical lead for Quantum Safe at Singapore's national cybersecurity agency. He has done substantive work (releasing guidelines, migration frameworks) but the episode doesn't probe deeply enough into his hands-on implementation experience or hard-won lessons from specific projects.
Radhi Koch, the lead cybersecurity consultant and the technical lead for Quantum safe at the Cybersecurity Agency of Singapore
I began ensemble in that sense in defense science and subsequently I decided to pursue my master's also in cryptography
The episode provides concrete timelines (March 2027 for migration plans, 2028 procurement requirement, December 31, 2031 completion deadline) and names NIST 2024 standards and the QRI/Handbook tools, but lacks specific company examples, named products, adoption metrics, or detailed case studies. The discussion of public-key cryptography (RSA, ECDSA, ECDH) is generic; there are no real-world failure modes, vendor landscape specifics, or performance benchmarks cited.
by March of next year 2027 they need to submit their condom safe migration plans to CSA
from 2028 onwards, procurement and implementation of new computer and computer systems uh, for these cris only they have a digital component
The host asks reasonable follow-up questions and attempts to clarify frameworks, but rarely pushes back or challenges assumptions. Questions are largely invitational rather than probing - e.g., asking about 'no regrets moves' rather than testing the feasibility of the five-year timeline or pressing on vendor readiness gaps. The host does not surface tensions (e.g., between voluntary guidelines and compliance pressure, or between interoperability and national sovereignty) that would deepen the conversation.
So help us tie all this into your mission with the csa
So if I'm in an organization listening to you explain this today for the first time, then my next step of action would be to go to the CSA website, download the qri, uh do the self assessment and then take that as a conversation starter into my organization. Right.
Computed from the transcript - who did the talking, and the words that came up most.
The Cybersecurity Agency of Singapore (CSA) serves as the national coordinator for protecting the digital foundations of the nation. Protecting essential services like telecommunications, finance, and energy requires a transition to quantum-safe cryptography before existing standards become vulnerable. This effort involves coordinating with both public and private stakeholders to ensure the digital economy remains resilient. Roddy Kok, the technical lead for Quantum Safe at CSA, explains the specific operational hurdles organizations face when replacing pervasive cryptographic components. He outlines the utility of the Quantum Safe Migration Handbook and the Quantum Readiness Index (QRI) as resources for organizations to assess their current posture. The conversation covers the necessity of aligning with international standards to maintain seamless global connectivity and trade. What You’ll Learn Why quantum readiness centers on operational execution rather than theoretical physics. The structure of the five core operational domains for migration. Specific deadlines for critical information infrastructure owners starting in 2027.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Crypto is the last thing you expect to fail.
Speaker B: Welcome to Shielded, the Last Line of Cyber Defense by PQ Shield, the podcast where we are moving the conversation around post quantum Cryptography. From the why to the how, let's future proof your defenses together. Welcome back to the podcast. Today we're joined by Radhi Koch, the lead cybersecurity consultant and the technical lead for Quantum safe at the Cybersecurity Agency of Singapore, or CSA for short. Roddy has a remarkable background spanning defense science, commercial, mobile startup, cryptography, and cybersecurity certification. Roddy, welcome to the podcast.
Speaker A: Thank you, Joe.
Speaker B: It's great to have you. I think this took a little while to come together. I think the first time we spoke about this was in October 2025, right around the time that you released the first version of your guidelines.
Speaker A: Yeah, the day has been quite, uh, a while. I mean, so much things happened over the past half a year and I'm glad that we can get around to doing this. Of course, there's a lot more things going on in this space and we're happy that we get to share our thoughts and, uh, our work.
Speaker B: That's great. And I think if we were to start summarizing what has happened in just the last six months, it would probably be enough for more than one episode of the podcast.
Speaker A: Yes.
Speaker B: Given especially the acceleration that we've seen to the topic just over the past few weeks, with Microsoft now also joining the 2029 club, as we like to call it. I believe just a few weeks ago, you were at the, uh, Etsy conference.
