Q-Day Is Closer Than You Think — Is Your Business Ready?
Dr. Colin Soutar, Managing Director and Global Quantum Cyber Readiness Leader at Deloitte, joins Alan Shimel, Founder, CEO & Editor-in-Chief of Techstrong Group, on Techstrong TV to discuss why businesses must start their post-quantum cryptography transition now. With Q-Day predictions ranging from 2028 to 2030 and NIST’s post-quantum standards already published, the roadmap exists — but most organizations haven’t started yet. Colin explains why the erosion of mutual authentication is the real quantum threat, why cryptographic governance matters, and how to identify your most critical assets for the transition.
Transcript
Hey everyone, welcome back here to Techstrong TV. I want to introduce you to our next guest. His name is Colin Suter.
Colin is the Global Quantum Cyber Readiness Leader at Deloitte, and he was one of our initial Quantum Security 25 list members. I was going to say nominees, but we actually announced the finalists, the winners, and he was one of the list members. So you can bet he probably knows a thing or two about quantum, and we're going to talk to him about it.
Let's welcome him first. Hey, Colin, welcome to Techstrong TV. Thank you, Alan.
Thanks for having me here. It's my pleasure. Colin, before we jump into quantum and what Deloitte is doing with quantum and everything else, let's hear a little bit about your journey to quantum, if you will.
Yeah. Interesting. So I started off in emerging technology in biometrics way back in the mid-'90s.
I did a two-year postdoc at NASA, and then started with a company, ended up being called BioScript, out of Toronto, Canada. And we were one of the early pioneers of biometrics. And so I saw the interaction between such emerging tech, potential regulations, how public reacts to it, and so on, firsthand.
In fact, after the tragic events of 9/11, I helped NIST, the National Institute of Standards and Technologies, to develop national and international standards for biometrics. So I've sort of watched emerging tech evolve before, in the backdrop of frameworks, regulations, standards, and so on. So about six years ago, when Deloitte started looking at the topic of quantum, both sides of the quantum coin, we would say, the use cases and the applications of quantum, as well as the cyber implications, which I lead globally.
We started looking at that, and it was a good choice for me then to lead that, given that background. And so, I've been doing that for the last six years, as I mentioned. Excellent.
That's interesting, right? From emerging tech to, well, and quantum may be the ultimate emerging tech, as we say. Colin, a lot of people look at Deloitte and say, "Okay, they're advising the biggest companies in the world.
Deloitte does a lot of things, but what have they got to do with quantum? " Well, like I mentioned, there's the two sides of the quantum coin, right? There's the applications, simulation and modeling.
My colleague, Scott Buchholz, has been leading that for the same time as I have, and we've worked together very closely. So he's looking at those applications of the quantum computer. And that helps our global clients align on how to get value out of quantum computers.
And in fact, they're getting value out of modeling techniques that are sort of quantum-like or using quantum thinking. In other words, based on the physics that quantum computers will operate under. And they're already seeing some benefits there in terms of efficiency of algorithms.
On the other side, we are concerned that our clients, especially global clients, but all of our clients, are able to essentially put the cyber risk aspect to bed and not have to worry about it in the long term. Really what we're talking about, the good news is to mitigate the threat of a cryptanalytically relevant quantum computer being able to break asymmetric cryptography. We're looking at the mitigation being a classical algorithm, essentially.
It runs on a normal machine, right? It runs on a classical computer. And those have been out, as I'm sure you're aware, for almost two years now.
It's August 13th, I think, 2024. And so we are trying to help our clients navigate that transition in a fairly straightforward way with all the different dynamics that are going on around third parties, supply chain, all the steps that they have to take, and so on. Ten years from now, we want our clients to look back and say, "Well, we dealt with the cyber risk aspects and things were fine there.
We're still interoperable with all of the business partners that we need to be. " So those are the main reasons that Deloitte is looking to drive this industry forward. Absolutely.
And at some level, though, you've got to think that, hey, Deloitte is a company that other companies and organizations and governments and everyone else looks to for thought leadership, for guidance, right? It's a big part of the business. And you would almost be negligent at some level at this stage of the game not to have your eye on the quantum prize, so to speak, and on the market and what's going on.
