top of page

CUBA PQC SPOTLIGHT: STATE‑CENTRIC CYBERSECURITY, ZERO PQC READINESS

  • Writer: Brian Couzens
    Brian Couzens
  • 6 days ago
  • 2 min read

Cuba operates one of the most state‑controlled cybersecurity regimes in the Western Hemisphere. Its legal architecture is built on Decreto 360/2019, Decreto‑Ley 35/2021, and Resolution 105/2021, all of which focus on ICT security, cyberspace defence, telecom control, and mandatory incident reporting - none of which contain PQC migration, crypto‑agility, or quantum‑risk provisions.


Government Posture: Strong Control, No Quantum Strategy


Cuba’s cybersecurity model is centralised under MINCOM (Ministry of Communications) and OSRI (Office of Computer Network Security). These bodies enforce ICT security, regulate telecom infrastructure, and maintain a national catalogue of critical ICT systems.


But Cuba has:

No PQC roadmap  

No cryptographic inventory requirements  

No ML‑DSA / ML‑KEM transition plan  

No crypto‑agility mandates  

No national quantum‑security strategy


The regulatory posture is defensive and surveillance‑oriented, not cryptographically modernised.


Quantum Risk Profile: High Exposure, No Mitigation


Cuba’s infrastructure is vulnerable to quantum‑era threats because its cryptographic standards remain classical and static. Based on global quantum‑risk analysis, sectors most exposed include telecommunications (tightly controlled but reliant on legacy crypto; Decreto‑Ley 35 empowers shutdowns but not cryptographic upgrades), critical ICT infrastructure (catalogued under Decreto 360 but protected with pre‑quantum controls), finance and state records (long‑lived data with no HNDL mitigation), and transport and logistics (no PQC guidance for aviation, ports, or customs systems).


Cuba has no national quantum‑security strategy, unlike countries actively preparing for quantum threats.


Cybersecurity Strengths


Cuba does have mandatory incident reporting (Resolution 105), a national incident‑classification model, strong central enforcement, and sector‑specific ICT protection rules. But these strengths do not extend to cryptographic modernisation or quantum readiness.


Bottom Line


Cuba’s cybersecurity regime is state‑centric, surveillance‑heavy, and technically outdated. It has zero PQC readiness, zero migration planning, and zero crypto‑agility requirements. Critical sectors operate entirely on classical cryptography with no mitigation for Harvest‑Now‑Decrypt‑Later threats. Cuba is one of the least prepared nations in the Americas for quantum‑era cryptographic risk.


SITG-Consulting This should worry you. You are only as strong as your weakest link in any trust chain - and if anything in your ecosystem touches Cuba, no matter how big or small, that link inherits its exposure. Quantum risk doesn’t respect borders or ownership; it propagates through every connected system.




 
 
 

Comments


bottom of page