Speaker A: Yes, I was in, uh, Ottawa, the beautiful place, and happy to be at the conference again. And from what we saw, definitely we felt that there was this acceleration. The timelines are all aligned, uh, falling in place. And the concern has shifted much more to how do we meet these timelines rather than when it's Q Day. I mean, of course we're still concerned when Q Day will be, but that is no longer the main preoccupation. I mean, in a way, some of these activities are naturally kind of driven by this type of compliance pressures, we might put it. But it's amazing to see how year on year, just a matter of 12 months from the last conference, and to see how things have moved, shifted. These are amazing domain to be in right now. Yeah, very dynamic, Very much so. I'm sure over the next five, 10 years, we'll probably see things speed up and heat up much more.
Speaker B: Uh, so the Etsy conference being in Ottawa for you was a little bit like coming home too, right? I think you spent some time there.
Speaker A: Yeah, I did my master's at University of Waterloo and uh, not too far from Ottawa and it's always nice, even though it's a long flight from airport, but it's always nice to be back to enjoy your hospitality in Canada.
Speaker B: So give us a little framing and a little summary of what got you into the position you hold now with the csa. I know it wasn't necessarily a very straight line. You had some exciting experiences in the startup world and defense use cases. So I'm curious to hear you share a little bit of that story.
Speaker A: Yeah, thanks. Well, I've always kind of enjoyed learning about math and uh, went on to do. Started off doing my degree in mathematics and naturally being interested in this sudden bow type of uh, discrete math, algebra and our theory. Cryptography had a protraction being the field that brings all this together and it actually puts all these supposedly, uh, more esoteric things into actually practical use and it's actually used to secure our world. So Big Droid was exciting and it's challenging. So I began ensemble in that sense in defense science and subsequently I decided to pursue my master's also in cryptography learning, you know, advancing my understanding of these things. And subsequently I went to work in a mobile security startup to actually put this into practice, to actually get to the development side of the applied side of. Yeah, yes, yeah. And then there I saw the challenges of actually when it's not just from the textbook, I mean the algorithms are there, but actually how do you put these things in? You worry about performance, how do you control the access, how do you manage your keys is not just one key that does encryption, but it's actually a series of keys, uh, hierarchy of them. And how do you manage them, distribute them and handle the life like that was actually pretty much eye opening. And I true that learned a lot more about actually the practice of actually
Speaker B: handling crypto and really other challenges and limitations in an actual life system.
Speaker A: Yeah. Uh, so subsequently I joined CSA as a certifier because we're certifying products. Cryptography is actually at the heart of this and there's a need to make sure that the algorithm embedded correctly and robustly and don't understand how this thing ties in with the rest of the security of the product. So there's a fit for this. And I was able to put into practice and apply what I've learned previously into now, now into the product certification realm actually to try to help uh, achieve security assurance from the Products that we use. And with regards to Quantum, I like to share that as a uh, cryptographer we learn about attacks eventually they will want to defend against. And then that was at the turn of the millennium. Um, this new attack was actually supposed to be able to break things that we would deem as secure. Traditionally it's like factoring is difficult and we are supposed to be able to secure our comms and our digital activities through just the uh, RSA alone. But then here there's this thing called a quantum computer, seemingly just a theory back then, but can actually undermine all this. And it was very intriguing. And so that during my time about lui, try to pick up a bit more of that and being also at a heart of quantum activities in Canada, that helps. And subsequently now in these recent years when we see that this is, the quantum computing is coming to, is really being built, scaled up and it becomes a reality that our crypto is going to maybe broken soon with these things. And hence I found that this was a good time to get into this space and also put together, try to apply what skills I have and this and help balancing out work in this
Speaker B: space, tying that in into a bigger mission. And I think you're raising an important point because you said it's important to make sure that the implementations are actually secure and hold against those attacks, known attacks, but then also new attacks. And I think that still holds true today. Having a strong set of primitives available is one thing, but having really solid implementation is yet another thing. And typically I think you would probably agree to this. It's the implementation that's got to break first before someone actually brute forces the actual underlying primitives. Right?
Speaker A: Yes, indeed. When we typically, when we discuss this trap we think about the algorithms. Algorithms need to be secure. And then recently we have the standards that have been published in 2024 by NIST and which is extremely useful. But the story doesn't end there.
