top of page
FINMA Quantum Computing PQC Guidance
FINMA's new guidance on Quantum Computing is welcome. It sends an important signal. Quantum risk is no longer a theoretical technology discussion. It is a governance and operational resilience issue that financial institutions are expected to address now. I agree with the direction of travel. Board-approved strategies, risk analysis, cryptographic inventories, crypto-agility and supplier management all deserve attention. However, I was struck by how extraordinarily light the
Brian Couzens
Jul 121 min read


Cryptographic Inflation: The Economics of Uncertainty
PQC Economics For the past three years, almost every serious discussion about Post-Quantum Cryptography has started with the same question: How much will it cost? Governments have published rough estimates. Boards want numbers. Vendors are selling calculators. Consultants are packaging migration roadmaps. But that question is still too narrow. It treats PQC like a software upgrade. It is not. The economics of PQC are not driven by cryptographic algorithms. They are driven by
Brian Couzens
Jul 104 min read


CBOM: The Difference Between Discovery and Intelligence
The Missing Discipline The post-quantum conversation has a numbers problem. Vendors love to say they have found millions of cryptographic assets. That sounds serious. It sounds comprehensive. It sounds like the sort of number a board should pay attention to. But in most environments, that number is doing a lot of rhetorical work. What organisations usually have are millions of cryptographic instances. The same library. The same certificate. The same key store. The same implem
Brian Couzens
Jul 85 min read


NIST: CSF2.0
NIST CSF 2.0 may be one of the most important Quantum Readiness frameworks available today. Not because it contains a section on quantum computing. It doesn't. Not because it tells organisations which algorithms to deploy. It doesn't do that either. What CSF 2.0 does provide is something far more important. Governance. The 2024 update elevated governance to a core function, recognising that cybersecurity is no longer solely a technology challenge. It is a board, executive and
Brian Couzens
Jun 252 min read
bottom of page