Post-Quantum Cryptography is a “Board-Level Survival” Issue
We’ve spent 15 years telling ourselves that quantum computing is a “future problem,” but as a Quantum Security 25 leader and Qrypt CTO Denis Mandich makes clear, Q-Day is no longer a distant sci-fi fantasy—it’s an imminent deadline for global economic survival. From the silent gathering of “Harvest Now, Decrypt Later” data to the devastating potential for nation-states to forge code-signing keys and hijack entire government agencies, the risk isn’t just about tomorrow’s math; it’s about today’s architectural fragility. If your C-suite hasn’t prioritized a 2029 migration deadline for your most sensitive data, you aren’t just behind the curve—you are essentially operating with a wide-open back door in a world that can’t afford to lose this race.
Transcript
Hey everyone. Welcome back here to Techstrong tv. Our next guest is Dennis Manic Mandich.
Dennis is one of the Secur Quantum Security 25 winners from our first, uh, list of the top 25 leaders in quantum security. First of all, Dennis, congratulations for making the list well deserved. And secondly, welcome to Tech Trunk TV For having me and putting me on the list.
That was a lot of fun to get that. You know, I, I gotta be honest, I was only one of, I think about five judges and, um, no one of us made, you know, a decision. It was done collectively.
But what was interesting is, you know, the, the way the process worked is first we went through our own list, then we shared that list with the other judges and the overlap from judge to judge to judge if, if I tell you, I think there were five or six names at the end that we maybe didn't make everyone's list, so to speak. And so it, it wasn't as hard as I thought it was gonna be with that amount of judges, which I guess it, it shows, you know, the, well, it shows one or two things, either there wasn't really a lot of people to choose from or, you know, the people that we picked really have set themselves apart as, as leaders here. Dennis, why don't, and that's a great segue.
Why don't we, if you don't mind, tell people how a little bit of your journey, a little bit of how you came to be a, a leader here in quantum security? Well, I'll start with kind of the middle, which is that the reason why your list is probably small is 'cause it's a small industry. There's a small number of people who can get into Quantum at all.
And my, my background is in, I'm a physicist by background, but I spent 20 years in the intelligence community and one of the things I saw in a couple of my last positions was the scale of IP theft by China from the US and the tools were available in the intelligence community. They were even available in some of the biggest companies, but they just didn't use them and they weren't really gonna be very helpful in the quantum era. And so back in 20 16, 20 17, we helped stand up the Quantum Economic Development Consortium, which is the national industry organization that we have today with only a couple of dozen companies now it's, you know, over 200 companies in the space, but that's still not huge compared to, you know, computer, uh, science, computer development, quantum computing and so on.
So we really helped stand up the industry so we're pioneers in this space, especially on the security side of it, which is probably why I ended up on the list because there aren't that many people that do what we do. Most people are just worried that, hey, Q day's coming, can we just update our algorithms, update TLS and so on? And that's just not gonna do it.
That's where really Crip comes in. Absolutely. You know, and the other thing though that we have seen as a result of going through this exercise, Dennis, is that I can't tell you when Q Day's gonna be here.
I'm not even sure I'll be able to tell you Q day's here when Q Day's here. It may be a little while after Q Day where I can look back and say, yep, you know, Q Day is here already, but it's no longer the five to 10 years out that we've been talking about for the last, I don't know, 15 years or maybe more. It's, it's sooner, you know, it's much closer on the horizon.
Where, where if we don't start taking, or maybe this is, uh, I'll ask you, should we be taking prudence steps now? Yeah. As you said, we won't know when Q Day is.
If it happens in China, we're gonna experience a deep seek type moment where they'll surprise us. The difference here is that China, since this is very broad implications for intelligence collection and optimization, operationalization of all the data that they're sitting on already, they won't tell anyone. They'll sit on that as long as possible to protect their sources and methods.
That's much higher priority than any money that they could make out of it. Or any data that they could exploit for diplomatic or military purposes, they'll sources and methods are more important than intelligence collection. Absolutely.