Speaker B: It's a starting point.
Speaker A: Yes, I like to think of it as the, it's not the beginning or the end, it's actually the end of the beginning. We actually have still a lot more things to do Standardiz. How do these algorithms actually fit into our uh, protocols? How do these protocols get. They need to be standardized and then they need to be implemented and then securely, hopefully and then also certified. So there's actually still a series uh, of things that needs to be done before organization can do their integration and put this into operation.
Speaker B: That important last step of the third party validation and the certifications right there's an external organization that actually looks at the vendor claims and says, yes, we've looked at it and this is solid. So help us tie all this into your mission with the csa. Now, maybe for some of our listeners who might not necessarily be familiar with the cybersecurity agency in Singapore, what's the overall mission and how does quantum safe tie into that?
Speaker A: Yeah, well, CSA stands for the Cybersecurity Agency of Singapore. And we have been a national cybersecurity agency. I mean, uh, it's. So at our core, our mission is to keep Singapore's cyberspace safe and secure because that underpins our national security, the power of digital economy. And we need this to be secure and safe. So it's to protect our digital way of life. And, uh, because Singapore is a highly connected and digital first nation, so any threats to our digital infrastructure is a threat to our daily way of life.
Speaker B: Really?
Speaker A: Yes. Uh, so when it comes to quantum readiness, this being a scope within the cybersecurity realm, our role is that of the national coordinator and uh, strategic guide as to what needs to be done for quantum safe. And so we work with a lot of public and private stakeholders to bring about this transition to quantum safety. And our job is to demystify the threat and to give the organizations, especially the owners of the critical Information infrastructure, or CRI for short, some concrete steps on how to protect the system before this threat materializes.
Speaker B: So in the conversation around quantum safe or quantum resilient migration, oftentimes I hear critical national infrastructure, CNI or critical Information Infrastructure being used. So jumping into the challenges and objectives for migration, in focusing maybe on the group of critical infrastructure providers, how would you frame that challenge that those organizations are facing now in the light of that development?
Speaker A: Well, one of the things that we kind of picked up in our initial conversations with these organizations is that of quantum. This is a bit too beyond me, right? Like it's immediate, like, oh, wow, yeah,
Speaker B: you need a physicist to explain that.
Speaker A: Exactly. And when things are seemingly out of reach, impossible, and you know, the composition structures down here, the person, you know, people may do that, you say they can't, uh, you can't get into this. This is not possible for them to grasp. On the other hand. Yes. And so you don't get actually many any headway with this conversation. So actually one of the things that we've been trying to do is to impress on want people that while the threat itself, uh, okay, definitely it's a quantum wire, it's using quantum computing to break crypto and how it does so is done in an amazing manner that I still find it hard to really drive through the graphs. But actually the solution of it, because the attack is on our cryptography. So the solution itself is actually just, uh, put in simple terms, it's just to replace your, uh, vulnerable crypto. So the solution itself is cryptographic. But when it comes to actually trying to put this in place, the challenge is that actually more operational in nature and it's actually tied into things that they are more familiar with. So how we want to change this perspective is because it's vulnerable crypto and you can think of it as a bug security vulnerability. And then what do we do with these things? We have security vulnerability, we identify where it is and then we find out what's attached and fix for it. And then we try to either fix it ourselves, get a vendor to fix it, or replace the system with this pattern in place. If we can't replace that component, like with the vulnerability in a nutshell, actually this itself is the thing you have attack, which is by a quantum computer. But the thing is that the fix is for cryptographic vulnerability. But the challenge is actually with us to the rest of the things. What do I mean by that? It's first of all to find out where your crypto is. You realize that actually it's everywhere. Crypto is usually very pervasive. Yes. And usually you don't realize that it's there. And sometimes when we think about, from perspective of, uh, security assurance, crypto is the last thing you expect to fail. You usually assume that the crypto is secure and is working. It's usually set at a much higher level than article security that's very transparent
Speaker B: also to the application or the end user. Yes.
