← Latest papers
💻 computer science

Post-Quantum Discovery as a Governance Capability: Evidence-Based Cryptographic Visibility and Exposure Prioritisation in a Critical Service Provider

This paper argues that post-quantum cryptography readiness for critical service providers should be treated as a governance capability, demonstrating through a European case study how evidence-based discovery and structured exposure prioritization transform cryptographic uncertainty into measurable accountability to support risk-based decision-making.

Original authors: Jelena Zelenovic, Leila Taghizadeh, Edoardo Pena-Gonzalez, Jaime Gomez Garcia, Bart Preneel

Published 2026-05-19
📖 5 min read🧠 Deep dive

Original authors: Jelena Zelenovic, Leila Taghizadeh, Edoardo Pena-Gonzalez, Jaime Gomez Garcia, Bart Preneel

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: The "Post-Quantum" Problem

Imagine your organization is a massive bank vault filled with secrets. For years, you've locked these secrets with a specific type of high-tech lock (current cryptography). However, scientists are building a "super-key" (a quantum computer) that will eventually be able to pick any of these locks.

The scary part isn't just that the super-key will exist in the future; it's that bad guys are already stealing your locked boxes today and hiding them in a warehouse. They plan to wait until the super-key is ready, unlock the boxes, and read the secrets. This is called "Harvest-Now, Decrypt-Later."

To stop this, you need to swap your old locks for new, quantum-proof locks (Post-Quantum Cryptography). But here is the problem: In a giant organization, nobody actually knows where all the locks are, who owns them, or how hard they are to change.

The Paper's Main Idea: "Discovery First"

The authors argue that before you start swapping locks, you need a governance capability called Discovery.

Think of this like a Home Inspection before you buy a house. You don't just start painting walls; you first need to know where the pipes are, which rooms are damp, and who owns the property.

The paper presents a real-world case study of a large European service provider (like a mix of a postal service, bank, and ID issuer) that did exactly this. Instead of guessing, they used tools to scan their entire digital infrastructure to create a "map" of every single lock they use.

The Core Tool: The "Quantum Exposure Register" (QER)

The authors created a special spreadsheet (a register) to organize their findings. They call this the Quantum Exposure Register (QER).

Imagine this register as a Triage Board in a hospital emergency room. Instead of treating every patient the same, the doctors prioritize based on how sick they are and how long they have been waiting.

The QER sorts every digital asset (like a customer database or a payment system) based on three questions:

  1. How critical is this? (Is it the heart of the business?)
  2. How long do we need to keep it secret? (Some secrets need to stay safe for 15 years; others only for 2 years).
  3. How hard is it to change the lock? (Can we change it next week, or does it take two years and a vendor's permission?)

The "Mosca Inequality": The Math Behind the Panic

The paper uses a simple formula to decide what needs fixing right now. It's like a countdown timer:

Time to keep the secret + Time to change the lock > Time until the Super-Key arrives

If the answer is YES, you are in danger.

  • Example: If you need to keep a secret safe for 15 years, and it takes 5 years to change the lock, but the Super-Key arrives in 8 years... You are in trouble. You won't finish changing the lock before the bad guys get the key.

The paper shows that by using this formula, the organization could instantly see which 12 critical services were in immediate danger and needed to be fixed first (Wave 1), while others could wait (Wave 4).

What They Found: The Three Big Surprises

When the organization went looking for their locks, they found three major problems that stopped them from just "swapping the locks":

  1. The "Hidden Lock" Problem (Fragmented Ownership):

    • Analogy: Imagine a building where the front door lock is owned by the janitor, the back door lock is owned by the IT guy, and the safe lock is owned by a vendor who lives in another country.
    • Finding: Nobody knew who was responsible for which lock. About 40% of the locks had no clear owner. You can't fix a lock if you don't know who has the key to the toolbox.
  2. The "Blurry Photo" Problem (Uneven Evidence):

    • Analogy: Some parts of the building were well-lit, so you could see the locks clearly. Other parts were dark and dusty (old legacy systems), so you could only guess where the locks were.
    • Finding: They had to assign a "Confidence Score" to their findings. Some locks were 100% confirmed; others were just educated guesses. This helped them avoid wasting money fixing things that didn't need fixing or ignoring things that did.
  3. The "Vendor Dependency" Problem:

    • Analogy: You own the house, but the locks were installed by a company that says, "We will change the locks in 3 years, but we haven't decided on the new model yet."
    • Finding: Many critical systems relied on outside suppliers. The organization couldn't fix their own locks until the suppliers promised to provide new ones. This meant the migration plan had to wait on the suppliers' schedules.

The Solution: A New Way to Govern

The paper concludes that Discovery is not just a technical task; it is a management tool.

By turning a chaotic mess of unknown locks into a structured list (the QER), the organization could:

  • Stop guessing: They knew exactly what they had.
  • Prioritize: They focused on the "Time-Exposed" items first.
  • Assign Accountability: They forced teams to say, "I am responsible for this lock."
  • Plan Realistically: They understood that some locks take longer to change than others.

Summary

This paper says that getting ready for the quantum future isn't about picking the best new lock first. It's about taking a flashlight into the dark corners of your organization, making a list of every lock you have, figuring out who owns them, and using a simple math formula to decide which ones to change today to prevent your secrets from being stolen tomorrow.

Without this "Discovery" step, any plan to upgrade security is just a guess. With it, it becomes a manageable, evidence-based project.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →