Skip to content

Leadership1 publisher3 min readPublished

ISARA's chief executive would scope post-quantum migration by cryptography in live use

His case against inventory-first discovery is mechanically sound and commercially interested. The essay never says how much smaller a use-based scope would be, which is the figure a budget actually needs.

The Board Room · Leadership desk

Photograph accompanying ISARA's chief executive would scope post-quantum migration by cryptography in live use
Photo: isara.com

What happened

  • His account of a typical large-enterprise inventory is that most of it is dormant: retired binaries left on disk, certificates never pulled from the trust store, keys for services decommissioned two years ago.
  • The illustrative dashboard he describes carries 12,000 certificates and 47 implementations of one algorithm, and he says most of those certificates are not where the risk sits.
  • He also argues the live set moves daily, so that the cryptography protecting the network at 9 a.m. is not what was protecting it at 5 p.m. the previous day.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision Anyone who booked a cryptographic inventory as a quarter-end deliverable now has to decide whether that artifact closes the discovery phase or opens a standing measurement, since Yamada's claim is that the finished report describes a state the environment has left.
  • constraint Excluding dormant material holds only while it stays dormant, so the exclusion list has to be re-checked on a schedule rather than signed once, which is a heavier ongoing obligation than a filed inventory.
  • cost The saving from re-scoping is unpriced in the source, so the discovery work has to be paid for before anyone can show the board how much smaller the migration became.
  • precedent If evidence of use becomes the accepted proof of post-quantum progress, the standard deliverable of the whole posture-management category changes, and the push is coming from inside that category.

The argument arrives with a commercial address, and that is worth stating before weighing it. Atsushi Yamada is chief executive of ISARA Corporation and advises enterprises on crypto posture management for the post-quantum era [1], and what his essay attacks is the first deliverable that, by his own account, every posture vendor in the market currently sells [3]. A vendor telling buyers the standard first invoice is for the wrong artifact is not disqualified by the interest. It is a claim about which deliverable deserves the money, and it holds or fails on mechanism.

The mechanism is about attention rather than about cryptography. Yamada's illustrative dashboard carries 12,000 certificates and 47 implementations of the same algorithm, and his contention is that most of the 12,000 are not the problem [7]. He sorts the dead weight into four kinds: retired applications whose binaries stay on disk, archived certificates never pulled from the store, orphaned private keys, and shared libraries whose whole primitive surface gets flagged although the linked binary calls only RSA, ECDH, AES and SHA-2 [9][6]. What he would count instead is the subset actively negotiating sessions, signing tokens and encrypting data in flight with weak parameters or deprecated protocols [8].

The board-deck version is that re-scoping shrinks the migration. The essay does not support that in the form a budget needs, because it prices one side only: figures for the bloat, none for the live set [15]. The reduction is directional rather than sized, and the only way to size it is to commission the use-based discovery whose payoff you were trying to estimate first.

A skeptic on the security team would say dormant is not the same as harmless, and the essay half agrees. Archived certificates can in rare circumstances be reactivated, which Yamada calls its own problem [10], and among his examples of daily change is a retired application brought back for a migration project [11]. That concession does not overturn the priority ordering; it changes what exclusion means. Material set aside because nothing calls it has to stay watched, so the exclusion list becomes a standing check rather than a signed decision [16].

The separation worth keeping is between this quarter and this decade. Post-quantum migration is a multi-year program, and what a security leader can actually change this quarter is the acceptance criterion for the discovery phase. Yamada's version of that criterion is evidence of use, refreshed, because in his telling the cryptography protecting the network at 9 a.m. is not what was protecting it at 5 p.m. the day before [12], and any dated report describes a state the environment has already left [13]. Adopting it converts next quarter's line item from a report into a running feed, and that is the trade being made whether or not anyone names it in the approval memo.

What to watch

  • Whether any posture vendor publishes a measured ratio of live to dormant cryptographic objects across real customer estates.
  • Whether procurement language for post-quantum discovery starts requiring continuous evidence of use instead of a dated inventory report.
  • Whether the reactivation case, a retired application revived for a migration project, gets a named control rather than a footnote.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories