industry · quantum risk
Is Shared responsibility Quantum Proof? Industry Quantum Risk
Verdict
Shared responsibility models are not quantum-proof controls. They assign who must migrate which algorithms—diagram ownership for TLS, KMS, and identity explicitly.
Overview
Providers secure the cloud; customers secure in the cloud. PQC work appears on both sides of that line.
Write RACI for crypto inventory or it will not happen.
Cryptographic profile
- Signatures: Provider control-plane TLS, Customer app TLS and keys
- Hash: N/A
- Public-key exposure: Mis-assigned ownership leaves classical crypto unowned.
- Vertical: cloud
What breaks
- No owner for customer-managed certificates
- Blind trust in provider defaults
- Identity federation left out of cloud reviews
Mitigations
- RACI for keys, certs, and IdP
- Contractual crypto transparency
- Annual joint review with major providers
FAQ
Related?
/industries/cloud and cloud-kms
SaaS?
/industries/cloud/saas-tenants
Key concepts (technical dictionary)
Terms used on this page — open a definition: