Securing Tomorrow’s Cloud: Strategy for PQC Readiness

Securing Tomorrow’s Cloud: Strategy for PQC Readiness

Source: YouTube · SANS Cloud Security · published Oct 30, 2025 · 26:43

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

Post-Quantum Cryptography (PQC) demands immediate action because adversaries are stockpiling encrypted data to decrypt once quantum computing matures around 2030, and most organizations need 3-4 years to execute a migration 0:28.

Key Takeaways:
• The "harvest now, decrypt later" threat targets RSA and ECC, which quantum computers will eventually break; AES with sufficient key length remains safe 0:28.
• NIST has standardized quantum-safe algorithms—Kyber for key establishment and Dilithium, Falcon, and SPHINCS+ for signatures—that organizations must adopt 0:28.
• Cloud providers are upgrading KMS and certificate services, but shared responsibility means you must still protect your own VMs, containers, and applications 0:28.
• OpenSSL 3.5 is a critical implementation trigger, with OS vendors like Red Hat planning adoption by late 2025 or early 2026 0:28.
• Migration requires phased execution: secure buy-in and budget (3-4 months), inventory and assess all crypto assets (12-24 months), then implement using hybrid approaches for legacy systems 0:28.

With Q Day potentially arriving by 2030 and historical crypto migrations taking up to a decade, organizations must start inventorying their cryptography and building a migration roadmap now 0:28.

Sources:

  • 0:04 Speaker introduces SEC 502 cloud security class
  • 0:19 Speaker's background in healthcare and enterprise consulting
  • 0:28 PQC introduction and full quantum threat discussion
  • [0:40](h

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Uh quick introduction again. Uh I teach uh SEC 502 which is the uh cloud security tactical defense class. If you're familiar with that, I'll be here teaching that. So looking forward if you're one of my students, I hope to see you there. So without further ado, um a little bit more about me. Uh worked in the healthcare industry. Uh actually I have a a a a partner in crime back there that I used to work with. Thanks for joining us, Andy. I appreciate that. Um, basically PQC. How many of you have heard of that? Any raise of hands? Well, oh, good. All right. That gives me an idea where you're coming from. If you haven't heard about it, that's what we're here to show you about. All right. So, I've been told it's really good to start a presentation with a joke, especially when the topic is a li…