Founder, @AppliedQuantum | Former CISO, CTO, Big 4 Partner, #Quantum & #Cyber Entrepreneur | #QuantumComputing #QuantumSecurity #PQC

Geneva, Switzerland
"Is anyone actually harvesting encrypted data today?" Yes. Signals intelligence agencies have collected communications in bulk for decades. Adding encrypted traffic to existing collection is operationally trivial and virtually costless. The question is not whether HNDL is happening. It's how long your data stays valuable versus how long until a CRQC arrives. I mapped the evidence, the operational logic, and why detection is impossible. postquantum.com/post-quantum… #HNDL #CyberSecurity #PostQuantum #InfoSec
4
313
Venture due diligence has gone missing where the checks are largest. Frontier rounds now close in days, and no lead investor in the deals I examined has said it checked the physics. The ordinary startup gets the opposite treatment: on Carta's platform the median company waited 774 days between seed and Series A in late 2024, up from 420 three years earlier. Meanwhile Thinking Machines Lab raised a $2 billion seed at $12 billion with no public product, and quantum took $4.9 billion of venture money in 2025 against $1.4 billion of market revenue. I started looking in July, when an investor asked me whether an orbital data center could shed its heat. I needed one afternoon with the Stefan-Boltzmann law to show it could not, and the startup that commercialized the idea is valued at $2.3 billion. Deal speed and who leads the rounds are measurable. That the physics check was skipped is my inference, and the lead investors could correct it by saying what they checked. My recommendation is for limited partners: above a threshold you set, require an independent technical feasibility review that the fund did not write and the founder did not choose. Disclosure: I invest in quantum startups and my firm does this kind of review. postquantum.com/quantum-comm… #VentureCapital #DueDiligence #DeepTech #QuantumComputing #ArtificialIntelligence #LimitedPartners #PrivateMarkets #Investing
2
4
345
I ran the numbers on Infleqtion's careful qLDPC work from IEEE Quantum Week. The company quotes a ratio of 5.4 to one, and that figure covers data qubits only. - 18 logical qubits in 98 physical data qubits, a [[98,18,4]] code - About 196 physical qubits in total if each of the 98 checks gets its own ancilla (my estimate, since Infleqtion hasn't published one) - About 1.6x fewer qubits than a distance-3 surface code, and 4.5x fewer than distance 5 - Distance 4, so one correctable error per block - Compiled and verified in NVIDIA's new CUDA-Q Logical, not yet run on neutral-atom hardware I find CUDA-Q Logical the more consequential launch. With it, the people writing QEC codes and the people writing compilers work on separate layers, and NVIDIA says Fermilab cut a development cycle from five months to three weeks. If it becomes the standard layer, hardware makers will compete on fidelity and scale. Full analysis: postquantum.com/engineering-… #QuantumComputing #QEC #qLDPC #NVIDIA #Infleqtion #FaultTolerantQuantumComputing #NeutralAtoms
6
481
IBM cut the cost of quantum error mitigation by 63x. - The technique combines error detection with probabilistic error cancellation on a 156-qubit Heron processor - Sampling overhead dropped from 85,000 to 1,359 at six Trotter steps - Multiple independent research groups converged on the same idea, which validates the approach - The remaining overhead still scales exponentially with circuit noise - Zero bearing on the timeline to a cryptographically relevant quantum computer IBM is making near-term quantum processors more useful for physics simulations. The technique extends what noisy machines can do today. It does not change when fault-tolerant machines arrive or when encryption is at risk. IBM spends circuit repetitions to handle errors. Quantinuum and QuEra spend physical qubits. Neither is universally better. The right choice depends on the hardware. My full analysis: postquantum.com/quantum-rese… #QuantumComputing #IBM #ErrorMitigation #QuantumErrorCorrection #FaultTolerance #CRQC #PostQuantumCryptography #QuantumAdvantage
2
4
15
960
Harvard extended a diamond qubit's coherence 3.2x with sound instead of microwave pulses. I care less about the 3.2x than about the sound, because microwave pulses conflict with the phononic cavities a chip-scale quantum network needs. Marko Lončar's group at Harvard SEAS is working toward chips where phonons carry quantum information between spin qubits. Protecting those qubits from noise normally takes trains of microwave decoupling pulses, which interfere with continuous coupling between the spin and the cavity. The team applied a continuous acoustic field to a single silicon-vacancy spin instead. The field dresses the spin into states far less sensitive to low-frequency noise, and the dephasing time rose from 680 nanoseconds to 2.2 microseconds. Because the protective field is itself acoustic, the method is designed to work inside the cavities. I would not call it a breakthrough. The experiment ran on a surface acoustic wave device, so operation inside a cavity is still untested, and 2.2 microseconds is far below the millisecond coherence NV centers reach with conventional decoupling. In my analysis I compare it with the 2026 NV center results from UPenn and QuTech and look at where diamond fits as a quantum network node. postquantum.com/quantum-rese… #QuantumComputing #QuantumNetworking #QuantumHardware #QuantumPhysics #Diamond #Phononics #NaturePhysics #QuantumTechnology
2
1
8
524
A MacBook Pro just did a job the quantum industry has been building specialized chips for. Twelve of its cores worked out, in real time, which errors a simulated quantum computer with 408 error-corrected qubits was making. An error-corrected quantum computer checks its qubits for errors in constant, repeated rounds. A decoder on a classical computer has to keep up with those rounds. If it falls behind, the backlog can slow the whole computation exponentially. Superconducting machines run a round every microsecond or so. For that reason IBM builds its decoder on FPGAs, a kind of reprogrammable chip, and Riverlane has designed one as a custom chip. Both cost more and take longer to change than software. Trapped ions are slower. A round takes milliseconds, about a thousand times longer, and IonQ's new paper shows that is enough time for an ordinary processor. In the largest run, decoding added 0.02% to the run time at a two-qubit error rate of one in 10,000. Software on a standard processor is easier to change, and it scales by adding cores. I think that gives anyone building or integrating a machine with millisecond cycles, such as IonQ's, a real alternative to specialized decoding chips. All of it ran against a simulated machine. The hardware test comes in 2027, when IonQ expects to reach fault tolerance in its lab. My full analysis, including what the paper left out: postquantum.com/engineering-… #QuantumComputing #QuantumErrorCorrection #QEC #IonQ #TrappedIons #FaultTolerance #QuantumEngineering
2
5
19
1,284
September 21 was the last day FIPS 140-2 validations counted for new U.S. federal systems. Every remaining FIPS 140-2 certificate is now on NIST's Historical list, and many products still have no FIPS 140-3 replacement with a certificate. The modules keep running, and CMVP still supports buying and using them for existing systems. Buyers of new systems are the ones affected, because agencies should no longer specify Historical modules in new acquisitions. FedRAMP's July FAQ counted 285 modules in active CMVP review and 234 more in lab testing. A cloud provider in the middle of an authorization, a defense contractor self-assessing against SP 800-171 requirement 3.13.11 and a bank running payment HSMs now all have to check each deployed module against its certificate status. Post-quantum algorithms already appear as approved services on at least five FIPS 140-3 certificates, from Geomys, AWS, Thales and Crypto4A. CNSA 2.0 requires new in-scope National Security System acquisitions to support ML-KEM-1024 and ML-DSA-87 from January 1, 2027. Where an HSM is near end of life, I would plan the FIPS 140-3 move and the PQC move as one refresh and pay for the hardware change once. My full analysis, with a three-track triage for systems still on Historical certificates: postquantum.com/security-pqc… #FIPS #CMVP #PQC #PostQuantum #Cryptography #FedRAMP #CMMC #CNSA2 #CISO #Cybersecurity
1
1
6
431
Two RSA factoring records fell in 16 days this month, both with AI agents writing GPU code. Your RSA-2048 encryption is fine. No need to panic. RSA-896 was factored on September 19 by Stephen Weis at Anthropic, using Claude on 2,048 idle GPUs. On September 3, Eric Lu at Cognition factored RSA-260 with Devin. Both ran the same number field sieve on spare GPU capacity. At this month's efficiency, 2,048 GPUs would need about 500 million years to factor RSA-2048. Breaking it is still a job for a quantum computer. That doesn't exist yet. RSA-1024 is about 30 times harder than RSA-896. At the same GPU prices, that is roughly $28 million and five months on 2,048 dedicated GPUs. NIST deprecated 1,024-bit RSA in 2014, but the keys are still around: DKIM email-signing records, archived TLS sessions, firmware burned into devices. Find them and rotate what you can. But the classical approach to breaking RSA-2048 is still not feasible. My full analysis: postquantum.com/security-pqc… #Cryptography #RSA #PostQuantum #PQC #Cybersecurity #CISO #QuantumComputing #InfoSec
3
2
9
630
