SAML and OIDC PQC: Identity Provider Migration Considerations
Identity infrastructure sits at the boundary of most enterprise security models. For IAM engineers and security architects, post-quantum migration of…
Blog
Expert analysis, quantum security news, and industry developments from QSECDEF. 224 articles across insights and news.
Identity infrastructure sits at the boundary of most enterprise security models. For IAM engineers and security architects, post-quantum migration of…
The concern that post-quantum TLS will slow down HTTPS connections is widespread and, in most production environments, wrong. This analysis covers…
When Apple launched iMessage PQ3 in February 2024, coverage declared that iPhones were now quantum-safe. When Google deployed hybrid post-quantum TLS…
Signal, iMessage, and WhatsApp all made post-quantum announcements between 2023 and 2024. Each application addressed a specific cryptographic…
Most organisations do not have a cryptography problem. They have a hardcoded cryptography problem. The distinction matters because the solution to the…
Before 2021, most cyber insurance questionnaires asked whether you had a firewall and an incident response plan. Then ransomware losses climbed…
Post-quantum VPN migration is not a single task. Enterprise VPN infrastructure spans three distinct protocol families, each with a different…
The terminology around quantum security has drifted badly enough that practitioners working from plausible-sounding assumptions are making procurement…
Writing about quantum threats to blockchain almost always starts at Layer 1: Shor's algorithm breaks secp256k1, Bitcoin and Ethereum wallet keys are…
Most post-quantum migration guidance directs organisations to ML-DSA for all signature needs. For firmware signing pipelines, long-lived code signing…
Every time you sign a contract digitally, download a software update, or visit a website over HTTPS, a digital signature is working in the background.…
Government security programmes increasingly encounter QKD in briefings and vendor pitches, often without a clear picture of where it has been…
If you are evaluating hybrid post-quantum TLS deployment for production infrastructure, this article provides the numbers: CPU cycles, key sizes,…
Classical optical repeaters work by measuring the incoming signal and re-amplifying it. Measure, copy, transmit. This is precisely what quantum…
Critical national infrastructure is a different post-quantum problem. The data lifetimes are longer, the patching cycles are slower, and the…
Hardware announcements in quantum computing follow a reliable pattern: a large headline number, a spectacular benchmark, and a wave of coverage about…
The standard reassurance that older data is encrypted and therefore protected does not hold against a CRQC running Shor's algorithm. This article…
The quantum threat does not map uniformly onto cryptography. Shor's algorithm breaks asymmetric cryptography completely. Grover's algorithm weakens…
Every security professional has read the headlines about national quantum programmes. What most enterprise security teams have not done is translate…
The IBM Nighthawk and Google Willow announcements attracted more executive-level attention than any quantum hardware development in years. Both…
Security teams at financial institutions, critical infrastructure operators, and defence contractors typically carry memberships with ISC(2), ISACA,…
Quantum security training is a buyer's market in the worst sense: provider marketing has converged on the same vocabulary regardless of actual…
Less than the briefings suggest, but more than the sceptics acknowledge. This article works through the hardware landscape as it stands in 2026,…
Underwriter questionnaires are beginning to incorporate quantum security posture into risk assessment. This article maps what a credible answer looks…
NIST published FIPS 203, 204, and 205 in August 2024. DORA entered full enforcement in January 2025. The regulatory infrastructure exists. The CPD…
Google's Willow chip in December 2024 confirmed below-threshold quantum error correction in hardware for the first time. Understanding what it…
There is no single EU quantum security regulation. There is instead a cluster of four general cybersecurity instruments whose requirements for…
Google's Willow chip and IBM's Nighthawk processor are genuine scientific milestones. Neither changes the 2033-2035 Q-Day central estimate.…
Available quantum security training clusters at opposite extremes: PhD-depth theory with no migration connection, or awareness briefings that explain…
Zero Trust Architecture removes implicit network trust. Post-quantum cryptography migration removes algorithm vulnerability to a future quantum…
Subscribe to the QSECDEF newsletter for weekly updates on quantum security, new lecture recordings, and upcoming events.
Subscribe to Newsletter