For years, quantum computing has been discussed as a future technology—powerful, promising, and still years away from practical impact. But according to cybersecurity experts, that mindset is rapidly becoming outdated. In this episode, ATPGov’s Senior Systems Engineer, sat down with Joey Swartz, Quantum Security Strategist, to discuss one of the most pressing cybersecurity challenges facing federal agencies and defense organizations today: post-quantum cryptography (PQC) and the road to quantum resilience.
Their message was clear: while a cryptographically relevant quantum computer may still be several years away, organizations need to begin preparing now.
Traditional computers process information using bits that exist as either a 0 or a 1. Quantum computers operate differently, leveraging quantum states that can represent 0, 1, or both simultaneously. This dramatically increases computational power and opens the door to solving problems that are practically impossible for today’s systems.
Why does that matter for cybersecurity?
Because modern encryption standards—particularly public-key cryptography—were designed around mathematical problems that classical computers cannot solve efficiently. Quantum computing changes that equation. The industry often refers to “Q-Day” as the moment a quantum computer becomes powerful enough to break today’s commonly used cryptographic algorithms. While predictions vary, many experts now estimate that Q-Day could arrive within the next five to ten years. Recent advances in quantum hardware and growing investment from global powers suggest the timeline may be shrinking rather than expanding.
The Real Threat Is Already Here: Harvest Now, Decrypt Later
One of the most important concepts discussed in the episode is Harvest Now, Decrypt Later (HNDL). The theory is simple:
- Adversaries steal encrypted data today.
- They store that data for years.
- Once quantum computers become capable of breaking current encryption, they decrypt the information.
This means organizations protecting data with long-term value may already be at risk—even if quantum computers aren’t yet capable of cracking encryption. Examples of high-value data include:
- Medical records
- Intelligence reports
- Personnel and clearance information
- Research and development data
- Patent information
- Defense operational data
If the information remains valuable years from now, it could be a target today.
Why Organizations Need a Plan Now
The challenge isn’t just the arrival of Q-Day. The challenge is the time required to prepare. According to our research and experience, migrating large enterprises to post-quantum cryptography could take three to five years or longer, depending on the complexity of the environment. This isn’t a simple software upgrade, because cryptography is embedded into:
- Applications
- Databases
- VPNs
- Email systems
- Identity and access management platforms
- Digital signatures
- Network communications
- Cloud services
Organizations that wait until Q-Day arrives will almost certainly be too late.
Discovery First: You Can’t Protect What You Can’t See
One of the strongest themes from the discussion was the importance of cryptographic discovery. Before organizations can remediate risk, they need to understand:
- Where cryptography is being used
- Which algorithms are in operation
- Which applications contain vulnerable code
- Where key management processes exist
- Which systems contain data that requires prioritization
Cryptography is woven into virtually every aspect of modern IT environments. As a result, discovery must be comprehensive and continuous—not a one-time exercise. The experts emphasized that inventories should become living documents that are constantly updated as systems change, applications evolve, and remediation efforts progress.
The Four-Step Approach to PQC Readiness
For organizations wondering where to begin, Our team recommends a structured four-step approach.
1. Inventory and Assess
Start by identifying where cryptography exists across the environment. Gather information from existing scanners, security tools, asset management platforms, and cryptography-specific discovery solutions.
2. Integrate and Centralize
Consolidate cryptographic visibility into a centralized management platform. Integrate with systems such as:
- CMDBs
- ServiceNow
- Jira
- HSMs
- Key management systems
The goal is to create a single operational picture of cryptographic risk.
3. Analyze Applications and Source Code
Many organizations rely on custom-built applications with cryptographic libraries buried within source code.
Scanning code repositories helps identify:
- Hard-coded algorithms
- Vulnerable cryptographic implementations
- Areas requiring redevelopment or modernization
This information should feed directly into development workflows and remediation plans.
4. Prioritize and Remediate
Once risk is identified, organizations can begin targeted remediation. This includes:
- Upgrading cryptographic libraries
- Implementing quantum-safe VPNs
- Deploying crypto proxies
- Modernizing applications
- Transitioning to approved post-quantum algorithms
The key is prioritization based on business value and risk.
The Importance of Crypto Agility
Perhaps the most important long-term concept discussed was crypto agility. Historically, many applications were developed with cryptographic algorithms hard-coded directly into the software. Changing encryption often required major redevelopment efforts. Crypto agility changes that model.
A crypto-agile environment allows organizations to swap cryptographic algorithms in and out without rebuilding applications from scratch. This flexibility will become critical as standards evolve and future threats emerge. Quantum-safe algorithms may be the focus today, but cybersecurity has shown repeatedly that cryptography must continue evolving. Organizations that build crypto agility into their architecture will be better positioned to adapt to whatever comes next.