China published 119 candidates for its next generation of cryptography standards on September 20. Within three days there were 104 public findings against 65 of them. An AI-assisted sweep found most of the bugs. The actual design breaks came from cryptanalysts. Markku-Juhani Saarinen's AI-assisted sweep of the submitted code produced 64 findings across 48 candidates: a signature verifier that accepts any signature, key generators that ignore their random seed, decapsulation checks that hand back the real shared secret. Every one of those implementations passed its own known-answer tests. All six practical design breaks arrived on day two. A single Tins signature reveals the signing secret. The Facto-DSA-128 public key gives up a signing trapdoor in seconds. The MoFang and Neulaser hash functions collide at full rounds. Tsinghua Hash Lab and a team at the Chinese Academy of Sciences posted the hash attacks on ICCS's own public forum, and one of the day-two researchers also disclosed AI assistance. The division of labour this week was breadth from the AI-assisted sweep and depth from people working one scheme at a time. I expect every open standards competition to get both from now on. Nothing deployed is affected, and ML-KEM and ML-DSA are untouched. Also, I have to admit that I was wrong. Last year I expected China's post-quantum competition to be less open than NIST's, with submissions and analysis hard to see from outside China. I'm glad to see that I was wrong. ICCS published all 119 first-round candidates on September 20, with English specifications, source code, a common programming interface and public forums for comment. postquantum.com/security-pqc… #PostQuantum #PQC #Cryptography #Cryptanalysis #Cybersecurity #AISecurity #China #QuantumSecurity
2
4
14
483
A bank in Tel Aviv was told twenty months ago to take a quantum plan to its board. A utility in Ohio has never been asked. Same threat. (Almost) same NIST algorithms. Four very different PQC migration approaches globally. I tried to compare these PQC migration approaches, fresh from GISEC in Dubai and ahead of my related closing keynote at the PQC Summit in College Park on Tuesday. Some of what I found: Hong Kong's regulator scored its banks 2.3 out of 10 in July and set a target of 10 by 2030. FINMA surveyed 60 Swiss institutions, found 72% had taken no quantum-safe measures, and demanded board-backed roadmaps by mid-2027. The three NERC CIP standards shaping a US utility's 2026 compliance year say nothing about post-quantum cryptography. Not one. Canada put PQC clauses into every new federal contract in April. The US equivalent is still a rulemaking. Germany has recommended FrodoKEM and Classic McEliece alongside the NIST picks since 2020, and Europe got them into ISO in June. Chrome will accept only Merkle Tree Certificates in its quantum-resistant root store, while Europe's eIDAS trust lists are built on X.509. The post-quantum PKI can fork along a line that already exists in law. And nobody, anywhere, has enforced a PQC requirement yet. The full comparison, with a one-page table by jurisdiction and five things I think each migration could borrow from the others: postquantum.com/post-quantum… #PQC #PostQuantum #QuantumComputing #CyberSecurity #CISO #InfoSec #Regulation #CryptoAgility
3
2
6
967
Quantum capability has doubled about every 1.4 years at Quantinuum and every 2.1 years at IBM since 2018. Roadmaps promising scientifically useful machines in the early 2030s need that rate to quadruple. That number comes from a new benchmark out of Sandia National Laboratories, published with Quantinuum and NVIDIA. It is called QUOPS, and it measures physical qubits and error-corrected logical qubits on the same scale, which nobody had managed before. The result that should change how you read press releases came from one machine in two configurations. Quantinuum's Helios-1 scored 1,504 on physical qubits. The same ions running error-corrected logical qubits scored 40. Roughly 2.7% of the capability, same hardware, same lab, same summer. The authors are careful to say this is the cost of one deliberately simple code rather than the cost of fault tolerance in general. It is still the most clarifying measurement published this year, in a field where "we now have logical qubits" has become a press release genre. One finding inverts a common assumption. Google's Willow already runs fast enough for the workloads the paper benchmarks against, by three to four orders of magnitude. What it cannot do is finish a large enough circuit. My full analysis, including why Quantinuum co-authoring a benchmark its machines top matters less than it first appears: postquantum.com/quantum-rese… #QuantumComputing #QuantumBenchmarking #FaultTolerance #QuantumErrorCorrection #Quantinuum #Sandia #QuantumHardware #DeepTech
1
11
32
2,081
Last Thu I was in Dubai watching a regulator run a live quantum incident drill for supervisors. On Tuesday I'm in College Park closing the PQC Summit event (which runs the day before Quantum World Congress at the same place). Same threat and (mostly) same algorithms, but the approach to PQC migration differs around the world. I'll try and cover that. My talk is A Global Update on PQC Migration, and the short version is this: the U.S. leads on standards, on binding deadlines and on internet-layer deployment. What it doesn't lead on is binding instruments for banks, utilities and hospitals, the treatment of migration as an enterprise transformation rather than an algorithm swap, and the sovereignty question that allies discuss with each other and not with Washington. I'll bring what I see across clients in the Middle East, Europe, Asia and the Americas: Canada's contract clauses, Europe's certification and market-access gates, supervisors writing to boards in Tel Aviv, Hong Kong and Zurich, China running QKD underneath its own algorithms. And the honest finding that no regulator anywhere has enforced any of it yet. Dustin Moody and Bill Newhouse open the morning. Britta Hale, Robert Campbell, Debbie Taylor Moore, James H. Dickerson, George Thomas and Garland Garris are in between. Strong lineup, and worth the early start. Agenda: quantumworldcongress.com/PQC… #PQC #PostQuantum #QuantumComputing #CyberSecurity #CISO #InfoSec #QuantumWorldCongress #Regulation
