top of page


A policy for a policy
๐๐จ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ซ๐๐๐ฅ๐ฅ๐ฒ ๐ง๐๐๐ ๐ ๐ฌ๐ญ๐๐ง๐๐๐ฅ๐จ๐ง๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ฒ ๐๐จ๐ฅ๐ข๐๐ฒ? Iโm starting to think the default answer of โyesโ might be wrong. I recently reviewed the Dutch Governmentโs Framework Cryptography Policy for the Central Government. Whatโs interesting is that it doesnโt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read
ย
ย
ย


๐๐๐ฉ๐ฅ๐จ๐ฒ๐ฆ๐๐ง๐ญ ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐๐๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ. ๐๐ฅ๐ข๐ฆ๐ข๐ง๐๐ญ๐ข๐จ๐ง ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐ฉ๐ซ๐จ๐ ๐ซ๐๐ฌ๐ฌ.
This week I read the best description of how to measure success against quantum risk. It comes from a recent Department of War (DoW) strategy document, and it is a breath of fresh air. ๐ ๐ช๐ฎ๐จ๐ญ๐: "Quantum resistance is not achieved when PQC is rolled out, but when quantum-vulnerable solutions are deprecated." Let's dissect what that means because it cuts straight through the marketing theatre dominating cybersecurity right now. ๐๐๐๐ข๐ง๐:"Quantum-Vulnerable" Any algor
Brian Couzens
Jun 252 min read
ย
ย
ย
bottom of page