top of page


The GDPR Enforcement Wave That Will Force Post Quantum Migration
The compliance problem nobody is treating as a compliance problem Post quantum cryptography keeps getting framed as a future technical upgrade. That framing is already outdated. GDPR does not care about quantum timelines, industry uncertainty, or vendor roadmaps. GDPR cares about foreseeable risk, state of the art, and negligence. Quantum risk satisfies all three today. The industry keeps waiting for quantum capability. Regulators are waiting for none of it. Why GDPR already
Brian Couzens
12 minutes ago2 min read


Your Product Is Not Your Proof: Why Independent Validation of AI and PQC Products Is Now Non-Negotiable
Products built on artificial intelligence and post-quantum cryptography are entering regulated markets at a pace that governance has not kept up with. Data sheets carry performance assertions. Pitch decks promise protection against threats that have not yet materialised at scale. The claims are confident. The evidence behind them, in too many cases, does not exist. This is a vendor-side problem, and it is one the market will correct. Where the Assurance Layer Should Be The de
Brian Couzens
14 hours ago5 min read


Mapping Hidden Structure: What a Bible Visualization Teaches Us About Quantum Risk and PQC
Introduction: Why This Image Matters A striking data visualization has been circulating again. At first glance it looks like abstract digital art. Curved arcs sweep across a black background in layers of color. Beneath them sits a long row of vertical bars of different heights. It is visually impressive, but the real impact comes when you understand what you are looking at. The image is a map of more than sixty three thousand cross references inside the Bible. Every vertical
Brian Couzens
2 days ago2 min read


Expose the Evidence: ASEAN PQC (Post Quantum Cryptography) Readiness 2026
Expose what ASEAN member states can actually demonstrate about post quantum migration. Not what they intend. Not what they announce. What they can prove. SITG Consulting has released ASEAN Post Quantum Cryptography Readiness 2026, published on Zenodo under CC BY 4.0: https://doi.org/10.5281/zenodo.22218529 The report assesses all ten ASEAN member states against the same locked five tier framework applied to the EU 27 and the United Kingdom. Evidence cut off: 17 August 2026. P
Brian Couzens
4 days ago3 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (24-30 August 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 31 August 2026 Stop assuming quantum progress moves in isolated pockets. This week, capital and hardware advanced on the same timeline across multiple regions. Pasqal listed on Nasdaq. Canada announced its largest quantum manufacturing investment to date. IBM expanded its hardw
Brian Couzens
5 days ago12 min read


Merkle Trees and Why They Matter More Today Than Ever
Reassess your cryptographic primitives. Merkle trees are no longer theoretical constructs - they now underpin integrity, lineage, and quantum‑era resilience. Merkle trees are one of those ideas that quietly sat in the background for decades and suddenly became central again. The reason is simple: we are now operating in environments where trust cannot be assumed, data volumes are extreme, and regulators expect mathematical proof rather than promises. Merkle trees give you a w
Brian Couzens
5 days ago3 min read


Node vs Endpoint: Why the Difference Matters for PQC Migration
Stop treating PQC migration as an endpoint problem. It isn’t - and that mistake is already breaking real architectures. Post-quantum cryptography migration is often discussed in terms of endpoints: laptops, smartphones, servers and IoT devices. That is an important starting point, but it is not the complete picture. Many cryptographic sessions are terminated by infrastructure components positioned between communicating systems. VPN gateways, reverse proxies, API gateways, loa
Brian Couzens
6 days ago4 min read


Where Does Your Randomness Come From? The Silent Cryptographic Failure - ENTROPY
In enterprise cybersecurity architecture, few assets receive less scrutiny relative to their importance than entropy generation. While security operations teams dedicate vast resources to managing key lifecycles, configuring TLS handshakes, and planning post-quantum migrations, the physical and algorithmic sources providing the initial randomness remain largely unexamined. This blind spot represents a fundamental architectural vulnerability: when the underlying random bit gen
Brian Couzens
7 days ago3 min read


Post-Quantum Cryptography, (PQC) Crypto Modernisation and Key Sizes: Why It Matters Now
A digital signature that fitted in 70 bytes under ECDSA now runs to 3,309 bytes under ML-DSA-65. A key exchange that moved in 32 bytes under X25519 now carries 1,184 bytes under ML-KEM-768. Under SLH-DSA, the conservative hash-based fallback, a single signature runs from 7,856 bytes at the smallest parameter set to 49,856 bytes at the largest. These are not rounding differences. They are a different category of object, and the protocols, hardware and certificate architecture
Brian Couzens
Aug 299 min read


Beyond Q-Day Hype: What the Latest Quantum Cryptanalysis Preprint Reveals
The quantum computing debate often devolves into speculative "Q-Day" panic. However, a recent arXiv preprint (arXiv:2608.23785) shifts the conversation from vague warnings to a parameterised, data-driven framework. By evaluating physical qubit scaling, error-correction overhead, and algorithm efficiencies, the study establishes concrete timelines for classical cryptographic collapse and post-quantum migration. The 3-Tier Risk Hierarchy: Separating Fact from Speculation The re
Brian Couzens
Aug 272 min read


