<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PQC:  This is a Crane Crash in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88670#M7798</link>
    <description>&lt;P&gt;"But for a ha'peth of tar the roof was ruined."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Sigh*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The standards bodies need to work better, faster and more co-operatively. Though I feel minds and attentions are focused elsewhere at the moment...&lt;/P&gt;</description>
    <pubDate>Sat, 14 Mar 2026 14:20:26 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2026-03-14T14:20:26Z</dc:date>
    <item>
      <title>PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88623#M7785</link>
      <description>&lt;P&gt;HI All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, its Post Quantum Cryptography - look at the attachment and digest the current state of the world.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;This is a global shift in cryptography with no coordination, no shared timeline, and no agreement on what “done” even looks like.&lt;BR /&gt;&lt;BR /&gt;Different countries are moving at completely different speeds under different mandates, with no mechanism to reconcile any of it.&lt;BR /&gt;&lt;BR /&gt;Some are enforcing 2025–2026 deadlines. Others are pushing into the 2030s. Many haven’t even started.&lt;BR /&gt;&lt;BR /&gt;And yet the systems we run, the data we move, and the vendors we depend on operate across all of them at the same time.&lt;BR /&gt;&lt;BR /&gt;The cryptography protecting global data flows is about to be governed by timelines that are years apart.&lt;BR /&gt;&lt;BR /&gt;In some cases, more than a decade.&lt;BR /&gt;&lt;BR /&gt;And it’s not just timing.&lt;BR /&gt;&lt;BR /&gt;There is no consistent view of what PQC actually is.&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt; Definitions vary by country&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_2:"&gt;2️⃣&lt;/span&gt;&amp;nbsp;Interpretations vary by regulator&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_3:"&gt;3️⃣&lt;/span&gt; Implementations vary by vendor&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_4:"&gt;4️⃣&lt;/span&gt; Validation approaches are not aligned&lt;BR /&gt;&lt;BR /&gt;This is incompatibility built into the system.&lt;BR /&gt;At the same time, quantum-washing is accelerating.&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_5:"&gt;5️⃣&lt;/span&gt; Vendors are relabeling existing capabilities&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_6:"&gt;6️⃣&lt;/span&gt; Claims are getting ahead of standards&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_7:"&gt;7️⃣&lt;/span&gt; “Quantum-safe” is being used without consistency&lt;BR /&gt;&lt;BR /&gt;THIS IS OUR OPINION&lt;BR /&gt;This is a shambles.&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_8:"&gt;8️⃣&lt;/span&gt; No one is controlling the global picture&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_9:"&gt;9️⃣&lt;/span&gt; No one is accountable across borders&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_10:"&gt;🔟&lt;/span&gt; No one is resolving this operationally&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt; No one is forcing convergence&lt;BR /&gt;&lt;BR /&gt;So the outcome is not hard to see.&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_2:"&gt;2️⃣&lt;/span&gt; Fast jurisdictions inherit slower ones&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_3:"&gt;3️⃣&lt;/span&gt; Third-party risk becomes your exposure&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_4:"&gt;4️⃣&lt;/span&gt; Cross-region requirements conflict&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_5:"&gt;5️⃣&lt;/span&gt; Waiting for alignment puts you behind&lt;BR /&gt;&lt;BR /&gt;This doesn’t fail cleanly.&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_6:"&gt;6️⃣&lt;/span&gt; Controls stop being recognised&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_7:"&gt;7️⃣&lt;/span&gt; Vendors fail requirements overnight&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":keycap_1:"&gt;1️⃣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":keycap_8:"&gt;8️⃣&lt;/span&gt; Assessments vary by jurisdiction&lt;BR /&gt;&lt;BR /&gt;And you cannot rely on market claims.&lt;BR /&gt;&lt;BR /&gt;That is the failure mode.&lt;BR /&gt;Nothing is coming to fix it in time.&lt;BR /&gt;&lt;BR /&gt;If your strategy assumes alignment or a clean rollout, it is already out of step with reality.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Thanks to Brian C&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;A href="https://www.linkedin.com/posts/bcouzens_pqc-data-caveat-activity-7434157806317920257-rK8i?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAABDJOQBQQrvUEu9Tk813CQtgtvZWdr_eDo" target="_blank" rel="noopener"&gt;https://www.linkedin.com/posts/bcouzens_pqc-data-caveat-activity-7434157806317920257-rK8i?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAABDJOQBQQrvUEu9Tk813CQtgtvZWdr_eDo&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Read, Digest and Understand the current status.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 23:44:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88623#M7785</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-03-11T23:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88629#M7787</link>
      <description>&lt;P&gt;Well, at least there is a nice infographic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This kind of flips things back to a lot of countries waiting for a compelling event.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Until then - likely Vendors will do what they do - when, why and how TBC. I suspect that Chrome will be the lead horse here.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 02:38:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88629#M7787</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-12T02:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88630#M7788</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This goes back to Quantum Washing - fibbing/marketing if you like.&amp;nbsp; Browsers will cover PQC TLS 1.3 but going down the line of hybrid or under bonnet using RSA or ECC will be using a hybrid approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even CloudFlare made announcements but actually they were fibbing too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Chinese have created their algorithms, perhaps they want to remain private rather than interoperate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is rather like COVID for cryptography, some take the regular injections and other suffer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 03:51:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88630#M7788</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-03-12T03:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88631#M7789</link>
      <description>I mean that’s marketing for you, some of the markitecture will be breathtaking…&lt;BR /&gt;&lt;BR /&gt;Security by obscurity isn’t great, but you increase work rates and one think that’s always bothered me is really who has the quickest and best cryptanalysts? Pretty sure they’re not on Reddit etc..&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Mar 2026 03:55:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88631#M7789</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-12T03:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88633#M7791</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A lot of harm will be caused, quantum washing is the best term of effectively putting in place hybrid approach using traditional PKI algorithms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 03:57:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88633#M7791</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-03-12T03:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88635#M7793</link>
      <description>Yeah, I don’t disagree.&lt;BR /&gt;&lt;BR /&gt;However I think your infographic proves the point. And illustrates the problem, few will act until they see the impact, and but then it’s often too late.</description>
      <pubDate>Thu, 12 Mar 2026 04:02:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88635#M7793</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-12T04:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88642#M7796</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem being there is no universal or overarching approach or universal standard that all countries have to adopt in order to work or collaborate with each other.&amp;nbsp; This could cause major issues in the coming years unless an overall governing body rules over the top - imagine the effect on Financial Markets if one cannot trade due to interoperability issues or having to go through translation gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 20:13:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88642#M7796</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2026-03-12T20:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: PQC:  This is a Crane Crash</title>
      <link>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88670#M7798</link>
      <description>&lt;P&gt;"But for a ha'peth of tar the roof was ruined."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Sigh*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The standards bodies need to work better, faster and more co-operatively. Though I feel minds and attentions are focused elsewhere at the moment...&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2026 14:20:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PQC-This-is-a-Crane-Crash/m-p/88670#M7798</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2026-03-14T14:20:26Z</dc:date>
    </item>
  </channel>
</rss>

