top of page
An Analysis of ASD's PQC Vendor Approach.
One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migration plans and technical roadmaps. That misses the point. Modern organisations no longer control much of their own cryptography. It sits inside cloud platforms, software, managed services, operational technology and hardware supplied by third parties. Your programme cannot move fast
Brian Couzens
20 hours ago1 min read


THE AI CHALLENGE - GOVERNANCE
Without sounding narcissistic, we’re often told we’re opinionated. Everyone is 100 percent correct. We are, and we will remain so. Not for ego. For rigour. If a proposition is weak, confused or stretching novelty beyond necessity, it should be challenged. Governance is a mature discipline. Reinventing it with diagrams and slogans helps nobody. Yesterday was a good example. A post appeared describing AI governance as a neat four layer staircase. I challenged it: "This is a per
Brian Couzens
1 day ago2 min read


Kudankulam Shows Why Critical Infrastructure Security Is a Governance Problem, Not Just a Cybersecurity Problemcff
Sensitive documents reportedly linked to India's Kudankulam Nuclear Power Plant have been exposed following a ransomware attack affecting a contractor. According to Reuters, the leaked material includes engineering drawings, supplier information and inspection records, while there is currently no evidence that reactor control systems themselves were compromised. That distinction matters. Too often, critical infrastructure security is viewed through the lens of perimeter defen
Brian Couzens
2 days ago1 min read


The White House Quantum Summit wasn’t the story.
America’s transition from quantum strategy to quantum execution was. In the span of three weeks, the United States compressed years of quantum policy into a coordinated national programme: Executive Order 14412 accelerating Post-Quantum Cryptography (PQC) migration Executive Order 14413 strengthening the national quantum innovation ecosystem The Department of Defense PQC Strategy OMB M-26-15 defining a structured federal migration roadmap QuantumEAGLe aligning government and
Brian Couzens
2 days ago2 min read


Global Post-Quantum Cryptography (PQC) Consulting | Quantum Risk, Quantum Readiness & Cryptographic Governance | SITG-Consulting
Quantum Computing Will Change Cyber Security. Preparation Starts Today. Every organisation relies on cryptography. Banks rely on it to secure financial transactions. Governments rely on it to protect national infrastructure. Healthcare providers rely on it to safeguard patient records. Manufacturers rely on it to secure operational technology. Cloud providers rely on it to establish trust. Every VPN, SSL certificate, digital signature, software update, encrypted database, aut
Brian Couzens
3 days ago5 min read


A Watershed Moment for UK Financial Regulation - Or Just the Beginning?
The designation of #Amazon Web Services, #Microsoft, #Google Cloud, and #Oracle as the UK’s first Critical Third Parties (#CTPs) is not just another operational resilience milestone. It is a structural shift in where systemic risk is understood to live-and who regulators believe must be accountable for it. For the first time under the Financial Services and Markets Act 2023, the Bank of England, #PRA, and #FCA will exercise direct, joint oversight over organisations that sit
Brian Couzens
3 days ago2 min read


CMMC Phase II Suspended: What the Department of War's Decision Really Means
The United States Department of War has announced the immediate suspension of CMMC Phase II requirements while it undertakes a 60-day review of the programme. Predictably, headlines have already begun suggesting that CMMC has been paused or that cybersecurity requirements are being rolled back. Neither interpretation is correct. The announcement is not a retreat from cybersecurity. It is a reassessment of how cybersecurity assurance should be delivered. What Has Changed? The
Brian Couzens
3 days ago3 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (6-13 July 2026)
SITG-Consulting | Forensic Strategist | Cyber Resilience, Quantum Risk & Governance | Transformation, ERM & Independent Validation | Writer | White Paper Author | Evidence-Based Decision Making July 13, 2026 This week's signals ran along two separate tracks that are starting to converge: hardware architecture and cryptographic supply chain. On the hardware side, three independent teams in Switzerland, the United States and Australia advanced non-standard qubit and photonic ar
Brian Couzens
3 days ago10 min read
EPC 342 - 08 v16.0.1 - Issued 24 June 2026
EPC 342 - 08 v16.0.1 - Issued 24 June 2026 SITG-Consulting Review & Dissection A MUST READ FOR ANY EUROPEAN PAYMENT PROVIDER The European Payments Council has released #EPC342‑08v16.0.1, its 2026 update on cryptographic algorithm usage and key‑management practices. This deck provides SITG-Consulting independent review and dissection of the document - what it gets right, where it stops, and the enterprise‑level gaps it leaves unaddressed. Necessary, but not sufficient. This is
Brian Couzens
4 days ago1 min read


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
5 days ago4 min read
FINMA Quantum Computing PQC Guidance
FINMA's new guidance on Quantum Computing is welcome. It sends an important signal. Quantum risk is no longer a theoretical technology discussion. It is a governance and operational resilience issue that financial institutions are expected to address now. I agree with the direction of travel. Board-approved strategies, risk analysis, cryptographic inventories, crypto-agility and supplier management all deserve attention. However, I was struck by how extraordinarily light the
Brian Couzens
5 days ago1 min read


BREAKING: Quantum Just Got Secure-by-Design - And Silicon Is Moving First
🚨 BREAKING: Quantum Just Got Secure-by-Design - And Silicon Is Moving First The last 24 hours in PQC and quantum have been louder than anyone expected. 💥 Europe may have just fired the starting gun on secure-by-design quantum hardware. 🇪🇺 SEALSQ and Quobly signed a $5M deal to embed post-quantum cryptography directly into Quobly’s silicon quantum processors. 🤝 Not PQC at the application layer. ❌ Not PQC wrapped around the cloud. ☁️ PQC integrated into the cryogenic contr
Brian Couzens
6 days ago2 min read


