tech · quantum risk
Is Risk committee quantum Quantum Proof? Cyber Program & PQC
Verdict
Risk committees should track cryptography migration as a multi-year risk with KRIs (inventory coverage, hybrid %, critical vendor roadmaps)—not a single IT project checkbox.
Overview
Deeper than the board one-pager: scenarios (HNDL on archives, forged identity, payment signing), residual risk acceptance, and exception budgets.
Program inventory focus: Unowned crypto risk falls between cyber and technology committees. Typical classical surfaces: KRIs for crypto migration. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: KRIs for crypto migration
- Hash: N/A
- Public-key exposure: Unowned crypto risk falls between cyber and technology committees.
What breaks
- No KRI
- Infinite exceptions for classical-only systems
Mitigations
- Quarterly crypto risk dashboard
- Exception time-bounds
- Internal audit sampling of inventory
FAQ
Cyber insurance angle?
See insurance page; still verify with brokers—educational only.
Model CRQC year?
Use ranges and data shelf life; avoid false precision.
Key concepts (technical dictionary)
Terms used on this page — open a definition: