<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A case study in Quantum Washing in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85900#M5229</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;Well in critical infrastructure, it is even more important given encryption standards will be changing.&amp;nbsp; More emphasis on the actual equipment vendors themselves to prepare.&amp;nbsp; In Australia we have the SOCI Act, all critical infrastructure must migrate to PQC by 2030 this is mandated.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You best way forward is to do a discovery, risk assessment on current systems - what is likely to at risk, and what the impact is likely to be, and then commence preparing a budget with management to resolve it.&amp;nbsp; In UK, they have similar mandates, along side USA, and Europe.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is going to be embedded electronics, IoT, IoMT systems, four years appears to be a long run way, it is not.&amp;nbsp; Prepare now, discovery, risk management and ensure management is educated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure you have a record, that you did raise it as a problem, they ignore at their own risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Nov 2025 02:59:22 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2025-11-27T02:59:22Z</dc:date>
    <item>
      <title>A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85840#M5222</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently China released a piece on their new Quantum Chip. It is not, read this case study in Quantum Washing, which are becoming more prevalent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://postquantum.com/industry-news/chinese-photonic-quantum-chip/" target="_blank"&gt;https://postquantum.com/industry-news/chinese-photonic-quantum-chip/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 05:06:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85840#M5222</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-11-25T05:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85841#M5223</link>
      <description>&lt;P&gt;I have to admit I have never heard of Quantum Washing in the context of Cybersecurity.&amp;nbsp; Is this real or is the author renaming Quantum-safe Crypto?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 06:36:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85841#M5223</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-11-25T06:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85856#M5224</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The author is pointing out the amount of hype being generated by various other authors and countries such as China.&amp;nbsp; &amp;nbsp;It is not a real, established scientific or professional term. It relates to the misuse of the word "quantum" as a buzzword in pseudoscience, marketing and pop culture.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Often the Chinese in particular within their Universities have made claims, but when scruntinised have found to be false and misleading.&amp;nbsp; There is a significant amount of "Hype" being generated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The application of quantum principles is a complex and ongoing area of research, but is often cited with fantastic or magical concepts.&amp;nbsp; &amp;nbsp;So we have to be on the ball so to speak, to realise - trust but verify again, on exactly what their claim is.&amp;nbsp; Hence the term "Quantum Washing" to illustrate the growing and expanding amount of exaggeration within this fast moving world of Quantum Computing, Mechanics.&amp;nbsp; &amp;nbsp;It illustrates unsubstantiated claims are being made, which are growing rapidly rather like automated advanced attacks via AI tools.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 23:39:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85856#M5224</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-11-25T23:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85867#M5226</link>
      <description>&lt;P&gt;Thanks John,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately there are too many folks (countries) that stretch the truth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only have a beginner's knowledge of quantum and at this point in my career have no interest in gaining more.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the explanation, it truly helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2025 10:10:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85867#M5226</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-11-26T10:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85889#M5227</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well I forecast about five years from now, you will be changing your current system to a Quantum Computer, Quantum Networking and Post Quantum Cryptography will be abound.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some good "free" courses on IBM Skills build (&lt;A href="https://skillsbuild.org/" target="_blank"&gt;https://skillsbuild.org/&lt;/A&gt;) great courses with practical examples, with good certificates via Credibly etc.&amp;nbsp; &amp;nbsp;Well Recommended - if you change your mind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is coming, and it will affect us all no matter how senior or young you are&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep developing..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2025 19:13:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85889#M5227</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-11-26T19:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85899#M5228</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;Happy to say that I will be taking down my shingle soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I realise that Quantum is the way of the future however not sure how Quantum will fit into a manufacturing environment where we cannot even patch.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the link to the course, I will spend sometime going through them&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 02:52:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85899#M5228</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-11-27T02:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85900#M5229</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;Well in critical infrastructure, it is even more important given encryption standards will be changing.&amp;nbsp; More emphasis on the actual equipment vendors themselves to prepare.&amp;nbsp; In Australia we have the SOCI Act, all critical infrastructure must migrate to PQC by 2030 this is mandated.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You best way forward is to do a discovery, risk assessment on current systems - what is likely to at risk, and what the impact is likely to be, and then commence preparing a budget with management to resolve it.&amp;nbsp; In UK, they have similar mandates, along side USA, and Europe.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is going to be embedded electronics, IoT, IoMT systems, four years appears to be a long run way, it is not.&amp;nbsp; Prepare now, discovery, risk management and ensure management is educated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure you have a record, that you did raise it as a problem, they ignore at their own risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 02:59:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85900#M5229</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-11-27T02:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85918#M5231</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;We already have a risk manifest with all systems classified along with the impacts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that some discrete manufacturers will have an issue upgrading some systems......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have all systems classified in terms of risk, exposure, etc and can see issues in trying to comply to any "law' that states we must move to PQC by 2030,&amp;nbsp; I do not think these folks have taken a serious look at what they are asking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;some systems will be straight forward, but other systems such as physical sensors or actuators, etc might require a total retrofit of a production line which could cost in the millions/billions&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not having seen the laws, it is difficult to see how this might affect those systems.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Canada, new&amp;nbsp;&lt;SPAN class=""&gt;laws (part of Bill C-8) the&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class=""&gt;Critical Cyber Systems Protection Act&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(CCSPA) &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;as well as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;existing guidance from the Canadian Centre for Cyber Security&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.darktrace.com/blog/understanding-the-canadian-critical-cyber-systems-protection-act" target="_blank" rel="noopener"&gt;https://www.darktrace.com/blog/understanding-the-canadian-critical-cyber-systems-protection-act&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 18:20:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85918#M5231</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-11-27T18:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: A case study in Quantum Washing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85919#M5232</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other one, which I have reported previously on is the CA &amp;amp; Browser Forum mandate to shift:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External Certificates from 398 days expiration to 200 days commencing 15 March 2026&lt;/P&gt;&lt;P&gt;15 March 2027 expiration 100 days&lt;/P&gt;&lt;P&gt;15 March 2029 to 47 days&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Domain Certificate Validation (DCV) 15 March 2026 to every 200 days&amp;nbsp;&lt;/P&gt;&lt;P&gt;DCV 15 March 2027 to every 100 days&lt;/P&gt;&lt;P&gt;DCV 15 March 2029 to every 10 days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above required Crypto-Agility for the forth coming PQC revolution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Been doing a lot of risk assessment, financial assessment on the issues and penalties.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy to share my findings privately, if required to justify the rationale, as doing the same here with others too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One need automation and a full Certificate Lifecycle Management (CLM) at CMM Maturity Level 4 to cope, Level 5 is required for Crypto Agility.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition within your risk register record the current specific cryptographic algorithms and mode being used - ideally you need a Cryptographic Bill of Materials similar to a SBOM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 19:46:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/A-case-study-in-Quantum-Washing/m-p/85919#M5232</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-11-27T19:46:24Z</dc:date>
    </item>
  </channel>
</rss>

