top of page


DigiCert's 2026 Quantum Readiness Outlook
Every week I see organisations announcing their Post-Quantum Cryptography strategy. Strategies. Roadmaps. Working groups. Steering committees. Pilot programmes. Then along comes some actual data. DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia. 87% say they are planning, testing or implementing PQC. Only 7% have deployed quantum-safe or hybrid cryptography across most of their
Brian Couzens
Jul 272 min read
ย
ย
ย


FIPS 140-3 Gap Analysis: fix the module before the lab, not after
For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis. The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module wit
Brian Couzens
Jul 232 min read
ย
ย
ย


THE AI CHALLENGE - GOVERNANCE
Without sounding narcissistic, weโre often told weโre opinionated. Everyone is 100 percent correct. We are, and we will remain so. Not for ego. For rigour. If a proposition is weak, confused or stretching novelty beyond necessity, it should be challenged. Governance is a mature discipline. Reinventing it with diagrams and slogans helps nobody. Yesterday was a good example. A post appeared describing AI governance as a neat four layer staircase. I challenged it: "This is a per
Brian Couzens
Jul 162 min read
ย
ย
ย


Kudankulam Shows Why Critical Infrastructure Security Is a Governance Problem, Not Just a Cybersecurity Problemcff
Sensitive documents reportedly linked to India's Kudankulam Nuclear Power Plant have been exposed following a ransomware attack affecting a contractor. According to Reuters, the leaked material includes engineering drawings, supplier information and inspection records, while there is currently no evidence that reactor control systems themselves were compromised. That distinction matters. Too often, critical infrastructure security is viewed through the lens of perimeter defen
Brian Couzens
Jul 151 min read
ย
ย
ย


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
Jul 124 min read
ย
ย
ย


A policy for a policy
๐๐จ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ซ๐๐๐ฅ๐ฅ๐ฒ ๐ง๐๐๐ ๐ ๐ฌ๐ญ๐๐ง๐๐๐ฅ๐จ๐ง๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ฒ ๐๐จ๐ฅ๐ข๐๐ฒ? Iโm starting to think the default answer of โyesโ might be wrong. I recently reviewed the Dutch Governmentโs Framework Cryptography Policy for the Central Government. Whatโs interesting is that it doesnโt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read
ย
ย
ย
PQC Discovery Sprint
One of the questions we're asked more than any other is: "What actually happens during a Discovery Sprint?" This carousel answers that question. Rather than talking about methodology, we've opened the lid on a real engagement for an anonymised digital challenger bank. You'll see how assumptions are tested, how evidence is gathered, why cryptographic inventories rarely reconcile, and how governance failures become visible long before any discussion about post-quantum algorithm
Brian Couzens
Jul 71 min read
ย
ย
ย


DATA, PQC, HNDL and HNFL
#PQC and #Data: The Three #Cryptographic Domains Post-quantum risk is about the data being protected, not the algorithms themselves. Every cryptographic dependency maps to one of three data states. If you do not know which state you are protecting, you do not know what you are securing. #Data in #Motion Information moving across networks or channels. TLS sessions, VPN tunnels, 5G key agreement, SWIFT messages, API calls. Quantum relevance: interception and harvest. If the con
Brian Couzens
Jul 32 min read
ย
ย
ย
The Lexicon
Words matter. Especially when organisations are making strategic decisions. One of the biggest problems across cyber security, governance, risk, resilience and quantum isn't technology. It's language. Different vendors define the same term differently. Standards use different terminology. Consultants invent new phrases. Boards are expected to make decisions using inconsistent vocabulary. That creates confusion before the real work even starts. To address that, we've made the
Brian Couzens
Jul 11 min read
ย
ย
ย


You know every day I challenge people who have discovered a new genre of Governance.
๐๐๐ ๐๐๐๐๐'๐. ๐
๐
๐. Every few weeks someone announces the next revolution. AI Governance. Quantum Governance. Sovereign Intelligence. Machine-Layer Authority. Algorithmic Governance. No. You've discovered a new technology, a new risk profile or a new application. You haven't discovered a new discipline. So let me ask one question. ๐๐ก๐ฒ ๐๐จ ๐ฒ๐จ๐ฎ ๐ญ๐ก๐ข๐ง๐ค ๐ฒ๐จ๐ฎ'๐ฏ๐ ๐ฌ๐ฎ๐๐๐๐ง๐ฅ๐ฒ ๐๐จ๐ฎ๐ง๐ ๐ญ๐ก๐ ๐๐ฎ๐ซ๐ ๐๐จ๐ซ ๐๐ฏ๐๐ซ๐ฒ๐ญ๐ก๐ข๐ง๐ ๐ ๐จ๐ฏ๐๐ซ๐ง๐๐ง๐๐ ๐ก
Brian Couzens
Jun 302 min read
ย
ย
ย


NIST: CSF2.0
NIST CSF 2.0 may be one of the most important Quantum Readiness frameworks available today. Not because it contains a section on quantum computing. It doesn't. Not because it tells organisations which algorithms to deploy. It doesn't do that either. What CSF 2.0 does provide is something far more important. Governance. The 2024 update elevated governance to a core function, recognising that cybersecurity is no longer solely a technology challenge. It is a board, executive and
Brian Couzens
Jun 252 min read
ย
ย
ย


THE DEADLINE JUST MOVED. AGAIN.
That should concern every board, regulator, CISO and risk committee still treating post-quantum cryptography as a distant technology problem. The United States has issued a new Executive Order accelerating PQC migration requirements. Notably: โข PQC key establishment for High Value Assets by 31 December 2030 โข PQC digital signatures for High Value Assets by 31 December 2031 This is the second major shift in federal timing expectations. That matters. Governments do not compress
Brian Couzens
Jun 231 min read
ย
ย
ย


Special Forces
Is it just me, or has the World become one giant credential parade? I am going to try and make this a regular feature. The working title is: **The Sunday Slop** *Another week. Another guru.* Former Navy SEAL. Former Secret Service. Former MI6. Former Commando. Former Special Operations. Former Intelligence Officer. Former Special Agent. Former Operator. Former Tactical Something. Former Strategic Something Else. At this point I am beginning to wonder whether LinkedIn has a mi
Brian Couzens
Jun 212 min read
ย
ย
ย
๐ ๐จ๐ฎ๐ง๐๐๐ซ ๐๐ซ๐จ๐๐ฎ๐๐ญ ๐๐๐ฏ๐ข๐๐ฐ ๐๐ง๐ ๐๐๐ฅ๐ข๐๐๐ญ๐ข๐จ๐งโข
For many years, SITG Consulting has delivered independent product assurance, validation and challenge as part of our broader Assurance and Validation services. What has changed is demand. Every week we receive enquiries from founders, technology companies, investors and advisory firms seeking independent assessment of products, platforms, governance frameworks and strategic claims. Many of those conversations begin in the same way. "We have built something." "Can we prove it?
Brian Couzens
Jun 192 min read
ย
ย
ย
bottom of page
