Nexus: A Claroty Podcast
Nexus is a cybersecurity podcast hosted by Claroty Editorial Director Mike Mimoso. Nexus will feature discussions with cybersecurity leaders responsible for the security and protection of cyber-physical systems. Guests include cybersecurity researchers, executives, innovators, and influencers, discussing the topics affecting cybersecurity professionals in OT, IoT, and IoMT environments.
Nexus: A Claroty Podcast
Ellen Boehm on Post-Quantum Readiness in Critical Infrastructure
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Ellen Boehm, Senior Vice President Strategy and AI Innovation at Keyfactor, joins the Nexus Podcast to discuss post-quantum cryptography (PQC) readiness in critical infrastructure organizations. A recent Executive Order on PQC installed a December 2030 deadline for federal agencies to transition high-value systems and key generation to PQC. The EO also directs CISA, other federal sector risk management agencies to assist with road map development.
In this episode, Ellen discusses readiness in this context. She also delves into how critical infrastructure organizations overseeing fleets of cyber-physical systems (CPS) assets transition those environments and avoid disruptions. Governance, budgeting, supply chain management, and the AI-driven threat landscape are also discussed.
This episode was recorded during the Black Hat USA Conference.
Subscribe and listen to the Nexus Podcast here.
All right, welcome back to the next podcast. Ellen Boehm, the senior VP of Strategy and AI innovation at Key Factor, is my guest. Great. Flat cat going for you. It's hot. It is hot. But it's a consensus here.
Speaker 1Yeah, but it's been great. It's having a lot of fun, had a lot of good conversation. So I'm looking forward to this one.
SpeakerTell me a little bit about your role in Key Factor.
Speaker 1So I lead strategy and innovation. And what that means is taking a look a few years out about where the market's going in terms of tech, in terms of what our customers need to help be able to continue to have a strong digital infrastructure that is running their enterprise. So I'm looking at new and emerging markets and technologies that we can kind of bring into our portfolio and add into our trust control plane to be able to help our customers manage and have that sort of zero trust mentality as things continue to evolve.
SpeakerSo we're going to talk a lot about post-quantum crypto. Seems like we've been hearing about this for a while. Bring me up to speed, bring the listeners up to speed on where we are. I know there was an executive order recently from the White House that kind of quantified some stuff, but you're in you're intimately involved with it. Yes.
Speaker 1Yes. Yeah. So we've been following this for a long time, and we have a lot of really smart people at the company that are cryptographers and that have been involved in the NIST standardization process from a testing perspective to take some of these candidate algorithms and put them into our into our products and be able to test the strength of them and just sort of advise along with the community. So we have, yes, we've been working for a long time in parallel to the uh development of this cryptographically relevant computer that is going to be able to crack the encryption that we know and use today with RSA and ECC. So you mentioned the executive order. I think that that is so there was an executive order, I think it was 14409 was the one basically saying we need, as federal agencies, to understand high-value assets and critical uh applications that need to migrate to PQC, we're gonna put some deadlines around that. And I think having executive orders that are putting some numbers and dates, and and there was a an OMB memorandum that gave a little bit more specifics about this is what you have to do, this is how you should become more crypto agile. When we see these written pieces of documentation with dates tied to them, I think it raises everybody's attention back to the subject of this is going to happen. This computer is going to be available to crack this code at some point in time, and we need to stop just talking about it and move to how do we actually be more post-quantum ready.
SpeakerDo you imagine or let me back up? Where where are we with I know it's an impossible question to answer, but where are we with PQC in terms of just development, implementation, et cetera?
Speaker 1Yeah. So from the from the NIST uh algorithms that we've been testing, I do believe like MLDSA is one that seems to be pretty solid and people are recommending use of it, testing of it, implementing it. So I feel like that is we do have a couple candidates that we can use. And I know that NIST is continually looking for additional digital signature algorithms and encryption key candidates. So it's gonna be an ongoing process. It's not gonna be like, let's pick one and it will be good forever.
