<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why organizations should stop worrying about Y2Q and start focusing on compliance in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88555#M7780</link>
    <description>&lt;P&gt;Unfortunately, I think it's just human nature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless the checks and balances are in place there will be backsliding, it behooves us all to point it out gently, but firmly and help things improve. Failures, and their modes can start from the top down, or the bottom up and quite often in the middle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen some incredibly good organizations, and some that are striving to improve, but these problems are not really about cryptography, or quantum cryptanalysis or even a particular geographical region, they are ubiquitous.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To misappropriate a proverb:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The price of peace (and quiet), is eternal vigilance..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Calm and resolute counsel is a must:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"This is coming, that's the problem, here's what you can do, constant automated scanning to the latest and grates, vulnerability passement, pen testing, advisory at the start, attestation against standards, internal audit helped us to find, external audit had something we must correct, the regulator requires this be fixed(or will if it's not done)."&lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2026 02:09:01 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2026-03-09T02:09:01Z</dc:date>
    <item>
      <title>Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88115#M7746</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is Part 1:&lt;/P&gt;&lt;H3 id="ember50"&gt;Demystifying Post quantum Topics — Part 1&lt;/H3&gt;&lt;P class=""&gt;As I fly back from the &lt;A class="" href="https://www.linkedin.com/company/pki-consortium/" target="_blank" rel="noopener"&gt;PKI Consortium&lt;/A&gt;’s PQC Conference in Kuala Lumpu&lt;STRONG&gt;r&lt;/STRONG&gt;, I’m wrapping up days filled with insightful talks and energizing conversations. Among the many ideas that kept my mind busy, one stands out: demystifying a few topics that, in my view, carry too much weight in the post quantum cryptography (PQC) conversation.&lt;/P&gt;&lt;P class=""&gt;Over several days, brilliant post quantum experts gathered to exchange ideas and energize everyone’s neurons. Some discussions navigated through well-established concepts and recommendations. Sometimes I found myself disagreeing with them. Responding to these provided an enlightening opportunity to challenge and clarify ideas that many hold firmly.&lt;/P&gt;&lt;P class=""&gt;With full respect for differing opinions and in the spirit of healthy debate, I intend to challenge four commonly accepted notions in a slightly provocative way to encourage you, dear reader, to reconsider your current analysis. I’ll publish each reflection in a separate article over the coming days.&lt;/P&gt;&lt;P class=""&gt;Let’s begin with the first one&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;H3 id="ember55"&gt;Organizations Should Not Worry Too Much About “Y2Q”&lt;/H3&gt;&lt;P class=""&gt;“&lt;STRONG&gt;When will Y2Q arrive?&lt;/STRONG&gt;” is an omnipresent question in most talks, articles, and recommendations. It’s used for various purposes: sometimes to warn of an imminent risk, sometimes to spark curiosity, and other times to dismiss the threat due to the uncertainty around quantum cryptanalysis progress.&lt;/P&gt;&lt;P class=""&gt;However, &lt;STRONG&gt;this question often creates distraction and uncertainty among decision-makers&lt;/STRONG&gt;. Quantum computing and cryptography are complex subjects, and no one can confidently predict a date. Several hyped forecasts from a few years ago about production-grade quantum computers have not materialized, fueling skepticism.&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Organizations need&lt;/STRONG&gt; &lt;STRONG&gt;facts and certainty&lt;/STRONG&gt;. They must keep their communications secure and interoperable in an increasingly hyperconnected world, which means adopting secure standards.&lt;/P&gt;&lt;HR /&gt;&lt;H3 id="ember59"&gt;Facts beat speculation&lt;/H3&gt;&lt;P class=""&gt;According to &lt;A class="" href="https://csrc.nist.gov/pubs/ir/8547/ipd" target="_self"&gt;NIST IR 8547 (ipd)&lt;/A&gt;, classical public-key cryptography will be &lt;STRONG&gt;disallowed by 2035&lt;/STRONG&gt;, and today’s most common configurations will be &lt;STRONG&gt;deprecated by 2030&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class=""&gt;National security agencies (NSAs) and other bodies around the world are setting similar schedules. So if there’s a global consensus, it’s this:&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Transition critical use cases to PQC by 2030-2031&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Complete migration by 2035&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;That’s as clear, relevant, and broadly agreed upon as it gets. Y2Q isn’t.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;You will not find any more relevant or broadly agreed-upon milestones. Y2Q is not one of them. These official timelines should serve as the foundation for every organization’s migration roadmap.