Very possible. A Q day, like you said, already happened and they've outspent the entire us, all of our industries combined. We have entire facilities in China dedicated to winning the quantum race at all costs.
They're gonna graduate tens of thousands of physicists to do that. And we're, we're behind in this race, and this is one we really can't afford to lose. Sounds like a rosy picture.
You know, it's, it was a tough news weekend, Dennis. Go easy on us. I don't have good News in this space.
Yeah, I mean, but but that being said, so look, I'm a, I'm a believer in global progress and you know, I think we're past the, the, the juncture where something pioneered in one country stays in that country, right. I, I think, I think in sharing information is probably the greatest thing the internet has done. Whether, whether you put up a firewall or, or what have you.
Information wants to be free at some level and somehow it makes itself out there. Um, talk to us a little bit, you know, so your background as you mentioned physicist and and intelligence, and talk to us kinda how you came up with the, you didn't wake up one day and say, God darn it, I want to co-found a company. No, No one does.
Um, and I, I've done a few of them myself, believe me. But tell us kind of the, the origination story, if you will, for crypt. The always, um, in these interviews, I quote General Alexander, who's the head of the NSAA little more than 10 years ago, and he came out and said it, look, this is the greatest transfer of wealth from one country to another in the form of IP theft.
And we don't know if we survive this as the world's global economic superpower, but you can only give up so much of your industry to another country before you become second. And, uh, my position is I have three kids, I don't want them to have to work for Huawei one day. And so I felt that we had to bring something to market that would really solve this problem that, you know, the intelligence community enjoys extraordinarily powerful cybersecurity tools, encryption technologies that are not public, obviously.
And we want to bring something like that to industry that would really solve this problem once and for all. I don't think people realize that the cryptography that we've been using and that we're about to upgrade is 1970s technology. It was made for telecom networks and infrastructure when a handful of copper wires and switches connect to people, not the world we live in today.
And that's really what we wanted to do. We wanted to bring something that even if this next generation of algorithms completely fails, which is likely we're told to be crypto agile, they'll likely be replaced in the future. That's no consolation for anyone whose data has been harvested and will be exploited at some point.
So we need to solve the architectural piece of changing the way we do business in cryptography. And that's where it really crip comes in. So you, you, you went my list.
So there, where do we, so what exact, how, how exactly is Crip doing this? How is it helping us? So in, in the past we always bundled the encryption keys and the data together in the same channel.
So you've probably heard Harvest now and decrypt later. Yep. Context of Q Day.
Well, that's been going on for generations, not has nothing to do with quantum meters. And the fact that you can do that at all to capture that data in an encrypted state and exploit it when a flaw is found in the way the libraries were implemented, the way we generated ease, the random numbers used for those systems, and then it's all packaged together to be able to decrypt in the future. At any point, when someone at Black Hat reveals a vulnerability that they discovered, that's not a good situation to be in when we have many other tools available to eliminate that mechanism entirely.
So if you think about public key infrastructure, the way we send every H-T-T-P-S session, every, uh, email, every text message that we do that is based on that older technology. And all we do fundamentally is distribute encryption keys in that channel. And what crypto does is eliminate the key distribution mechanism and we replace it with simultaneously generating keys at the end points.
So the keys are never in the channel and they're not correlated with the data. So even if somehow you're able to break any of those channels, it doesn't help you with decryption. So we eliminate the harvest now, decrypt later problem, even if these next generation of algorithms fail.
That's high level how we do it. Excellent, excellent. Um, Dennis, you mentioned before, who knows when Q Day comes.
Did it come your advice for people out here who are grappling, wondering, I mean obviously use craft, right? But beyond that, you know, what, what, what's your best advice for folks? I think it's, it's collectively, you know, we're all in this together and especially in your company, this isn't the CISOs problem or the CIO's problem, it's the entire company's problem.
It could be an existential threat for many of these companies. So treat it as a transition that we absolutely have to do. That's table stakes.
