Prioritising post-quantum cryptography migration activities in financial services


As post-quantum cryptography (PQC) becomes integrated into mainstream information technology (IT) products and services, financial services institutions must begin to execute their transition strategies.

This document provides actionable guidelines to incorporate quantum safety into existing risk management frameworks by assessing the ‘Migration Priority’ based on the ‘Quantum Risk’ and ‘Migration Time’ of business use cases and highlighting opportunities for immediate execution. A critical first step is to inventory all business use cases that rely on public key cryptography.

Read more…
Source: Europol


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Health Care Data of 2 Million People in Mexico Exposed Online

    August 7, 2018

    A MongoDB database was exposed online that contained health care information for 2 million patients in Mexico. This data included information such as the person’s full name, gender, date of birth, insurance information, disability status, and home address. The database was discovered by security researcher Bob Diachenko via Shodan, which is a search engine for all Internet connected devices and not just web ...

  • Salesforce.com Warns Marketing Customers of Data Leakage SNAFU

    August 3, 2018

    Potentially impacted customers include organizations like Aldo, Dunkin Donuts, GE, HauteLook, Nestle Waters, News Corp Australia and Sony. Cloud behemoth Salesforce.com is warning customers about an API error that may have leaked data for some users of its Marketing Cloud offering. The issue was in play between June 4 to July 18, according to an alert that ...

  • Thousands of U.S. Voter Personal Records Leaked by Robocall Firm

    July 18, 2018

    The information was exposed on a public Amazon S3 bucket by a Virginia-based political campaign and robocalling company. Researchers have discovered yet another misconfigured repository bucket – this time leaking the information of U.S. voters. The information was exposed on a public Amazon S3 bucket by a Virginia-based political campaign and robocalling company called Robocent. Kromtech Security researchers, ...

  • Data Regulators See Spike In GDPR Complaints

    July 2, 2018

    Companies are seeing a sharp spike in requests for information on how their data is collected and processed following the introduction of the General Data Protection Regulation (GDPR) across Europe a month ago, with many requesting extensions to the legal deadline for their replies. The regulation has also shaken up the online advertising business, with some adtech firms ...

  • UK Tax Agency Collects 5.1M Biometric Voice IDs, May Violate GDPR

    June 24, 2018

    Her Majesty’s Revenue and Customs (HMRC) in the UK is under investigation by that country’s regulator over the collection of more than 5 million biometric voice IDs. The Information Commissioner’s Office (ICO) is investigating the tax agency’s practice, which may violate the recently implemented General Data Protection Regulation, following an official complaint from watchdog group Big ...

  • GDPR: US news sites blocked to EU users over data protection rules

    May 25, 2018

    A number of high-profile US news websites are temporarily unavailable in Europe after new European Union rules on data protection came into effect. The Chicago Tribune and LA Times were among those posting messages saying they were currently unavailable in most European countries. The General Data Protection Regulation (GDPR) gives EU citizens more rights over how their ...