&lt;/P&gt;&lt;P class=""&gt;Everyone has a role to play:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Security agencies&lt;/STRONG&gt; identify threats.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Standardization bodies&lt;/STRONG&gt; define the rules.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Organizations&lt;/STRONG&gt; do business securely and interoperably by following those standards.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Focusing on these dates also strengthens &lt;STRONG&gt;internal sponsorship&lt;/STRONG&gt;. Y2Q frames the issue as a speculative cybersecurity risk; compliance with evolving standards makes it a concrete regulatory requirement, especially vital in regulated industries.&lt;/P&gt;&lt;HR /&gt;&lt;H3 id="ember69"&gt;The two common objections I hear&lt;/H3&gt;&lt;H3 id="ember70"&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt; “What if Y2Q happens earlier?”&lt;/H3&gt;&lt;P class=""&gt;The published timelines are already quite tight. The current issue is that the Y2Q narrative often promotes &lt;EM&gt;crypto-procrastination&lt;/EM&gt;, delaying decisive actions to initiate the transition, due to the lack of concrete milestones and facts. &lt;STRONG&gt;A compliance-driven mindset, by contrast, promotes decisive, measurable progress&lt;/STRONG&gt;. If Y2Q arrives sooner than expected, we can expect the NSAs and standards bodies to update the official milestones.&lt;/P&gt;&lt;H3 id="ember72"&gt;&lt;span class="lia-unicode-emoji" title=":keycap_2:"&gt;2️⃣&lt;/span&gt; “What if Y2Q is delayed — or never comes?”&lt;/H3&gt;&lt;P class=""&gt;This highlights how the Y2Q framing leads to crypto-procrastination. The initial steps of PQC transition are &lt;STRONG&gt;no-regret moves&lt;/STRONG&gt; that strengthen cryptographic management, putting it on par with other cybersecurity practices such as vulnerability management. By starting now, organizations will be better prepared to address vulnerabilities, whether quantum-related or not (such as poorly managed keys or certificates), and will be able to adapt rapidly when necessary.&lt;/P&gt;&lt;HR /&gt;&lt;H3 id="ember74"&gt;The compliance reality&lt;/H3&gt;&lt;P class=""&gt;From a compliance standpoint, crypto-procrastinating is risky. &lt;STRONG&gt;Who would take responsibility for assuming that NSAs and standardization bodies are wrong?&lt;/STRONG&gt; Failing to act on the hope that PQC won’t be needed is hard to justify under current regulations such as&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="" href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202401774" target="_self"&gt;&lt;STRONG&gt;DORA (Art. 6.4 of the RTS)&lt;/STRONG&gt;&lt;/A&gt;, or&lt;/LI&gt;&lt;LI&gt;&lt;A class="" href="https://docs-prv.pcisecuritystandards.org/PCI DSS/Standard/PCI-DSS-v4_0_1.pdf" target="_self"&gt;&lt;STRONG&gt;PCI-DSS (Requirement 12.3.3)&lt;/STRONG&gt;&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;What happens if an organization delays migration for a few years and the quantum-vulnerable cryptography end of life policy stay in place? &lt;STRONG&gt;The costs and risks of a rushed migration, or the reputational damage from maintaining non-compliant cybersecurity practices, can be severe. &lt;/STRONG&gt;Moreover, compliant organizations are unlikely to delay their own transitions simply to maintain backward compatibility with laggards. &lt;STRONG&gt;Betting against established standards could even be existentially risky for a single organization.&lt;/STRONG&gt;&lt;/P&gt;&lt;HR /&gt;&lt;H3 id="ember78"&gt;In summary&lt;/H3&gt;&lt;P class=""&gt;In my view, organizations and the PQC community supporting them should not use Y2Q as the guiding principle for defining transition milestones. That responsibility lies with NSAs and standardization bodies. &lt;STRONG&gt;Organizations must follow standards, not speculation.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;This doesn’t mean they should ignore advances in quantum computing or other cryptanalytic threats, but these developments should &lt;STRONG&gt;inform awareness&lt;/STRONG&gt;, not &lt;STRONG&gt;dictate strategy&lt;/STRONG&gt;. Roadmaps should be grounded in &lt;STRONG&gt;standardization and compliance&lt;/STRONG&gt;, not in hypothetical countdowns.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Source:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.linkedin.com/pulse/why-organizations-should-stop-worrying-y2q-start-jaime-g%C3%B3mez-garc%C3%ADa-5edyf/" target="_blank" rel="noopener"&gt;https://www.linkedin.com/pulse/why-organizations-should-stop-worrying-y2q-start-jaime-g%C3%B3mez-garc%C3%ADa-5edyf/&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Regards&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Caute_Cautim&lt;/P&gt;&lt;HR /&gt;</description>
      <pubDate>Tue, 17 Feb 2026 21:06:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88115#M7746</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-02-17T21:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88121#M7747</link>