SpeakerTurn it on tomorrow.
Speaker 1And turn it on and nothing's gonna break, right? So it's uh it's not just about picking the algorithm, it's about having a whole plan for how you migrate your enterprise because there's so many digital connections that rely upon cryptography. We also need to know where that cryptography currently is today and what it is tied to, what business applications depend on it. And that is almost even that's step maybe let's say that's step two in the process is discovery. Step one is let's identify that this is a problem from a business level problem because CISOs and CIOs, and I think even CEOs need to understand that business applications could get interrupted if we don't think about a readiness plan to migrate, at least the most critical ones now. So let's come up with a team and then let's start to do some discovery about what we even have, and then we can get more into readiness conversations.
SpeakerI mean, when the the day comes, the time comes, how expensive is this going to be? How big of an overhaul are enterprises looking at?
Speaker 1Yeah. So I think it really depends on how organized you are right now. Do you have governance around your cryptography? And do you have a tool or a set of tools or a system to manage in an inventory what you currently have? Do you have an automation tool to be able to be crypto agile and actually go in and rotate out that cryptography and refresh it? And do you have a way to monitor that and show an alert when perhaps something is, you know, here's a new key and it's out of date and it's it needs to be swapped? So it's it's more about that continuous platform management that we need to get in into place.
SpeakerAnd in terms of the threat landscape, how does this alter, if if at all, what's what attackers can do? Is just strictly a defensive measure?
Speaker 1That's a great question. So I feel like we attackers also so I'd say attackers are probably aware that this is also going to happen, and they are doing this sort of uh you you've probably heard harvest now, decrypt later, harvest now, forage later. The more capability that we have or they have to take information and store it and wait for the point at which later they can decrypt it and then do whatever they want with it. So that's probably already happening now. So that I think should also be a warning or a for foreshadowing to we should be able to update these systems as soon as we can, especially if it's a high value system or a critical application that's running your business, because um that data maybe is already lost. So thinking about what you need to protect, especially if you're in a uh a a vertical where like confidentiality or you know, patient information or things that you need to keep for a long time, right? Um there's there's some risk in that.
SpeakerSo I saw an article that you wrote that where you talked about um this being fundamentally a readiness problem versus a crypto problem. Explain what you meant by that.
Speaker 1Yes. So readiness to me is having a holistic program for figuring out what you need to update first, and that goes back to discovery. So step one is discover all of the assets that you have. And that's often a big problem. You could have millions or maybe not millions, maybe let's say tens of thousands of identities between certificates, keys, tokens, and underlying crypto that has just built up over time, especially if you're a really large company. We have many of our customers are Fortune 100s, they have done acquisitions. There have been different, you know, different groups that have developed over time different policies. So part of it is just getting all that under control, getting all of it under management. So that's the big discovery piece. That is that is one big part of readiness. And then the second is just understanding what is the order in which you're going to start remediation, and that prioritization should be based around business impact. So step one are what are the the pieces the systems that can't go down or would be most critical if they were hacked into, or you you just your your business relies on them, and that could be anything financial or customer, or you know, how how you're serving your end customers, or if in the product security case, it's the devices that you're selling that generate the revenue for your business. And so it's everyone has a different answer for that, but you have to be able to prioritize that and then come up with a migration plan that likely involves automated tools, probably some some vendor tools. So ask your vendors questions around how are you approaching post quantum and do you have PQC ready product that I can incorporate into, you know, so it's it doesn't have to only be all on you. Like that's that's another part of readiness. And the last piece would just be having it, having the right governance around it and the right automation around this, so that if you don't already have an automated way to to be crypto agile and to update in the future, because yes, let's say you update until to ML DSA and or some other pick your favorite algorithm for that use case you're looking at, there's going to be another one in the future that you're likely going to need to change to. So let's let's kind of get ahead of that. We know from past migrations like SHA-1 to SHA 2. Yeah, it took decades to get all of that stuff updated. And so now we're trying to figure out how we can be a little bit more structured, use tools that we have today to have automated discovery, continuous discovery, and not think of this as a single point in time. It's it becoming much more operational because we have the tools to be automated.
