top of page


PQC without Data Lineage Creates Hidden Quantum Era Exposure
Post‑quantum cryptography is being sold as the next great migration. Replace RSA and ECC, update certificates, test applications, move on. That narrative is incomplete. It protects the lock, not the contents of the safe. The real exposure begins when an organisation cannot prove where its most valuable data has been. The Crown Jewel is the data itself — the record, design, or transaction whose loss would cause material harm. If that data has travelled through environments you
Brian Couzens
1 day ago3 min read


What NISQ Hardware Tells Us About Quantum Risk
Why today's limitations in noisy quantum machines still matter for assurance, PQC planning and governance By Dr Clauden Higgsbottom Published August 2026 Executive Summary NISQ algorithms such as QAOA, VQE and other variational circuits have not yet demonstrated practical advantage on real-world workloads. Their strategic value is different: they provide measured evidence about noise, circuit depth, sampling cost, hybrid workflows and operational reliability. That evidence he
Brian Couzens
2 days ago6 min read


PQC War Rooms: The Global Enterprise Risk Transformation CISOs Cannot Outsource
Post-quantum cryptography is still being treated by too many organisations as an algorithm migration. That is the wrong frame. PQC is becoming a trigger for a much broader enterprise risk transformation. The algorithms are being standardised. The harder problem sits around them: discovering where cryptography actually exists, identifying who owns it, understanding which suppliers control critical dependencies, determining which data cannot afford to remain exposed, and creati
Brian Couzens
3 days ago10 min read


Why 47-Day SSL Certificates Will Break Legacy Discovery Tools
The 47-day certificate era is coming - and your #discovery tools are about to break. ⏳🔒 Nearly all security and infrastructure teams know about Ballot SC-081v3 passed by the CA/Browser Forum: • March 15, 2026: Validity capped at 200 days • March 15, 2027: Ceiling drops to 100 days • March 15, 2029: Mandatory 47-day max lifespan We talk often about auto-renewals, but we aren't talking enough about discovery. If your discovery strategy relies on active network port scans run m
Brian Couzens
4 days ago2 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (10 - 16 August 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 17 August 2026 This week closed a loop opened the week before and started several new ones. Nine days after an AWS cryptographer's preliminary algorithm reopened questions about the mathematics beneath ML-KEM, a formal, machine-checked refutation from researchers at MIT, Stanfo
Brian Couzens
5 days ago14 min read


Post-Quantum Cryptography Has an Entropy Problem
Post-quantum cryptography is moving from strategy decks into production environments. Organisations are inventorying cryptography, testing hybrid deployments, planning certificate changes, updating firmware, and preparing for ML-KEM and ML-DSA adoption. But one dependency is often treated as infrastructure plumbing rather than a security control: entropy. That is a mistake. PQC does not change the mathematics of entropy. Shannon entropy is still Shannon entropy. What changes
Brian Couzens
5 days ago4 min read


47-Day Certificates Are Coming: Why PKI, KMS and Post-Quantum Migration Can No Longer Be Separate Projects
The Certificate Lifespan Collapse: Why PKI, KMS and PQC Must Become One Enterprise Architecture For decades, enterprise security treated digital certificates and cryptographic keys as static operational overhead. Organisations deployed Public Key Infrastructure (PKI) certificates with multi-year lifespans, stored symmetric keys in isolated Key Management Systems (KMS), and operated on the assumption that standard public-key algorithms (RSA, ECC) would remain mathematically se
Brian Couzens
Aug 1510 min read


SITG Consulting Solutions: Tailored Transformation Solutions
Digital transformation demands precision. Organisations face complex risks daily. Quantum computing, evolving regulations, and cyber threats challenge stability. SITG Consulting delivers tailored transformation solutions. These solutions build resilience and enable strategic growth. This post explores how SITG Consulting drives effective change for enterprises, critical infrastructure, and government organisations. Understanding the Need for Tailored Transformation Transforma
Brian Couzens
Aug 143 min read


PQC Roadmap vs PQC Migration Roadmap: What Enterprises Need to Know
When Is a PQC Roadmap Not a PQC Roadmap? Why a cloud provider's PQC roadmap is not the same thing as an enterprise post-quantum migration roadmap The post-quantum cryptography industry has a terminology problem. We are increasingly seeing vendor roadmaps presented, discussed and referenced as though they describe how an organisation should migrate to post-quantum cryptography. They do not. They may be extremely useful. They may be technically sophisticated. They may contain d
Brian Couzens
Aug 149 min read


Claude AI Watermarks: What They Mean for AI Trust and Provenance
Claude, AI Watermarks and the New Battle for Digital Trust AI-generated text is becoming impossible to distinguish reliably from human writing. Anthropic has now decided that the answer is to mark it. That sounds simple. It isn't. There is a bigger question underneath Anthropic's decision to embed invisible watermarks into Claude-generated text: Can we build meaningful trust in AI-generated content through provenance, or are we simply creating another signal that will eventua
Brian Couzens
Aug 136 min read


