Prioritising post-quantum cryptography migration activities in financial services


As post-quantum cryptography (PQC) becomes integrated into mainstream information technology (IT) products and services, financial services institutions must begin to execute their transition strategies.

This document provides actionable guidelines to incorporate quantum safety into existing risk management frameworks by assessing the ‘Migration Priority’ based on the ‘Quantum Risk’ and ‘Migration Time’ of business use cases and highlighting opportunities for immediate execution. A critical first step is to inventory all business use cases that rely on public key cryptography.

Read more…
Source: Europol


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • The Cybersecurity 202: The U.S. needs a law that requires companies to disclose data breaches quickly, cybersecurity experts say

    October 15, 2018

    A slight majority of digital security experts surveyed by The Cybersecurity 202 say the United States should follow in the European Union’s footsteps and pass a law that requires companies to disclose data breaches quickly. Europe’s General Data Protection Regulation requires companies with customers in the E.U. to notify regulators of a breach within 72 hours or face a severe ...

  • Up to 35 Million 2018 Voter Records For Sale on Hacking Forum

    October 15, 2018

    Just weeks before the midterms, voter information from 19 states has turned up on the Dark Web. Up to 35 million voter records have been found up for sale on a popular hacking forum from 19 states, researchers discovered. Researchers at Anomali Labs and Intel 471 on Monday said that they discovered Dark Web communications offering a ...

  • Heathrow Fined £120,000 Over Lost USB Stick

    October 9, 2018

    The unencrypted stick, containing personal data on staff, was found by a member of the public before being handed in to a national newspaper Heathrow Airport said it has begun a company-wide data security training programme after the Information Commissioner’s Office (ICO) fined it £120,000 over an embarrassing data breach last year. The ICO said an unencrypted ...

  • French police officer caught selling confidential police data on the dark web

    October 3, 2018

    A French police officer has been charged and arrested last week for selling confidential data on the dark web in exchange for Bitcoin. The officer worked for Direction Générale de la Sécurité Intérieure (DGSI, translated to General Directorate for Internal Security), a French intelligence agency charged with counter-espionage, counter-terrorism, countering cybercrime and surveillance of potentially threatening ...

  • Boffin: Dump hardware number generators for encryption and instead look within

    October 1, 2018

    Hardware-based random number generators (HWRNGs) for encryption could be superseded after a Philippines-based researcher found that side-channel measurement of the timing of CPU operations provide enough entropy to seed crypto systems with the necessary randomness. In a paper presented on Saturday at the International Conference on Innovative Research in Science, Technology and Management (ICIRSTM) in Singapore, JV Roig, ...

  • UK Conservative Party conference app leaks MPs’ personal details

    September 29, 2018

    A mobile conferencing app developed for the UK’s Conservative Party leaked the private details of people who registered to attend party conferences, including the details of party members and UK government officials. The leak was discovered on Saturday afternoon, September 29, by Guardian columnist Dawn Foster who posted her findings on Twitter.  Foster discovered that anyone who ...