Encryption & Key Management
,
Next-Generation Technologies & Secure Development
,
Security Operations
Bank Cybersecurity Veteran Moona Ederveen-Schneider on Demystifying the Process
Enterprises need to start planning and executing their transition to post-quantum cryptography, and the best way to get started is through tabletop exercises, said Moona Ederveen-Schneider, founder of consultancy Resilia Connect.
See Also: OnDemand | Getting started with OpenTelemetry: Planning and tips for observability teams
The financial services cybersecurity strategy veteran has developed a free framework to help organizations transition to the post-quantum computing world, and tabletop exercises are essential for not only bringing all necessary stakeholders together, but also demystifying what initially might look like an insurmountable task.
Government guidance in the United States and Britain is clear: Have migration goals detailed within the next two years. By 2030, don’t consider legacy encryption algorithms to be safe anymore, and begin implementing post-quantum cryptography in high-priority systems. By 2035, legacy encryption algorithms should be fully deprecated.
But some sectors are ahead of others. Financial services, which plans its technology changes in five or 10-year cycles and has the trust of global financial markets to consider, is ahead of the game, Ederveen-Schneider said. Other sectors likely to be hit just as hard by the “harvest now, decrypt later” threat of quantum computers including healthcare, legal services and governments are farther behind, she said.
The key is to start planning now. “Ultimately, the organizations that will be the strongest position are the ones that didn’t wait for a regulatory trigger or a sector norm. They moved early, they scrambled less and when the moment came, they were ready,” she said.
In this video interview with ISMG, Ederveen-Schneider also discussed:
- Why having crypto agility – being able to change quickly – immediately improves an organization’s security posture;
- How to bolster an across-the-organization approach to post-quantum cryptography, including involving HR, legal, finance and compliance audit teams;
- The signal being sent by the likes of Google and Cloudflare announcing an internal deadline of 2029 deadline for full quantum readiness.
Ederveen-Schneider is the founder of consultancy Resilia Connect, author of the “Practical Post-Quantum Transition Framework” and serves on the faculty of the University of Cambridge Professional and Continuing Education’s Cybersecurity Strategy and Leadership Accelerator program. Her research focuses on the transition to post-quantum cryptography as well as artificial intelligence security governance. She previously served as FS-ISAC’s executive director for EMEA and in cybersecurity roles at multiple major banks.