1
2
474
Data centers in space are a stupid idea. Quantum AI data centers in space are a way stupider one. I have wanted to write this for two years, and an investor's question finally gave me the excuse. In vacuum, the only way to shed heat is radiation. Starcloud's 5 GW proposal needs 10 square kilometers of radiator, about three times Central Park, plus 16 square kilometers of solar panels. So, in short, for this to work we need a structure with the footprint of half of Manhattan and the weight of a Nimitz-class aircraft carrier - seven times the mass of everything currently in Earth orbit combined, parked in a debris field where fragments arrive at 10 km/s, taking hundreds of debris hits a day, with 69,000 kilograms of pressurized glycol per second flowing through the pipes behind those radiators. At 2025's record launch rate, lifting it would take every rocket on Earth 35 years. Every strike on one of those pipes is a catastrophic rupture, not a leak - and at this size it would be hundreds of them per day. No crew. No repair vehicle exists... Few people tried to model the costs and optimistically concluded that orbital compute is 3x to 10x terrestrial. They did not consider one tenth of what is really needed - the coolant plumbing, the 350 GPUs a day that fail under training load and cannot be swapped, the deorbiting of 100,000 tonnes, the resonance problem, and many others. Add those and the real cost for the Starcloud's proposed data center could run in trillions of dollars. And this idea got funded hundreds of millions of dollars? Then someone proposed putting superconducting quantum computers up there. Millikelvin cryostats. Helium-3 from weapons stockpiles (500 fridges would eat two thirds of world supply). Daily calibration by people who cannot reach the hardware. Cosmic rays that crash error correction chip-wide. For a quantum AI advantage nobody has demonstrated on any commercial workload. Hyperscale orbital data centers are decades away, if ever. Nobody pitching quantum AI in orbit has solved a single one of the three problems it stacks. They are counting on the VCs not to ask and to be sufficiently impressed with the concentration of buzzwords. postquantum.com/quantum-comp… #QuantumComputing #DataCenters #AI #SpaceTech #VentureCapital #QuantumAI #OrbitalComputing #Starcloud #TechHype
7
2
15
994
"We migrated to ML-KEM. We're done." Migrated once is not migrated. ML-KEM is the first post-quantum algorithm you will deploy. It will not be the last. FN-DSA is still in development. SLH-DSA is already standardized but rarely deployed. Your regulatory timeline runs to 2031. The algorithm set will change, and when it does, you will need to change again. In v3.0 of the PQC Migration Framework, the end state is crypto-agility, not algorithm deployment. The program closes only when a second algorithm change has been rehearsed on Tier-1 systems inside the agility window. One rehearsal in the framework took 29 hours 30 minutes on the first attempt. The bottleneck was the decision queue, not the cryptographic engineering. Every algorithm change after the first one should cost less. That's the principle in my updated framework that puts crypto-agility first. pqcframework.org, CC BY 4.0. #PQC #postquantum #cybersecurity #cryptography #infosec #quantumcomputing #cryptoagility
1
6
413
I fact-checked The Economist's quantum computing primer, the best mainstream coverage I've seen. It still gets several things wrong that matter for migration planning: Shor's algorithm breaks RSA, ECC, and Diffie-Hellman. Not "many types of encryption." AES-256 is safe. That distinction is worth billions in correctly scoped migration budgets. IBM's Nighthawk (120-qubit advantage chip) and Starling (200-logical-qubit fault-tolerant system, 2029) are different machines. The article implies one path. Google's Willow "task in hours" was the Quantum Echoes OTOC experiment. The below-threshold error correction result, the actual milestone, appears later with no connection. McKinsey's $600B quantum finance forecast is reprinted without the caveat that its published arithmetic doesn't reproduce from its own inputs. If even The Economist gets this wrong, check your sources on every quantum claim you see. postquantum.com/industry-new… #QuantumComputing #PQC #Cybersecurity #InfoSec
2
1
11
692
