Quantum Security News
Navigation
Cryptography

The Vital Role of Cryptography in Our Digital World

CT

Cystel Team

PUBLISHEDJanuary 27, 2025
READ TIME12 min read
The Vital Role of Cryptography in Our Digital World

The Vital Role of Cryptography in Our Digital World

Having attended the Quantum Bootcamp hosted by the Institute of International Finance (IIF) and listening closely to Jaime Gómez García — Global Head of Santander's Quantum Threat Program and Chair of the Europol Quantum Safe Financial Forum — we were inspired to amplify his message further.

Quantum technology is shaping the future of finance and beyond. Here are the key takeaways from his talk, and why staying ahead of this transformative trend is becoming a regulatory necessity, not just a technical one.

The Quantum Threat to Cryptography

The advent of quantum computers poses significant challenges to cryptography across three critical dimensions: confidentiality, authentication, and legal history.

Threat Dimension Key Impacts
#1 Confidentiality Harvesting of comms data ("harvest now, decrypt later"); encrypted storage data (backups)
#2 Authentication Recovering authentication private keys; creating fake credentials; signing malicious code
#3 Legal History Recovering signing private keys; manipulating signed documents; creating fake documents with valid signatures

Confidentiality is at risk as quantum-enabled attackers could potentially decrypt stored communications and data, rendering them vulnerable. Authentication faces a similar threat — attackers may impersonate individuals or even entire supply chains. For instance, when software like Microsoft Office is installed, users trust its authenticity because of a verified digital signature. However, quantum attackers could forge a seemingly legitimate signature, distributing manipulated software laden with malware.

Finally, in terms of legal history, digital documents signed today could be compromised in the future. Quantum-powered attackers might calculate private keys used for signing documents, enabling the creation of fraudulent contracts or documents with seemingly valid signatures. A critical risk posed by advances in quantum computing is the potential to negate the validity of digitally signed documents. If a cryptographic algorithm were compromised, the integrity of all documents signed with that algorithm could be invalidated. In sectors like banking, this could affect hundreds of millions of documents, causing widespread disruption.

The takeaway: cryptography is foundational to the digital economy, and its security underpins trust in modern digital systems.

Preparing for the Quantum Computing Timeline

A chart showing 2024 opinion-based estimates of the cumulative probability of a digital quantum computer able to break RSA-2048 in 24 hours, rising from roughly 9% at 5 years to 26% at 10 years, 47% at 15 years, and 68% at 20 years

The timeline for the emergence of cryptographically relevant quantum computers remains uncertain. Experts have highlighted estimations that indicate a significant risk within the next decade: predictions suggest that by the early 2030s, there is roughly a 26% probability that such a computer could exist. This raises a critical question — how significant is a 26% risk that a nation-state or threat actor could potentially break cryptographic systems? The implications demand proactive measures to safeguard digital infrastructure before this becomes a reality.

Securing the Digital Economy in the Post-Quantum Era

A diagram showing migration time and shelf-life time bars running in parallel with a threat timeline, illustrating that migration must complete before the threat timeline catches up to data that still needs to remain confidential

The emergence of quantum computers raises significant questions about trust in the digital economy. Preparing for the transition to post-quantum cryptography requires careful planning, guided by principles such as Michael Mosca's theorem. This involves two key considerations: the shelf life of data and the migration time. For example, data like a mortgage contract must remain secure for the duration of its validity, yet quantum computers capable of breaking encryption could emerge within that timeframe. Migration to post-quantum cryptography must therefore occur faster than the predicted arrival of these computers.

How Long Will the Migration Phase Be?

Historically, transitions in cryptography have taken decades — evident today as some systems still rely on outdated versions of protocols like TLS, which secure web communications.

A bar chart showing protocol support for secure web services: strong presence of obsolete protocols standardized in 2008 like SSL and early TLS versions, and TLS 1.3, standardized in 2018, still not completely supported despite being a pre-requisite for PQC

Protocols superseded in 2008 remain relevant in roughly 30% of cases, while TLS 1.3 — the latest version standardized in 2018 and the only one supporting post-quantum cryptography — has achieved around 70% adoption. Over more than 15 years, outdated and vulnerable algorithms have yet to be fully eliminated. This highlights the complexity of migration efforts, which require several years and long-term data protection strategies.