From Cryptographic Inventory to 2030: A Practical Roadmap for Vendor PQC Readiness
Your internal systems may be quantum-safe on paper, but your accountability does not end at your digital perimeter. Third-party software, integrations, and external vendors represent the largest unmapped exposure in the upcoming Post-Quantum Cryptography (PQC) transition. While internal migration roadmaps sit under direct governance, external supplier migration timelines are often decided without your input, creating liabilities that land squarely on your balance sheet. W
Brian Couzens
Aug 263 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (17-23 August 2026) PQC and more
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 24 August 2026 This was a week in which post-quantum cryptography stopped being a standards conversation and became a procurement, assurance and deployment conversation across three continents simultaneously. A Canadian module cleared the highest independent hardware validation
Brian Couzens
Aug 2420 min read


What Is an Endpoint, and Why Does It Matter for PQC Migration?
You likely interacted with several cryptographic endpoints before finishing your morning coffee. Your smartphone authenticated to Wi-Fi. Your laptop established a corporate VPN session. Your browser negotiated secure connections to email, cloud software, or online banking. Every single interaction relied on asymmetric cryptography to authenticate entities, perform key exchanges, verify digital signatures, or establish encrypted channels. Understanding where those cryptographi
Brian Couzens
Aug 233 min read


PQC without Data Lineage Creates Hidden Quantum Era Exposure
Post‑quantum cryptography is being sold as the next great migration. Replace RSA and ECC, update certificates, test applications, move on. That narrative is incomplete. It protects the lock, not the contents of the safe. The real exposure begins when an organisation cannot prove where its most valuable data has been. The Crown Jewel is the data itself — the record, design, or transaction whose loss would cause material harm. If that data has travelled through environments you
Brian Couzens
Aug 213 min read


What NISQ Hardware Tells Us About Quantum Risk
Why today's limitations in noisy quantum machines still matter for assurance, PQC planning and governance By Dr Clauden Higgsbottom Published August 2026 Executive Summary NISQ algorithms such as QAOA, VQE and other variational circuits have not yet demonstrated practical advantage on real-world workloads. Their strategic value is different: they provide measured evidence about noise, circuit depth, sampling cost, hybrid workflows and operational reliability. That evidence he
Brian Couzens
Aug 206 min read


PQC War Rooms: The Global Enterprise Risk Transformation CISOs Cannot Outsource
Post-quantum cryptography is still being treated by too many organisations as an algorithm migration. That is the wrong frame. PQC is becoming a trigger for a much broader enterprise risk transformation. The algorithms are being standardised. The harder problem sits around them: discovering where cryptography actually exists, identifying who owns it, understanding which suppliers control critical dependencies, determining which data cannot afford to remain exposed, and creati
Brian Couzens
Aug 1910 min read


Why 47-Day SSL Certificates Will Break Legacy Discovery Tools
The 47-day certificate era is coming - and your #discovery tools are about to break. ⏳🔒 Nearly all security and infrastructure teams know about Ballot SC-081v3 passed by the CA/Browser Forum: • March 15, 2026: Validity capped at 200 days • March 15, 2027: Ceiling drops to 100 days • March 15, 2029: Mandatory 47-day max lifespan We talk often about auto-renewals, but we aren't talking enough about discovery. If your discovery strategy relies on active network port scans run m
Brian Couzens
Aug 182 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (10 - 16 August 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 17 August 2026 This week closed a loop opened the week before and started several new ones. Nine days after an AWS cryptographer's preliminary algorithm reopened questions about the mathematics beneath ML-KEM, a formal, machine-checked refutation from researchers at MIT, Stanfo
Brian Couzens
Aug 1714 min read


Post-Quantum Cryptography Has an Entropy Problem
Post-quantum cryptography is moving from strategy decks into production environments. Organisations are inventorying cryptography, testing hybrid deployments, planning certificate changes, updating firmware, and preparing for ML-KEM and ML-DSA adoption. But one dependency is often treated as infrastructure plumbing rather than a security control: entropy. That is a mistake. PQC does not change the mathematics of entropy. Shannon entropy is still Shannon entropy. What changes
Brian Couzens
Aug 174 min read


47-Day Certificates Are Coming: Why PKI, KMS and Post-Quantum Migration Can No Longer Be Separate Projects
The Certificate Lifespan Collapse: Why PKI, KMS and PQC Must Become One Enterprise Architecture For decades, enterprise security treated digital certificates and cryptographic keys as static operational overhead. Organisations deployed Public Key Infrastructure (PKI) certificates with multi-year lifespans, stored symmetric keys in isolated Key Management Systems (KMS), and operated on the assumption that standard public-key algorithms (RSA, ECC) would remain mathematically se
Brian Couzens
Aug 1510 min read
bottom of page
