top of page


DigiCert's 2026 Quantum Readiness Outlook
Every week I see organisations announcing their Post-Quantum Cryptography strategy. Strategies. Roadmaps. Working groups. Steering committees. Pilot programmes. Then along comes some actual data. DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia. 87% say they are planning, testing or implementing PQC. Only 7% have deployed quantum-safe or hybrid cryptography across most of their
Brian Couzens
Jul 272 min read
ย
ย
ย


TLS 1.3 hasn't become TLS 1.4.
It has become less tolerant of the past. This month, the IETF published RFC 9846, which replaces RFC 8446 while keeping the protocol as TLS 1.3. On the surface, it looks like a minor revision. It isn't. One change stands out: Implementations MUST NOT negotiate TLS 1.0 or TLS 1.1. Not "SHOULD NOT." Not "avoid where possible." MUST NOT. That matters because we're reaching a tipping point. For years, organisations carried obsolete cryptography because "it still works." Increasin
Brian Couzens
Jul 252 min read
ย
ย
ย


Quantum Is No Longer a Cyber Risk. It's a Fiduciary Duty.
Buried in a legal update this week was a signal that should concern every Board. Lawyers are now being trained on post-quantum cryptography, quantum evidence, AI-quantum convergence and Q-Day. Think about that. The legal profession is preparing for the consequences. Is your Board? Now imagine the cross-examination. "When did you become aware that quantum computing would eventually render your cryptography obsolete?" "You knew your regulators had already issued migration guida
Brian Couzens
Jul 191 min read
ย
ย
ย


Kudankulam Shows Why Critical Infrastructure Security Is a Governance Problem, Not Just a Cybersecurity Problemcff
Sensitive documents reportedly linked to India's Kudankulam Nuclear Power Plant have been exposed following a ransomware attack affecting a contractor. According to Reuters, the leaked material includes engineering drawings, supplier information and inspection records, while there is currently no evidence that reactor control systems themselves were compromised. That distinction matters. Too often, critical infrastructure security is viewed through the lens of perimeter defen
Brian Couzens
Jul 151 min read
ย
ย
ย


The White House Quantum Summit wasnโt the story.
Americaโs transition from quantum strategy to quantum execution was. In the span of three weeks, the United States compressed years of quantum policy into a coordinated national programme: Executive Order 14412 accelerating Post-Quantum Cryptography (PQC) migration Executive Order 14413 strengthening the national quantum innovation ecosystem The Department of Defense PQC Strategy OMB M-26-15 defining a structured federal migration roadmap QuantumEAGLe aligning government and
Brian Couzens
Jul 152 min read
ย
ย
ย


A Watershed Moment for UK Financial Regulation - Or Just the Beginning?
The designation of #Amazon Web Services, #Microsoft, #Google Cloud, and #Oracle as the UKโs first Critical Third Parties (#CTPs) is not just another operational resilience milestone. It is a structural shift in where systemic risk is understood to live-and who regulators believe must be accountable for it. For the first time under the Financial Services and Markets Act 2023, the Bank of England, #PRA, and #FCA will exercise direct, joint oversight over organisations that sit
Brian Couzens
Jul 142 min read
ย
ย
ย


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
Jul 124 min read
ย
ย
ย


A policy for a policy
๐๐จ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ซ๐๐๐ฅ๐ฅ๐ฒ ๐ง๐๐๐ ๐ ๐ฌ๐ญ๐๐ง๐๐๐ฅ๐จ๐ง๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ฒ ๐๐จ๐ฅ๐ข๐๐ฒ? Iโm starting to think the default answer of โyesโ might be wrong. I recently reviewed the Dutch Governmentโs Framework Cryptography Policy for the Central Government. Whatโs interesting is that it doesnโt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read
ย
ย
ย


CBOM: The Difference Between Discovery and Intelligence
The Missing Discipline The post-quantum conversation has a numbers problem. Vendors love to say they have found millions of cryptographic assets. That sounds serious. It sounds comprehensive. It sounds like the sort of number a board should pay attention to. But in most environments, that number is doing a lot of rhetorical work. What organisations usually have are millions of cryptographic instances. The same library. The same certificate. The same key store. The same implem
Brian Couzens
Jul 85 min read
ย
ย
ย


