AGP Picks
View all

Jim West urges action on quantum risk at ISACA GRC 2026

2 hours ago
By AI, Created 04:59 UTC, Aug 19, 2026, AGP -

Cybersecurity expert Jim West is speaking this week at ISACA and IIA’s 13th annual Governance, Risk, and Control Conference in San Diego and virtually. His sessions push GRC leaders to move from awareness to concrete planning on quantum cryptography, layered defenses and broader cybersecurity strategy.

Why it matters: - Quantum computing threatens the cryptography that protects long-life sensitive data, and West argues organizations need to act before attackers can decrypt what is being captured today. - The message reaches the people who can change policy and architecture: boards, risk leaders, auditors, CISOs and system owners. - The conference is aimed at governance, risk, control, audit and cybersecurity professionals who influence enterprise resilience.

What happened: - Jim West is speaking at the 13th annual Governance, Risk, and Control Conference, jointly presented by ISACA and The Institute of Internal Auditors, from Aug. 17-19, 2026, in San Diego and virtually. - West delivered two sessions at the conference. - One session was "The Encryption Endgame: Beating the Quantum Clock," focused on the governance, risk and operational impact of quantum computing on modern cryptography. - The second session was "The Art of War in Cybersecurity: Cybersecurity Strategy in an Ever-Changing Threat Landscape," delivered on the first day of the conference.

The details: - "The Encryption Endgame" was first created and delivered by West in 2017 and has evolved with the quantum threat landscape. - The session covers harvest-now/decrypt-later risk, sensitive long-life data exposure, weakening legacy public-key cryptography and the need for quantum-readiness roadmaps. - West’s core guidance is to secure sensitive communications now rather than waiting for a formal Q-Day announcement. - West also recommends building a complete cryptographic inventory and prioritizing remediation by how long data must remain protected. - West urges organizations to layer defenses using the NSA’s Commercial Solutions for Classified framework, built on the rule of two, alongside Zero Trust architecture. - West said Q-Day is not just a technology problem and called it a governance failure if organizations do not act. - West said encrypted traffic captured today may become readable in the future. - West said boards, risk leaders, auditors, CISOs and system owners should treat quantum security as a resilience, disaster recovery and trust-infrastructure issue. - The strategy session tied cybersecurity planning to 2,500-year-old guidance from "The Art of War." - Attendees can find more detail in West’s book, The Art of War in Cybersecurity, which expands on the presentation themes.

Between the lines: - West is positioning quantum risk as an enterprise architecture and risk management problem, not just a cryptography upgrade. - His approach blends technical controls with governance, recovery planning and layered architecture, which signals that post-quantum migration is likely to be a multi-year program. - The emphasis on CSfC and Zero Trust suggests a bridge strategy while formal post-quantum cryptography standards continue to mature. - West’s background, certifications and continuing education volume are being used to underscore that the topic cuts across multiple domains, from cryptography to defense operations. - His recent writing in ISACA Journal and GRC Outlook reinforces the same message: crypto-agility, hybrid migration, certificate reissuance, key rotation and third-party readiness matter now. - A profile in CP Magazine highlighted his broader, cross-framework approach to cybersecurity and his warnings about harvest-now/decrypt-later attacks.

What's next: - Organizations that have not started a cryptographic inventory or migration plan will face more pressure to do so as post-quantum standards advance. - West’s message suggests the next phase is execution: inventory, prioritize, engineer and govern dependencies before the threat becomes fully operational. - The conference’s virtual and in-person format extends that guidance to a broad risk and security audience beyond San Diego.

The bottom line: - West’s central warning is simple: the quantum clock is already ticking, and waiting for Q-Day is a losing strategy.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Cryptocurrency Insider Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Cryptocurrency Insider Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.