Blog

Unbreakable today does not mean unbreakable tomorrow

The word “unbreakable” has something reassuring about it. When a cybersecurity technology is presented as extremely difficult to bypass, when it rests on robust mechanisms, when it has been rigorously tested and complies with recognized standards, an organization can legitimately consider that it has excellent protection. The risk appears when that confidence in a high-performing technology progressively turns into certainty that the problem has been settled once and for all.

Cybersecurity operates in an environment where nothing is truly static. Technologies change, software is updated, infrastructures are transformed, uses evolve, and new vulnerabilities are discovered. Attackers' capabilities are advancing too, notably thanks to automation and artificial intelligence. An extremely robust protection today can remain effective for many years while eventually being affected by a new attack method, a poor implementation, a dependency that has become vulnerable, or simply by the transformation of the environment it had been designed to operate in.

The strategic question therefore goes beyond choosing the best protections available at a given moment. An organization must also develop the ability to understand, monitor, and evolve them. In a technology environment undergoing permanent change, adaptability itself becomes a security property.

Every cybersecurity architecture represents, to a certain extent, a response to the knowledge available at the time of its design. An organization knows certain vulnerabilities, assesses the adversary capabilities it can reasonably anticipate, chooses suitable technologies, applies recognized standards, and builds protection mechanisms matched to its risks. This snapshot may be excellent, but it begins to age as soon as the environment changes. A new vulnerability may be discovered, an application updated, a supplier may modify its infrastructure, an acquisition may add new systems, or an artificial intelligence may be given access to information no automated system previously had. Security therefore cannot be regarded solely as a state that has been reached; it must become a permanent capacity for adaptation.

This necessity becomes even more important as attackers evolve faster. Cybercriminals also benefit from technological progress. Automation can speed up certain analyses, artificial intelligence can assist in gathering information or creating personalized fraudulent campaigns, and synthetic content can make some manipulation attempts far more convincing. Operations that previously required a great deal of human time can progressively be carried out more quickly and at greater scale. The relevant question for an organization then becomes as much about the quality of its current protection as about the time needed to understand and master a new situation when it arises.

This capacity for adaptation nonetheless runs up against a reality well known in IT environments: the best technologies often end up becoming deeply embedded in operations. They are built into applications, tied to processes, learned by employees, and used by other systems that in turn become dependent on how they work. A few years later, replacing a component that has become fundamental can represent a complex, costly, and risky project. Technological dependency thus becomes a dimension of cybersecurity, particularly when the organization no longer has a sufficiently precise view of where a technology is used and which other systems depend on it.

Cryptography is an excellent illustration of this phenomenon. Cryptographic algorithms and protocols are embedded in the applications, certificates, APIs, devices, embedded systems, communications, and infrastructures that may remain in service for many years. When a change becomes necessary, the main challenge can then go far beyond selecting a new algorithm. It is first necessary to know which mechanisms are in use, where they are located, which data they protect, which systems depend on them, and what consequences replacing them could have on the rest of the environment.

This is precisely what crypto-agility seeks to resolve. It consists in developing the ability to identify the cryptographic mechanisms in use, understand their dependencies, assess their level of risk, and replace them progressively when circumstances require it. A crypto-agile organization does not claim to know today which technology will meet all of its needs in fifteen or twenty years. It prepares its architecture instead so that it will be able to change when a technological shift, a new vulnerability, or a new standard makes that transition necessary.

Preparing for post-quantum cryptography already puts this philosophy into practice. Some families of algorithms widely used today could eventually become vulnerable to sufficiently powerful quantum computers. The new post-quantum standards make it possible to prepare for that transition, but their strategic importance goes beyond replacing one generation of algorithms with another. Cryptographic mechanisms will continue to evolve after that transition. New vulnerabilities will be discovered, new standards will appear, and some technologies that look promising today will themselves be replaced. The durable competence therefore consists in knowing how to evolve rather than in seeking a solution one might consider final.

Post-quantum risk also has a present-day dimension when the information being protected must remain confidential for long periods. Encrypted data can be intercepted today and stored in the hope of being decrypted later, a strategy generally referred to as Harvest Now, Decrypt Later. Not all information obviously presents the same risk. Data whose value disappears after a few weeks has a very different profile from a trade secret, intellectual property, sensitive government information, or certain personal data that must remain confidential for several decades. Post-quantum preparation therefore begins with understanding information assets and how long their confidentiality must be preserved.