CBOM - The Real Story
๐๐๐ ๐๐ข๐ฌ๐๐จ๐ฏ๐๐ซ๐ฒ ๐๐ง๐ ๐ซ๐๐ฆ๐๐๐ข๐๐ญ๐ข๐จ๐ง ๐ฏ๐๐ง๐๐จ๐ซ๐ฌ ๐ฅ๐จ๐ฏ๐ ๐ญ๐๐ฅ๐ฅ๐ข๐ง๐ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ญ๐ก๐๐ฒ ๐ก๐๐ฏ๐ "๐ฆ๐ข๐ฅ๐ฅ๐ข๐จ๐ง๐ฌ ๐จ๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ข๐ ๐๐ฌ๐ฌ๐๐ญ๐ฌ." That sounds impressive. In reality, it frequently conflates cryptographic #instances with unique cryptographic #dependencies. There is a fundamental difference. The same cryptographic library, certificate, key store, or implementation can appear thousands of times across ser
Brian Couzens
Jul 82 min read
ย
ย
ย
PQC Discovery Sprint
One of the questions we're asked more than any other is: "What actually happens during a Discovery Sprint?" This carousel answers that question. Rather than talking about methodology, we've opened the lid on a real engagement for an anonymised digital challenger bank. You'll see how assumptions are tested, how evidence is gathered, why cryptographic inventories rarely reconcile, and how governance failures become visible long before any discussion about post-quantum algorithm
Brian Couzens
Jul 71 min read
ย
ย
ย


AI is not a new construct
๐'๐๐ ๐๐๐๐๐๐๐๐๐๐ ๐๐๐๐ ๐๐ ๐๐๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐ ๐๐. Codswallop. Absolute codswallop. - NO YOU HAVE NOT ๐๐ ๐ก๐๐ฌ๐ง'๐ญ ๐๐ฑ๐ฉ๐จ๐ฌ๐๐ ๐ ๐ ๐จ๐ฏ๐๐ซ๐ง๐๐ง๐๐ ๐ ๐๐ฉ. ๐๐ญ'๐ฌ ๐๐ฑ๐ฉ๐จ๐ฌ๐๐ ๐ ๐ค๐ง๐จ๐ฐ๐ฅ๐๐๐ ๐ ๐ ๐๐ฉ. ๐'๐ฏ๐ ๐๐๐๐ง ๐ ๐จ๐๐ฌ๐ฆ๐๐๐ค๐๐ ๐๐ฒ ๐ก๐จ๐ฐ ๐ฆ๐๐ง๐ฒ ๐ฉ๐๐จ๐ฉ๐ฅ๐ ๐ข๐ง ๐๐ฒ๐๐๐ซ, ๐ซ๐๐ฌ๐ข๐ฅ๐ข๐๐ง๐๐, ๐ซ๐ข๐ฌ๐ค ๐๐ง๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐ข๐๐ง๐๐ ๐ฌ๐ญ๐ข๐ฅ๐ฅ ๐๐จ๐ง'๐ญ ๐ฎ๐ง๐๐๐ซ๐ฌ๐ญ๐๐ง๐ ๐ฐ๐ก๐๐ญ ๐ ๐จ๐ฏ๐๐ซ๐ง๐๐ง๐๐ ๐ข๐ฌ. Eve
Brian Couzens
Jul 12 min read
ย
ย
ย
The Lexicon
Words matter. Especially when organisations are making strategic decisions. One of the biggest problems across cyber security, governance, risk, resilience and quantum isn't technology. It's language. Different vendors define the same term differently. Standards use different terminology. Consultants invent new phrases. Boards are expected to make decisions using inconsistent vocabulary. That creates confusion before the real work even starts. To address that, we've made the
Brian Couzens
Jul 11 min read
ย
ย
ย


