
























Dave Krauthamer is the field CTO and a board member at QuSecure.

getty
For more than 40 years, we have been building the modern internet on foundations that were never designed for the world we live in today. When the architects of the early internet created its protocols, they were solving a very different problem. Their focus was connectivity, not security. The scale was small, participants were trusted and the environment was controlled.
No one imagined billions of connected devices, smartphones everywhere or critical infrastructure operating on global networks. The constant exchange of sensitive information across open systems was never part of the design assumptions. Security was layered on later.
We added encryption, certificates and identity frameworks. These were necessary, but built on an architecture never designed to validate identity everywhere or manage cryptography at scale.
Crypto agility means algorithms are no longer permanently embedded. They become adaptable components that can be upgraded or replaced without rewriting applications or replacing infrastructure.
But agility must extend beyond algorithms. True resilience requires flexibility across the entire cryptographic stack—libraries, keys and policies. Library agility enables rapid patching. Key agility allows dynamic rotation.
Equally important is identity. For decades, systems assumed trust within a network perimeter. That model no longer works. Strong identity must be foundational to every interaction.
Modern TLS 1.3 with mutual authentication allows both sides of a connection to verify identity before exchanging data. When identity becomes intrinsic, networks become far more resilient. This enables true zero-trust architecture. Access decisions are based on identity, device posture and policy—not location. Microsegmentation further limits lateral movement by restricting communication paths.
Together, these capabilities transform how secure networks operate. However, they require a level of visibility and orchestration most organizations lack today.
Many security teams still lack a clear picture of where cryptography exists. Encryption is embedded across applications, APIs, devices, containers and third-party services. Without discovery, it cannot be managed.
Continuous cryptographic discovery helps to change this. By identifying where encryption is used, which algorithms are deployed and how keys are managed, organizations gain a living map of their environment.
With visibility comes policy-based management. Leaders can define which algorithms are allowed, how keys are rotated and how identity is enforced. When vulnerabilities emerge, remediation can be orchestrated centrally. Instead of chasing changes across systems, organizations can enforce security consistently and automatically.
This is the power of centralized cryptographic orchestration. Encryption, identity, keys and policies become a unified system rather than isolated components. Security teams can understand, govern and evolve their posture with precision.
The challenges we face today are the result of decades of incremental decisions as the internet expanded beyond its original design. Each layer added capability, but also complexity. Now, for the first time in a generation, the industry is being forced to reexamine its cryptographic foundations.
The path forward is about embracing a fundamental shift in how cryptography is governed. Start by treating cryptographic policy as a living control system—one that is continuously aligned with emerging regulatory expectations such as DORA, PCI DSS and CNSA 2.0, but not constrained by them.
From there, the real inflection point is integration. Cryptography must be embedded into the systems that already define how organizations understand their environments. When cryptographic context is anchored to asset intelligence—whether through CMDBs or other system-of-record platforms—it stops being invisible and starts becoming actionable.
This visibility, however, is only valuable if it is dynamic. Continuous discovery into environments must be built, creating a real-time inventory of where encryption lives, how it is implemented and where risk is accumulating.
Rather than relying on fragmented, manual remediation, leaders must also ensure active remediation across the stack, including algorithms, protocols, libraries, certificates and keys, so vulnerabilities are addressed systematically rather than manually.
Finally, this entire model depends on continuous feedback. Cryptographic posture must be monitored as rigorously as any other critical system. The goal is to identify weaknesses early while they are still theoretical, not after they are exploited.
Taken together, this represents a shift from managing cryptography as a technical function to governing it as a strategic capability that evolves in real time alongside the threats it is designed to mitigate.
The migration to post-quantum cryptography is not just a defensive response. It is an opportunity to modernize secure communications.
If approached thoughtfully, we can build networks where identity is verified by default, cryptography evolves dynamically and policies are enforced consistently across every system. In other words, we can create the kind of secure infrastructure the early architects of the internet could not have imagined.
Moments like this are rare. When they arrive, they give us the chance to correct the past and build something far stronger for the future. Right now, we have that opportunity.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。