QKD Explained: What Quantum Key Distribution Actually Does and Does Not Solve
QKD is a key exchange protocol with genuine information-theoretic security properties. It is also a specialised technology with fundamental…
Blog
Expert analysis, quantum security news, and industry developments from QSECDEF. 224 articles across insights and news.
QKD is a key exchange protocol with genuine information-theoretic security properties. It is also a specialised technology with fundamental…
Every PQC migration programme has a first step. Most organisations get it wrong. Without a complete cryptographic inventory, there is no way to know…
A score without interpretation is noise. This guide explains the five factors behind the QSECDEF Post-Quantum Risk Assessment, what drives each factor…
AI model weights, training data pipelines, and KMS key hierarchies carry specific quantum vulnerabilities that standard enterprise TLS migration…
Energy and utilities OT faces the hardest PQC migration problem in critical national infrastructure, combining 20-40 year device lifetimes,…
Manufacturing ICS faces two distinct quantum risks: cryptographic vulnerabilities in OPC UA and SCADA authentication, and HNDL exposure of IP with…
UK and US government PQC migration obligations mapped to procurement, accreditation, and classification workflows, with a frank assessment of the 2031…
PQC migration budgets stall because of framing. This article gives CISOs the structure for a three-part board case: regulatory mandate, HNDL exposure,…
PQC migration programmes that complete certificate inventory and stop miss the infrastructure layer: Vault transit keys, Terraform state encryption,…
The GRI 2024 survey places a 14 to 34 per cent probability of a CRQC capable of breaking RSA-2048 by 2033 to 2035. This article explains the…
Three major national security agencies have publicly declined to recommend QKD for production systems. This analysis explains why, and what it means…
A SBOM tells you what components are in your software. A cryptographic bill of materials tells you which algorithms those components use and which are…
No single tool covers all six cryptographic surfaces. This analysis maps source code, binary, TLS, certificate, cloud, and container scanning layers…
Disclosure frameworks covering quantum risk are already active. This analysis maps the SEC, FCA, NIS2, and DORA obligations that apply now and what…
QKD node hardware starts at $100,000 to $150,000 per site. This analysis maps the full cost structure, total cost of ownership, and the three…
No PQC migration can be planned without knowing what cryptographic algorithms are actually running in production. This article explains what a CBOM…
CRYSTALS-Kyber and ML-KEM are not the same thing. NIST introduced substantive changes in FIPS 203 that break interoperability with pre-standardisation…
QKD's security guarantee applies in a narrow set of conditions. This decision framework, drawing on NSA, NCSC, and BSI positions, identifies the three…
QKD and PQC solve different problems at different layers of the security stack. This article explains precisely why QKD cannot substitute for PQC…
Five independently maintainable implementation layers for crypto agility: abstraction, policy server, hybrid protocols, key rotation, and certificate…
Cost benchmarks for PQC migration by organisation segment, what drives budget variance, and how to structure a phased, defensible programme budget.
How Mosca's inequality drives the urgency score, what each input measures, and why two organisations with identical data can produce different risk…
How the Quantum Exposure Snapshot score is calculated, what each input contributes, and what organisations in each score band should do next.
Committee composition, meeting cadence, RACI assignments, and charter elements for CISOs and CTOs standing up a quantum security steering programme.
The UK's thirteen CNI sectors face divergent quantum security exposure. Regulatory fragmentation, OT constraints, and inconsistent CAF B4…
Organisations receiving PQC migration roadmaps from vendors with a financial interest in the outcome face a structural conflict. This analysis sets…
NIST published three post-quantum cryptography standards in August 2024. Boards that treat PQC as a technical matter are making a governance error.…
Tier-1 financial services: 18 to 36 months. Mid-market: 12 to 24 months. Defence under CNSA 2.0: 36 to 60 months. A phase-by-phase analysis of what…
Most enterprise cyberattacks are unaffected by quantum computing. Three categories are not. This analysis maps quantum relevance against the 10 most…
Google Willow demonstrated below-threshold error correction in December 2024. What that milestone actually means for the timeline to a…
Subscribe to the QSECDEF newsletter for weekly updates on quantum security, new lecture recordings, and upcoming events.
Subscribe to Newsletter