top of page


CRYPTOANALYSIS: LET ME EXPLAIN THIS FFS
The sensational headlines surrounding Anthropicโs AI work on HAWK reveal a fundamental misunderstanding of how global cybersecurity actually operates: cryptanalysis is not a panic event; it is the continuous quality-control engine of the digital world. The framing that "AI broke post-quantum security and everything is collapsing" is pure noise. Here is the reality. 1. This Is an Ongoing Discipline Run by Dedicated Teams Cryptanalysis isn't something that happens once in a blu
Brian Couzens
Aug 12 min read
ย
ย
ย


DigiCert's 2026 Quantum Readiness Outlook
Every week I see organisations announcing their Post-Quantum Cryptography strategy. Strategies. Roadmaps. Working groups. Steering committees. Pilot programmes. Then along comes some actual data. DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia. 87% say they are planning, testing or implementing PQC. Only 7% have deployed quantum-safe or hybrid cryptography across most of their
Brian Couzens
Jul 272 min read
ย
ย
ย


TLS 1.3 hasn't become TLS 1.4.
It has become less tolerant of the past. This month, the IETF published RFC 9846, which replaces RFC 8446 while keeping the protocol as TLS 1.3. On the surface, it looks like a minor revision. It isn't. One change stands out: Implementations MUST NOT negotiate TLS 1.0 or TLS 1.1. Not "SHOULD NOT." Not "avoid where possible." MUST NOT. That matters because we're reaching a tipping point. For years, organisations carried obsolete cryptography because "it still works." Increasin
Brian Couzens
Jul 252 min read
ย
ย
ย


FIPS 140-3 Gap Analysis: fix the module before the lab, not after
For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis. The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module wit
Brian Couzens
Jul 232 min read
ย
ย
ย
FIPs140-3 A Thematic Review
A half-year read on where FIPS 140-3 validation actually stands. Between January and mid-July 2026, 30 new FIPS 140-3 certificates were issued or announced across non-hyperscaler, non-tier-1 vendors, spanning HSMs, authentication, cryptographic libraries, edge/IoT and embedded modules. With FIPS 140-2 fully retiring on 21 September 2026, this is no longer a future consideration. It's active, measurable, and already reshaping vendor selection. This SITG-Consulting Thematic Rev
Brian Couzens
Jul 181 min read
ย
ย
ย
An Analysis of ASD's PQC Vendor Approach.
One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migration plans and technical roadmaps. That misses the point. Modern organisations no longer control much of their own cryptography. It sits inside cloud platforms, software, managed services, operational technology and hardware supplied by third parties. Your programme cannot move fast
Brian Couzens
Jul 161 min read
ย
ย
ย


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
Jul 124 min read
ย
ย
ย


A policy for a policy
๐๐จ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ซ๐๐๐ฅ๐ฅ๐ฒ ๐ง๐๐๐ ๐ ๐ฌ๐ญ๐๐ง๐๐๐ฅ๐จ๐ง๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ฒ ๐๐จ๐ฅ๐ข๐๐ฒ? Iโm starting to think the default answer of โyesโ might be wrong. I recently reviewed the Dutch Governmentโs Framework Cryptography Policy for the Central Government. Whatโs interesting is that it doesnโt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read
ย
ย
ย
PQC Discovery Sprint
One of the questions we're asked more than any other is: "What actually happens during a Discovery Sprint?" This carousel answers that question. Rather than talking about methodology, we've opened the lid on a real engagement for an anonymised digital challenger bank. You'll see how assumptions are tested, how evidence is gathered, why cryptographic inventories rarely reconcile, and how governance failures become visible long before any discussion about post-quantum algorithm
Brian Couzens
Jul 71 min read
ย
ย
ย


DATA, PQC, HNDL and HNFL
#PQC and #Data: The Three #Cryptographic Domains Post-quantum risk is about the data being protected, not the algorithms themselves. Every cryptographic dependency maps to one of three data states. If you do not know which state you are protecting, you do not know what you are securing. #Data in #Motion Information moving across networks or channels. TLS sessions, VPN tunnels, 5G key agreement, SWIFT messages, API calls. Quantum relevance: interception and harvest. If the con
Brian Couzens
Jul 32 min read
ย
ย
ย
The Lexicon
Words matter. Especially when organisations are making strategic decisions. One of the biggest problems across cyber security, governance, risk, resilience and quantum isn't technology. It's language. Different vendors define the same term differently. Standards use different terminology. Consultants invent new phrases. Boards are expected to make decisions using inconsistent vocabulary. That creates confusion before the real work even starts. To address that, we've made the
Brian Couzens
Jul 11 min read
ย
ย
ย