Good piece on the WEF platform about why PQC migration keeps stalling despite NIST finalizing standards two years ago. The answer isn't apathy. It's architecture. PQC has to move through the entire stack (silicon, firmware, OS, applications, cloud, network) and every layer waits on the layer below it. Miss one and the system looks migrated but isn't. Critical infrastructure operators face this worst: long-lived assets, regulated environments, globally sourced equipment. What they procure this year locks in their quantum security posture for a decade or more. weforum.org/stories/cybersec… #PQC #Cybersecurity #QuantumSecurity
1
3
387
WEF Top 10 Emerging Technologies 2026 puts PQC and quantum simulation on the same list. First time two quantum related entries have appeared together. The signal is right. The details need work. NIST's evaluation: 8 years, not "2 years." The IBM/Moderna milestone: mRNA structure prediction, not protein folding. The terminology: "hybrid classical-quantum" is wrong; it's hybrid classical/post-quantum. And calling the entire PQC field "lattice-based cryptography" misses the point. NIST built a diversified portfolio on purpose. Full fact-check: postquantum.com/industry-new… #PQC #QuantumSecurity
3
617
At most cyber conferences, AI gets all the attention. Quantum gets one panel on the final day. In a side room. GISEC in Dubai - the largest cyber event in the Middle East and Africa and the world's third largest cyber event - just went the other way. I was in Dubai to talk about PQC migration in large enterprises. Then I walked the exhibition floor properly. On vendor stands I saw almost as many mentions of quantum, Harvest Now Decrypt Later (HNDL), even Trust Now Forge Later (TNFL), as I saw of AI. To put that in perspective: just two years ago, I was explaining those exact acronyms on a 5-person panel... to an audience of four. GISEC programme was quantum focused too. The Quantum Security Summit took the whole final day on its own stage. The International Telecommunication Union and the UAE Cyber Security Council ran the Global Quantum Drill on 17 and 18 September. H.E. Dr Mohamed Al Kuwaiti, who heads the UAE Cyber Security Council and runs cybersecurity for the UAE government, said from the stage that today's conversation is AI and tomorrow's is quantum, then pointed out there was a whole venue of quantum at the event. He wasn't exaggerating. Credit where it's due. The UAE Cyber Security Council and the UAE's Technology Innovation Institute ran CyberQ as a standalone 2-day quantum security conference for two years, and I spoke at both. It was pioneering: one of the first events anywhere devoted entirely to quantum security. Folding it into GISEC this year was the smarter play. A quantum-only conference reaches people who already care. A quantum summit inside a 25,000-person cyber event reaches cyber pros who haven't started. Which is still most of them. That's a deliberate decision about how to move a market, and this region has a habit of moving earlier than most. Now heading to Washington DC for something else I've been looking forward to. More on that shortly. #CyberSecurity #QuantumComputing #PQC #GISEC #CISO #InfoSec
2
1
2
443
87% of organizations say they're pursuing PQC. 7% have actually deployed quantum-safe certificates at scale. DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT/cybersecurity leaders in the US, UK, and Australia. The execution gap is real, but the barrier data is what matters. Top challenge: legacy complexity (26%). Executive buy-in? 8%. Don't know where to start? 3%. This is no longer a persuasion problem. It's an execution problem. The report also completely ignores Trust Now, Forge Later. For a CA publishing a quantum readiness survey, the absence of any distinction between key establishment and signature migration is a significant gap. EO 14412 splits these into separate deadlines for a reason. Less than 2 points of deployment progress in a year. The deadlines will arrive first. postquantum.com/security-pqc… #PQC #QuantumSecurity #InfoSec
7
551
"Our vendors say they'll handle PQC. Do we really need our own migration program?" - Yes. Vendors update on their timelines, optimizing for their priorities. Without an internal program driving requirements, tracking commitments, and testing deployments, you have no control over your PQC migration timeline. "Our vendors will handle it" is a decision to outsource your timeline to someone with no obligation to meet it. Phase 7 of the PQC Migration Framework introduces firmness grades for every vendor date: committed, forecast, announced, unknown. A committed date has contractual weight. An announced date is a press release. Most roadmaps I have reviewed mix the two. Your regulator does not mix them. EO 14412 requires key establishment by December 31, 2030 for federal high-value systems. CNSA 2.0 requires new acquisitions from January 1, 2027. FINMA found only 8% of Swiss institutions with a PQC roadmap. The HKMA found roughly half of surveyed banks with no formal plan. A good way to start - check out the open, free, CC BY 4.0 PQC Migration Framework pqcframework.org #PQC #postquantum #cybersecurity #cryptography #infosec #riskmanagement #quantumcomputing
1
1
5
521