      <description>&lt;P&gt;I like the what if it comes sooner/what if it's delayed(or never comes) dichotomy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, if it arrives early then your experiments might get prime time thrust upon them!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it's late or never comes? It probably means we have worse things happening and bigger fish to fry...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 10:08:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88121#M7747</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-02-18T10:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88142#M7748</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;Yes like runaway Agentic AI or Crawdbot....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 19:14:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88142#M7748</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-02-18T19:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88154#M7750</link>
      <description>&lt;P&gt;Yah, though we're also quite capable of doing it through war, civil strife, big space rocks, pandemic and not enough TP etc - I think it's just that scale and impact would be required to effectively stop work on quantum computing, or to make us not care about easy cryptanalysis.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 02:25:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88154#M7750</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-02-19T02:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88160#M7751</link>
      <description>&lt;P&gt;Many moons ago (well not really.....back in 2010s), one of our Physical Security Managers kept talking about a Pandemic and what affect it would have on our environment (discrete manufacturing).......EVERYONE stared at him and snickered (behind his back).......no one was concerned, no one planned, and yet everyone was shocked when it happened.&amp;nbsp; The lesson here is that we should look at everything as a possibility of what might, could, will happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As Security professionals, we need to start planning and agree that there are many things that could affect the way we think/act with quantum.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great write up.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 09:11:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88160#M7751</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2026-02-19T09:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88168#M7752</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is directly about Governance, Architecture, Infrastructure and Trust - we have to get executive buy in, or they may not be executives for their organisations for much longer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main thing this is not about a cryptographic migration, a technical subject - it is Governance from the top, they own it, must own it and must get going.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least those in USA and Europe have until 2035 we only until 2030 here in Australia, New Zealand&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 19:44:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88168#M7752</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-02-19T19:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88179#M7753</link>
      <description>&lt;P&gt;"But, but, but... I just don't have the time!"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interesting continuum I've observed with humans is the ability to argue against doing the correct thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It grows from the bottom...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From not wanting to try to update packages to the latest usually an unholy alliance between developers who don't test their code on N+1/+2 etc, and security 'architects' who would like to evaluate a smaller sample size of platforms and components. the downs stream of this tends to be monumental last gasp upgrades, and customers internal and external running for extensions to exceptions...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...that management then has to sign off on, training them to accept it rather than budget to hire enough/competent engineers...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...which in turn has security leadership fighting against audit and trying to refuse to see things as a risk, because it goes in the RoR and that looks bad for KPIs etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...and the fish rots from the head(fish don't normally do this BTW, just incase any fishmonger seize on the analogy).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not so much the exact same thing, but until 'you/me' become 'we" throughout and everyone is aligned, no stagnant platforms/packages, know laws and standards and make sure you're ready&amp;nbsp; -&amp;nbsp; take it all seriously.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the poster children for this kind of thing would be Yahoo! during Marissa Mayer's tenure as CEO, still my go to poster child for an anatomy of organizational security disaster coming from leadership.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Mistakes were made" and sadly probably will continue to be made ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2026 08:23:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88179#M7753</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-02-20T08:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88251#M7754</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is the stance of an organisation in the Asia-Pacific part of the world, this is a big governance failure.