There Is No Silver Bullet
One of the most practical takeaways from the discussion was that quantum readiness is not a product purchase—it’s a program. Just as organizations discovered with Zero Trust, no single tool can solve the entire challenge. Success requires a combination of:
- Discovery capabilities
- Code analysis
- Key management
- Automation
- Policy enforcement
- Continuous monitoring
- Executive reporting
- Operational governance
Organizations should focus on integrated platforms that provide end-to-end visibility and coordination rather than relying on isolated point solutions.
Measuring Progress Toward Quantum Resilience
How can leadership determine whether their organization is actually becoming quantum-ready? The discussion offers several guiding questions:
- Do we have continuous visibility into cryptographic risk?
- Is our inventory dynamic and automatically updated?
- Do we have a dedicated team overseeing quantum readiness?
- Can we prioritize remediation based on business risk?
- Can we clearly report our posture to leadership?
- Are our workflows integrated and automated?
- Can we adapt quickly as cryptographic standards evolve?
Organizations that can confidently answer “yes” to these questions are well on their way toward true crypto agility and long-term resilience.
The BLUF
Quantum computing may not be fully mature yet, but the actions organizations take today will determine how well they withstand tomorrow’s threats.
The path forward isn’t panic—it’s preparation.
Start with visibility. Build a cryptographic inventory. Prioritize critical data. Develop crypto agility. And most importantly, treat post-quantum readiness as a strategic transformation rather than a one-time technology project. Organizations that begin the journey now will be in a far stronger position when Q-Day eventually arrives.
Synopsis
SUMMARY
- 00:00 Show Intro and Mission; Briefing Setup and Speakers
- 01:43 Why Quantum Matters Now
- 03:18 Quantum Basics and Q-Day
- 06:14 Harvest Now Decrypt Later
- 07:42 Building a PQC Backbone
- 10:16 Proxies and Data Priorities
- 13:45 Crypto Discovery Essentials
- 16:56 Day One Four-Step Plan
- 18:58 CBOM and Business Decisions
- 21:13 Tools for Actionable Remediation
- 24:19 Operational Challenges at Scale
- 27:17 Measuring Crypto Agility
- 31:01 Wrap Up and Next Steps
This episode is brought to you by ATP Gov. Visit us online at www.atpgov.com or follow us on LinkedIn.
Transcript
[00:00:00] Host: Welcome to The Bottom Line Up Front, the podcast that cuts through the noise to deliver distilled insights from today’s most important technical webinars, presentations, and demonstrations. Designed for federal and military IT leaders, each episode breaks down complex technologies into mission-ready takeaways so you get the key points fast.
Whether it’s cybersecurity, cloud architecture, or emerging defense technologies, we highlight what matters most and how trusted integrators like ATPGov can help implement and operationalize these solutions across your agency or command. No fluff, no filler, just the bottom line up front.
[00:00:37] Jason Gustetic: Thank you for joining today’s briefing, Quantum Security: Where to Start and What to Do Now, hosted by ATPGov.
My name is Jason Gustedt, and I’ll be your moderator today. Today, we have Erik, senior systems engineer with ATPGov. Erik leads cybersecurity sales enablement, and has spent more than 20 years supporting intelligence, community, and Department of Defense organizations. His background spans [00:01:00] complex enterprise systems, data centers, IT security, analytics, and software development, giving him a unique perspective on the operational challenges organizations face as they prepare for cryptographic modernization.
Also joining Erik is Joey Schwartz, Quantum Security Strategist with ATPGov. Joey supports combatant commands and foreign military sales initiatives, and brings extensive experience at the intersection of emerging technology and national security. A former US Army Major and graduate of the John F.
Kennedy Special Warfare Center and School, Joey is a frequent speaker on quantum computing threats and the implications of post-quantum cryptography for government and defense organizations.
[00:01:42] Joey Swartz: Happy to be here.
[00:01:43] Host: I wanna start off by saying if quantum computing still feels like science fiction, you’re not alone in this.
Because here’s the reality: the timeline is accelerating, the stakes are real, and the decisions organizations are making today will directly impact whether their data is [00:02:00] secure or exposed tomorrow. And across our recent webinars and podcast episodes, we’ve unpacked what quantum really means, from the harvest now decrypt later threats to federal mitigation timelines, to also include practical steps like cryptographic inventorying, quantum-safe VPNs, and hybrid encryption strategies.
The consistent message in all this is that this isn’t something you can wait for and react to, it’s something you have to plan for now. So in today’s session, we’re gonna bring all of that research together, and I’ll be asking questions of Joey, and I’ll be asking questions that many of you are probably already thinking about.
