HNDL in Financial Services: Regulatory and Operational Implications
Financial services institutions hold the data categories with the longest regulatory retention periods, are documented targets of nation-state cyber…
Blog
Expert analysis, quantum security news, and industry developments from QSECDEF. 224 articles across insights and news.
Financial services institutions hold the data categories with the longest regulatory retention periods, are documented targets of nation-state cyber…
The NSA's preferred schedule had 2025 as the target year for software and firmware signing. That date has passed. This article works through each CNSA…
NIST IR 8547 is not a threat assessment document. It is a schedule. This article provides the specific dates, specific algorithm names, and specific…
Harvest-now-decrypt-later exposure is calculable, not qualitative. An organisation that knows its network topology, data retention requirements, and…
Post-quantum cryptography readiness has a specific structure. Six areas must all advance for a migration to succeed: cryptographic discovery,…
On 20 March 2025 the NCSC published its first dedicated PQC migration timeline, setting milestones at 2028, 2031, and 2035. For operators of essential…
DORA's ICT risk management obligations are live. This article maps the specific Articles 6 and 9 obligations and their RTS implementations to…
For organisations operating in the EU, ETSI standards are not an alternative to NIST — they are the regulatory translation layer. This article maps…
The board case for PQC investment changed materially in August 2024 when NIST published final standards and opened the deprecation clock. This article…
Not all data needs migrating at the same urgency. This article applies the Mosca inequality to specific data categories with specific confidentiality…
The EU Cyber Resilience Act's main conformity obligations apply from December 2027. For manufacturers whose products use quantum-vulnerable…
The obligation to protect personal data with measures 'appropriate to the risk' under UK GDPR Article 32 includes the current threat model. That model…
The most common reason PQC migration programmes stall at planning is the absence of a reliable answer to one question: what cryptographic assets do we…
A cryptographic library is not a commodity procurement. Choose a library without ML-KEM support today and you face a choice between deferring…
Multi-framework PQC compliance is the problem most organisations face in 2026. NIST IR 8547, CNSA 2.0, DORA, and NIS2 share a technical foundation but…
The Harvest Now, Decrypt Later attack is not a theoretical concern for 2033. The interception is happening now. A five-component operational framework…
The PQC migration problem in operational technology environments is harder than in IT. Hardware cycles of ten to twenty years, compute-constrained…
Getting quantum risk onto the board agenda is not the hard part. Most boards will hear "governments are retiring current encryption standards by 2030"…
FIPS 203 defines three parameter sets for ML-KEM. The choice between them carries real implications for performance, security margin, and integration…
Most NIS2 implementation programmes treat cryptography as a checklist item: TLS version current, certificates valid, data encrypted at rest,…
The EU AI Act's August 2026 enforcement threshold arrives for high-risk AI systems in critical infrastructure. What Article 15's state-of-the-art…
PKI migration is the longest-lead item in most enterprise PQC programmes. Root CA sequencing, ML-DSA algorithm selection, HSM readiness, OCSP…
IR 8547 answers the question the FIPS standards do not: when must the old algorithms stop. A CISO and security architect guide to the deprecation and…
Not all encrypted data is equally exposed to Harvest Now, Decrypt Later attacks. A retail transaction from last Tuesday carries effectively no HNDL…
The audit companion to the sub-tier supplier guide. Where that article answers what you must do, this one answers whether you have done it. A 7-domain…
The waiting period is over. NIST finalised FIPS 203, 204, and 205 on 13 August 2024. The NCSC published its phased UK migration timeline in March…
Prime contractors are working through their own CMMC Level 2 assessments. Sub-tier enablement gets deprioritised. The absence of a formal notification…
DORA has been live since January 2025. Its ICT risk management framework explicitly names quantum advancements as a cryptanalytic threat category.…
Knowing what each NIST post-quantum standard requires is the first problem. Sequencing them correctly is the second. This article provides the…
NSA's CNSA 2.0 replaces CNSA 1.0's public-key algorithms entirely. Defence suppliers who cannot demonstrate CNSA 2.0 algorithm support will not…
Subscribe to the QSECDEF newsletter for weekly updates on quantum security, new lecture recordings, and upcoming events.
Subscribe to Newsletter