&lt;/P&gt;&lt;P&gt;It is likely that the owners of such organisations will simply go into liquidation both financially and with the associated loss of brand, trust, reputation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not a technical issue, nor is it a crypto-technical migration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The message is simple:&amp;nbsp; Start now, educate staff, executive team and prepare or because of the rapid emerging threats and other sectors around the world, who are actively migrating - they will be left behind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no half way house on this matter, yes you can use hybrid algorithms but don't hide behind the words Quantum-Safe like some very large organisations who are currently "Quantum Washing" directly under the hood.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some nations have gone down the hybrid approach, but others have stuck to the NIST standards - China has its own set of standards and has gone on its pathway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you cannot protect your organisations critical data, which must be protected for the next five years, you have a problem, and are likely to have privacy legislation hounding you or international compliance regulations which are stepping up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everyone is running out of time - adoption and migration is directive from the top of the organisation.&lt;/P&gt;&lt;P&gt;Failure will only ensue if, you commence from the bottom up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 05:20:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88251#M7754</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-02-23T05:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88555#M7780</link>
      <description>&lt;P&gt;Unfortunately, I think it's just human nature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless the checks and balances are in place there will be backsliding, it behooves us all to point it out gently, but firmly and help things improve. Failures, and their modes can start from the top down, or the bottom up and quite often in the middle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen some incredibly good organizations, and some that are striving to improve, but these problems are not really about cryptography, or quantum cryptanalysis or even a particular geographical region, they are ubiquitous.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To misappropriate a proverb:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The price of peace (and quiet), is eternal vigilance..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Calm and resolute counsel is a must:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"This is coming, that's the problem, here's what you can do, constant automated scanning to the latest and grates, vulnerability passement, pen testing, advisory at the start, attestation against standards, internal audit helped us to find, external audit had something we must correct, the regulator requires this be fixed(or will if it's not done)."&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2026 02:09:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88555#M7780</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-09T02:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88622#M7784</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have far more problems coming - see my next message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 23:38:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88622#M7784</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-03-11T23:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88628#M7786</link>
      <description>&lt;P&gt;Plus Ca Changes...&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 00:29:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88628#M7786</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-12T00:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88632#M7790</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15 March 2026 is nearly upon us - certificates lifespan reduces to 200 days from 398 days.&lt;/P&gt;&lt;P&gt;DNSSEC for External CA's mandated and Domain Validation Control (DCV).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLM is regulatory and compliance issue - using open-source using ACME protocol will not provide evidence based information required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 03:55:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88632#M7790</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-03-12T03:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why organizations should stop worrying about Y2Q and start focusing on compliance</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88634#M7792</link>
      <description>Yeah what I meant though was “The more things, change the more they stay the same.”&lt;BR /&gt;&lt;BR /&gt;It’s a general pattern of neglect - “it’s all good fun till someone looses an eye…”&lt;BR /&gt;&lt;BR /&gt;People and organisations often wait and see until it’s too late.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Mar 2026 03:58:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-organizations-should-stop-worrying-about-Y2Q-and-start/m-p/88634#M7792</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-12T03:58:26Z</dc:date>
    </item>
  </channel>
</rss>

