DigiCert Study: Preparing for a Safe Post-Quantum Computing Future in APAC

IT leaders in APAC are sounding the alarm about the need to invest now in quantum-safe transition planning; lack of clear ownership, budget or executive support are obstacles in path to preparation. 

NEWS HIGHLIGHTS

The global study reveals that 61% of those surveyed are concerned that their organization will not be prepared to address the security implications of PQC. 74% of organizations are concerned that bad actors can conduct “harvest now, decrypt later” attacks now, in which they collect and store encrypted data with the goal of decrypting it in the future.It also shows that IT leaders believe that cyberattacks are becoming more sophisticated (60%), targeted (56%) and severe (54%). In APAC specifically, IT leaders also expressed concern about the timeframes in which to prepare. 39% say that their organizations have less than five years to get ready. The biggest challenges are not having enough time, money and expertise to prepare, with almost half of respondents saying that organizations’ leadership is only somewhat aware or not aware about the security implications of quantum computing.53% of APAC respondents currently have a strategy (19% percent) or will have in the next six months (34%) to address the security implications of quantum computing. Many organizations are in the dark about the characteristics and locations of their cryptographic keys. Slightly more than half of respondents globally (52%) say their organizations are currently taking an inventory of types of cryptography keys used and their characteristics.

SINGAPORE, Oct. 19, 2023 /PRNewswire/ — Today, at its annual Trust Summit conference, DigiCert released the results of a global study exploring how organizations are addressing the post-quantum computing threat and preparing for a safe post-quantum computing future. Key findings reveal that while IT leaders are concerned about their ability to prepare in the timeframes needed, they are hampered by obstacles which include lack of clear ownership, budget, and executive support.

Quantum computing harnesses the laws of quantum mechanics to solve problems too complex for classical computers. With quantum computing, however, cracking encryption becomes much easier, which poses an enormous threat to data and user security.  

“PQC is a seismic event in cryptography that will require IT leaders to begin preparation now. Forward-thinking organizations that have invested in crypto agility will be better positioned to manage the transition to quantum-safe algorithms when the final standards are released in 2024,” said Amit Sinha, CEO of DigiCert.

“In the APAC region, where digital transformation is rapidly evolving, the need for quantum-safe cryptography is paramount. As industry bodies and governments drive progress, we urge businesses to prioritize their preparations for PQC to safeguard their data and maintain trust in an increasingly interconnected world,” said Armando Dacal, Group Vice President APJ at DigiCert.

Study Highlights

Ponemon Institute surveyed 1,426 IT and IT security practitioners in the United States (605), EMEA (428) and Asia-Pacific (393) who are knowledgeable about their organizations’ approach to post quantum cryptography.

Key findings from the study, sponsored by DigiCert, include:

Sixty-one percent of respondents say their organizations are not and will not be prepared to address the security implications of PQC.Almost half of respondents (forty-nine percent) say their organizations’ leadership is only somewhat aware (twenty-six percent) or not aware (twenty-three percent) about the security implications of quantum computing.Only thirty percent of respondents say their organizations are allocating budget for PQC readiness.Fifty-two percent of those surveyed say their organizations are currently taking an inventory of the types of cryptography keys used and their characteristics.

Key highlights in APAC include:

Thirty-nine percent of organizations say that their organizations have less than five years to get ready.Fifty-three percent of respondents currently have a strategy (19% percent) or will have in the next six months (34%) to address the security implications of quantum computing.Sixty-three percent of organizations do not have a centralized crypto-management strategy (23%) or they have a very limited one, only applied to certain applications or use cases (37%)

Challenges organizations face to be ready for a safe post quantum computing future

Key findings indicate that security teams must juggle the pressure to keep ahead of cyberattacks targeting their organizations while preparing for a post quantum computing future. Only fifty percent of respondents say their organizations are very effective in mitigating risks, vulnerabilities and attacks across the enterprise. According to the research, ransomware and credential theft are the top two cyberattacks experienced by organizations in this study.

Forty-one percent of respondents say their organizations have less than five years to be ready. The biggest challenges are not having enough time, money and expertise to be successful. Currently, only 30 percent of respondents say their organizations are allocating budget for PQC readiness.

Many organizations are in the dark about the characteristics and locations of their cryptographic keys. Only slightly more than half of respondents (52 percent) say their organizations are currently taking an inventory of the types of cryptography keys used and their characteristics. Only 39 percent of respondents say they are prioritizing cryptographic assets and only 36 percent of respondents are determining if data and cryptographic assets are located on-premises or in the cloud.

Very few organizations have an overall centralized crypto-management strategy applied consistently across the enterprise. Sixty-one percent of respondents say their organizations only have a limited crypto-management strategy that is applied to certain applications or use cases (36 percent), or they do not have a centralized crypto-management strategy (25 percent).

To secure information assets and the IT infrastructure, organizations need to improve their ability to effectively deploy cryptographic solutions and methods. Most respondents say their organizations do not have a high ability to drive enterprise-wide best practices and policies, detect and respond to certificate/key misuse, remediate algorithm remediation or breach and prevent unplanned certificates.

