top of page


🇸🇬 Singapore PQC Spotlight: Strategy, Deployment, & Timelines
Singapore is Asia's most operationally advanced PQC adopter. With a unified strategy, live quantum safe networks, and proactive regulators, PQC has moved from theory to structured deployment. Government Posture: Centralised & Risk-Based Leadership: Strategy led jointly by CSA, National Quantum Office, MAS, and IMDA. Standards: PQC is the primary migration path, aligned with NIST FIPS 203, 204, and 205. Core Milestones: End 2025: CII operators must complete full crypto invento
Brian Couzens
Jul 232 min read


🇰🇷 South Korea PQC Spotlight: High Capability, Master Plan in Motion, Mandates Not Yet Issued
South Korea is a global semiconductor and technology powerhouse. It does not have a CNSA style, economy wide crypto retirement deadline, but it does have a government backed PQC Master Plan, sector wide pilots, and a national playbook aimed at transforming the country’s cryptographic infrastructure by 2035. Industry is still moving faster than regulation, but the state is not passive. Korea is building a phased and coordinated PQC transition. Government Posture: Master Plan a
Brian Couzens
Jul 222 min read


NZ SPOTLIGHT: The Quiet Five Eyes Laggard With One World‑Class PQC Contribution
New Zealand is the only Five Eyes member with no PQC retirement deadline. Conservative and advisory in posture, yet home to one of the globally significant contributors to ML‑DSA. This is NZ’s real PQC position. Government posture: NZISM v3.8 (Sept 2024), Section 2.4 requires agencies to inventory cryptographic assets, monitor GCSB updates, and prepare migration plans. No PQC algorithms are approved, and no deadline exists for retiring RSA, DH, ECDH or ECDSA. GSMA’s 2025 tra
Brian Couzens
Jul 221 min read


Australia - Quantum Era Readiness and PQC Transition: 🇦🇺 SPOTLIGHT:
Australia has moved from awareness to structured execution under the Australian Signals Directorate (ASD) and Australian Cyber Security Centre (ACSC) guidance. It is not the loudest, but it is the most disciplined in the Five Eyes on migration planning. 1. National Mandate: ASD and ACSC’s PQC Transition Framework The ACSC’s Planning for Post Quantum Cryptography guidance (2022–2025) sets a three stage LATICE based timeline: Refined transition plan by end 2026 Migration begun
Brian Couzens
Jul 212 min read


CRYPTOGRAPHIC AGILITY. CAN IT ACTUALLY BE DONE?
For years we've been told organisations need cryptographic agility. NIST has repeatedly warned that cryptographic systems must be able to transition as algorithms become vulnerable or obsolete. The post-quantum migration is simply the latest and largest example. The destination has been clear. The implementation hasn't. IBM Research has now made a significant contribution to answering that question. Their 2026 papers introduce an application-level framework that separates cry
Brian Couzens
Jul 202 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (13 July - 19 July 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management July 20, 2026 This week the ecosystem moved from announcement to institutionalisation across three separate layers: standards, manufacturing and procurement. A code-based post-quantum algorithm reached ISO standardisation, giving the PQC landscape a second formal standards trac
Brian Couzens
Jul 2012 min read


Strengthening GCC Resilience Strategies in Cybersecurity
Cyber threats evolve rapidly. The Gulf Cooperation Council (GCC) faces increasing risks. Cyber resilience is no longer optional. It is essential. I focus on strengthening GCC resilience strategies. I provide clear, actionable insights. The goal is to enhance protection across critical sectors. These include financial services, government, healthcare, and infrastructure. Enhancing GCC Resilience Strategies GCC countries must adopt robust cyber resilience strategies. These stra
Brian Couzens
Jul 203 min read


Quantum Is No Longer a Cyber Risk. It's a Fiduciary Duty.
Buried in a legal update this week was a signal that should concern every Board. Lawyers are now being trained on post-quantum cryptography, quantum evidence, AI-quantum convergence and Q-Day. Think about that. The legal profession is preparing for the consequences. Is your Board? Now imagine the cross-examination. "When did you become aware that quantum computing would eventually render your cryptography obsolete?" "You knew your regulators had already issued migration guida
Brian Couzens
Jul 191 min read


Malaysia - Southeast Asia’s Quantum Risk Front Runner -PQC - 🇲🇾 SPOTLIGHT:
Malaysia has quietly become ASEAN’s most assertive mover on quantum risk and PQC. Not the most advanced, not the most resourced, but the most coordinated, the most visible, and the first to publish a national PQC roadmap. This is why Malaysia now sits in the regional spotlight. 1. First in ASEAN with a National PQC Roadmap Malaysia is the only ASEAN member with a formal PQC transition roadmap. It is structured, time bounded, and aligned with NIST’s migration track. Core pilla
Brian Couzens
Jul 192 min read
FIPs140-3 A Thematic Review
A half-year read on where FIPS 140-3 validation actually stands. Between January and mid-July 2026, 30 new FIPS 140-3 certificates were issued or announced across non-hyperscaler, non-tier-1 vendors, spanning HSMs, authentication, cryptographic libraries, edge/IoT and embedded modules. With FIPS 140-2 fully retiring on 21 September 2026, this is no longer a future consideration. It's active, measurable, and already reshaping vendor selection. This SITG-Consulting Thematic Rev
Brian Couzens
Jul 181 min read