This approach reveals the strategic importance of inventory. An organization wishing to replace a technology must first know where it is used. In the cryptographic domain, this means knowing the algorithms, certificates, protocols, applications, APIs, devices, and systems that take part in protecting information. That knowledge must then be complemented by a mapping of dependencies in order to understand the possible consequences of a change. Modifying one component can affect several others and turn an apparently simple operation into a major project. A living inventory thus becomes far more than technical documentation: it is a map for understanding how the organization will be able to evolve.

The same logic now applies to artificial intelligence. Organizations are rapidly adopting new models, platforms, and agents whose capabilities can change considerably within a few months. The data these systems can access must be reassessed, their permissions must follow their responsibilities, governance rules must take new capabilities into account, and dependencies on certain suppliers or models must be understood. Building governance solely around the tool used today risks creating a new form of rigidity. A mature organization seeks instead to develop governance structured enough to master current uses and adaptable enough to incorporate the technologies that will appear tomorrow.

This ability to change is also an essential dimension of resilience. Cyber resilience is often associated with the ability to maintain certain operations during an attack and to recover quickly after an incident. That definition remains fundamental, but resilience also has a strategic dimension that plays out over a much longer period. A resilient organization must be able to replace a component that has become vulnerable, change a protocol, revoke access, adopt a new standard, migrate its data, or change suppliers while retaining sufficient control over its operations. The better it understands its dependencies, the more it can carry out these transformations methodically rather than under the pressure of a crisis.

Cybersecurity standards, certifications, and frameworks contribute directly to this capability when they are used as foundations for continuous improvement. They make it possible to structure practices, formalize responsibilities, establish controls, measure maturity, and facilitate governance. Compliance obtained at a specific moment nonetheless remains a snapshot of the organization and its environment. Risks, technologies, and dependencies will continue to evolve after the audit or certification. A mature approach therefore consists in using compliance to support a lasting discipline of reassessing controls, updating risks, and incorporating technological change.

This vision connects directly with Hypersecurity as Quantum Beyond defines it. In an intelligent, distributed, and continually changing environment, security must be able to evolve along with what it protects. Identity mechanisms, detection technologies, cryptography, infrastructures, artificial intelligence, governance rules, dependencies, and resilience capabilities form an interdependent whole. A change in one of these dimensions can alter the risk level of the others. Hypersecurity therefore seeks to develop an architecture capable of observing these changes, understanding their consequences, and progressively adapting the organization's posture.

From this perspective, one of the most significant mistakes would be to regard an excellent protection as a definitive one. A robust technology deserves to be used and recognized for its value, but it also deserves to be monitored and reassessed throughout its lifetime. Maturity in cybersecurity does not consist in constantly questioning every technology. It consists in anticipating that their relevance, their environment, or their level of risk will eventually change, and in preparing the organization to make that transition before it becomes urgent.

Organizations need robust technologies, strong authentication, encryption, segmentation, access control, monitoring, and architectures designed according to the best available practices. These protections remain indispensable. Their long-term value, however, depends on the organization's ability to understand how they evolve and to adapt them when knowledge, technologies, threats, or its own operations change.

The cryptographic transitions ahead illustrate this reality particularly well. A durable post-quantum strategy rests on knowledge of the cryptographic environment, mapping of dependencies, understanding of data exposure, prioritization of migrations, and the development of genuine crypto-agility. This philosophy goes well beyond cryptography: it can be applied to infrastructures, identity, artificial intelligence, suppliers, data, and the governance mechanisms that make up the digital environment.

At Quantum Beyond, our experts work alongside the IT, cybersecurity, and governance teams already in place to strengthen this capacity for adaptation. Post-quantum readiness assessment, cryptographic inventory, Crypto Asset Discovery, Crypto Dependency Mapping, analysis of Harvest Now, Decrypt Later exposure, crypto-agility assessment, and the preparation of transition roadmaps make it possible, among other things, to turn a future technological change into an effort that can be prepared for starting today. Our role is to bring a complementary perspective to teams that already know their environment deeply, so that they can better understand their dependencies and prepare the decisions that will have to be made tomorrow.

From a Hypersecurity perspective, this capacity to evolve becomes one of the fundamental characteristics of a mature organization. A durable architecture does not rest on the promise that its protections will remain unbreakable forever. It rests on knowledge of its environment, mastery of its dependencies, and the ability to evolve early enough that its protections remain matched to the risks they must control.

Because a truly durable protection is one designed to be able to evolve before it becomes insufficient.