Speaker A: So once it's designed properly, the algorithms, you just assume that that is test. As long as you're compliant, it's going to be secure and you can rely on it. But then now when you try to do a discovery, you realize that it's everywhere. And we're not talking about all cryptography, we're just talking about public key cryptography, like, uh, our rsa, our uh, ECDSA and our ecdh. And these things are indeed used in all kinds of places for our communications. When we do key exchange, key establishment, and also as a digital nature, we use it for authentication and it's in our credit cards, our smart cards. So these things are actually everywhere and rely on it. Whenever we say we do something with security and it's digital, chances are you're going to have some crypto cryptography in there to actually allow you to have that function. So now that you know that it's everywhere and you need to find out where exactly it is, in what context this cryptography is being used and is it critical, what does it help protect and what happens if it goes down? What happens if it gets attacked? Then things that you previously assumed were secure, uh, public key. We always have the notion that public key is meant, like public. It's meant to be distributed. You don't worry about it. It's like encrypted data. You keep the key and the encrypted data can be released and you don't worry so much about it. But now we have to think about this slightly differently for our threat assessment. We need to think that we have this public keys that will be assumed rightly so then that is secure is actually no longer the case, at least not for all. And we have to find out where these are and because that itself becomes an attack vector and then we have to fix it. So the difference now is that the sure scale of it and just covering everything where these things is a massive undertaking. And of course following that is the prioritization of where these things are or other prioritization, which ones do we want to fix first? And to compound things is actually we need to do all these things within a short period of time. And, uh, we don't have the luxury of decades of doing this. Well, ideally, if we all have the benefit of hindsight, we might think that, okay, you should have done this earlier. But that's hard to change. It's challenging. I mean, the organizations have many things on their plate with cybersecurity and this is like yet another thing that they need to do, unfortunately. But it's a thing they do have to address. But that said, yeah, it's difficult for organizations to actually commit the time energy to something that is projected to be many years, uh, away. But nevertheless, this is the situation now and we have to try to condense all these things within the timelines we spoke of.
Speaker B: Well, I think I do appreciate your framing of, like you rightfully said, quantum is such an overloaded term for everyone. So to make it really simple and say the threat is quantum, the solution is cryptographic, and the challenge is operational. I think that's a beautiful framing. So how do you take that guidance into the guidelines and recommendations that CSA publishes to the, uh, critical infrastructure providers and any type of enterprise? That of course is faced with a similar challenge of having to migrate.
Speaker A: So in a way, the Good news. I mean, knowing that uh, it's an operational challenge that we're facing is not something that they can't do. And in fact probably have some skills, some processes, some expertise within the organizations that can actually do this. Because the challenges when you actually strip away the quantum, um, or even the cryptographic details is actually things. They're actually standard foundational, um, processes that I think as a Korea Games would somewhat.
Speaker B: It's the daily bread already, right?
Speaker A: In some sense, yeah. So that's what we hope to do to try to demystify the challenges. It's not something so out, uh, of this world is actually something that there are people can relate to already and to start thinking about the. In practical terms, what does it mean to look at these things? So if you think about the things we talk about in condosive migration, treasure assessment, maintaining inventory of assets, cryptography management and planning for tech refresh, these are
Speaker B: actually things that any IT department is doing anyways.
Speaker A: Yes. Should be familiar to them.
Speaker B: Right.
Speaker A: So they need to manage their dependencies, map their data flows and update the configuration files. And instead of discussing the peer finding subroutine insurer's algorithm, which is nice, it's interesting, but it doesn't help with the conversation that we need to have. So our focus is actually on providing guidance to help people get started with the things they need to do and to translate it into terms that they are familiar with and actually to get them started rather than them faced with this seeming war that it's not possible for them to overcome on their own.
Speaker B: So I think on the assessment side, I mean, of course one task is finding all your cryptography, understanding the threats, looking at even just simple things looking at, am I using TLS 1.3 everywhere? And then I think the next step is consolidating that information and then like you said, doing the threat assessment or doing the risk assessment and defining the most critical use cases first so you can address those in the next step as a first. Right. And I think you've taken the approach of giving guidance also for self assessments so that organizations can go in and check and determine where they stand in that process. Maybe you can share a little bit about that as well. And I think you called it the Quantum Readiness Index. QRI if I'm not mistaken.