What’s the hype versus what’s the reality? How urgent is this actually? And most importantly, what should you be doing today inside of your environment? So as Jason mentioned before, Joey Schwartz from ATPGov is joining me, and he’s deeply involved in helping agencies and enterprises navigate this shift from theory to action.
So Joey, I set the stage there for you. Let’s start with the big picture. For the folks who still [00:03:00] think quantum is a future problem, in air quotes, how real is the threat right now?
[00:03:05] Joey Swartz: Yeah, a good question, Erik. So I’m gonna back up just a tiny bit for folks who m- maybe don’t have a really deep understanding of post-quantum cryptography and, and the sort of issue that we’re facing, and then I’ll go into, you know, the timeline issue.
A quantum computer operates differently than a classical computer. It manipulates atoms instead of, uh, using electric impulses through a silicon wafer. The so what of that is that a quantum computer doesn’t just give me ones and zeros. It gives me a one, a zero, or both. So now I’ve increased my compute power by a significant margin, to the point where I can actually create enough compute power that I can use what’s called Shor’s algorithm to break encryption.
I basically don’t have enough compute power on the entirety of the Earth right now with classical computers. We could go for 10,000 years and use every chip we have, and we still wouldn’t break an AES 256 encryption. With quantum computers, we will have that power. Now, [00:04:00] quantum computers are here today.
The only challenge is they’re new, so we’re still working through some of the things like error rates, and they’re also pretty small. We measure quantum compute power by something called a qubit, just like we do a bit for classical computing, and the largest quantum computer in existence right now is 120 qubits.
So relatively small. You’ll hear us use the phrase Q-Day several times. Q-Day is the day when we get a cryptographically relevant quantum computer. So essentially, that’s the day when they get big enough and powerful enough that I can actually start breaking modern algorithms. So that’s obviously a problem, right?
We run everything on encryption, and the question then becomes, well, when does Q-Day happen, right? Well, Q-Day is somewhere around five to 10 years from now. It depends on the, who’s doing the estimate This is just my opinion, but I think all signs point to it actually coming in at that five-year mark, and there’s a couple reasons I say that.
DARPA, for example, most of the research for quantum computing is being done by nation state actors. It’s being funded by nations because it’s, it’s very [00:05:00] expensive, and the United States is no exception. So DARPA put out big research grants in the last couple years for companies to develop newer and better quantum computers, and last year Microsoft, uh, released its Majorana One.
In less than a year after that first quantum chip, they’ve got their second quantum chip out that has doubled the power. Having released Majorana Two, even in, it was just in the last few weeks, Microsoft has cut its estimate to build a scalable quantum computer in half. By twenty twenty-nine they expect to have a scalable quantum computer.
There’s also Chinese reports. Chinese researchers have done some breaking of very, very small encryption. I, I think it’s like fifty bits or something like that. But the fact is they were able to power the algorithm and do it. So there’s that, and then there’s also a continual revision down. So there’s this question of how many qubits do we need to actually break modern strong encryption?
And the first estimate started at, at a million qubits probably two or three years ago. In the last couple of years, that got revised down [00:06:00] to five hundred thousand, and now one estimate has it at a hundred thousand. We’ll see where the rubber meets the road when we get there. All those things are indicating to me that the pace of change makes it sooner rather than later.
Okay, so that’s our background. What’s the actual timing of this threat? Well, the timing of the threat actually is, is now, partly because of something called harvest now, decryption later. Harvest now, decrypt later, we have tons and tons of cybercrime being done all over the world, and there’s tons of data being exfiltrated, and many of these cybercrime organizations are affiliated with nation state actors.
So Salt Typhoon is sort of the gold standard there. Highly financed, well-resourced Chinese state organization, two hundred known incidents in eighty countries, and every time we go back and do a postmortem on a Salt Typhoon incident, we find out that they were there longer, they took more stuff, et cetera.
Right now, the data they took is usually encrypted, and so it’s, it’s not always worth anything, but they don’t lose anything by keeping it around, and China is absolutely one of the state actors that is doing tons of quantum [00:07:00] research. So ultimately, that harvest now, decrypt later risk, it’s here today. And then the other issue is, yes, Q-day is technically the day where I have to worry about my encryption algorithm being broken, but the problem is it’s going to take a long time for us to adapt.
So if I’m right, and if in five years we hit Q-day, it’s too late. You have to start preparing for it today because it will take anywhere from three to five years to get a major portion of your environment moved over to, to post-quantum algorithms. It’s gonna take a long time to get there, so technically the risk is now
[00:07:33] Host: Joey, I love how you have taken eight months of research here at ATP and condensed it down into a two-minute preamble-
so we can continue the conversation. That being said, in our research, you and I talk about this every day, and there is a lot of FUD, a lot of fear, uncertainty, and doubt in the ecosystem right now when people are trying to figure out how to move forward with PQC. So how do we balance the pressures of the 2029 and 2030 [00:08:00] mandates against the actual quantum risk?
