menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

You Can’t Protect What You Can’t Find

43 0
yesterday

Imagine asking the leadership of a large organization a simple question:

Where is your cryptography?

The first answers would probably sound reassuring. It protects customer information, secures cloud services, authenticates systems, and runs inside the applications and technologies that keep communications safe.

That reassurance begins to fade when the discussion becomes more specific. Which algorithms are being used? Which applications depend on them? Which certificates authenticate critical systems? Which devices contain cryptography that cannot easily be upgraded? Which implementations are controlled by cloud providers or software vendors? Which systems still depend on technology installed ten or twenty years ago?

The answers quickly become less clear.

This is one of the most important challenges organizations face as they prepare for the Quantum Era. Cryptography is everywhere in modern digital infrastructure, yet the people responsible for managing risk rarely need to know where it resides.

For decades, that invisibility was largely a sign of success. Cryptography became embedded in the background of digital life, quietly authenticating users, protecting transactions, securing communications, verifying software, and establishing trust between machines. The transition to post-quantum security is bringing that invisible infrastructure back into view.

Before an organization can change its cryptography, it first has to find it.

The infrastructure we stopped seeing

Most people interact with cryptography constantly without knowing it. When an employee connects remotely to a corporate network, when a customer logs into a bank account, when software verifies that an update is legitimate, or when two systems exchange sensitive information, cryptography is working somewhere in the background.

Inside a large organization, these mechanisms have accumulated over decades. Some were built internally. Others arrived inside commercial software, network equipment, cloud platforms, identity systems, industrial devices, or third-party services. New systems were added while older ones remained in operation. Vendors changed. Standards evolved. Applications were updated. Companies merged and infrastructure was integrated.

The result is a cryptographic environment that may be far more complex than the organization realizes.

This matters because post-quantum migration requires organizations to identify which cryptographic mechanisms may eventually become vulnerable and determine how they can be replaced. That process becomes considerably harder without a complete picture of what already exists.

This is where cryptographic visibility becomes essential.

An inventory needs context

The concept sounds simple: create an inventory of the cryptography used across the organization. In practice, discovering an algorithm, certificate, or cryptographic library is only the beginning.

Finding a cryptographic mechanism tells an organization........

© The Times of Israel (Blogs)