The Challenge of Cryptography Expertise

A photo of a person with their hand on their forehead, with speech bubbles reading "We're still dealing with outdated software, let alone addressing cryptography," "Our expertise in cryptography is very limited," and "I recognize the threat, but I struggle to get the organization on board"

Many cryptography experts struggle to engage their organizations in addressing these issues and must still contend with obsolete software that hampers progress. Organizations often face competing priorities and struggle to allocate resources effectively. Additionally, a significant challenge lies in the lack of sufficient expertise in cryptography, making it difficult to address security concerns adequately.

Awareness Gap in Quantum Safety Preparedness

A report by the German Federal Office for Information Security (BSI) highlights critical concerns about quantum safety preparedness among German companies. After surveying 100 major organizations, the study concluded that none of the participants would achieve quantum safety in time. Alarmingly, over half of the companies had no plans, or intended to start addressing the issue only after five years or more. Even more concerning, 32% of respondents believed quantum safety was not applicable to them — a misunderstanding stemming from a lack of awareness about how deeply cryptography is embedded in modern digital infrastructure.

A related 2022 survey by KPMG in Germany found a similar pattern when organizations were asked when they plan to begin transitioning to quantum-resilient cryptography:

A stacked bar chart titled "Please evaluate the following timescales," showing survey responses on data confidentiality duration, transition start plans, and time to realize quantum resilience, sourced from KPMG in Germany, 2022

Asked when they plan to begin transitioning to quantum-resilient cryptography, 32% of respondents said the question was not applicable to them, while a further 18% said more than five years and 11% said five years — leaving only a minority actively planning a near-term start. This underscores the urgent need for increased education and action to address these risks.

The Risks of 'Crypto Procrastination'

A timeline diagram titled "Augmented Mosca's theorem – Crypto-Procrastination," showing crypto-procrastination and an 8-year migration period running up against a 7-year shelf-life and threat timeline, with the risk impact starting around 2035

An emerging concern is what can be described as "crypto procrastination" — a delay in addressing the risks of quantum computing. Organizations are preoccupied with debating the timeline for when a quantum computer capable of breaking encryption will become a reality, rather than focusing on the immediate risks. This hesitation leads to inaction, compressing project timelines, increasing costs, and introducing new risks as deadlines approach.

The key takeaway: priorities must be set to avoid delaying critical actions. Proactive steps need to be taken now to mitigate future challenges and secure systems against emerging threats.

The Need for Better Cryptography Management

The push for improved cryptography management is not solely driven by the potential emergence of quantum computers capable of breaking encryption. Instead, it stems from historically poor cryptography management practices across industries. For decades, organizations have placed immense trust in cryptography without sufficiently addressing its vulnerabilities. However, regulatory bodies are now stepping in to enforce change.

NSA CNSA 2.0. The US National Security Agency has outlined a timeline for transitioning to post-quantum cryptography. According to the plan, US government agencies are expected to adopt post-quantum cryptography by default between 2025 and 2027, and completely phase out classical cryptography between 2030 and 2033.

A Gantt-style timeline titled "CNSA 2.0 Timeline," showing software/firmware signing, web browsers/servers and cloud services, traditional networking equipment, operating systems, niche equipment, and custom/legacy equipment all reaching exclusive CNSA 2.0 use between 2030 and 2033

Beyond the phase-in schedule, CNSA 2.0 also sets explicit deprecation dates for classical algorithms:

Digital Signature Algorithm Family Parameters Transition
ECDSA [FIPS186] 112 bits of security strength Deprecated after 2030
ECDSA [FIPS186] ≥ 128 bits of security strength Disallowed after 2035
EdDSA [FIPS186] ≥ 128 bits of security strength Disallowed after 2035
RSA [FIPS186] 112 bits of security strength Deprecated after 2030
RSA [FIPS186] ≥ 128 bits of security strength Disallowed after 2035
Key Establishment Scheme Parameters Transition
Finite Field DH and MQV [SP800-56A] 112 bits of security strength Deprecated after 2030
Finite Field DH and MQV [SP800-56A] ≥ 128 bits of security strength Disallowed after 2035
Elliptic Curve DH and MQC [SP800-56A] 112 bits of security strength Deprecated after 2030
Elliptic Curve DH and MQC [SP800-56A] ≥ 128 bits of security strength Disallowed after 2035
RSA [SP800-56B] 112 bits of security strength Deprecated after 2030
RSA [SP800-56B] ≥ 128 bits of security strength Disallowed after 2035

Digital Operational Resilience Act (DORA). Organizations in Europe face increasing regulatory requirements for cryptography management. DORA mandated financial institutions to implement an enhanced cryptography management policy by January 17, 2025:

