
Don’t Fear The Future: How To Prepare For The Post-Quantum World
In Partnership With

You’ve got to feel for the average (or even the well-above-average) cybersecurity leader. Assailed from all sides by threat actors turbocharged and enabled by large language model so-called “AI” tools, expected to achieve perfect defence of the enterprise and its crown-jewel data even against first-of-a-kind or hitherto unforeseeable attacks, they also have to ensure the company complies with a plethora of different security standards and, depending on the industry, state-mandated regulations. Like everyone else in the enterprise, they’re used to being told to “do more with less”, but to make matters worse, whenever they go to the board to ask for more money for tooling they believe is essential to carry out these missions successfully, they have a total absence of the definitive metrics that would help them make a business case – because in security, your most important statistic is the zero in the box that tallies the number of incidents the company has experienced.
So you could forgive the cyber leadership cohort if they’d maybe not got much remaining bandwidth to spend time planning for notional threats that may arise a year or two down the line. But the coming post-quantum world – in which quantum chips arrive in the commercial realm, exponentially increasing the computational power available to all kinds of miscreant, and in the process obliterating the encryption that secures data, connections and identities – is the kind of existential threat that no prudent security manager can afford to ignore. Even postponing thinking about it could leave CISOs open to criticism that they’d been guilty of dereliction of a core duty.
This is no idle concern. Today’s encryption standards are not based on perfect mathematical solutions, but on making the mathematical problems encryption relies on too difficult to solve using current computing capability. Quantum chips will reduce the time that would be required to solve those problems from centuries to seconds – meaning not only that access controls cease to provide any protection, but also that encrypted documents that might have been stolen in the past can be opened and read in the future.
But the post-quantum threat is difficult enough to wrap your head around even if you’re comfortable thinking about encryption, keys and quantum computing theory. Explaining to the board why they need to devote time, internal resource, and – likely – significant money right now to addressing a problem that may not start to bite for a few years is another matter entirely.
This, though, is where startup One Intelligence have decided to park their tanks. The company, founded by mathematicians and cryptographers, reckons it has a solution that will quantum-proof businesses, with minimal downside, no new kit, and no specialist cryptographic knowledge needed. And in the process, it will also solve some of the biggest challenges that are already being faced by networked businesses, and which are already understood – and budgeted for – by responsible corporate leaderships.
After deciding they were ready to emerge from stealth mode, the newly de-cloaked One made their first public pitch to cybersecurity professionals via a RANT roundtable held in London in mid-July. The ensuing discussion proved eye-opening, sobering and – perhaps – encouraging, in more or less equal measure.
Severed Crossed Fingers
“I’d like to ask you, as we go through this tonight, that if you only remember one thing, it would be trust,” Brett Nakfoor, One’s global vice president of sales and marketing, said at the outset. “How do you solve for quantum, ransomware and AI attacks? Trust. We decided to solve the problem of quantum security – and we did, with a new class of math. We can mathematically prove that we can prevent quantum-computer and AI attacks. We are provably secure.”
Just as importantly, Nakfoor added, the solution One have come up with can be quickly and easily integrated into existing technology stacks and will not require customers to spin up new departments of specialist mathematicians, cryptographers or quantum experts to be able to successfully deploy it and manage it.
“We found out, luckily, that with this new math we could create a solution at the transport layer,” he explained. “Instead of putting security in afterwards, we decided to invert that. You can put more information into a packet, and deliver it all the way up from the transport layer – layer 3 – up to the human layer – level 7. But we’re all adding an eighth layer now – the AI agents.”
One’s concept solves that problem, too, Nakfoor said. The solution allows the user to “embed trust objects into an interaction before it starts,” he added.
“This opens up a whole new world of how you deliver solutions to your business,” he said. “What we’re positing is that we’ve commoditised the delivery of quantum security in our delivery of the software, and you can control all forms of AI in doing that. That’s a bold statement, but we’re happy to answer questions – and if you want to give us real-world examples, we’ll talk about how we can help fix them.”
What followed was an absorbing exercise in just that – as a high-level group of CISOs, BISOs and other senior security leaders outlined their current concerns and future fears, and, either directly or by implication, sought to discover how the One proposition might help them realign their businesses for this coming new world.
Pay Your Way In Pain
Rob Black, RANT’s host for the evening, opened up the discussion by asking attendees to describe the issues that were top-of-mind for them about post-quantum security. These early exchanges ran the gamut between immediate worries and long-term headaches, but also surfaced some scepticism over the extent to which specific companies or sectors might be exposed to certain dangers. As so often in cybersecurity, some argued, these ostensibly new and novel concerns may well just serve to remind organisations of the necessity of looking after some long-established basics.
“We have long-lived data, and shorter-lived data,” one security leader began. “If it’s only relevant and used for a short time then that’s OK – but we don’t have a solution for securing that long-lived data. We know we have to figure it out, but we don’t know how yet. And we don’t know how to work out how long that data might be of value to somebody.”
“We’re tackling that question as well,” another attendee said. ” It’s driven out of historic issues people have around data security. Without a decent understanding of what data you hold, and the metadata associated with it, you’d have a lot of work to do.”
There was also clear interest in one class of attack that, in a way, defies the passage of time. A patient attacker, able to identify data with a long useful lifespan, could steal or copy encrypted files now, and wait until quantum technology is available, and then decrypt it. Even businesses that may consider themselves to have little information that falls into that category may still have to consider it, as a third leader, whose company manufactures specialist physical devices, noted.