You know every day I challenge people who have discovered a new genre of Governance.
๐๐๐ ๐๐๐๐๐'๐. ๐
๐
๐. Every few weeks someone announces the next revolution. AI Governance. Quantum Governance. Sovereign Intelligence. Machine-Layer Authority. Algorithmic Governance. No. You've discovered a new technology, a new risk profile or a new application. You haven't discovered a new discipline. So let me ask one question. ๐๐ก๐ฒ ๐๐จ ๐ฒ๐จ๐ฎ ๐ญ๐ก๐ข๐ง๐ค ๐ฒ๐จ๐ฎ'๐ฏ๐ ๐ฌ๐ฎ๐๐๐๐ง๐ฅ๐ฒ ๐๐จ๐ฎ๐ง๐ ๐ญ๐ก๐ ๐๐ฎ๐ซ๐ ๐๐จ๐ซ ๐๐ฏ๐๐ซ๐ฒ๐ญ๐ก๐ข๐ง๐ ๐ ๐จ๐ฏ๐๐ซ๐ง๐๐ง๐๐ ๐ก
Brian Couzens
Jun 302 min read
ย
ย
ย


Microsoft's quantum computing technology called into question, again
Science is doing exactly what science is supposed to do. A new peer-reviewed critique published in Nature has challenged aspects of Microsoft's Majorana-based quantum computing research, arguing that the evidence may not conclusively demonstrate the physics the company claims. Microsoft strongly disagrees and maintains its roadmap remains on track. This is not a story about Microsoft "failing." It is a reminder that extraordinary scientific claims invite extraordinary scienti
Brian Couzens
Jun 261 min read
ย
ย
ย


NIST: CSF2.0
NIST CSF 2.0 may be one of the most important Quantum Readiness frameworks available today. Not because it contains a section on quantum computing. It doesn't. Not because it tells organisations which algorithms to deploy. It doesn't do that either. What CSF 2.0 does provide is something far more important. Governance. The 2024 update elevated governance to a core function, recognising that cybersecurity is no longer solely a technology challenge. It is a board, executive and
Brian Couzens
Jun 252 min read
ย
ย
ย


๐๐๐ฉ๐ฅ๐จ๐ฒ๐ฆ๐๐ง๐ญ ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐๐๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ. ๐๐ฅ๐ข๐ฆ๐ข๐ง๐๐ญ๐ข๐จ๐ง ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐ฉ๐ซ๐จ๐ ๐ซ๐๐ฌ๐ฌ.
This week I read the best description of how to measure success against quantum risk. It comes from a recent Department of War (DoW) strategy document, and it is a breath of fresh air. ๐ ๐ช๐ฎ๐จ๐ญ๐: "Quantum resistance is not achieved when PQC is rolled out, but when quantum-vulnerable solutions are deprecated." Let's dissect what that means because it cuts straight through the marketing theatre dominating cybersecurity right now. ๐๐๐๐ข๐ง๐:"Quantum-Vulnerable" Any algor
Brian Couzens
Jun 252 min read
ย
ย
ย


The #EO14409 isnโt a genesis point - it is a compliance hammer.
The #EO isnโt a genesis point - it is a compliance hammer. There is an immense amount of noise surrounding the newly issued Executive Order 14409, "Securing the Nation Against Advanced Cryptographic Attacks." Many commentators treat it as a sudden wake-up call that magically creates a post-quantum cryptography (PQC) migration strategy out of thin air. Before making that claim, look at what already existed. Federal policy did not start on 22 June 2026. Agencies have been opera
Brian Couzens
Jun 242 min read
ย
ย
ย


THE DEADLINE JUST MOVED. AGAIN.
That should concern every board, regulator, CISO and risk committee still treating post-quantum cryptography as a distant technology problem. The United States has issued a new Executive Order accelerating PQC migration requirements. Notably: โข PQC key establishment for High Value Assets by 31 December 2030 โข PQC digital signatures for High Value Assets by 31 December 2031 This is the second major shift in federal timing expectations. That matters. Governments do not compress
Brian Couzens
Jun 231 min read
ย
ย
ย


Special Forces
Is it just me, or has the World become one giant credential parade? I am going to try and make this a regular feature. The working title is: **The Sunday Slop** *Another week. Another guru.* Former Navy SEAL. Former Secret Service. Former MI6. Former Commando. Former Special Operations. Former Intelligence Officer. Former Special Agent. Former Operator. Former Tactical Something. Former Strategic Something Else. At this point I am beginning to wonder whether LinkedIn has a mi
Brian Couzens
Jun 212 min read
ย
ย
ย
bottom of page