Requirement Actions
Financial entities shall develop, document, and implement a policy on encryption and cryptographic controls, designed based on approved data classification and risk assessment, including rules for when to encrypt data and for key lifecycle management (Art. 6.1 and 6.2) Organizations must verify and update their cryptography and data security policies
Financial entities shall include criteria to select cryptographic techniques and use practices based on leading standards, adopting mitigation and monitoring measures where reliable techniques cannot be met (Art. 6.3) Cryptography policies must specify valid algorithms based on standards; non-compliant use cases must be mitigated via use case and technical inventories
Financial entities shall include provisions to update or change cryptographic technology to ensure resilience against cyber threats (Art. 6.4) Crypto-agility
Financial entities shall record the adoption of mitigation and monitoring measures with a reasoned explanation (Art. 6.5) Monitoring of cryptography use cases and algorithms

PCI DSS. PCI DSS has long included cryptography requirements, with the new Requirement 12.3.3 taking effect on April 1, 2025, introducing further expectations for mature cryptography management:

Requirement Actions
Strong cryptography requested throughout the standard Organizations must verify and update their cryptography and data security policies
Methods to mitigate attacks on cryptography usage, including attempts to exploit weak, insecure, or inappropriate cryptographic implementations, algorithms, cipher suites, or modes of operation (Req. 6.2.4) Organizations must include cryptography controls in their QA and security audit processes
Up-to-date inventory of all cryptographic cipher suites and protocols in use Cryptographic inventories
Active monitoring of industry trends regarding continued viability of all cryptographic algorithms Crypto-agility
A documented strategy to respond to anticipated changes in cryptographic vulnerabilities (Req. 12.3.3)

NIST. Beyond Europe, NIST has outlined timelines for the deprecation of classical cryptography, with some algorithms phased out by 2030 and completely disallowed by 2035.

The takeaway is clear: compliance with these regulations is non-negotiable. Organizations must act now — not out of fear of quantum computing, but to meet imminent regulatory demands.

Meeting Regulatory Requirements with Quantum Cybersecurity

To meet regulatory requirements, organizations can adopt a structured quantum cybersecurity roadmap, such as the one Cystel uses with clients:

Cystel's Quantum Cybersecurity Assessment and Roadmap, showing five stages: Cryptographic Asset Scanning and Inventory, Quantum Risk Assessment and Prioritisation, Quantum Risk Solution Evaluation and Selection, and Quantum Safe Cryptography Implementation, preceded by a Pre-Assessment Stage 0

  • Pre-Assessment (Stage 0) — Educating internal teams about quantum threats and conducting a Business Impact Assessment (BIA) to prepare for next steps.
  • Cryptographic Assessment and Inventory (Stage 1) — Identifying weak or non-compliant algorithms to ensure compliance with standards.
  • Risk Assessment and Prioritization (Stage 2) — Creating a prioritized plan of action to address vulnerabilities.
  • Solution Evaluation and Selection (Stage 4) — Identifying and implementing the best quantum-safe cryptographic solutions.
  • Implementation and Ongoing Review (Stage 5–6) — Bringing quantum-safe cryptography into service, integrating it with existing systems, and continuously monitoring its effectiveness.

Cystel's Testing and Assurance of PQC Upgrades slide, describing Stage 6: bringing quantum-safe cryptography into service with ongoing review, with the SOC forming a key part of the monitoring process

Ensuring thorough testing and assurance of post-quantum cryptographic upgrades is critical. This includes verifying that updated systems integrate well with external parties and do not compromise functionality — with the SOC forming a key part of this as the eyes and ears of the systems being monitored.

By following these steps, companies can proactively address quantum threats and align with evolving regulatory standards.

References

  1. Institute of International Finance (IIF), Quantum Bootcamp — talk by Jaime Gómez García, Global Head of Santander Quantum Threat Program and Chair, Europol Quantum Safe Financial Forum.
  2. German Federal Office for Information Security (BSI), "Kryptografie und Quantencomputing" market survey.
  3. SSL Labs, "SSL Pulse" — TLS protocol adoption data.
  4. KPMG in Germany, 2022 quantum-resilience readiness survey.
  5. National Security Agency, "CNSA 2.0" transition timeline and FAQ.
  6. European Union, Digital Operational Resilience Act (DORA), Article 6.
  7. PCI Security Standards Council, PCI DSS Requirement 12.3.3.
  8. National Institute of Standards and Technology (NIST), post-quantum cryptography transition timelines.
Mosca's theoremcrypto-agilityTLSdigital signaturesIIF

Related Intelligence

Continue your research into quantum security.