SpeakerWell, what triggered all of this? I mean, was it just kind of these these older algorithms being finally cracked after, like you said, decades of people trying? And I remember all these hacking contests here and a DEF CON uh, you know.
Speaker 1Yeah. So yes, I think it you know, just over time compute power is becoming, you know, more readily available. Like the just the way that tech evolves. The other piece that I think is new and happening all at the same time is the emergence of AI agents that are being used instead of people to try to to find vulnerabilities, to try to find weaknesses. And and I think AI agents are, they can do good, and they can also, you know, so we should be trying to use them to be able to test against what has been developed and proposed as strong. So I think that whole emergence of that tech and AI agents ultimately being able to be autonomous, work together on their own with you know some initial instructions and guardrails around them. That is is going to that's that's almost a risk that I think is accelerating the need for us to have this PQC readiness program and mindset in place because that that whole space is happening way faster than I think a lot of us think.
SpeakerThe last six months have been just been every single week.
Speaker 1Like you know, there's okay, here I made this agent and I told it to play in the sandbox nicely, and then it got out and it did this thing.
SpeakerBut so we're gonna hear lots of stories about it but I mean it seems like a useful application that it could help accelerate this, yeah.
Speaker 1Totally, yes. So I know this isn't an AI conversation, but I think it is also another just the timing is probably good for us to help reiterate this conversation about PQC readiness. It's not just going to be traditional attackers or people or what you know, and or even just software. Um it could be agentic actors that are starting to work together in a way that we, you know, maybe can't even predict.
SpeakerSo a lot of my listeners are in critical infrastructure, dealing with cyber physical systems, OT, etc. Um, obviously very complex proprietary environments. Um if I'm a so in in one of those critical industries, what should I be doing now? What kind of conversation should I be having? Because a lot of these uh systems and and environments don't tolerate downtime, they're afraid of disruptions and for good reason. So it's a very different dynamic. I'm just wondering what your experience is there.
Speaker 1Yes. So I totally get it. I I appreciate that we have we it's it's very complex. We have legacy hardware running very critical systems that power our society, whether that be water, oil and gas, electricity, it's just stuff that we rely on. You know, I think about what if the what if the power went out here in Vegas and then the air conditioning wouldn't work, we would all be really unhappy and very sweaty. And but just that just one little example of if of the impact that it would have on on humans. So very important to think about how we take what we've done in the enterprise IT side of the house and move best practices over to OT, but also understanding there's completely different constraints, and we have these control systems that are, they run on different protocols. Those protocols might not be able to do modern cryptography to you know use some of the stuff we've been talking about, or there could be even the controllers could be more constrained and they can't handle a post-quantum certificate because it is bigger and has more processing, it takes more processing. And if we we need like real time, we've got our toss systems, it's it's gotta be fast, it can't and it can't break and it has to so all of that to say architecture might need to be different. I think similar to what we're talking about discovery of crypto assets within enterprise environments, the the same sort of thing is important for operational technology is well, firstly, knowing what devices are on your network, which is having the understanding the crypto assets that exist within those devices, and then how do you maybe segment off and upgrade certain systems at the SCADA level or have a gate some kind of gateway in the middle? So to me, it's all it's about architecture. I think it all could be solved, even when we do have some legacy devices in there. But again, using similar best practices for authentication and encryption and connection. So even when someone does get inside of the operating environment, we have the these controls in place to be able to revoke access or prevent access and shut things down. And you know, we won't hear these stories about someone breaking into another water system, which seems to be pretty popular.
SpeakerSo the you mentioned earlier harvest now decrypt later. It's it's kind of a a meme out there with relation with relative to this. But any of this operational data particularly vulnerable to that scenario, or any more vulnerable than traditional IT data?