How do we mitigate that, and how do we put into perspective the reality that this could actually take years but we don’t wanna procrastinate?
[00:08:10] Joey Swartz: Yeah, I mean, I think the way that we do that is by investing in what I like to call a PQC backbone, right? And, and for me, fundamentally, the IBM tool set is what does that.
I need to have inventory capabilities, I need to have code scanning capabilities, and I need to have proxy capabilities. The inventory, I just need to know where I’m starting. Code scanning, we- almost every environment has some kind of custom application, and they don’t have an actual CBOM that I can pull from a scan or from a library or from a, a vendor, so I need to know, like, what my cryptographic risk is in that static code.
And then I also have to have proxying. IBM’s the only vendor with all those capabilities in the same portfolio, um, with all those things so tightly integrated. And so what I, I need to start by doing is giving myself the knowledge of where I’m at and then figure out, okay, what’s riskiest right now? [00:09:00] What do I need to deploy proxies in front of?
Because the proxies are ultimately gonna help me with balancing that pressure. You would be crazy to go out and start proxying stuff right now without having an inventory though. You need to know where you’re at. That inventory needs to be a living document, right? You will pull your hair out trying to do this if you don’t have some sort of organization to how you’re approaching it.
But between the organization and then the proxying, that’s gonna give us some time where we can start working on the actual meat and potatoes of things, which is if I have an application that’s PQC ready, I switch it to using PQC. If I have something that is not PQC ready, develop that application. Start moving things like VPNs over to a quantum safe VPN, stuff like that.
It allows me to do the actual changes and move to that native PQC footprint while having some immediate protection of my most critical data
[00:09:51] Host: Yeah, and comically, when we think about this, the way people originally approached the PQC problem, it was like the Y2K bug. We’re all running around with our hair on [00:10:00] fire trying to figure out how to go from a two-digit date to a four-digit date, but we didn’t have enough time to execute that, and we thought all the lights in the country were gonna go out as a result.
That’s really not the case with the PQC strategies that are here. We have time to implement them, but to your point, we have to do it in an organized way. But you hit on something really important earlier, so I wanna dig a little bit deeper into harvest now, decrypt later, because that also gets used as part of this get everybody excited about getting it done as soon as possible.
So it is a serious threat, but how serious is it? And you were talking about the proxies. How do those approaches help with the organizations in kind of spacing out the timeline on their roadmaps?
[00:10:38] Joey Swartz: Good point on the whole, like, Y2K sky is falling thing, because we don’t wanna approach PQC that way. PQC, uh, remediation and getting to a sort of native quantum safe movement, it’s gonna take a long time.
As we’re looking at it, what we need to do is we need to evaluate the value of the data. The risk for harvest now, decrypt later is the fact that some data is [00:11:00] persistent. So, uh, medical records, insurance records, these are all actually, like, top targets of any cyber criminal are gonna be medical things because of the amount of PII they have in them, the amount of billing information they have in them.
But you’re gonna get into things like intelligence systems. Think of all the background check systems. The security clearance system got hacked, you know, what, 10, 15 years ago now. All these things that have some serious value, even if it takes 10 years for you to open the file, that’s kind of where you wanna balance the focus with harvest now, decrypt later The main thing is just coming up with a plan sooner rather than later, because I want you to kind of, again, think about if it’s already vulnerable and I don’t mitigate it until five years from now, I’ve just given them five more years of data.
So I wanna start by mitigating that very important data now. Eh, do I care maybe if they have all of my, you know, unclassified, not sensitive emails? Probably not, but I’m gonna care about things like research and development. I’m gonna care about patent data. I’m gonna care about medical records from the VA [00:12:00] or troop movement at DoD or DoW.
So it’s just prioritizing that. And then the other thing is kinda how does that work? I’ve mentioned the proxies, but I wanna give a little color here in terms of what they’re actually doing. Those proxies can sit at various places. They can either be forward or reverse proxies, and they can sit across the enterprise, right?
Whether it’s on-prem or in the cloud. IBM’s Quantum Safe for Mediator is the tool that creates those actual proxies, and it does a couple of things for me. The first is if I have a vulnerable application, it’s not PQC ready, it allows me to put a proxy in there that can actually intercept that communication from the application.
It’s going to re-encrypt that data in a post-quantum algorithm. And so Salt Typhoon can have it ’cause they can’t do anything with it. At that point, I’m just finding a way to translate that data into a different encryption. The other thing I’m doing is I’m actually also setting the stage for being able to make sure that everybody can play on the same backbone, because otherwise, one challenge I have is if I have [00:13:00] applications talking in PQC and other applications that don’t, then there’s a communication error between them, and I wanna make sure that we’re not creating any networking errors, we’re not creating any application errors.
