Understanding the Quantum Threat
As companies navigate the transition towards post-quantum cryptography (PQC), recent research from Axiad sheds light on a worrying disparity between perceived confidence and actual preparedness among enterprises.
Axiad, a leader in identity security, conducted a survey among 315 security and IT leaders across the United States. Although the results indicate that a significant majority of organizations believe they are on top of their cryptographic inventory, there is a stark reality that contradicts these claims.
76% of those surveyed confirmed that their organization maintains a continuously updated list of cryptographic assets. However, nearly half (46%) did not have a designated leader for PQC migration. Moreover, 51% admitted they have never evaluated whether their public-facing systems support post-quantum key exchange. This inconsistency reflects a larger issue where confidence levels among executive leaders greatly outpace tangible actions taken at the operational level.
The Confidence vs. Reality Gap
The survey revealed that seniority within an organization correlates directly with the perceived readiness for PQC. For example, 90% of Chief Information Security Officers (CISOs) articulated confidence in their cryptographic management practices, whereas only 33% of security architects and PKI engineers shared this sentiment. This discrepancy raises serious questions about the ground-level realities faced by those directly managing cryptographic assets.
David Canellos, CEO of Axiad, remarked, “PQC readiness cannot be based on what an organization believes it has under control. It has to be based on what it can actually see, verify, and act on.” He pointed out that assumptions about knowledge regarding cryptographic assets often crumble in the face of specific inquiries about ownership and testing practices. The significance of establishing transparent visibility into these assets is crucial as the world shifts towards post-quantum solutions.
Awareness Versus Action
The research underscores a concerning trend: while awareness of issues like 'harvesting' cryptographic keys for later decryption has spread widely—67% ranking it as a top priority—actual initiatives to address these vulnerabilities are lacking. A third of the respondents reported no concrete actions had been taken, with many stating they were waiting for clearer regulatory frameworks.
Key observations from the study include:
- - 25% of organizations have either outdated or incomplete cryptographic inventories.
- - 22% acknowledged contradictions in their claims regarding PQC readiness.
- - 42% indicated that competing security priorities are a major roadblock, and budget constraints are highlighted by 36% as an ongoing challenge.
Interestingly, even among the subset of organizations that profess meeting all critical readiness markers, nearly half struggle due to conflicting priorities and financial limitations. This variance underlines that PQC migration is not solely a technical undertaking; it represents operational challenges intertwined with identity management.
Moving Towards True Readiness
Successful transition towards PQC involves more than merely knowing where cryptographic materials exist. Companies need to establish clear ownership across assets and correlate each asset to what it protects. Such frameworks will allow firms to navigate the multi-faceted landscape of cryptographic risks. Identifying what matters first, understanding ownership, and managing transitions without service disruptions is imperative.
Organizations can enhance their preparation by utilizing Axiad's PQC Readiness Tester, which assesses existing infrastructure to determine support for post-quantum key exchange protocols. Axiad’s full report on PQC confidence gaps provides invaluable insights to guide enterprises towards actionable preparedness in a rapidly evolving digital ecosystem.
For further assistance, organizations can find the complete report
here and evaluate their current infrastructure using Axiad's PQC tools at quantum.axiad.io.