Speaker A: Yep. So there were two publications that we released, uh, last October during our Singapore International Cyber Week. So we announced this back then. Uh, the two publications are the uh, Quantum Safe Migration Handbook and the Quantum Readiness Index, which we call QRI for short. And these are two practical resources that we released for public consultation back in October and we're going to be releasing this very soon the final version. We took in the comments and updated our publications and we'll be releasing them soon. So this was done joining together with our government agencies GovTech and IMDA. So these tools are meant to help organizations in their journey. So we developed these tools in uh, consultation with industry experts, tech companies, cybersecurity consultancies and some professional associations as well. So these documents are meant to serve as a companion pair. So in a nutshell uh, the handbook tells you how to do your work, whereas the index helps you assess where you currently stand. So the handbook provides valuable guidance on what is at stake, where to focus, how to build your readiness step by step and includes a list of no uh, regrets move, no regrets moves and as the immediate first steps that the uh organization org or to take and as well as guidance uh on identifying the organization's crown jewels based on your system types. So we've updated recommendations on the quantum safe algorithms and as well as include uh, um, guidance for our critical information infrastructure owners. The second publication, the QRI is a self assessment questionnaire to complement the Quantum Safe Migration Handbook. So it's meant to help organization understand their current level of readiness and to enable system owners and security practitioners to prioritize their areas they need to do for quantum safe migration. So it's a case of questions uh, that they answer and then knowing and to reflect what is the state. And then it also points them to the kind of actions that they need to do in response to get them up to the next level of readiness. So this kind of information is m more grounded in details that they can understand. It will facilitate conversations they need to have with their senior management and decision maker on their state of readiness. And uh, then that can be used to seek buy in on the recommendation steps to strengthen their safe posture.
Speaker B: So if I'm in an organization listening to you explain this today for the first time, then my next step of action would be to go to the CSA website, download the qri, uh do the self assessment and then take that as a conversation starter into my organization. Right.
Speaker A: Yeah, that is absolutely right. That's one of the things that you can get started especially if you uh, aren't already familiar with this space. You need to some way of understanding yourself first before you can chat out your part.
Speaker B: Yeah, it breaks down the complexity to something that is actionable for.
Speaker A: Yeah. So looking at the doing the self assessment and then it will point you to the kind of actions. And then if you want the details, you refer to the handbook for the more detailed guidance and practical considerations as well as explanation providing further context about data, uh, condoms, a problem that maybe organizations may not be that aware of and familiar with. And then this assessment isn't just meant to be as a one off assessment. It'll be good to have a periodic review so that you know where you stand.
Speaker B: Could go back to it and make sure that you've not fallen back down a level by some sort of uh, unintended consequences from using a new service or a new application. Now in those two documents, I mean obviously we've spoken about the solution beyond cryptographic. The challenge being operational. How do you address those different domains within the guidance? Is there any reflection of that as well in the way that those documents are structured?
Speaker A: So the five domains are first of all risk assessment, second is governance, third is technology, fourth is training and capability and the fifth is external engagement. So first of all risk assessment, this domain addresses the identification and prioritization of your organization's crown jewels and structured, uh, assessment of quantum related risks. So this is meant to help inform your prioritization and decision, uh, making within the organization. Next, governance. And this relates to the establishment of accountability, decision making authority and structures for oversight to guide your quantum safe migration in your organization and to translate these decisions into organizational plans, policies, policies so that you can ensure that all these things are done in alignment with your broader business and cybersecurity objectives. Because we want to stress that actually all these activities shouldn't exist as something outside. Yes, it's not a separate thing, but it's all meant to be weaved into your existing things.
Speaker B: So you want to follow the organizational frameworks and be sure that it is a natural part of the daily business. Really not something we do once and then forgot about. Yeah, yeah, yeah, yeah.
Speaker A: So the next is technology and then it covers, you know, when you examine suitable quantum safe cryptographic replacement options that you could use, what PTC you're going to use, does it fit your requirements, the use case, and maybe you have some performance requirements that you require certain kind of. Yeah, it will be different for different
Speaker B: use cases as well.