Microsoft's quantum computing technology called into question, again
Science is doing exactly what science is supposed to do. A new peer-reviewed critique published in Nature has challenged aspects of Microsoft's Majorana-based quantum computing research, arguing that the evidence may not conclusively demonstrate the physics the company claims. Microsoft strongly disagrees and maintains its roadmap remains on track. This is not a story about Microsoft "failing." It is a reminder that extraordinary scientific claims invite extraordinary scienti
Brian Couzens
Jun 261 min read
ย
ย
ย


๐๐๐ฉ๐ฅ๐จ๐ฒ๐ฆ๐๐ง๐ญ ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐๐๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ. ๐๐ฅ๐ข๐ฆ๐ข๐ง๐๐ญ๐ข๐จ๐ง ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐ฉ๐ซ๐จ๐ ๐ซ๐๐ฌ๐ฌ.
This week I read the best description of how to measure success against quantum risk. It comes from a recent Department of War (DoW) strategy document, and it is a breath of fresh air. ๐ ๐ช๐ฎ๐จ๐ญ๐: "Quantum resistance is not achieved when PQC is rolled out, but when quantum-vulnerable solutions are deprecated." Let's dissect what that means because it cuts straight through the marketing theatre dominating cybersecurity right now. ๐๐๐๐ข๐ง๐:"Quantum-Vulnerable" Any algor
Brian Couzens
Jun 252 min read
ย
ย
ย
The Department of Warโs Post-Quantum Cryptography Strategy landed just a day or so ago, but it deserves far more attention than itโs getting.
The DoW just gave us a document worth promoting - my favourite line is ๐๐ฎ๐๐ง๐ญ๐ฎ๐ฆ ๐ซ๐๐ฌ๐ข๐ฌ๐ญ๐๐ง๐๐ ๐ข๐ฌ ๐ง๐จ๐ญ ๐๐๐ก๐ข๐๐ฏ๐๐ ๐ฐ๐ก๐๐ง ๐๐๐ ๐ข๐ฌ ๐ซ๐จ๐ฅ๐ฅ๐๐ ๐จ๐ฎ๐ญ, ๐๐ฎ๐ญ ๐ฐ๐ก๐๐ง ๐ช๐ฎ๐๐ง๐ญ๐ฎ๐ฆ-๐ฏ๐ฎ๐ฅ๐ง๐๐ซ๐๐๐ฅ๐ ๐ฌ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง๐ฌ ๐๐ซ๐ ๐๐๐ฉ๐ซ๐๐๐๐ญ๐๐. The Department of Warโs Post-Quantum Cryptography Strategy landed just a day or so ago, but it deserves far more attention than itโs getting. In my view, it is much more relevant and operationally impor
Brian Couzens
Jun 251 min read
ย
ย
ย


THE DEADLINE JUST MOVED. AGAIN.
That should concern every board, regulator, CISO and risk committee still treating post-quantum cryptography as a distant technology problem. The United States has issued a new Executive Order accelerating PQC migration requirements. Notably: โข PQC key establishment for High Value Assets by 31 December 2030 โข PQC digital signatures for High Value Assets by 31 December 2031 This is the second major shift in federal timing expectations. That matters. Governments do not compress
Brian Couzens
Jun 231 min read
ย
ย
ย


ISO/IEC 18033-2:2006/Amd 2:2026 has published.
Three post-quantum KEMs now sit inside one of the principal international standards for asymmetric encryption: ML-KEM, Classic McEliece and FrodoKEM. Read that again. Not one algorithm. Three. From three different mathematical families. Why this matters before the detail. A standards body had a choice. It could have ratified the market's preferred answer, ML-KEM, and closed the question. It did not. It standardised a structured lattice scheme, an unstructured lattice scheme a
Brian Couzens
Jun 162 min read
ย
ย
ย
bottom of page