Speaker 1Yeah, I mean to me, I f I think about sure, if somebody hacks into a corporation, you know, because they they really don't like, you know, the the president or the the CEO of that company. Okay, that makes the news. To me, it's when it impacts like my mom or you know, somebody's grandma that is just trying to get a glass of water. Like that is much more widespread in in terms of impacting a society from like a scare tactic perspective perspective to say, oh, look at what I can do. Yeah. That elevates and and maybe feeds egos and things like that. I don't want to get too like political in terms of um that. But you know what I'm saying? It's it's I think critical infrastructure, we call it critical because it is. Um that's why I was encouraged to see in in the executive order on PQC reference to these critical industries be cut or critical infrastructure verticals that that can even include healthcare and hospitals. And you think about like back in COVID when there was challenges with being able to just get people seen and uh another pandemic could that we've seen we we've seen the impacts of that. So where am I going with this? Yes, I think those have broader impact just because of people and humans, and that's we we talk a lot about AI and tech and but we're all here and we're living and we're on earth and we we're we we thrive off of sort of human connection. That's never gonna go away, even depending on whatever technology we're using to to get to the next level. So whenever it impacts humans and how we live, I think that elevates up the need for us, especially like in, you know, I live in the US and I'm American and we have certain things we rely on to be to be safe and to to live our lives, and that's kind of what we count on our you know, our government and those uh uh entities to provide. So executive order, I think, is a a good step to help us move in that right direction. And in critical infrastructure, companies should also be thinking about how they can follow along with that.
SpeakerSo related question, you mentioned visibility earlier. How tough is it to have a comp you know pretty accurate inventory of your crypto, of your certificates within these, again, operational environments?
Speaker 1I think it is it's challenging because I don't think people have had the tools to be able to do discovery. It's been something we've been talking about, and I'm seeing many more vendors offer solutions like that, like we do, because it's because we are seeing a need to discover things that we that aren't there, and that's that's part of what our customers have been telling us. When we've been talking about automation and readiness, they're like, okay, that's great, but I can't be ready when I don't know what I don't have. So we go back to the discovery step. So that's always step one. So I think there's you know other tools and there's tools to do these types of things. So figure out what works for your business and just make sure that you're at least doing a scan and then you're doing it continuously, and that you have sensors that you can connect to systems that you're that that you're using that that have that that can catch all of this this stuff, whether it's certs or keys or tokens or API keys, you need to know what they are, where they are, and then get them into a system so that you can figure out what to do with it.
SpeakerSo once migration happens, is is there an order to it? Is there a kind of start slow philosophy or uh how do you imagine it playing out?
Speaker 1So I think it it needs to start with what is the most critical piece. You also don't have to do everything all at once. And I would recommend starting with if you upgrade one piece of of your environment, understand what is talking to it, what are all of the endpoints that have had secure connections to it in the past because you don't want to break any of those if all of a sudden they can't talk because it's like you know, you were speaking one language and I'm speaking another language, and now we're just disconnected. So it's prioritizing based on business use case, impact the business, and then to getting that as secure as possible, and then figuring out what it's connected to, and then that would be the next, the next round of things, and doing it in a way that you don't break the business.
SpeakerAnd so what does governance of all of this look like? Does it change radically once migrations start?
Speaker 1So I think governance is something that is is is broader than just this team, the crypto team, and governance should involve others from you know application, development, security, probably even compliance, and coming up with a if you don't already have a a plan, a governance plan or a governance tool, um, this has to be part of it. So cryptography and digital trust infrastructure needs to be a part of the solution. So yes, I think it's it's it's broader than this, and um it should it should encompass this as well.
SpeakerAnd does it change who's involved, who take who's part of it?