Speaker A: Yeah. And also sometimes for the algorithms there may be some limitations that there is the number of times you use the keys and the kind of things you need to do around to make sure that your usage of the algorithm is secure. So not all algorithms may fit your
Speaker B: use case, uh, for using like a stateful mechanism.
Speaker A: So alongside your cryptographic choice, this need to come hand in hand together with your strengthening of your cryptographic management practices, um, and as well as agility considerations so that you can enable timely adaptation and updating and uh, replacement of your crypto product use, uh, as the technology and standards evolve. The point here also wanted to stress that we don't expect that right now at this juncture that everything is risky as it is, but it's important to know what are your options so that you can plan ahead. And when these things come on board, come online, you are able to actually go and to dive right into actually putting them into practice and merging them rather than say that oh, now that they're ready, we just try to decide and choose what to use and uh, that you might lose very more time.
Speaker B: And so you acknowledge there is going to be changes and then you consider that from the beginning to build out in such a way that it doesn't hit you by surprise that uh, oh, now I have to swap algorithms or use a different technology. Okay, very good, thank you.
Speaker A: So the next things are training capability. That's more to do with your organization's awareness of the content trap. You need to begin with that and then you need to identify and develop the competencies within your organization needed to plan, govern and implement your quantum safe migration.
Speaker B: So upskilling existing employees or maybe hiring additional people with the required skill set,
Speaker A: or it may be augmenting through consultancy, et cetera. So is that to ensure that at least your organization and internal stakeholders actually possess the knowledge and skills?
Speaker B: You can check all the boxes.
Speaker A: And of course again coming back to the previous point about the nature of the challenges, it wouldn't be that they need to suddenly uh, go for the crash course in quantum scenarios or understand why your PQC is secure. That's not, that's uh, they need to know what are the things that are available, how to use them and the kind of considerations they need to have when they're thinking about this and planning. So it shouldn't be a major. Yeah, to get to the point where they can get started on things. And last but not least, when it comes to external engagement, this itself is actually in a way integral part of all these things. Because regardless of whether you're a big small organization or whether you are uh, a developer manufacturer yourself, you're going to be using a lot of things that come from uh, other organization providers, service providers, vendors. So this itself is indeed a major part of it. To know what are your based on your existing fitness prospective vendors and what do they have are they ready with the products? Do they have a timeline, um, roadmap in place and if you continue to rely on them, would you be ready in time, even if many of them do not have their products realized? So you need to identify which ones are most likely able to support you on the quantum safe journey. Because this kind of dependencies are uh, a fact of life. So identifying your dependencies on this external products and services is a necessary part of your manual hand planning.
Speaker B: Of course it's the important part for procurement to know what to ask for as they purchase a new system.
Speaker A: Yeah, so these are things that we feel that is important to, as you said, what are the things they need to ask um, of uh, the vendors so that they can plan and to eventually decide on their requirements on what to adjacent this up is a part that the organizations need to get a handle on and also where possible they need to try to engage with the broader ecosystem to stay informed of the developments and the expertise out there and that can help them support their uh, migration efforts. Because in a way, uh, one thing I took away from the conferences is that although many times the people who are there at a conference, they are maybe competitors can be doing things very differently, but ultimately this itself is a shared goal and uh, everyone common goal that everyone has. And so the only way for us to be able to meet this goal and objective is to do this in a collaborative manner, to cooperate with others, share information, share ideas. Because we are living a very connected. And it's hard to say that you draw the boundaries, say this is. I just worry about my side and not about yours because when we have our transactions transnational, if something breaks down on my end, or rather on your end, I may not be able to do my research as usual anymore. And the other thing is that if there's a breakdown in the trust in the system, then people may move away from the system and do something that is uh, suboptimal instead. So actually our best approach collectively is to actually look to it.
Speaker B: So it's not going to work in isolation as a silo.
Speaker A: So that's why we feel that we need to go out and tell people, talk to people and bring people together on how to solve these problems together. And no one really has a monopoly over all the ideas, all the solutions on things because so many things need to be solved in different levels and ah, we need to.
Speaker B: Yeah, if you look at the entire global digital ecosystem, it's going to take many building blocks to really build this out. Right. There's no one Solution, there's no one vendor to rule them all to solve it for everyone. So there's going to take the joint approach that you called out.
