top of page
EPC 342 - 08 v16.0.1 - Issued 24 June 2026
EPC 342 - 08 v16.0.1 - Issued 24 June 2026 SITG-Consulting Review & Dissection A MUST READ FOR ANY EUROPEAN PAYMENT PROVIDER The European Payments Council has released #EPC342โ08v16.0.1, its 2026 update on cryptographic algorithm usage and keyโmanagement practices. This deck provides SITG-Consulting independent review and dissection of the document - what it gets right, where it stops, and the enterpriseโlevel gaps it leaves unaddressed. Necessary, but not sufficient. This is
Brian Couzens
Jul 131 min read
ย
ย
ย


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
Jul 124 min read
ย
ย
ย
FINMA Quantum Computing PQC Guidance
FINMA's new guidance on Quantum Computing is welcome. It sends an important signal. Quantum risk is no longer a theoretical technology discussion. It is a governance and operational resilience issue that financial institutions are expected to address now. I agree with the direction of travel. Board-approved strategies, risk analysis, cryptographic inventories, crypto-agility and supplier management all deserve attention. However, I was struck by how extraordinarily light the
Brian Couzens
Jul 121 min read
ย
ย
ย


BREAKING: Quantum Just Got Secure-by-Design - And Silicon Is Moving First
๐จ BREAKING: Quantum Just Got Secure-by-Design - And Silicon Is Moving First The last 24 hours in PQC and quantum have been louder than anyone expected. ๐ฅ Europe may have just fired the starting gun on secure-by-design quantum hardware. ๐ช๐บ SEALSQ and Quobly signed a $5M deal to embed post-quantum cryptography directly into Quoblyโs silicon quantum processors. ๐ค Not PQC at the application layer. โ Not PQC wrapped around the cloud. โ๏ธ PQC integrated into the cryogenic contr
Brian Couzens
Jul 112 min read
ย
ย
ย


๐จ ๐๐๐๐๐๐๐๐: ๐๐ฎ๐๐ง๐ญ๐ฎ๐ฆ ๐๐ฎ๐ฌ๐ญ ๐๐จ๐ญ ๐๐๐๐ฎ๐ซ๐-๐๐ฒ-๐๐๐ฌ๐ข๐ ๐ง - ๐๐ง๐ ๐๐ข๐ฅ๐ข๐๐จ๐ง ๐๐ฌ ๐๐จ๐ฏ๐ข๐ง๐ ๐ ๐ข๐ซ๐ฌ๐ญ โก
The last 24 hours in PQC and quantum have been louder than anyone expected. ๐ฅ Europe may have just fired the starting gun on secure-by-design quantum hardware. ๐ช๐บ SEALSQ and Quobly signed a $5M deal to embed post-quantum cryptography directly into Quoblyโs silicon quantum processors. ๐ค Not PQC at the application layer. โ Not PQC wrapped around the cloud. โ๏ธ PQC integrated into the cryogenic control electronics themselves. ๐ง Weโre talking about Cryo-CMOS ASICs with PQC ac
Brian Couzens
Jul 112 min read
ย
ย
ย


Cryptographic Inflation: The Economics of Uncertainty
PQC Economics For the past three years, almost every serious discussion about Post-Quantum Cryptography has started with the same question: How much will it cost? Governments have published rough estimates. Boards want numbers. Vendors are selling calculators. Consultants are packaging migration roadmaps. But that question is still too narrow. It treats PQC like a software upgrade. It is not. The economics of PQC are not driven by cryptographic algorithms. They are driven by
Brian Couzens
Jul 104 min read
ย
ย
ย


SITG-Consulting Solutions: Crafting Future-Ready Solutions
In todayโs fast-evolving landscape, organizations face unprecedented challenges. Cyber threats grow more sophisticated. Quantum computing promises disruption. Regulatory demands tighten. SITG Consulting crafts solutions that anticipate these shifts. The focus remains clear: build resilience, ensure compliance, and enable sustainable transformation. This approach positions SITG Consulting as a trusted partner for global enterprises, financial services, critical infrastructure,
Brian Couzens
Jul 93 min read
ย
ย
ย


