Quantum Security News
Navigation

Assessing Quantum Cybersecurity Risks: An Introduction to Navigating the New Threat Landscape

CT

Cystel Team

PUBLISHEDMay 6, 2024
READ TIME3 min read
Assessing Quantum Cybersecurity Risks: An Introduction to Navigating the New Threat Landscape

Assessing Quantum Cybersecurity Risks: An Introduction to Navigating the New Threat Landscape

In cybersecurity risk assessment, Cryptographically Relevant Quantum Computers (CRQCs) not only pose a new threat by significantly boosting computational power, but also introduce a fresh attack method known as store now, decrypt later. While this doesn't cause a radical shift in how risk assessments are conducted, it underscores the need to grasp how CRQCs alter the risk landscape.

Following are some key considerations in risk assessment frameworks:

  • Current CRQC Threat Landscape Analysis — understanding the potential adversaries and their capabilities
  • Asset Inventory with Cryptographic Safeguards — cataloguing assets and assessing the robustness of existing cryptographic measures
  • Prioritization Methodology — evaluating assets based on data sensitivity, required confidentiality duration, associated costs, and operational impact
  • Deployment of Quantum-Resistant Controls — implementing cryptographic solutions that can withstand quantum attacks
  • Periodic Reassessment — adapting to evolving quantum standards and reassessing the risk posture
  • Ongoing Threat Monitoring and Mitigation Plans — establishing protocols for continuous threat detection and response

Mosca's inequality: a breach occurs when security shelf life plus migration time exceeds time to compromise

Conducting a Quantum Cryptanalytic Risk Assessment (QCRA)

A Quantum Cryptanalytic Risk Assessment (QCRA) specifically targets threats and vulnerabilities arising from CRQCs. Any QCRA should encompass the current CRQC threat landscape, asset inventory with cryptographic safeguards, prioritization methodology, deployment of quantum-resistant controls, periodic reassessment as quantum standards evolve, and ongoing threat monitoring and mitigation plans. Prioritization criteria should include data sensitivity, length of confidentiality, cost, and operational feasibility.

The key steps in conducting a QCRA are as follows:

  1. Identify and Define Assets — Begin by identifying and defining the assets that are at risk from quantum computing. This includes data, systems, applications, and communication channels that rely on cryptographic algorithms.
  2. Evaluate Threats — Assess the potential threats posed by CRQCs. Consider both immediate threats, such as the "store now, decrypt later" attack where a Quantum Capable Threat Actor (QCTA) gains access to sensitive data that can be decrypted once a CRQC is available, as well as future threats from QCTAs with access to CRQC.
  3. Assess Impact — Determine the potential impact of a successful quantum attack on the identified assets. This involves evaluating the consequences of compromised confidentiality, integrity, and availability of the assets. Consider the potential financial, reputational, and operational impacts.
  4. Analyse Vulnerabilities — Identify the vulnerabilities in the current cryptographic mechanisms used to protect the assets. Evaluate the resilience of the cryptographic algorithms and protocols against quantum attacks. Consider the level of quantum resistance provided by the algorithms and the potential for quantum attacks to break the encryption.
  5. Prioritise Risks — Prioritise the identified risks based on their potential impact and likelihood of occurrence. This helps in determining which assets and cryptographic mechanisms require immediate attention and mitigation efforts.
  6. Mitigation Strategies — Develop and implement mitigation strategies to address the identified risks. This may involve upgrading cryptographic algorithms to quantum-resistant alternatives, implementing post-quantum cryptography, or adopting quantum key distribution protocols. Consider the feasibility, cost, and impact of implementing these strategies.

It is important to note that the specific steps and methodologies for conducting a QCRA may vary depending on the organization and the risk assessment framework being used.

A Risk Model Example: Crypto-Agility Through a Climate-Risk Lens

One notable approach, described by risk teams at Wells Fargo, borrows its structure from the mathematical models used to capture the economic externalities of climate change.

The model works by identifying the risks associated with CRQCs — including compromise of the cryptography used by individual system nodes — alongside the remediation and cost required to mitigate each node's exposure.

This approach provides a risk view across applications (data sources) and specific nodes, helping organizations understand the potential risks posed by CRQCs and take proactive measures to protect against those risks.

The risk model emphasizes the importance of increasing crypto-agility to keep up with the changes in cryptographic technologies and protocols that will consistently evolve as quantum computing matures. It also highlights the need for collaboration with third parties to ensure they are implementing post-quantum cryptography (PQC) to safeguard against quantum computers.

Related Intelligence

Continue your research into quantum security.