{"id":7096,"date":"2025-01-28T09:00:00","date_gmt":"2025-01-28T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cryptographic-agility-legislative-possibilities-benefits"},"modified":"2025-01-28T09:00:00","modified_gmt":"2025-01-28T15:00:00","slug":"cryptographic-agilitys-legislative-possibilities-business-benefits","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/28\/cryptographic-agilitys-legislative-possibilities-business-benefits\/","title":{"rendered":"Cryptographic Agility&#8217;s Legislative Possibilities &amp; Business Benefits"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd4681ec2c3b0dcdb\/6798efeee55c500c3f321445\/Cryptographic_security_%281800%29_Sergey_Tarasov_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of cybersecurity&#8217;s major pitfalls is assuming that risks will always stay the same. Failing to consider&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/emerging-threats-vulnerabilities-prepare-2025\">emerging threats<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;has caused detriment in the security field. When varied threats already exist that are time-tested and successful, like ransomware, phishing, or business email compromise, security professionals often don&#8217;t consider that new risks arise daily.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/quantum-leap-advanced-computing-vulnerable-cyber-target\">Quantum computing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;and the potential for cracked algorithms are among the first instances where security professionals have a heads-up on an emerging trend. As a result, both professionals and legislators can use this time to their advantage and prepare by putting forth maximum effort to approach cryptographic agility. This model is defined as the ability for technology to seamlessly switch to new protocols or mechanisms when algorithms become insecure (without system interruption).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Possibility of Cryptographic Agility Adoption\">The Possibility of Cryptographic Agility Adoption<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A critical question that has emerged as quantum computing and algorithm cracking approaches is whether&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/making-the-case-for-cryptographic-agility-and-orchestration\">cryptographic agility<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;is genuinely possible for the average tech company.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Quantum computing is not a new concept, and new cryptographic algorithms to prepare for that hypothesis have been developing progressively <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nist.gov\/news-events\/news\/2016\/12\/nist-asks-public-help-future-proof-electronic-information\">since 2016<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;(note the National Institute of Standards and Technology&#8217;s call for new algorithms \u2014 three of which were published last fall). Yet the United States is far from documenting robust legislation to mandate cryptographic agility in the US market.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unfortunately, this puts the data stored on US soil at risk, leaving US businesses to fend for themselves. Small players within the US may be at the mercy of legislation and large tech companies to pave the way for cryptographic agility (such as through&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/shared-responsibility-or-shared-fate-decentralized-it-means-we-are-all-cyber-defenders\">the Shared Responsibility Model<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">).&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NIST has done a solid job of widely distributing the three new encryption standards it has published (<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/08\/nist-releases-first-3-finalized-post-quantum-encryption-standards\">ML-KEM, ML-DSA, and SLH-DSA<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">). Still, proper enforcement may only be possible at the federal level, which is required to make cryptographic agility a widespread practice in security departments.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cryptographic Agility: A Legislative Necessity&nbsp;\">Cryptographic Agility: A Legislative Necessity&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One reliable way to plan for any emerging threat, including quantum computing that could crack standard algorithms, is to look to the courts. US security professionals and tech businesses should consistently look toward Europe, since its cybersecurity legislation is often further ahead and more mature.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Two examples are the emerging&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/ico.org.uk\/for-organisations\/the-guide-to-nis\/what-is-nis\">NIS<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;and&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/preparing-for-dora-amidst-technical-controls-ambiguity\">DORA<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;regulations, which strongly emphasize cryptographic agility as a security best practice. Though these sweeping directives were enacted outside US borders, they provide a framework America could use to build its quantum computing legislation.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A significant challenge regarding quantum computing and the cracking of standard algorithms is that we know it is coming \u2014 though not precisely when. The field lacks detail on how soon key cracking and invalidation will occur (though heavily debated, news articles emerged last fall indicating that&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.forbes.com\/sites\/craigsmith\/2024\/10\/16\/department-of-anti-hype-no-china-hasnt-broken-military-encryption-with-quantum-computers\">Chinese agencies had cracked reputable algorithms<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014 some argue the risk is coming sooner than 2030).&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This uncertainty underscores the strong benefit legislation would provide ahead of the arrival of quantum computing.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Business Benefit of Cryptographic Agility\">The Business Benefit of Cryptographic Agility<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Implementing a cryptographic agility model has benefits beyond data security and privacy protection. This adoption also has significant business benefits.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cryptographic agility is a strategic move for a company. Preparing before quantum computing fully emerges is an opportunity to positively contribute to a company&#8217;s bottom line, because cryptographic agility could be an organization&#8217;s market differentiator. With so few businesses embracing this best practice, implementing it today would present a distinct competitive advantage. Security and safety are not the only motivators for implementing a cryptographic agile program.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Time to Prepare With Cryptographic Legislation Is Now\">The Time to Prepare With Cryptographic Legislation Is Now<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A quantum computing risk assessment is challenging to conduct because no professional in the security space has been able to identify, with precision, how many years it will take until an algorithm like AES-256 (a popular symmetric model which is often the topic during encryption resiliency debates) is found to have flaws. Instead, the field has relied on very vague definitions and estimates, ranging from 10 years to 30 years down the road. Industries and legislators are postponing the goal of becoming cryptographically agile by decades, using both excuses that &#8220;we have time&#8221; and &#8220;we do not know when this risk will be realized.&#8221; Nevertheless, the time to prepare with cryptographic agile legislation is now \u2014 and even without it, businesses that adopt the model have a distinct competitive advantage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The cybersecurity field is fortunate to have adequate notice; they must prepare before quantum computing emerges and alters the trusted algorithms technology has relied on.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cryptographic-agility-legislative-possibilities-benefits\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY One of cybersecurity&#8217;s major pitfalls is assuming that risks<\/p>\n","protected":false},"author":12,"featured_media":7097,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7096","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cryptographic-agilitys-legislative-possibilities-business-benefits.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7096","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7096"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7096\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7097"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}