Skip to Content (custom)

Angle

For Encrypted Data, “Q-Day” Is Coming. Here Are Seven Steps To Prepare.

  • Cyber Breach
  • 1 min

Key Takeaway: Every day spent relying on today’s encryption expands tomorrow’s exposure. “Q-Day,” the moment quantum computers can break today’s encryption, is closer than many organizations think. With the apparent inevitability of safeguards becoming obsolete, teams must start preparing before migration becomes a crisis. This includes inventorying cryptography, prioritizing long-life sensitive data, aligning policy with practice, coordinating stakeholders, and requiring quantum readiness across your provider ecosystem.

Quantum computing, though in its infancy, has the potential to erode, and perhaps even destroy, the very foundations of present-day digital security. As quantum machines become more powerful, today’s uncrackable encryption schemes may become trivial to break. This is no small development as encryption is widely considered best practice and used by virtually all of the top companies and entities globally to protect the most sensitive and important data. Opinions vary as to how soon that moment, so-called “Q Day,” will arrive, but the threat is real. Adversaries are already stealing encrypted data today, betting they’ll be able to crack it in five to ten years once quantum computing catches up. 

As revealed in an an earlier article on the topic, four essential steps mitigate the threat to previously accessed or exfiltrated but encrypted data. This includes inventorying such encrypted data that was accessed, exfiltrated, or exposed, rerun analysis of breach notification obligations assuming the encryption will no longer prevent viewing, use, and/or access, consider disclosure, and implementing emerging standards and protocols. 

However, even without a prior breach, if you’re holding sensitive data with a long shelf life, addressing the post-quantum computing (PQC) threat with current gold standard encryption no longer safeguards your data. Given that, action ought to begin without delay, as implementing and operationalizing new safeguards will take focused effort along with time and money. Below are seven steps for organizations to take now while there is time, and the task is still manageable.

Step One: Routinize Ongoing Assessment of New Solutions That Address the Quantum Threat

This includes understanding emerging minimum standards and best practices. The current state of those standards and practices form the basis for the next step.

Step Two: Assess Your Current Data Encryption Policies

This requires a multi-fold approach. You must determine the extent to which your current policies are up-to-date and aligned with existing regulations and obligations. The safe working assumption is that, until verified otherwise, your current written policy may require updating. With that in mind, assessment must focus on identifying both current and future gaps. Another crucial issue to address is whether you have contractual obligations to your end clients related to encryption, such as under data security or safeguarding provisions.

Step Three: Verify Your Current Data Encryption Practice

Does your practice align with your policy? This includes classifying three types of users. The first is the groups and functions within your business that use encryption today. This requires assessment of their alignment with the relevant policy. Any gaps you find demand attention. The second set of users are those that are not currently using encryption but should, whether for business or policy reasons. The time is now to update your policies accordingly and make necessary changes. The third cohort is those who do not currently need to use encryption but will be impacted by the advent of quantum computing.

Step Four: Build a Project Plan To Address Deficiencies

Planning must include all relevant stakeholders beyond IT and InfoSec. Legal has a critical role to play in assessing current and future legal obligations, and other functions (finance, procurement, HR, etc.) likely will, too. Additionally, budgeting must be a component of planning. This includes the expense of third-party expertise, consulting, and provider solutions.

Additionally, planning must address the proper sequence of steps relative to current and future risks, including how costs are likely to shift as both defensive measures and malicious actors’ capabilities rapidly evolve. However, that evolution is inevitable. Your plan should include vetting and assessing suppliers now.

Step Five: Address Insurance Costs

Addressing deficiencies and proactive risk mitigation may command discounts on insurance premiums. Conversely, failure to do so could lead to increased premiums. Both possibilities merit attention. Savings on premiums enable you to fund needed action, and it may also be possible to align with and piggyback on top of other IT initiatives, such as moving to M365 or the cloud. This is a key example of the importance of having a sufficiently broad stakeholder group involved as mentioned in step four. 

Coordination and knowledge sharing between your IT and InfoSec organization who are focused on designing, deploying, and operationalizing these changes with those in legal and procurement tasked with procuring insurance will drive these cost-saving opportunities and synergies. If the cross-functional and departmental coordination is not in place, you risk missing out on this type of teaming and cost savings.

Step Six: Tackle Third-Party Exposure

As demonstrated by many of the most notorious recent breaches, third parties continue to create vulnerabilities. In effect, you are only as safe as your providers. Addressing this attack vector requires a systematic and multifaceted approach, from due diligence to contracts terms, supplier onboarding, and ongoing supplier management. As with other cyber risks, you must ensure your providers are planning for the emerging quantum threat and taking the required action. It may be appropriate to include a contractual requirement towards that end, and the topic should be a part of conversations with all your suppliers who may have access to or touch your data.

Step Seven: Lay the Groundwork for Post-Quantum Computing Migration

In a certain sense, Q-Day isn’t a future problem, but rather a data classification problem that teams can begin to address now. This begins with building a cryptographic inventory. Most companies don’t know where or how encryption is used across their systems and vendors. You can’t migrate encryption practices that you haven’t mapped. 

Another foundational piece is designing for crypto-agility using systems that allow you to swap encryption algorithms without a multi-year overhaul. Flexibility for the future matters more than picking the “right” algorithm today. 

Finally, when prioritizing data for migration of encryption practices, take into account data shelf life, not just sensitivity. Data that needs protection for a decade and beyond, like legal records, health data, and financial history, should be first in line for migration since that type of data is most exposed to harvest-now-decrypt-later attacks.

The Time To Act Is Now

Each day that you continue to rely on current encryption standards only serves to increase future risk and increase the quantities of data subject to future exposure post Q-Day. Early adoption of new standards will enable you to reduce the amount of data that will rely on inferior and outdated technology. Moreover, this process, if done well, will take time to plan and implement. The sooner you can start the process, the sooner you can be more defensibly positioned for the approaching Q-Day.

This article originally appeared in the October issue of Cybersecurity Law & Strategy. Read it here.

Learn more about Epiq Cyber Incident Response Services.

Brandon Hollinder
Brandon Hollinder, Vice President, eDiscovery and Cyber Solutions

Brandon Hollinder leads and develops Epiq go-to-market strategy for its eDiscovery Managed Services and Cyber Incident Response business lines, partnering with clients to ensure the effective design and implementation of their technology and professional service solutions. He guides clients in their journeys as they look to adopt and successfully integrate advanced analytics and generative AI solutions, among others.


The contents of this article are intended to convey general information only and not to provide legal advice or opinions.

Subscribe to Future Blog Posts

Learn more about Epiq's Service offerings
Our Services
Related

Related

Related