🚨 𝐁𝐑𝐄𝐀𝐊𝐈𝐍𝐆: 𝐐𝐮𝐚𝐧𝐭𝐮𝐦 𝐉𝐮𝐬𝐭 𝐆𝐨𝐭 𝐒𝐞𝐜𝐮𝐫𝐞-𝐛𝐲-𝐃𝐞𝐬𝐢𝐠𝐧 - 𝐀𝐧𝐝 𝐒𝐢𝐥𝐢𝐜𝐨𝐧 𝐈𝐬 𝐌𝐨𝐯𝐢𝐧𝐠 𝐅𝐢𝐫𝐬𝐭 ⚡
The last 24 hours in PQC and quantum have been louder than anyone expected. 💥 Europe may have just fired the starting gun on secure-by-design quantum hardware. 🇪🇺 SEALSQ and Quobly signed a $5M deal to embed post-quantum cryptography directly into Quobly’s silicon quantum processors. 🤝 Not PQC at the application layer. ❌ Not PQC wrapped around the cloud. ☁️ PQC integrated into the cryogenic control electronics themselves. 🧊 We’re talking about Cryo-CMOS ASICs with PQC ac
Brian Couzens
6 days ago2 min read


Cryptographic Inflation: The Economics of Uncertainty
PQC Economics For the past three years, almost every serious discussion about Post-Quantum Cryptography has started with the same question: How much will it cost? Governments have published rough estimates. Boards want numbers. Vendors are selling calculators. Consultants are packaging migration roadmaps. But that question is still too narrow. It treats PQC like a software upgrade. It is not. The economics of PQC are not driven by cryptographic algorithms. They are driven by
Brian Couzens
Jul 104 min read


SITG-Consulting Solutions: Crafting Future-Ready Solutions
In today’s fast-evolving landscape, organizations face unprecedented challenges. Cyber threats grow more sophisticated. Quantum computing promises disruption. Regulatory demands tighten. SITG Consulting crafts solutions that anticipate these shifts. The focus remains clear: build resilience, ensure compliance, and enable sustainable transformation. This approach positions SITG Consulting as a trusted partner for global enterprises, financial services, critical infrastructure,
Brian Couzens
Jul 93 min read


A policy for a policy
𝐃𝐨 𝐨𝐫𝐠𝐚𝐧𝐢𝐬𝐚𝐭𝐢𝐨𝐧𝐬 𝐫𝐞𝐚𝐥𝐥𝐲 𝐧𝐞𝐞𝐝 𝐚 𝐬𝐭𝐚𝐧𝐝𝐚𝐥𝐨𝐧𝐞 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐲 𝐏𝐨𝐥𝐢𝐜𝐲? I’m starting to think the default answer of “yes” might be wrong. I recently reviewed the Dutch Government’s Framework Cryptography Policy for the Central Government. What’s interesting is that it doesn’t push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read


Business Transformation, Cyber Resilience, Quantum Risk and Governance Consulting
Organisations are investing billions in digital transformation, artificial intelligence, cloud migration and cybersecurity. Yet many programmes fail for one simple reason. Technology changes faster than governance, risk management and organisational control. At SITG-Consulting, we help organisations bridge that gap. We specialise in business transformation, cyber resilience, enterprise governance, post-quantum cryptography (PQC), quantum risk management, regulatory compliance
Brian Couzens
Jul 93 min read


CBOM: The Difference Between Discovery and Intelligence
The Missing Discipline The post-quantum conversation has a numbers problem. Vendors love to say they have found millions of cryptographic assets. That sounds serious. It sounds comprehensive. It sounds like the sort of number a board should pay attention to. But in most environments, that number is doing a lot of rhetorical work. What organisations usually have are millions of cryptographic instances. The same library. The same certificate. The same key store. The same implem
Brian Couzens
Jul 85 min read


CBOM - The Real Story
𝐏𝐐𝐂 𝐝𝐢𝐬𝐜𝐨𝐯𝐞𝐫𝐲 𝐚𝐧𝐝 𝐫𝐞𝐦𝐞𝐝𝐢𝐚𝐭𝐢𝐨𝐧 𝐯𝐞𝐧𝐝𝐨𝐫𝐬 𝐥𝐨𝐯𝐞 𝐭𝐞𝐥𝐥𝐢𝐧𝐠 𝐨𝐫𝐠𝐚𝐧𝐢𝐬𝐚𝐭𝐢𝐨𝐧𝐬 𝐭𝐡𝐞𝐲 𝐡𝐚𝐯𝐞 "𝐦𝐢𝐥𝐥𝐢𝐨𝐧𝐬 𝐨𝐟 𝐜𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐚𝐬𝐬𝐞𝐭𝐬." That sounds impressive. In reality, it frequently conflates cryptographic #instances with unique cryptographic #dependencies. There is a fundamental difference. The same cryptographic library, certificate, key store, or implementation can appear thousands of times across ser
Brian Couzens
Jul 82 min read
PQC Discovery Sprint
One of the questions we're asked more than any other is: "What actually happens during a Discovery Sprint?" This carousel answers that question. Rather than talking about methodology, we've opened the lid on a real engagement for an anonymised digital challenger bank. You'll see how assumptions are tested, how evidence is gathered, why cryptographic inventories rarely reconcile, and how governance failures become visible long before any discussion about post-quantum algorithm
Brian Couzens
Jul 71 min read
bottom of page