“Our own products are very cutting-edge technology – so we don’t have a massive issue [with harvest-now/decrypt-later] because the pace of change is very rapid: one of today’s blueprints, by the time you’ve figured out what to do with it, we’ve moved on,” they said. “However, our customers may take a different view. If they need to maintain their blueprints, those need to be retained securely for a very, very long time. So the data we collect for our customers is very important. And the moment you lose trust, the whole model evaporates.”
Hell Is Near
The issue of organisational or institutional awareness was also front-and-centre of mind for many in the room. Some felt the problem would be addressed in time, because a sense of urgency would emerge at corporate decision-making levels before too long, but organisations which tend to wait until they’re forced to change might struggle.
“Constantly having to explain the complexity of cryptography to the organisation is an issue,” one CISO said. “I think it’s an ongoing thing. Post-quantum will get everyone’s attention, from the CEO down, so everyone will be interested. Education goes hand in hand with it. I’m lucky enough to have a great crypto manager who manages this for us, but not everyone does. And – not wishing to tar everyone with the same brush – quite often those people who are good at crypto aren’t good at board presentations.”
“We’ve got people whose job is post-quantum, and people who manage crypto – they understand it really well. But is the organisation ready to understand? No,” agreed another senior security leader.
Black asked those around the table where they felt post-quantum security sat in their own, and their organisation’s, list of priorities. The first answer was, perhaps, a surprise.
“I was talking to someone from a regulator,” this security leader began. “They said it’s not a priority for them at the moment. There was a bunch of stuff they said we should be looking at, but they said that this isn’t in focus at the moment. Now, we don’t do things just because regulators tell us!” they laughed. “But it was an interesting observation.”
That good old favourite non-scientific data-gathering exercise – a quick show of hands – revealed that, among those in the room, no organisations currently viewed post-quantum security as their biggest concern, and a majority of those represented in the room worked for businesses which considered the threats posed by AI as their most urgent priority.
“The board’s got their hair on fire about it,” groaned one CISO. “At the moment, it’s all: ‘What are you doing about Mythos?'”
“A lot of board-level individuals can’t comprehend the impact post-quantum will have, but they can comprehend what AI can do,” another leader lamented. “It’s almost a race to the bottom – you must be doing better if you’re burning more tokens. Post-quantum is still abstract for them.”
“It won’t be tangible until someone gets badly burned,” another agreed.
Digital Witness
Mo Ali, One’s CEO, was peppered with questions about what One’s proposition entailed, how it worked, and where it ought to sit in security teams’ thinking. He stressed that a key challenge has been that, to date, cryptographic standards have relied on the mathematical problems inherent in them being too difficult for current computing capabilities to crack, whereas One’s approach has been not just to make the maths difficult to solve, but to ensure there is a known solution. Some attendees expressed concerns that, perhaps, One were seeking to alter some of the fundamentals on which current cryptographic solutions are based, but Ali was quick to correct this. The company isn’t changing anything, he argued: instead, they are “gluing things together.”
“The formal definition of ‘hardness’ is the problem,” he said. “We say, ‘This cipher can’t be broken because computing is not strong enough,’ then a couple of years later we say it can be broken. We’re defining post-quantum in a different way to what [U.S.-based standards body] NIST has done, but we’re still relying on the same fundamentals.”
Expanding on the point, he explained a little further about the approach the firm has taken. The company’s founders include people with backgrounds in quantitative trading, and some of their approach flows from that world.
“The quants said we need to rely on math,” Ali said, “but in cryptography, we don’t have quantitative cryptography. We need to know the force required to break it. Mathematically deterministic cryptography is harder, but that’s what we do. For years we’ve been using 128-bit blocks to encrypt – that means that the more we encrypt, the larger the keys, and the larger the key-management systems you need. We can encrypt an entire object – a database, a data centre – in one go. We made a programmable handshake, and we can embed policies in that handshake. We’re calling it Generative Trust Infrastructure.”
The terminology is important. Security specialists have long been aware of the concept of Zero Trust – and how difficult (if not impossible) it is to implement in any complete way. Generative Trust, ask Nakfoor pointed out, solves the problems Zero Trust implies because the “trust” element is “generated” at the inception, and baked in to the data at the point where it is created. And this means that the solution will work for agents created by AI tools, and every other entity or process, be it human or non-human.
“Machines have their own language, which is code,” Ali said. “Because we come from the high-frequency trading space, we really care about where information pops out for the first time. When it forms, we’re sitting there. That’s the intelligence part. You can’t solve Zero Trust because it’s assumption-based. We call it Generative Trust, because it’s generating trust across interactions.”
And by making it programmable – and easy to program – the company believes it has a solution not just to the post-quantum challenge, but to a host of current information-security problems, including securing AI systems and combatting ransomware.
“With a Generative Trust infrastructure, you can program ‘This is what I can do with this object’,” Nakfoor said. “If you’ve sent a document to me, I either obey your instructions [embedded in the document] or it isn’t usable. We can ensure it’s sent to the right person: you think you’re sending to me, but it goes to someone else – they wouldn’t be able to open the document because they don’t have the authorisation.”
“What we’re doing is building the world’s first foundational crypto model at the transport layer,” Ali explained. “It’s almost like an LLM – you can communicate with it using a prompt. You can write a command in plain English. If you have an AI at the application layer, and you want to encrypt all your databases, while leaving one cluster alone – just writing that prompt does it. You can create your own instructions. It controls LLMs in a formal, proofed way. It doesn’t hallucinate, or have the limits LLMs have. You can use version controlling, and encrypt infrastructure in real time.”