A policy for a policy
๐๐จ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ซ๐๐๐ฅ๐ฅ๐ฒ ๐ง๐๐๐ ๐ ๐ฌ๐ญ๐๐ง๐๐๐ฅ๐จ๐ง๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ฒ ๐๐จ๐ฅ๐ข๐๐ฒ? Iโm starting to think the default answer of โyesโ might be wrong. I recently reviewed the Dutch Governmentโs Framework Cryptography Policy for the Central Government. Whatโs interesting is that it doesnโt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read
ย
ย
ย


Business Transformation, Cyber Resilience, Quantum Risk and Governance Consulting
Organisations are investing billions in digital transformation, artificial intelligence, cloud migration and cybersecurity. Yet many programmes fail for one simple reason. Technology changes faster than governance, risk management and organisational control. At SITG-Consulting, we help organisations bridge that gap. We specialise in business transformation, cyber resilience, enterprise governance, post-quantum cryptography (PQC), quantum risk management, regulatory compliance
Brian Couzens
Jul 93 min read
ย
ย
ย


CBOM: The Difference Between Discovery and Intelligence
The Missing Discipline The post-quantum conversation has a numbers problem. Vendors love to say they have found millions of cryptographic assets. That sounds serious. It sounds comprehensive. It sounds like the sort of number a board should pay attention to. But in most environments, that number is doing a lot of rhetorical work. What organisations usually have are millions of cryptographic instances. The same library. The same certificate. The same key store. The same implem
Brian Couzens
Jul 85 min read
ย
ย
ย


CBOM - The Real Story
๐๐๐ ๐๐ข๐ฌ๐๐จ๐ฏ๐๐ซ๐ฒ ๐๐ง๐ ๐ซ๐๐ฆ๐๐๐ข๐๐ญ๐ข๐จ๐ง ๐ฏ๐๐ง๐๐จ๐ซ๐ฌ ๐ฅ๐จ๐ฏ๐ ๐ญ๐๐ฅ๐ฅ๐ข๐ง๐ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ญ๐ก๐๐ฒ ๐ก๐๐ฏ๐ "๐ฆ๐ข๐ฅ๐ฅ๐ข๐จ๐ง๐ฌ ๐จ๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ข๐ ๐๐ฌ๐ฌ๐๐ญ๐ฌ." That sounds impressive. In reality, it frequently conflates cryptographic #instances with unique cryptographic #dependencies. There is a fundamental difference. The same cryptographic library, certificate, key store, or implementation can appear thousands of times across ser
Brian Couzens
Jul 82 min read
ย
ย
ย
PQC Discovery Sprint
One of the questions we're asked more than any other is: "What actually happens during a Discovery Sprint?" This carousel answers that question. Rather than talking about methodology, we've opened the lid on a real engagement for an anonymised digital challenger bank. You'll see how assumptions are tested, how evidence is gathered, why cryptographic inventories rarely reconcile, and how governance failures become visible long before any discussion about post-quantum algorithm
Brian Couzens
Jul 71 min read
ย
ย
ย


๐ Quantum Weekly - The Global Signals That Actually Mattered (29 June - 6 July 2026)
July 7, 2026 The week that followed the two US executive orders resolved into a single structural pattern: the migration mandate is now propagating outward from government into the vendor base and the capital markets. The signals divide cleanly. On the governance side, the largest cloud provider brought its own quantum-safe deadline forward by two years and folded it into an existing engineering discipline, and a zero-knowledge protocol published a phased cryptographic transi
Brian Couzens
Jul 713 min read
ย
ย
ย