Organizations recognize they are lacking the expertise to stay out in front of post quantum requirements. As a result, hiring and retaining qualified personnel is the most important strategic priority for digital security (55 percent of respondents). This is followed by achieving crypto-agility (51 percent of respondents), which is the ability to efficiently update cryptographic algorithms, parameters, processes and technologies to better respond to new protocols, standards and security threats, including those leveraging quantum computing methods.

To be ready for post-quantum computing, organizations need to have a strategy that includes backing by senior leadership, visibility into cryptographic keys and assets, and centralized crypto-management strategies that are applied consistently across the enterprise with accountability and ownership.

Read the Full Report: Preparing for a Safe Post Quantum Computing Future

About DigiCert

DigiCert is a leading global provider of digital trust, enabling individuals and businesses to engage online with the confidence that their footprint in the digital world is secure. DigiCert® ONE, the platform for digital trust, provides organizations with centralized visibility and control over a broad range of public and private trust needs, securing websites, enterprise access and communication, software, identity, content and devices. DigiCert pairs its award-winning software with its industry leadership in standards, support and operations, and is the digital trust provider of choice for leading companies around the world. For more information, visit  www.digicert.com  or follow @digicert.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/digicert-study-preparing-for-a-safe-post-quantum-computing-future-in-apac-301961506.html

SOURCE DigiCert

第三季酒店業僱員數量升兩成 人資需求增加

澳門統計暨普查局資料顯示,今年第3季末酒店業的全職僱員按年增加21.7%至53,802名。

英皇娛樂酒店中期淨溢利1210萬港元

英皇娛樂酒店有限公司公佈中期業績公告,截至2023年9月30日止6個月期間轉虧為盈,錄得淨溢利1210萬港元。

美國今年“黑五”購物周近幾年“最便宜”

新華社北京11月29日電 美國上周迎來“黑色星期五”購物周。據路透社28日報道,今年“黑五”購物周堪稱數年來“最便宜”,大批消費者受零售商的大力促銷吸引,多番比價、“精明”購物。

澳門首十月酒店入住率超八成

澳門統計暨普查局資料顯示,今年首十月澳門酒店業客房平均入住率同比上升43個百分點至80.9%,住客增加1.6倍至1,104.1萬人次。

【法律解碼】新《金融體系法律制度》:需要了解的重要事項

新《金融體系法律制度》:需要了解的重要事項

【息息相關】REITs 時代

在澳門證券基金行業協會舉辦的論壇上,業內人士和專家一致認為,澳門在發展不動產信託基金(REITs)市場方面擁有優勢,可以進一步推動金融業發展,加快經濟多元化進程。

普華永道:2024年中國經濟增速有望超過今年

新華社北京11月26日電 普華永道會計師事務所中國資深經濟學家趙廣彬日前表示,隨著政府採取的一系列政策措施發力顯效以及私營部門投資增長,2024年中國經濟增速有望超過今年。

國際貿易中心執行主任:數字互聯互通將成為未來貿易關鍵因素之一

新華社日內瓦11月26日電(記者陳斌傑)聯合國和世界貿易組織的合設機構國際貿易中心執行主任帕梅拉·科克-漢密爾頓日前在瑞士日內瓦接受新華社記者書面採訪時表示,數字互聯互通將成為未來貿易中的關鍵因素之一。

【息息相關】“澳門居民的保險、保障嚴重不足”

作為新成立的保誠保險澳門分行總經理,馬竹豪看到澳門人壽保險業務的巨大潛力。他表示,這家擁有175年歷史的英國跨國企業將配合特區的多元化步伐,著眼於橫琴,為澳門市場注入創新元素。

協議生效!巴以停火4天

新華社加沙/耶路撒冷11月24日電 當地時間24日上午7時(北京時間13時),巴勒斯坦伊斯蘭抵抗運動(哈馬斯)和以色列在加沙地帶的臨時停火協議生效。雙方將休戰4天。

相關文章

10月入境旅客按月升二成

澳門統計暨普查局資料顯示,今年10月入境旅客按年增3.8倍至2,757,308人次,與9月相比上升19.8%。

【特刊】“‘一帶一路’已作出了改變,且將迎來更多變化”

澳門大學社會科學學院政府與公共行政學系副教授Francisco Leandro是“一帶一路”研究領域的權威專家。在接受採訪時,他預計該倡議將進一步改進,包括更看重“綠色絲綢之路”維度。

永利澳門第三季EBITDAR增至2.55億美元

永利澳門公佈,今年第三季度經調整後的物業EBITDAR為2.549億美元,環比增長3.57%。

美高梅中國第三季淨收入較疫前增10%

美高梅中國宣佈其第三季度淨收入為8.13億美元(約合65億澳門元),較2019年第三季度增加10%。

新濠第三季營運收入升至9470萬美元,淨虧損收窄

新濠博亞娛樂有限公司公佈,今年第三季度的營運收入為9470萬美元(約合7.6億澳門元),較上一季錄得的6430萬美元環比增長47%。

澳門企業家代表團赴滬參加進博會

澳門貿易投資促進局組織一行近50人的澳門企業家代表團4日赴滬參加第六屆中國國際進口博覽會,這是澳門連續第6年組織 本地企業參與進博會。 澳門特區行政長官賀一誠受邀於4日至5日赴上海,出席第六屆進博會開幕式及相關活動。