Speaker A: Yeah, it sounds very simple. Thanks for the analogy. I think I was thinking along the lines of like, yeah, it sounds very simple. You just take the ring and go to Vukin and just drop in. Yes, how difficult can that be? But actually when you start thinking about the journey, what you need to go through to the challenges along the way, there's going to be a lot of d and then just by having people that you can work together with to move on this journey together, it's going to be um, it will make it
Speaker B: possible, uh, for sure. Now since we're talking about journeys, every journey has a timeline. So I'm curious to hear about any potential dates that you put into your guidelines.
Speaker A: Yeah, so we've actually released a set of requirements for our uh, CII owners for their uh, quantum safe migration planning. And first of all by March of next year 2027 they need to submit their condom safe migration plans to CSA. And then from 2028 onwards, procurement and implementation of new computer and computer systems uh, for these cris only they have a digital component and they should either support quantum safe algorithms and technologies or the quantum safe ready library. And all these things uh, have been the completion of migration across their computer uh, and computer systems should be done by 2031, 31st December 2031 that is the vulnerable uh, crypto fee should not be used. So the point Super. Is that it's not about using just the case of like you are using quantum state algorithms mitake actually the focus should be on the not using vulnerable cryptography anymore.
Speaker B: So basically a five year window for the entire migration.
Speaker A: Yes.
Speaker B: And that first deadline March 2027. So let's call it seven, eight months from now with the roadmap or the migration plan. How granular, how detailed do you expect that to be? Or is it more of a high level roadmap that uh, CII providers need to put together and point out?
Speaker A: At this point it is definitely a challenge. We split it. There'll be a challenge to actually flesh this out in full. As we have spoken about. There's a lot of answers in this. I mean if you don't know what vendors are going to be able to provide you in this national way, you can pin down details on it. The aim here is that they know what you need to do and to put this together.
Speaker B: So yeah, I think it's great to hear the timelines that you're communicating to your CII infrastructure vendors or providers. And it falls right in line with what we're seeing globally as well. Right. If you look at the timelines that are communicated in Europe or in the US even in the latest executive order, I think this plays nicely into sort of the global timelines here. It also I kind of want to touch back on a point that you made earlier about interoperability and sort of co development. So just to have a little comment on that as well. And that is with regards to the type of algorithms, the type of cryptography that you're recommending for Singapore as well, following the global guidelines as well, were you cooking your own algorithms or where do you stand on that in our handbook?
Speaker A: Actually we, but we have and we are explicitly stating that we are actually referencing and aligning with the international standards, such as the P2G standards published by NICE. I mean there are two reasons for this. First of all interoperability is essential. Yes. I uh, mentioned about how there's a need to transact across borders and hence we need to. Our digital way of life and our economic activities should depend on this single connectivity. Whether it's global financial transactions, international trade, logistics or just everyday cross border data flows. Our systems must speak the same cryptographic language as of our neighbors or other global partners. Uh, so that's why we need to make sure that whatever standards we use are indeed going to be used by others and so that our people, our businesses can actually carry on doing as they can in the uh, pre quantum world. And secondly we also recognize that there's been an uh, event decade long uh peer review process that had gone into analyzing these international algorithms of and no algorithm is perfect. There's always going to be the question of whether these things can be broken in the future. Uh, the things that differ is that the global nature and the diversity of the research effort actually provides us, and probably with others around the world as well, with confidence in the security of these word nodes.
Speaker B: Yeah, thanks for sharing that as well. That's very good to hear. So you did mention that the regulations right now are somewhat more of a soft guideline versus actual compliance. Maybe you can share bit more about that thought as well.
Speaker A: Yes indeed. Right now these are uh, issued as formal uh, guidelines rather than uh, regulations for compliance. I mean we've designed it this way because we recognize that the post quantum landscape commercial products and implementation standards are still actively evolving and it's hard to know exactly what the progress will be in the coming years. So we recognize that but nevertheless we believe that having such timelines are useful and in fact we see them as necessary. What timelines do, as we have observed effect with uh, the other nation's timelines established, it sets uh, as common knowledge a baseline of expectations for both the system owners as well as the tech ecosystem. And it serves as waypoints for them to align their activities to this. So with this I think both the supply side and demand side, they know that within these numbers of years, because that's the timeline, um, they can both plan towards that timeline and then the supply of vendors is like marking out a certain flag along a mountain. And I say that by five hours you need to get there and everyone needs to move towards that timeline.