Quantum & Post-Quantum Cryptography 2026
The Mid-Year Global Intelligence Review Special Edition | January โ June 2026 About this Special Edition This special edition departs from the normal weekly format. Rather than examining a single seven-day reporting window, it assesses the cumulative developments that shaped the first half of 2026 across quantum computing, post-quantum cryptography (PQC), standards, regulation, government policy, commercial adoption, and enterprise readiness. The objective is not to report ev
Brian Couzens
Jul 410 min read
ย
ย
ย
Why Business Transformation Fails: It's Not Strategy. It's Control.
Every year organisations invest billions in business transformation. Digital transformation. Cloud migration. Cybersecurity. Operational resilience. Artificial Intelligence. Post-Quantum Cryptography. The strategies are ambitious. The technology is impressive. The budgets are substantial. Yet programme after programme fails to deliver the expected outcomes. Why? The answer is surprisingly consistent. Organisations rarely fail because they lack strategy. They fail because they
Brian Couzens
Jul 42 min read
ย
ย
ย
Post-Quantum Cryptography Discovery Sprint
The First Step Towards Post-Quantum Readiness Most organisations understand that quantum computing will eventually require a transition to post-quantum cryptography (PQC). Far fewer know where to begin. The greatest challenge is rarely selecting new cryptographic algorithms. It is understanding where cryptography exists across the organisation, how it is being used, what business processes depend upon it, and which assets are most exposed to future quantum risk. Our Post-Quan
Brian Couzens
Jul 42 min read
ย
ย
ย


Business Transformation Built on Governance, Security and Resilience
Successful transformation is not about deploying the latest technology. It is about changing how an organisation operates, governs risk, makes decisions and delivers measurable business outcomes. At SITG-Consulting, we help organisations design and execute complex transformation programmes that strengthen governance, improve operational resilience and prepare businesses for emerging technological and regulatory challenges. Our expertise spans business transformation, digital
Brian Couzens
Jul 42 min read
ย
ย
ย


SPOTLIGHT on QUANTUM KOREA 2026
The Tipping Point: How Quantum Korea 2026 Exposes the Industryโs Reality and Its Fault Lines Quantum Korea 2026, held from July 2 to July 4 at DDP Art Hall in Seoul, is not just another conference on the international technology circuit. It is a geopolitical signal, a commercial barometer, and a diagnostic event that shows exactly where the quantum industry is advancing, where it is stalling, and where the rhetoric still exceeds the reality. Under the banner โQuantum in Actio
Brian Couzens
Jul 37 min read
ย
ย
ย


DATA, PQC, HNDL and HNFL
#PQC and #Data: The Three #Cryptographic Domains Post-quantum risk is about the data being protected, not the algorithms themselves. Every cryptographic dependency maps to one of three data states. If you do not know which state you are protecting, you do not know what you are securing. #Data in #Motion Information moving across networks or channels. TLS sessions, VPN tunnels, 5G key agreement, SWIFT messages, API calls. Quantum relevance: interception and harvest. If the con
Brian Couzens
Jul 32 min read
ย
ย
ย


AI is not a new construct
๐'๐๐ ๐๐๐๐๐๐๐๐๐๐ ๐๐๐๐ ๐๐ ๐๐๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐ ๐๐. Codswallop. Absolute codswallop. - NO YOU HAVE NOT ๐๐ ๐ก๐๐ฌ๐ง'๐ญ ๐๐ฑ๐ฉ๐จ๐ฌ๐๐ ๐ ๐ ๐จ๐ฏ๐๐ซ๐ง๐๐ง๐๐ ๐ ๐๐ฉ. ๐๐ญ'๐ฌ ๐๐ฑ๐ฉ๐จ๐ฌ๐๐ ๐ ๐ค๐ง๐จ๐ฐ๐ฅ๐๐๐ ๐ ๐ ๐๐ฉ. ๐'๐ฏ๐ ๐๐๐๐ง ๐ ๐จ๐๐ฌ๐ฆ๐๐๐ค๐๐ ๐๐ฒ ๐ก๐จ๐ฐ ๐ฆ๐๐ง๐ฒ ๐ฉ๐๐จ๐ฉ๐ฅ๐ ๐ข๐ง ๐๐ฒ๐๐๐ซ, ๐ซ๐๐ฌ๐ข๐ฅ๐ข๐๐ง๐๐, ๐ซ๐ข๐ฌ๐ค ๐๐ง๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐ข๐๐ง๐๐ ๐ฌ๐ญ๐ข๐ฅ๐ฅ ๐๐จ๐ง'๐ญ ๐ฎ๐ง๐๐๐ซ๐ฌ๐ญ๐๐ง๐ ๐ฐ๐ก๐๐ญ ๐ ๐จ๐ฏ๐๐ซ๐ง๐๐ง๐๐ ๐ข๐ฌ. Eve
Brian Couzens
Jul 12 min read
ย
ย
ย
bottom of page