Speaking of the prize, I mentioned you were one of the initial Quantum Security 25 list members. And I don't pretend to be an expert in quantum security or anything quantum. Maybe it'd be very quantum of me to say I both pretend to be and don't pretend to be.
But in any event Looking at the list, it was certainly chock-full of a lot of distinguished folks who have made their mark in this industry, some because of their technical expertise, some because of their business expertise, some both. But really, the idea behind the list was to call out the fact that, hey, this is no longer a five to 10-year-out thing. " And then five years later, well, it's still five to 10 years out.
It's like nuclear fusion has been like this my whole life, too. The idea of harnessing the power of the sun to cure our, solve our energy needs and so forth. It's always five to 10 years out.
But now it looks like we're not in that five to 10 years out. Q-day, the proverbial Q-day, as they call it, might be within our grasp. There are several organizations, more than one, saying '28, '29, certainly by 2030, we will have achieved Q-day.
So where do you sit on that divide, Colin? What do you think? Well, there's a few things in there, so let me unpack that just a little bit.
First and foremost, on your introduction there around a firm like Deloitte and doing the right thing. It's actually something that stuck with me as I've traveled around and talked to different CISOs of large organizations, a lot of financial institutions, and try to help them through this journey. " Because, this was four years ago or so, and even at that point, there were still a lot of people that were saying, "Maybe this doesn't ever happen.
" But we, as an organization, had enough concern to say, "No, we need to try and get some messaging out there that is coherent, candid, non-calamitous. " And so we are trying to do that and have been trying to do that for the last six years or so. In terms of dates and predictions, I think we've been consistent throughout the journey that we've had in saying that it's less about a date, and it's more about making sure that one is prepared for when this threat materializes.
And I personally think that there's been a little bit of over-fixation, over-indexing by industry on harvest now, decrypt later. I'm not saying that it's not a real threat, but I think where it gravitates people's minds to is more around the confidentiality of data and personal information, of course, is very private. We want to retain that privacy.
But at the end of the day, the actual impact that a cryptoanalytically relevant quantum computer would have on commerce and business operations is that every single point of mutual authentication where devices come together, people come together, all of the online communications that we do, that will be eroded. The bedrock of trust that we have in that, that is going to be a huge implication. And so you think about that.
When is that going to happen? What's the probability it's going to happen? And you look to experts like Michele Mosca, and by the way, I feel very blessed to be on the same list as people like Michele in terms of the top, so thank you very much for that honor.
It really was a privilege. You look at the predictions that he's working with different experts around the world. In fact, they published in the report that came out, I think it was at the tail end of last year, and he just briefed on it at a conference.
There was actually less variability as time went forward as people think. " But in actual fact, if you look at the predictions that were made every time, there's a reasonable alignment in terms of when they thought that was going to happen. And so at the end of the day, what I say to our clients is, if there's a finite probability that this is going to happen in the next five to 10 years, and you can pick whatever that probability is, 50%, 100%, 10%, the impact is so significant that you want to make sure that you're well prepared.
And whether it's going to take five, 10 years to do the upgrade, some people say more than a decade. " And they said eight years. That's their opinion based, but it was a very sort of diligent set of steps that they'd worked through.
So to me, whenever there's enough proximity of the time that it will take to upgrade versus the time at which you think this threat is going to materialize, then it's time to act. That's the way that we look at it. Because by the way, Q-day, again, I'm not a big fan of Q-day because the impact that will be suffered, especially from economic means in terms of that lack of trust, that's likely to be well before the world knows that it exists.
A cryptanalytically relevant quantum computer, which a lot of people define as Q-day, and so we are more concerned again about being ready in advance of that day, whenever it is. I have a couple of thoughts on it. So first of all, in terms of the harvest now, decrypt later, to me, that information is radioactive in that it has a half-life.
Every period of time, it becomes less and less. Over every period of time, it becomes less and less useful because some of the information, I'm not going to say it's eternal, some of the information has a longer lived kind of thing, maybe your social security number or something like that. But the overwhelming majority of this information that's been pilfered, harvested now and to decrypt at some point in the future, we see it here with our email list.
Over time, the average email, it's almost ephemeral, in terms of the useful life of that information. It truly is radioactive. And so, if you told me you were harvesting stuff years ago, by the time you get-- First is having a computer that is, as you say, is capable of doing it, then B, it's getting access to that computer with your harvest now payloads or your harvest then payloads to decrypt them now.