Speaker 1I I think cryptography has because it's been this thing that underlies all of our digital infrastructure, and it's always just worked, a lot of people don't know that it could be a problem. And I think that's why elevating it up and having people across your PQC readiness team that are involved in different parts of the business to understand how important it is to to migrate and be ready is that's that's gonna be what's different. Is before it was just, you know, crypto is done by some really smart people that are kind of in the back office, but now cryptography is becoming a business continuity problem. So that's why I think it does have to involve other people. And then when we get to the the cases where it is where it could be something that could be uh like in the executive order case, not so much a regulation, but like a requirement, then more much more people will get involved because the it's just been elevated as a a business priority.
SpeakerAnd are you hearing uh any commonalities among challenges right now? I'm I'm thinking, for example, uh CISO asking for budget for this and getting some pushback from the C suite, because I can't think about twenty thirty. 2035 right now, and AI changes everything every week.
Speaker 1100%. Yes. So that's that's why we've been having conversations like this is to give people a bit more of a sense of urgency that they can level up to the CISOs because you're right. I think AI has been getting more attention because it is it's it's the buzzword these days. It's what everyone's talking about. It's it's more easily understood too if people have been using Copilot or Chat GPT and they're like, okay, I know what an sure I can understand a little bit about that because I do it at home to figure out you know what uh what's going on for the weekend, and I'm looking for some fun events and I wanted to organize it for me. And people can get that. Whereas PQC, they're like, Well, I don't I don't know how to relate to PQC as a at a C level perspective. So that's why bringing it into saying this is encrypting our data, this is encrypting our systems, this is making sure that we're gonna have this business continuity. So I think that that's that's kind of the approach that we're gonna have to take for it.
SpeakerYeah. And we probably should have talked about the supply chain too and how this impacts relationships with partners, with vendors, contractors, et cetera. I mean, what what is that going to look like?
Speaker 1Mm-hmm.
SpeakerThere has to be some compatibility, I imagine, right?
Speaker 1Right. Yes. Yeah. So that's obviously the in order to have whether you're building products, whether you're running an operation, you have a variety of different vendors involved. When it comes to security and certificates specifically needing to work across uh different vendor products, that's something that you have to be able to manage you know internally. So from a supply chain perspective, yeah, I think asking your vendors, are they will they have PQC ready product? How is that going to be compatible with your migration plan? That's that's also a really important conversation to have now and just understand is their timeline going to line up with your timeline? Because if you start migrating over your stuff, you it it needs to be compatible.
SpeakerWhat's your sense for how often these conversations are happening, not just with suppliers, but I mean everything we've talked about today?
Speaker 1Just I feel like it's it's starting to pick up again because I think the executive order was good. Other countries have have have already been talking about this, like the UK and Australia and so the US isn't the only one. It's just this was one of the recent ones that we talked about in the news. So I think that is elevating it up a bit. I think coming and you know, we talked about it at RSA, we talk about here at Black Hat. Um, I I think it still though needs to be to elevated more. And also if you haven't started your readiness plan right now, you probably are late. Don't panic. But 2029, if Google, you know, says, okay, that's the day they want to be ready, the year they want to be ready, that's three years from now. And getting budgets to your point, especially if it's a big company, like right now we're starting to plan for 2027. That means we're not gonna do anything until next year. But at least you can start a team, you can start putting that into the budget for next year, because then you're really only gonna have two and a half years to work on it. So let's but I I do feel encouraged that we're moving past the we've acknowledged that it's coming, we have some candidates that NIST said are good, let's come up with some actual plans and start working on it now or in 2027 as soon as we can.
SpeakerIs that gonna be kind of the final trigger, so to speak, when the Googles and AWS and Anthropics of the world say, okay, we're here?
Speaker 1I I believe so. I mean, so that has definitely been helping us is having some of these other companies in these big names, it's not just us saying it. It's not just the the you know governments saying it. It's it's sort of a community coming together and being like, okay, we all believe that this is this is real, yeah, and we're here to help.
SpeakerThis is a big deal.
Speaker 1Yes. Well I appreciate the time to to chat about it.
SpeakerYeah, thank you. This has been great. I really appreciate it. I think uh I've certainly learned a lot. So all right. All right, thanks for coming.
Speaker 1Thanks a lot.