PQC and Zero Trust: Building a Post-Quantum Trust Architecture
PQC without Zero Trust is like building a vault without knowing who has the keys. And Zero Trust without post-quantum cryptography? An excellent access-control system protecting cryptography that may eventually become untrustworthy. This is the uncomfortable conversation that organisations need to have. Post-quantum cryptography (PQC) and Zero Trust are often treated as separate cybersecurity transformation programmes. Different teams own them. Different roadmaps define them.
Brian Couzens
Aug 134 min read


UK Post-Quantum Cryptography Readiness: What the Evidence Actually Shows
UK Post-Quantum Cryptography Readiness: What the Evidence Actually Shows Every organisation holding data today with a shelf life beyond the next decade has a quantum problem, whether it has been named yet or not. Encrypted traffic intercepted now can be stored and decrypted later, once a cryptographically relevant quantum computer exists. That risk, harvest now, decrypt later, is why post-quantum cryptography readiness has moved from a research topic to a governance question
Brian Couzens
Aug 125 min read


PQC Readiness Assessment
Independent Design Review Before Board Approval A PQC Readiness Assessment is an independent, evidence-based review of an organisation's post-quantum cryptography strategy, its cryptographic estate, its third-party exposure and its migration readiness. It happens before implementation. Not after. The party designing a PQC programme may also be the party hoping to build it. That is not a compliance failure. It is a structural condition. No one inside that arrangement has the s
Brian Couzens
Aug 118 min read


Quantum Weekly 3 -9th August 2026
🌐The Global Signals That Actually Mattered (3 - 9 August 2026) Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 10 August 2026 This week's structural signal was theoretical provenance meeting sovereign procurement, moving on independent clocks. An Amazon Web Services cryptographer posted a preliminary polynomial-time quantum
Brian Couzens
Aug 1012 min read


Daniel Simon’s Dihedral Coset Algorithm: What Does It Actually Mean for Lattice-Based Cryptography and PQC?
A new preliminary paper from Daniel R. Simon has generated exactly the sort of reaction that serious cryptographic research does not need. “Another horror for lattice-based cryptography.” “This is the end for PQC.” Neither statement is an adequate description of what has actually been published. The paper is potentially extremely important. It is also a preliminary research result, and the distinction matters. Simon’s paper, “A Polynomial-Time Quantum Algorithm for the Dihedr
Brian Couzens
Aug 95 min read


Singapore's Quantum-Safe Migration Handbook: What It Actually Means for PQC Migration
Singapore has set the clock. It has not set the method. Singapore published two quantum-related documents on 16 July 2026: The Quantum-Safe Migration Handbook v1 The Quantum Readiness Index v1.0 The team at SITG-Consulting has reviewed both documents in detail. There is useful material here. The documents move the discussion beyond general awareness of quantum computing and towards organisational preparation, cryptographic discovery, governance, supplier engagement and migrat
Brian Couzens
Aug 88 min read


🇳🇱 NETHERLANDS PQC SPOTLIGHT: SOME OF EUROPE’S STRONGEST GUIDANCE, BUT STILL NO NATIONAL MANDATE
The Netherlands sits in Tier 2 of SITG-Consulting’s Europe’s Post-Quantum Readiness 2026 assessment. That is an important distinction. The Netherlands has produced some of the strongest practical PQC migration guidance we found anywhere in Europe. But strong guidance is not the same thing as a governed national migration programme. Government Posture: Strong Guidance, No Binding Migration Programme The Dutch position is built around two important pieces of work. The PQC Migra
Brian Couzens
Aug 62 min read


🇱🇹 LITHUANIA PQC SPOTLIGHT: THE ONLY EU MEMBER STATE TO REACH TIER 1
Lithuania stands apart in our assessment of post-quantum readiness across the EU-27. It is the only Member State to reach Tier 1, High Confidence. This does not mean Lithuania has completed its PQC migration. It means something more useful at this stage: the country has established publicly verifiable migration machinery, with governance, mandatory actions, implementation dates, inventory requirements and procurement provisions. Government Posture: From Awareness to Execution
Brian Couzens
Aug 52 min read


Europe’s Post-Quantum Readiness 2026: New EU-27 Assessment Reveals Major Differences in PQC Preparedness
SITG-Consulting has published Europe’s Post-Quantum Readiness 2026: An Empirical Assessment of the EU-27, an independent assessment of the publicly verifiable state of post-quantum cryptography readiness across all 27 European Union Member States. The research asks a question that is becoming increasingly important for governments, regulators, financial institutions, critical infrastructure operators and organisations operating across European borders: How ready is Europe to
Brian Couzens
Aug 44 min read


Africa’s Post-Quantum Readiness 2026: What We Found Across 54 Countries
SITG-Consulting went looking for something we expected to find. A continent-wide assessment of Africa’s preparedness for the transition to post-quantum cryptography. We could not find one. So the SITG-Consulting team conducted one. The result is Africa’s Post-Quantum Readiness 2026: A 54-Country Empirical Assessment, examining publicly verifiable evidence across every UN-recognised African sovereign state as at 3 August 2026. The headline number is difficult to ignore. 46 of
Brian Couzens
Aug 35 min read
bottom of page
