How to Perform a Cryptographic Inventory: A Discovery Method Field Guide
Nine discovery methods, what each one actually finds, where each one goes blind, and how to layer them so one tool's gap is another…
Archive
Nine discovery methods, what each one actually finds, where each one goes blind, and how to layer them so one tool's gap is another…
Operators face two problems enterprises mostly don't: most of their cryptography is written by someone else, and every cryptographic relationship has a counterparty they…
Algorithm swaps almost never happen cleanly. A more useful definition of crypto-agility, and the four mitigation patterns architects can deploy before a full replacement…
NIST's practice guide on post-quantum migration is a lab record, not a mandate. A GRC reading of its three volumes, and the four artifacts…
Post-quantum migration stalls on staffing more often than on cryptography. Seven capability areas, who in your organization already covers them, and how to find…
The post-quantum migration is an engineering problem, not a mathematics problem. Here is what competence looks like across the four domains that carry the…
Most PQC migration advice assumes you can change the code that checks a signature. In OT you often can't. Sorting assets by verifier agility…
A hybrid TLS handshake carries about 1,216 bytes where a classical one carried 32. We count the whole first flight and follow it across…
Most post-quantum vendor questionnaires ask about intent, and intent questions have one correct answer that every vendor knows. Four question shapes that don't.
Crypto-agility is measured in how long a substitution takes and how much of the system it touches. Here is what that means at the…