A lot of this needs to go into, you know, making sure that we’re not creating additional problems for ourself while we’re trying to fix another. And that kind of provides a lot more space for organizations to plan and transition
[00:13:22] Host: Yeah, and what you alluded to there, and you mentioned it before, if anybody caught it, is the discovery process and how important that is.
And you name-dropped, you talked about IBM there for a second. And we’re not gonna lean on any one vendor or the other because there are so many vendors now playing in the PQC space, as we’ve discovered over the last eight months. Eight months ago there were five, and now there’s 150. But discovery is at the heart of all this, and there are some major players in that space.
So let’s talk about cryptographic discovery. That’s across the networks, that’s across your source code, that’s across your inventories. Why is that such a foundational keystone part of the success of anybody’s PQC strategy?
[00:13:59] Joey Swartz: The biggest [00:14:00] reason is the fact that cryptography is so ubiquitous. Every single thing we do has some level of cryptography in it.
My emails are encrypted with TLS. Think of the signatures every time you do an electronic signature when you buy a house or you sign a contract or whatever, that has encryption to it. And there’s, in fact, right now there is a executive order related specifically to the signing certificates for things like that sitting on the president’s desk that says, “Hey, by the end of 2027, any signing certificate needs to be post-quantum algorithm.”
So it’s just the fact that it extends to everywhere, and because it extends to everywhere, you end up having this challenge of how do I know where it’s all at, right? Because I have application issues, I have key generation and key management issues, I have any number of places that are affected by this.
I also wanna focus on the fact that it’s more than just an initial picture, okay? Inventoring is not a one-and-done situation. Because cryptography touches everything in the environment, it means that as I remediate it, my picture changes [00:15:00] continually. How am I gonna check my progress, you know, without an inventory?
If, if I don’t have an inventory that’s being updated regularly, I, I just don’t know where I’m at and I’m kind of flying blind. Another thing is how can I report to higher echelons? Very important, especially in the federal government where you have multiple layers of management and command. You know, how am I gonna communicate where we’re at to somebody who’s trying to do a roll-up at a higher environment?
Good example, DOW CIO requiring that inventory currently. And then the other thing is how do I enforce compliance, right? My inventory isn’t just telling me where I’m at, it’s telling me is everybody listening. And so once we’ve made the move to certain algorithms and others have started to become deprecated or, or no longer considered safe, am I making sure that people are still doing that, still holding the standard?
The main thing I would say is that inventorying is really critical because of that ubiquity, but as I said, it, it needs to be dynamic. It needs to be integrated with the other tools because my inventory is, is not just giving me a picture and then I’m doing everything manually. I need to be able to initiate tickets.
I need to be [00:16:00] able to make sure that we’re automating that remediation process because it touches so many things. If we do it manually, w- we’re just swimming upstream. And it needs to be continuously updated. It needs to be a living document
[00:16:10] Host: Anytime a new technology comes to the forefront, technologists, strategists, practitioners, we love new buzzwords, right?
That’s our favorite thing. And this is rife with acronyms and new terms that people are probably googling as we speak, but there is a very important term, I think you foreshadowed here, that has surfaced as a result of the research we’ve been doing and everything we’ve been studying, and you kind of defined it without saying it, which is crypto agility.
Crypto agility is what this is really all about, and many organizations are struggling, as you kind of alluded to, where to start with their PQC journey, and that crypto agility is at the center of that. It starts with discovery, it allows them to future-proof their environment by swapping in and out different cryptographic algorithms, whether those be classical or PQC or whatever.
But we need to look at day one, and I know you’ve put together, with help from folks [00:17:00] at ATPGov, a four-step process on what that day one and that process and that assessment really looks like in practice. You wanna share that with everybody?
[00:17:09] Joey Swartz: Yeah. So the process is gonna start with that assessing and inventorying phase, and I’m gonna go back to the IBM portfolio here just ’cause it has so many features in that process.
So day one, I’m gonna install Guardian Cryptography Manager, IBM’s inventorying product. And what I’m gonna do is I’m not reinventing the wheel there. I’m not going out and doing all new scans on my own. I do have an Nmap scanner as part of that, that I can go out and do, but I have tons of scanners and tons of crypto objects already in my environment.
The only difference is each of them is looking at different things, so I don’t wanna have to go to, like, 10 interfaces. I want one crypto-specific tool that I’m gonna be able to manage that from. So I’m just gonna pull stuff I already have, and that’s gonna happen in a relatively rapid fashion, a couple of days.
