top of page

Post-Quantum Cryptography in Plain English: The Backfill Session at the MY Digital Trust Summit 2026

Writer: Brian Couzens
Brian Couzens
2 minutes ago
2 min read
brian couzens presenting at my digital trust summit 2026 KL - Malaysia


At the MY Digital Trust Summit 2026 in Kuala Lumpur, a speaker could not make the morning session. We were asked to fill fifteen minutes on post-quantum cryptography (PQC) for a non-specialist audience, at short notice.

No slides. No preparation. Just a stand-up talk for three hundred people, from an ASEAN perspective, in plain English. We call it the backfill session.


Watch the full talk



What the talk covers

The talk sets out three things in fifteen minutes: what post-quantum cryptography is, why it matters for ASEAN now, and what being ready looks like.

The locks we rely on. Every QR payment, bank login and signed software update across ASEAN rests on cryptography you never see. Public-key cryptography, the kind that lets two strangers set up a safe link without meeting, holds the whole system together. It sets up every safe link on the internet, signs every software update, and sits inside bank cards, national ID cards, and the cross-border payment links between ASEAN member states. That is the lock a quantum computer breaks.

Why now. The harvest-now-decrypt-later threat means data copied today can be read the day a large quantum computer arrives. ASEAN's payment networks now operate across borders, from Bangkok to Singapore to Kuala Lumpur, and a joined-up system is only as strong as its weakest link. Regulators in Singapore, Malaysia and Thailand have already set out PQC migration expectations. The US plans to phase out the old algorithms from 2030 and ban them by 2035, and those dates will reach ASEAN through the products the region buys.

What ready looks like. Five steps, none of which need a quantum computer: find where the cryptographic dependencies are, own the risk at board level, rank what moves first, stop purchasing systems with the old locks inside, and build for crypto-agility so the lock can be changed without rebuilding the door.


Who should watch this

Board members, risk committees, CISOs, CTOs and programme leads across financial services, critical infrastructure and government in ASEAN who have not yet had the post-quantum cryptography conversation. Fifteen minutes is all it takes to frame the question.


Brian Couzens is Founder and CEO of SITG-Consulting, a vendor-independent advisory firm specialising in post-quantum cryptography transformation and cryptographic governance. This talk was delivered at the MY Digital Trust Summit 2026 in Kuala Lumpur on 24 September 2026.

 
 
 

Comments


bottom of page