Booking Your Online Cyber Discovery Sprint: Cyber Discovery Sprint Setup
Cyber threats evolve rapidly. Organizations must adapt quickly. A Cyber Discovery Sprint offers a focused, intensive approach to identifying vulnerabilities and strengthening defenses. Booking your Cyber Discovery Sprint online streamlines the process. It ensures timely engagement and efficient preparation. This post outlines the essential steps for a successful cyber discovery sprint setup. Understanding Cyber Discovery Sprint Setup A Cyber Discovery Sprint is a short, targe
Brian Couzens
Jul 174 min read


Post-Quantum Readiness Is an ESG Risk. Here’s Why We Reclassified It.
For years, almost every discussion around post-quantum cryptography has started in the same place. Algorithms.Encryption.Standards.Migration.Cybersecurity. That is where the industry begins. It is also where the industry stops thinking. It is not where the risk ends. During the development of the 2026 Quantum Risk Global Doctrine, we reached a different conclusion: Post-Quantum Readiness can no longer be classified as primarily a cybersecurity programme. It exhibits every cha
Brian Couzens
Jul 174 min read
An Analysis of ASD's PQC Vendor Approach.
One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migration plans and technical roadmaps. That misses the point. Modern organisations no longer control much of their own cryptography. It sits inside cloud platforms, software, managed services, operational technology and hardware supplied by third parties. Your programme cannot move fast
Brian Couzens
Jul 161 min read


THE AI CHALLENGE - GOVERNANCE
Without sounding narcissistic, we’re often told we’re opinionated. Everyone is 100 percent correct. We are, and we will remain so. Not for ego. For rigour. If a proposition is weak, confused or stretching novelty beyond necessity, it should be challenged. Governance is a mature discipline. Reinventing it with diagrams and slogans helps nobody. Yesterday was a good example. A post appeared describing AI governance as a neat four layer staircase. I challenged it: "This is a per
Brian Couzens
Jul 162 min read


Kudankulam Shows Why Critical Infrastructure Security Is a Governance Problem, Not Just a Cybersecurity Problemcff
Sensitive documents reportedly linked to India's Kudankulam Nuclear Power Plant have been exposed following a ransomware attack affecting a contractor. According to Reuters, the leaked material includes engineering drawings, supplier information and inspection records, while there is currently no evidence that reactor control systems themselves were compromised. That distinction matters. Too often, critical infrastructure security is viewed through the lens of perimeter defen
Brian Couzens
Jul 151 min read


The White House Quantum Summit wasn’t the story.
America’s transition from quantum strategy to quantum execution was. In the span of three weeks, the United States compressed years of quantum policy into a coordinated national programme: Executive Order 14412 accelerating Post-Quantum Cryptography (PQC) migration Executive Order 14413 strengthening the national quantum innovation ecosystem The Department of Defense PQC Strategy OMB M-26-15 defining a structured federal migration roadmap QuantumEAGLe aligning government and
Brian Couzens
Jul 152 min read


Global Post-Quantum Cryptography (PQC) Consulting | Quantum Risk, Quantum Readiness & Cryptographic Governance | SITG-Consulting
Quantum Computing Will Change Cyber Security. Preparation Starts Today. Every organisation relies on cryptography. Banks rely on it to secure financial transactions. Governments rely on it to protect national infrastructure. Healthcare providers rely on it to safeguard patient records. Manufacturers rely on it to secure operational technology. Cloud providers rely on it to establish trust. Every VPN, SSL certificate, digital signature, software update, encrypted database, aut
Brian Couzens
Jul 145 min read


A Watershed Moment for UK Financial Regulation - Or Just the Beginning?
The designation of #Amazon Web Services, #Microsoft, #Google Cloud, and #Oracle as the UK’s first Critical Third Parties (#CTPs) is not just another operational resilience milestone. It is a structural shift in where systemic risk is understood to live-and who regulators believe must be accountable for it. For the first time under the Financial Services and Markets Act 2023, the Bank of England, #PRA, and #FCA will exercise direct, joint oversight over organisations that sit
Brian Couzens
Jul 142 min read


CMMC Phase II Suspended: What the Department of War's Decision Really Means
The United States Department of War has announced the immediate suspension of CMMC Phase II requirements while it undertakes a 60-day review of the programme. Predictably, headlines have already begun suggesting that CMMC has been paused or that cybersecurity requirements are being rolled back. Neither interpretation is correct. The announcement is not a retreat from cybersecurity. It is a reassessment of how cybersecurity assurance should be delivered. What Has Changed? The
Brian Couzens
Jul 143 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (6-13 July 2026)
SITG-Consulting | Forensic Strategist | Cyber Resilience, Quantum Risk & Governance | Transformation, ERM & Independent Validation | Writer | White Paper Author | Evidence-Based Decision Making July 13, 2026 This week's signals ran along two separate tracks that are starting to converge: hardware architecture and cryptographic supply chain. On the hardware side, three independent teams in Switzerland, the United States and Australia advanced non-standard qubit and photonic ar
Brian Couzens
Jul 1410 min read
bottom of page