But start looking at cybersecurity in general. The, you know, where are the crown jewels of my company and how to protect that as a board level decision. It's the C-suite and the company, it's responsible and the board should force that on their own companies.
But broader, the US government's already said, look, if by 2030, in some cases, 2035, if you have not at least transitioned to post quantum cryptography, you can't do business with the US government. They're a Fortune Zero company. So it's incumbent on people using these tools and people building them to get on board with this.
If I'm buying, you know, Microsoft Office or Zoom, I'm gonna demand that they tell me what their roadmap is for post quantum cryptography and what other security protocols will you implement to make me and my communications more secure. 'cause I shouldn't trust anybody else anymore. Agreed.
You know, Dennis, one of the things I've heard from companies and talking about this is, well, you know, we already have quantum proof algorithms for our certificates. Our RSA kind of encryption. It'll be, it'll be okay as long as we upgrade to these post quantum algorithms and and so forth.
You know, this is like Y 2K, we're going to get all spun up about nothing. What do you say to those people? Well, I mean, even this has told us, look, we don't know if these algorithms are secure at all saying that they're quantum secure or quantum safe.
We don't know that that's true because we Haven't had a quantum computer or roton. Yeah, We might not even need one because of the two finalists that were in the NIST competition for standardization. The other stronger one was broken by a laptop computer by discovery from math that was in a paper in the 1970s and eighties.
Oh geez. So unfortunately the PQC items that were transitioning, there's no proof that there's secure at all. We're just hoping that, and since no one's broken them yet, that they will endure for some period of time before AI figures out how to do it.
Or even a bigger quantum meter comes online. That's a, a much deeper issue, which goes back to the heart of harvest now and decrypt later, which is we do not know if any public key infrastructure system can be made secure. So that's where cryp comes in, is really eliminate that entire model and change the architecture of the system so we don't have to rely just on a little bit of math and a handful of cryptographers who put it together to get security at all.
Agreed. Agreed. Well, you know, with everything else going on in the world, there's one more thing we could throw on the, on the pile.
I'm gonna put you on the spot. Last question. Okay.
When do you think this gets real? That we gotta do this? Like now?
Yeah, fortunately, uh, it's coming before 2030. If we're to believe the head of IPM Google, they've already heard this. It's, it's not theoretical.
This is coming faster than anyone ever thought. Uh, like you said in the beginning, you know, in the nineties we thought we had 20 years, you know, the timeline keeps shrinking every year as the increase in speed of developments grows, that timeline gets shorter and shorter. So it's gonna take a few years to get this done, so at least we can focus on our high priority data and finish that before 2029.
Sure. The cat videos and stuff, all that stuff can wait, but the really important stuff that's existential threats to our businesses has to be done now and again, it's not, you know, flipping a switch or upgrading library. It's a lot more complicated than that.
We've never done this before. The last transition was decades ago when the internet was tiny. We didn't have, the cloud didn't exist.
We're, we're in a much different world now. That's extremely complex. It's extremely interlocked with other systems that we don't even know about.
You know, ai now we need to get on this right now. If we're gonna finish by 2029 for our most important stuff, the other stuff's gonna take 10 years. Yeah.
You know what, we, I don't think we mentioned for people want to get more information on Crypt, where do they go? com. com Don't use auto.
Correct. 'cause it'll do C-R-Y-P-T Yeah. Dot com Unfortunately.
Uh, so I miss a lot of emails because people don't realize that's happening in their email address. But, uh, we're available on the, uh, on the internet. We're a lot of the big conferences will be at RSA and so on.
You can come meet with us there and we're happy to help you. We'll be there as well. Hey, Dennis, congratulations on making the Quantum Security 25 list.
You know, kudos to you and thanks for coming on here and talking with us today. Appreciate it. Thanks for having me.
Thanks for the reward. Nice meeting you too. Nice meeting you.
Uh, we'll be at broadcast Ali all week on the RSA. If you want to stop by Dennis Manic, co-founder, CTO Crypt here on Textron tv. We're gonna take a break.
We'll be back.