top of page


CRYPTOANALYSIS: LET ME EXPLAIN THIS FFS
The sensational headlines surrounding Anthropic’s AI work on HAWK reveal a fundamental misunderstanding of how global cybersecurity actually operates: cryptanalysis is not a panic event; it is the continuous quality-control engine of the digital world. The framing that "AI broke post-quantum security and everything is collapsing" is pure noise. Here is the reality. 1. This Is an Ongoing Discipline Run by Dedicated Teams Cryptanalysis isn't something that happens once in a blu
Brian Couzens
Aug 12 min read


FIPS 140-3 Gap Analysis: fix the module before the lab, not after
For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis. The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module wit
Brian Couzens
Jul 232 min read


Cryptographic Inflation: The Economics of Uncertainty
PQC Economics For the past three years, almost every serious discussion about Post-Quantum Cryptography has started with the same question: How much will it cost? Governments have published rough estimates. Boards want numbers. Vendors are selling calculators. Consultants are packaging migration roadmaps. But that question is still too narrow. It treats PQC like a software upgrade. It is not. The economics of PQC are not driven by cryptographic algorithms. They are driven by
Brian Couzens
Jul 104 min read


DATA, PQC, HNDL and HNFL
#PQC and #Data: The Three #Cryptographic Domains Post-quantum risk is about the data being protected, not the algorithms themselves. Every cryptographic dependency maps to one of three data states. If you do not know which state you are protecting, you do not know what you are securing. #Data in #Motion Information moving across networks or channels. TLS sessions, VPN tunnels, 5G key agreement, SWIFT messages, API calls. Quantum relevance: interception and harvest. If the con
Brian Couzens
Jul 32 min read


Microsoft's quantum computing technology called into question, again
Science is doing exactly what science is supposed to do. A new peer-reviewed critique published in Nature has challenged aspects of Microsoft's Majorana-based quantum computing research, arguing that the evidence may not conclusively demonstrate the physics the company claims. Microsoft strongly disagrees and maintains its roadmap remains on track. This is not a story about Microsoft "failing." It is a reminder that extraordinary scientific claims invite extraordinary scienti
Brian Couzens
Jun 261 min read


𝐃𝐞𝐩𝐥𝐨𝐲𝐦𝐞𝐧𝐭 𝐦𝐞𝐚𝐬𝐮𝐫𝐞𝐬 𝐚𝐜𝐭𝐢𝐯𝐢𝐭𝐲. 𝐄𝐥𝐢𝐦𝐢𝐧𝐚𝐭𝐢𝐨𝐧 𝐦𝐞𝐚𝐬𝐮𝐫𝐞𝐬 𝐩𝐫𝐨𝐠𝐫𝐞𝐬𝐬.
This week I read the best description of how to measure success against quantum risk. It comes from a recent Department of War (DoW) strategy document, and it is a breath of fresh air. 𝐈 𝐪𝐮𝐨𝐭𝐞: "Quantum resistance is not achieved when PQC is rolled out, but when quantum-vulnerable solutions are deprecated." Let's dissect what that means because it cuts straight through the marketing theatre dominating cybersecurity right now. 𝐃𝐞𝐟𝐢𝐧𝐞:"Quantum-Vulnerable" Any algor
Brian Couzens
Jun 252 min read


THE DEFINITIVE CBOM OPERATING MODEL
From "Dark Matter" Liability to Defensible Fiduciary Asset 1. Executive Summary: The Fiduciary Imperative In a $100T digital economy, cryptography is the invisible keel holding the ship of state and commerce upright. It secures identity, privacy, and value transfer. Yet 95% of enterprises operate with near-zero visibility into where this cryptography lives, how it behaves, or whether it remains fit for purpose (NIST). This hidden exposure has evolved into Cryptographic Dark M
Brian Couzens
Jun 198 min read


ISO/IEC 18033-2:2006/Amd 2:2026 has published.
Three post-quantum KEMs now sit inside one of the principal international standards for asymmetric encryption: ML-KEM, Classic McEliece and FrodoKEM. Read that again. Not one algorithm. Three. From three different mathematical families. Why this matters before the detail. A standards body had a choice. It could have ratified the market's preferred answer, ML-KEM, and closed the question. It did not. It standardised a structured lattice scheme, an unstructured lattice scheme a
Brian Couzens
Jun 162 min read
bottom of page