Speaker B: I think that gives the supply side, the vendors the opportunity to get ready for that point when those quantum safe features are required. And then it also helps again we were talking about procurement earlier. It helps in your procurement as well if you're able to point towards an actual communicated timeline with milestones. Right?
Speaker A: Yeah. And believe that this um, is having the assurance that the confidence that the products are uh, going to be there, at least some products going to be there available. It will also, it makes more sense, it will give more motivation for the organizations to actually plan knowing that actually these things could actually be realistic plans that they can carry out. Uh, so we've having communicated these timelines, our focus is on providing the guidance and the knowledge necessary so that our critical systems can actually affect the migrations. And we like to think that it's more important for us right now to ensure that they can actually overcome these challenges which um, we have seen that they can be quite a fair bit to handle. But before thinking about how to regulate them, because if we try to regulate them and there's actually no way of achieving it, then it might actually not,
Speaker B: it doesn't serve the more frustration than anything else and conflicts. So sort of within this five year period I'm assuming there's going to be further support and guidance coming out of CSA with regards to some of the five domains where there's additional information acquired. Right. So help with uh, training and upskilling, be able to determine um, technology, which technology to look at. And is there any thought around because you did mention certifications in the beginning, is there any thoughts around that sort of looking ahead?
Speaker A: There are many different aspects of this entire journey that needs to be handled and what we're trying to do is to look at across all this, which are the things that the market looks like it's going to handle. Is it like a, uh, standardization of algorithms? Yes, it's perhaps could be. We wish for it to be more accelerated. But we know that there are good people globally that's working on these problems. So on our part we will look at what are the specific things that. Well, we would, as a uh, national agency we are best placed to do and to set and to bring people together together and to make sure that they have the necessary information and the correct guidance and direction on how to go about doing this. So uh, certification is one of the things we're looking at. We're looking at how to get the. Also studying the information about the market readiness. These are amongst all these things we're looking to see where is the areas that the organizations need the help. Yeah. The most help. Yeah.
Speaker B: Fantastic. So earlier you used the term no regret steps. So I think as we wrap up, I'd be curious to hear if you were to give recommendations to IT operations leaders, CISOs out there listening today. What's the initial no regrets that you
Speaker A: would recommend they take rather than a single one? Just broadly, I believe that they should get their organization ready and do your cryptographic discovery and prioritization and to speak to your vendors about their readiness to
Speaker B: support like engage the vendor supply chain
Speaker A: early products and services. Yeah, and these are a few of the no regrets moves that should and can be taken now. And these are uh, actions that grounded in uh, familiar processes or artist quality management and so they can take a start on them. Really there's no need to wait for the listings. And yeah, eventually when as things progress over the next five years I think then we'll see some of these things are copy fridge and. And things will fall in place. I think it's going to be exciting next five years with more can see
Speaker B: more acceleration on the topic.
Speaker A: For sure. Yes, for sure. I think the year on year you'll probably see that the conversation will evolve and the things that we will be talking about 12 months from now could be vastly different.
Speaker B: Well, um, looking forward to it.
Speaker A: Thanks for taking the time.
Speaker B: Rodney, thanks for sharing your insights. Really appreciate it.
Speaker A: Thank you Joe. I think it's been a pleasure being on this. Thanks for inviting cse.
Speaker B: Absolutely on this. Our pleasure. Yeah, thank you very much and totally listeners as always, don't forget to like subscribe and comment. Stay safe, stay vigilant and stay shielded until next time. Thanks Roddy.
Speaker A: Thank you.
Speaker B: To find out more about PQ Shield and how our cutting edge solutions can help you secure your data against the Quantum threat, visit pqshield.com don't forget to click subscribe so you never miss an episode. On behalf of the team here at PQ Shield, thanks for listening there.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.