We’re gonna run that through policy engine, we’re gonna build dashboarding, and that’s gonna sort of be that step one. That step two, I’m gonna start pulling in additional [00:18:00] integrations for that Guardian Cryptography Manager tool. So I’m gonna start pulling in, for example, my HSMs, integrating that into the platform.
I’m gonna be pulling in transparent database encryption, doing all of my key management stuff, making sure I have all of that stuff viewable from a single central area. And then I’m gonna start integrating into other tools like ticketing systems, CMDBs, ServiceNow, Jira, all of the sort of big names I can put bidirectional integration in place so that I can run my operations through that.
From there, I’m, I’m also gonna be installing the Quantum Safe Explorer. I’m gonna be scanning my static code, and all of that, again, gets put back into the same platform. It gets integrated into, into Jira, so I’m using that information in my CI/CD pipeline. And then I’m gonna move on to sort of that final phase where…
I say final phase, it’s, it’s iterative over years, but that sort of final four-step installation is putting remediation in place. I’ve identified what’s most risky, what’s most relevant to protect, and I’ve got my proxies in place. And at that point, then we’re [00:19:00] kicking off the marathon
[00:19:01] Host: And there’s a very important deliverable that gets created in that four-step process, and that’s the cryptographic bill of materials.
And the reason I wanna hone in on that is because as we know, this particular PQC journey involves not just one team running a scan and generating a report, it involves the network team, the IT infrastructure team, the OT teams, the DevSecOps teams. They all have to run their own cryptographic algorithm discoveries, produce a cryptographic bill of materials, and then hand that off to the ISOs and ISMs and the proud folks over on the security team to assess that.
This is much like doing your cat ones, your cat twos, your cat threes for your ATO process. You’ve gotta go back and assure that all of these libraries have been changed out, that they’re up to speed, they meet the mandates, et cetera. That’s a huge amount of additional pressure now, but the key is that CBOM.
So how should the business logic change with respect to this new variable that we have to pile on top of all the other mission [00:20:00] criticalities that influence, you know, our day-to-day life in federal space?
[00:20:04] Joey Swartz: Yeah, I mean, I think there’s gonna be a lot of, um, what I would call business process decision-making, right?
You- you’re gonna get that prioritized output from the cryptography manager interface, but you’re gonna have to go through and ask some, some questions that are business-focused. They won’t give you the easy answer. What’s my lowest hanging fruit? You mentioned updating libraries, crypto agility. I might have applications that run on crypto libraries and the crypto’s not hard-coded.
I can swap those out, and we may be okay to use that, and so I might have some low-hanging fruit I can take care of right away. You know, how difficult is it to remediate these things from a development standpoint? I think one way this is very different from regular sort of zero trust operations is that many of my zero trust remediations are patches or updates, things like that.
This is primarily, not entirely, but a huge chunk of this is development-based. It’s application-based. So it’s, it’s a little bit heavier lift. And then you really have to think about staff and stakeholder. Yes, I [00:21:00] might have a tool that’s very, very easy for me to make PQC ready, but how many different stakeholders have to go through it?
And so ultimately I think there’s a number of different things you have to take from that CBOM, and it’s not just plug and play. You gotta go through that business context.
[00:21:13] Host: You stumbled backwards into zero trust, one of the hot ticket items in the technological zodiac calendar from a couple years ago.
But we’ve been able to actually take all the different vendors and products and offerings that exist in the PQC world today, starting from when we were looking at this early summer last year into the fall when there were very few vendors, to now where we’re, you know, 150-plus vendors, and we were able to actually take them and overlay them on top of the DoD seven pillars of the zero trust, and there’s actually vendors that can satisfy those requirements as we align them.
Maybe not naming names, you’ve mentioned some tools already. What I’m getting at here is what couple of tools, ’cause I don’t think you can solve this problem with just one tool. There’s no silver bullet, just like there is no silver bullet- Yeah … [00:22:00] for solving zero trust. What tools help organizations go from awareness to actionable remediation?
What do they need in their toolkit?
[00:22:08] Joey Swartz: And I’m, I’m banging the drum pretty hard on IBM. I’ll mention some other things as well. But IBM overall is gonna have that sort of big programmatic spine for me, right? So Guardian Cryptography Manager is gonna give me prioritized recommendations. It’s gonna keep me informed with progress, and it’s gonna prevent backsliding, enforcing compliance.
So I’m not just looking at a list of things. This is, “Hey, how do we actually move the program along?” Quantum Safe Explorer, we’re going to be integrating into an existing CI/CD pipeline. We don’t have to reinvent the wheel. But even more than that, Quantum Safe Explorer is not just telling me something’s vulnerable, it’s telling me where in the code it’s vulnerable, and I can use that as part of my next steps.
