The potential benefits of quantum computing are profound — as are the threats. The point at which the quantum threat becomes real is known as Q-Day, with the availability of a quantum computer powerful enough to break the cryptographic systems that secure data and communications in our digital economies and societies. Public safety organizations will be among the first tested in the quantum era as criminals and state-sponsored attackers look to steal sensitive data, disrupt critical infrastructure and communication networks and undermine national security.
To protect against these outcomes, government agencies, defense organizations, emergency response services and others in public safety must address their quantum vulnerabilities ahead of Q-Day. The best way to start is by creating a quantum security blueprint — a “quantum playbook” — that will help navigate the complexities of this threat.
A Guide for the Quantum Era
The purpose of a quantum playbook is to guide organizations as they look to leverage the benefits of quantum computing while protecting against its threats. It can help organizations develop strategies, implement quantum-safe technologies and train personnel on related issues.
A quantum playbook must be comprehensive to be effective, including risk assessment, cryptographic transition plans, training and awareness programs, incident response plans, collaboration frameworks and regulatory compliance measures. That might sound like a lot to cover. It is. Fortunately, organizations don’t have to start from zero. Existing cybersecurity frameworks can be adapted to include quantum-specific considerations, a process that might involve conducting gap analyses, engaging stakeholders and running pilot programs.
Other frameworks that can serve as models when preparing for quantum-driven disruptions include directives from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the EU Digital Operational Resilience Act (DORA).
Applying Key Principles for Quantum Security
In collaboration with the National Security Agency (NSA) and the National Institute of Standards and Technology (NIST), CISA has issued directives to help public sector organizations prepare for the quantum era. These directives emphasize the importance of developing a quantum-readiness roadmap to guide the transition to quantum-safe cryptographic standards. Key steps include conducting a thorough inventory of current cryptographic systems and evaluating the potential impacts of quantum computing on them, working with technology vendors to ensure their products support quantum-safe cryptographic algorithms and assessing reliance on quantum-vulnerable cryptography within the supply chain.
CISA urges organizations to plan their migrations to quantum-safe cryptographic standards early by conducting inventories with the help of automated tools and performing detailed risk assessments. The directive also calls for collaboration among public sector organizations, including sharing best practices and engaging with industry partners to stay updated on the latest developments in quantum security.
While targeted at enhancing digital operational resilience within the EU’s financial sector, DORA is a valuable model for any industry preparing for quantum-driven disruptions. It requires financial entities to implement robust information and communications technology (ICT) risk management frameworks, report major ICT-related incidents to authorities, manage risks associated with third-party ICT service providers and conduct regular resilience testing. Similar to CISA’s directive, DORA promotes the sharing of cyber threat intelligence across the sector as well as with authorities.
Adopting the principles in the CISA and DORA directives will help organizations cover many aspects of digital resilience but may not fully address the unique needs of public safety. These gaps can be filled by developing sector-specific guidelines, enhancing collaboration and providing advanced training for public safety personnel on quantum threats and mitigation strategies.
Defense-in-Depth for Quantum Threats
Another element that must be included in a quantum playbook is a defense-in-depth strategy, which should include the following concepts:
- Crypto resilience – Adopting different types of quantum-resistant cryptographic technologies so if one type is compromised, there’s another layer of protection in place.
- Crypto agility – Being able to switch between cryptographic algorithms and protocols without significant disruption.
- Layered network cryptography – Applying layers of network cryptographic protection across different levels of the network to complement application-layer cryptography.
By incorporating these concepts, public safety organizations can enhance their defense against both current and future threats, including those posed by quantum computing.
Navigating the Quantum Era
As quantum computing evolves, public safety organizations must proactively address the associated risks. A comprehensive quantum playbook, based on frameworks like the CISA and DORA directives and combined with a robust defense-in-depth strategy, will ensure organizations are well prepared. Continuous improvement will also be key to building a resilient defense, which requires staying informed of new developments in quantum technology and the latest threats.
Importantly, a quantum playbook isn’t something public safety sector organizations need to create alone or should. Collaboration with others in the sector — and with experts in quantum-safe network solutions like Nokia — will help organizations face the challenges of the quantum era and embrace its opportunities.
The author, Steve Vogelsang, is CTO for its Federal Division at Nokia.