And that's another time frame. I think by the time that happens, a small percentage of that information is actually going to be really, really valuable. On the other hand, as you mentioned, the withering of trust, just a simple handshake.
I go to a website, I'm me, you're, it's it. This is really that website. I think that starts ripping at the fabric of what we've built here in the web and the internet.
The good news is, is I think that is something that NIST and the industry have sort of gotten, not in front of, but they're not as behind as we've seen in other technology sort of innovation cycles. They're out there, they're pushing certificates to expire faster so that you need to upgrade and hopefully, these certificates you're upgrading to have post-quantum algorithms built in. People are becoming more aware that a good partnership, it seems still, between private industry and government here in terms of tackling that core issue.
So maybe I'm just a damn fool optimist, but I'm hoping this is one that we can kind of get in front of. Well, the thing is that if you never get started, you don't give yourself the latitude of being an optimist, right? Yeah.
And that's sort of our overall perspective. It shouldn't really be a game of hope. And by the way, when we have often found that, again, sort of taking a step back, sure, quantum is the threat that we talk about here, but some of the cryptographic governance techniques, the policies, just even having a cryptographic center of excellence or a clear line of responsibility with an organization, those are big steps forward that one could argue should've been taken over the last two or three decades.
We've been kind of lucky in that asymmetric cryptography to date has stood the test of time. So we are, or I should say, the variants that have been used, we are definitely seeing that, and we're positioning this much more as cryptographic governance and starting to try and-- You asked earlier about Deloitte specifically and we obviously have an audit practice, and we are at arm's length from the audit practice in terms of independence. However, some of the preparation, internal audit readiness activities, getting customers and clients ready so that they're able to address this problem, we're starting to look now more towards can that be done in essentially a self-regulatory way?
Our concern, and we talk to regulators quite often around the world, our concern is that there may not be a clear enough message that the regulators want to put out there in time, and organizations may be waiting for that before they can get the proper attention at the board level. So we're trying to drive industry momentum around essentially self-regulation, and we put out a profile to the NIST Cybersecurity Framework. I had the pleasure of helping NIST to develop that back, what, 13 years or so ago now.
And that stood the test of time as a reasonable outcome-based process to determine what cyber capability should look like, while applying that logic to cryptographic resiliency is what we've taken the next step. " This is not going to be a straight do A, B, C, and D and we're done. That's the thing.
It's a dynamic environment, and so it's very important, we think, to put out some sort of line in the sand there that people can address. Absolutely. Colin, these are 15-minute interviews, and we're about out of time.
But for people who want to maybe follow you, follow the practice at Deloittestay abreast of this? What's your best advice for them? I think we will continue to be out there advocating that it's good to get started.
We're not being alarmist, but we are saying you should start now. You could always put it on pause a year from now, two years from now. But getting started now allows you to figure out where are the most important assets and business processes, mission-critical operations, that you should address initially.
And don't get overly distracted, as I said earlier. Harvest now, decrypt later. And I look at that in two areas, personal information, as you talked about, and then also national security information.
So national security information clearly has high significance and should always be protected to the utmost degree. I think as we go forward over the next five to 10 years, the way that we authenticate ourselves as individuals is going to modify a little bit, too. So there'll be other means by which to protect that information.
The bigger impact is going to be on the erosion of trust by not having these mutual authentication channels that we've relied upon today. And that ultimately comes down to interoperability between organizations that want to do transactions together. If one, two, three, four, or five have upgraded and the sixth one hasn't, will that sixth one still be trusted?
Can they still do business together? That's where it's really going to hit operations. Yeah.
And it'll be lumpy. It'll be lumpy, for sure. Anyway- It's not going to be straightforward.
Yeah. That's for sure. Colin, thank you for coming on and talking to us a little bit about this real issue.
Congratulations again on being selected in the Quantum Security 25 initial list. Keep up the great work, and hopefully we'll talk to you again soon. Thank you so much, Alan.
It's been a pleasure. My pleasure. Colin Suter, Global Quantum Cyber Readiness Leader at Deloitte, and one of the initial Quantum Security 25 list members.
We're going to take a break on Techstrong TV. We'll be back in a moment.