So I can dump it into Jira and say, “Hey, fix this. Here’s what needs to go get fixed,” to my development team. But I can also use it in conjunction with, with new code tools, so I can integrate this with Claude, I can integrate this with IBM Bob. Pretty much [00:23:00] any AI code tool will be able to use these results to help you with the coding remediation.
So I’m getting the instructions from an automatic scanner, and I’m dumping them into an automatic coder. And yes, as the human, I’m gonna be in the loop, but it’s really moving to actionable remediation. Quantum Safe Remediator, yeah, it’s giving me immediate protection via proxies, but I also have a test harness in there too.
It’s pointless if I solve one problem, uh, by getting the PQC right, but the application doesn’t work well. I need to make sure the applications are working well, I’m not creating new problems. But then there’s a number of different things that you’ll be able to, to move on to as you get this information.
Yes, I’m gonna be working on applications, but I’m also gonna be looking at, okay, uh, does my key manager have the ability to work through PQC algorithms? Do I have enough hardware? So for example, do I have big enough TPM cards? Do I have HSMs that are capable of much larger algorithms? Do I have any sort of good entropy, right?
I need good entropy. I need good real quantum random number [00:24:00] generation if I’m gonna strengthen my algorithms. And, and that’ll strengthen not just my existing or my PQC algorithms, it’ll strengthen my classical algorithms as well. The tools are sort of a starting point, and they feed into the ones I’ve talked about, you know, mostly today.
They feed into everything else, and they allow us to start saying, “Okay, I know where my OT security is right now. Let me go ahead and put something like BlastWave in front of my OT tools,” and that can use PQC algorithms, and all that information’s gonna flow up into that centralized system
[00:24:29] Host: Yeah, and there’s so many interoperation points involved in this because we are dealing at such a low level on a lot of different technology.
Some of those are open source, some of those are closed, where we have to wait for the manufacturers to get involved. I mean, if we just talk about operating systems alone, we know that Red Hat is working on making the later versions of Red Hat all PQC ready. You know, Microsoft is trailing behind, things like that.
There’s a lot of moving parts. So that is to say, this is not a smooth road. It’s full of cobbles. And I wanted to ask you, from your opinion, [00:25:00] looking at everything we’ve looked at over the last eight months plus, what’s the biggest operational challenge that agencies are facing when trying to fix these types of cryptographic issues at scale?
I mean, this is unlike anything we’ve ever done before. And from the tools that you’ve been suggesting, how does their automation help, or are there some drawbacks where, like you said, the human still has to be involved to make sure it goes over as smoothly as possible?
[00:25:23] Joey Swartz: The biggest challenge with deployment is just the breadth of things that cryptography touches.
The fact that so much of this is application-based. I mean, I can’t just go… And beware if anybody comes to you and tells you, “Our new hardware tool is gonna solve your PQC challenges.” It’s not true. That hardware tool may have a card that can handle the additional strain of quantum algorithms. It may be beefier, it may be compatible to do those things, but PQC touches everything.
It’s a program, it’s not one tool. And so that breadth of what it touches is truly the biggest challenge. My biggest advice for that challenge is, it’s human advice, not necessarily tool advice. [00:26:00] View it as, you know, years long journey. You’re gonna take two or three years to even get, get a bunch of this remediation done.
You can get to immediate protection in a few months, but it’s gonna take a while to start moving through that. So view it as an iterative process, and just put it as part of one of those continuous improvement cycles. But that’s kind of why the automation is so important. I’m glad to see that entities, um, like IBM have built in so much integration, so much automation.
The point is that I don’t want to go from platform to platform. I want to be able to create messaging, to be able to open tickets, to be able to run things between these platforms because it touches so much. If we create more manual steps, we’re just gonna be behind
[00:26:38] Host: Yeah, and I think you underscored a very important point is that manufacturers like IBM, Palo Alto, and others, even Red Hat, the operating system manufacturers, they’re building platforms and not point solutions.
And if I look back over my 20-plus years in the technology space, it’s always been, you know, something like zero trust, where I’m gonna create this little tool that does this fun little function. [00:27:00] This is so comprehensive and so expansive that the big investment is building these comprehensive platforms that can attack this at every level, which I think is really cool.
We haven’t seen this in a long time. So that’s something to keep in mind is when you’re investing in these products, you’re investing in a platform and not just a Band-Aid solution. But to that end, let’s talk about the future a little bit, because this is a shifting sands type of environment. It’s constantly evolving.
Like I said, over the last eight months, we’ve gone from five products to 150-plus products, and it continues to grow. Let’s reframe that, ’cause I don’t wanna focus just on the vendors, but let’s talk about what does true crypto agility look like in a federal organization, and how should our leadership measure progress toward quantum resilience in the next few years?
[00:27:47] Joey Swartz: Yeah, great question. To make sure I define the term, too, I don’t remember if I did an actual definition or not, but for folks listening, crypto agility is basically our ability to swap out algorithms. Right now, many applications are written with [00:28:00] their cryptographic frameworks actually hard-coded in the, in the application code.
So if I wanna change my algorithms, I have to go actually redevelop my application, and that’s not where we wanna be from here on. Twenty years ago it was fine, but the landscape is changing now. So what I want is I wanna be able to have a cryptographic library that is actually attached to that application so that if I need to change my algorithms, I just pull the library out and I insert a new library in, and that gives me crypto agility.
It gives me the ability to change my crypto kind of as needed. Why is that really that important? ‘Cause, you know, we’re just changing this one time, right? I don’t know. I don’t think so. When we finally hit Q-day, it might be that one of the quantum-resistant algorithms has some sort of problem that we don’t know about.
As of now, we believe that they’re quantum-safe, and we’ll see kind of how they hold up because, you know, this is just like any other zero trust. There’s always somebody trying to find that weakness in the armor. So for me, the way I think about how we would, you know, measure crypto agility is gonna [00:29:00] be kind of actually through a series of questions.
Can I answer yes to these questions honestly? So does my organization have a dynamic, integrated, and automatically updated posture tool? If I don’t have that, I think I’ve already failed at crypto agility ’cause I don’t know what I’m doing. Now, do I have a team with eyes on the crypto problem, or is this just something we’re responding to sporadically?
There has to be a team, whether they’re, they’re full-time or they’re sort of tasked with extra duty, but do I have a team that’s dedicated to continuous iterative improvement? ‘Cause it’s not gonna happen in one sprint. Can I say, within a few hours of research, what our next steps should be based on business value, risk conditions, et cetera?
And maybe it’s a couple days, maybe it’s a couple hours. It’s gonna depend a little bit on the, the complexity, but the point is, do I have the ability to come up in a short period of time with what the next step in that iterative process is? If we get to the end of the step we’re on and then we just feel like we’re in the dark again, that’s not gonna be sufficient to address this threat Can I convey my [00:30:00] posture and risk to higher echelons?
They’re gonna wanna know it. I don’t wanna be hand jamming spreadsheets. People are doing that right now with the DOW mandate. We don’t wanna hand jam spreadsheets of CBOMS to try and report that higher. And then, kind of the final question to me is, is my process, is all of this stuff we’ve just talked about integrated and automated?
I don’t want silos. I don’t want any more manual processes than I need to, ’cause there’s already gonna be a lot of human-centric processes as part of this movement. So we wanna make sure we’re not creating ex- extra problems for ourselves. And I would say that the tools that we have available, PQC tools, they’re ready for primetime, okay?
I know there’s some, some worry about whether the tools are ready. Am, am I gonna spend millions of dollars on vaporware? No, like, that’s not where the market is. You need to be smart about what you’re starting with, because some things are niche and some things are enterprise. So you gotta be smart that way.
But overall, PQC’s ready, it’s here, and we can help de-risk it at ATP. We can actually give you a good sense of, what am I actually going to get by [00:31:00] investing this money?
[00:31:01] Host: Well, Joey, I can’t thank you enough for bringing us up to speed. I’ve had so much fun working on this with you since last summer. I’m really looking forward to seeing where the PQC journey is going and continuing this research.
And with that said, I wanna remind everybody that’s listening that they can stay on the pulse of our PQC and quantum computing research by following our podcast, The Bottom Line Up Front, everywhere you download, stream or listen to podcasts, and be sure to visit our website atpgov.com for the latest articles related to PQC.
You can email any of us at info@atpgov.com or reach out via social media on LinkedIn.
[00:31:37] Joey Swartz: Awesome.
[00:31:38] Jason Gustetic: Fantastic. Thank you again to everyone who joined us today. Appreciate your time and participation. Have a great afternoon.
[00:31:45] Host: Be sure to reach out to ATP Gov today at www.atpgov.com or email info@atpgov.com or check us out on social media on LinkedIn.
Thanks for listening, and be sure to subscribe to The Bottom Line Up Front wherever you get your podcasts. And [00:32:00] stay tuned for more distilled insights from the front lines of tech and national security. So until next time, stay secure, stay mission ready.
About this Podcast
The Bottom Line Up Front, is ATP Gov’s podcast that cuts through the noise to deliver distilled insights from today’s most important technical webinars, presentations and demonstrations designed for federal and military IT leaders. Each episode breaks down complex technologies into mission ready takeaways, so you get the key points.
Fast.
Whether it’s cybersecurity, cloud, architecture, or emerging defense technologies, we highlight what matters most and how trusted integrators like ATP Gov can help implement and operationalize these solutions across your agency or command.
No fluff. No filler, just the bottom line up front.