Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Commvault: Crypto Agility for Post-Quantum Readiness

Commvault
08/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


differentiate ourselves, right? Unlike traditional algorithms where it's like, okay, you increase the cipher sizes, change the cipher, crypto agility allows us to switch. And the reason why that's super important, and you mentioned ML, when NIST was going through and validating and making recommendations for FIPS 203, 204, and 205, there was an algorithm called Psyche. And it's really easy to remember, because if anyone was growing up in the 90s, we were all like Psyche, when you used to like fake someone out. It's really easy to remember, Psyche made it through three rounds, and then they were able to actually crack it with like a single core CPU. Oh, you just never know. And if we trace that philosophy back to Psyche, what we're even seeing today with HQC, which is another algorithm that uses a different mathematic computation. So KEM uses lattice, whereas HQC uses error correcting codes. NIST understands that if these mathematical calculations somehow get cracked, there needs to be a failsafe. So that's why crypto agility is super important. So when we were implementing PQC, we kind of saw the writing on the wall, even though HQC was one of those things that was still kind of not completely approved, and it's still not. It's probably going to end up being approved this year, or maybe early next year. They understood that when Psyche got cracked, they probably need a failsafe, and it needs different mathematical proofs. NIST is kind of doing the work to do that. And then if you've been watching the news, there's even another nine algorithms that they're kind of going through and putting them through its paces. So NIST is going to continually do that. So fast forward to what we implemented. We implemented MLKEM. We implemented MLDSA. And then we have a couple other algorithms that are not super optimized, but they're possibilities for us to switch to. And then we even have the ability to switch to HQC, just in case. So again, as these algorithms are being used to protect our pipelines and making sure that if data was exfiltrated, they are completely quantum resistant to today's standards. If those were to get cracked at some future point, for us, it's a flip of the switch. We can switch algorithms. Because of crypto agility and the way our encryption framework works, you would be able to re-encrypt the data with the new ciphers right out the gates. We're looking at that as fully protecting our customers' base, not only for today, but also for tomorrow. And then keep a close eye on what NIST is doing, so that as these changes in the landscape happen, whether they be more secure, or maybe there's optimizations that are made. Because again, you're going to need some compute, you're going to need some networking package changes like MTUs. Those things are going to happen. We continue to keep a finger on the pulse, just so that we can provide not only that optionality, but the best balance of security and performance for our customers to meet all their different needs.

TL;DR

  • Crypto agility means building the ability to swap cryptographic algorithms quickly, rather than committing permanently to a single post-quantum standard.
  • SIKE, a NIST PQC finalist, was broken by a single-core CPU after three evaluation rounds — proving that no algorithm should be treated as permanently secure.
  • Commvault has implemented MLKEM and MLDSA with the flexibility to switch to HQC and other algorithms as NIST's standardization process continues to mature.

Summary

In this short clip from Commvault's STRIVE series, Michael Fasulo makes the case for crypto agility as the cornerstone of any serious post-quantum cryptography strategy. Rather than treating quantum readiness as a one-time migration to a single approved algorithm, Fasulo argues that organizations must build encryption frameworks capable of switching algorithms on demand as the threat landscape and NIST standards continue to evolve. He illustrates the risk of static cryptographic approaches by referencing SIKE (Psyche), a post-quantum candidate that survived three rounds of NIST evaluation before being broken by a single-core CPU — a stark reminder that no algorithm is permanently safe. Fasulo also highlights HQC, an error-correcting-code-based alternative to lattice-based KEM schemes, which NIST is advancing as a mathematical failsafe. Commvault's implementation of MLKEM and MLDSA, alongside the ability to switch to HQC and other candidates, is presented as a practical embodiment of crypto agility — enabling customers to re-encrypt data with new ciphers at the flip of a switch. The segment closes with a commitment to tracking NIST's ongoing evaluation of nine additional algorithms, balancing security strength with real-world performance considerations such as compute overhead and network MTU changes.

Chapters

0:00 - Why Crypto Agility Matters
0:27 - The SIKE Cautionary Tale
0:46 - HQC and NIST's Failsafe Strategy
1:50 - Commvault's PQC Implementation

Key Quotes

0:35 "Psyche made it through three rounds, and then they were able to actually crack it with like a single core CPU."
1:05 "NIST understands that if these mathematical calculations somehow get cracked, there needs to be a failsafe."
2:19 "If those were to get cracked at some future point, for us, it's a flip of the switch. We can switch algorithms."

FAQ

What is crypto agility and why does it matter for quantum readiness?

Crypto agility is the architectural capability to adopt, replace, or transition between cryptographic algorithms without redesigning the underlying security framework. It matters because post-quantum standards are still evolving — NIST continues to evaluate new algorithms and previously approved candidates can be broken, as happened with SIKE.

Which post-quantum algorithms has Commvault implemented?

Commvault has implemented MLKEM and MLDSA, both aligned with NIST FIPS standards, and has also built in the ability to switch to HQC and other candidates as they receive approval — providing a mathematical failsafe if lattice-based approaches are ever compromised.


Categories:
  • » Webinar Library » Commvault
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Zero Trust
  • AI & Machine Learning
  • Technical Deep Dive
  • Thought Leadership
  • Compliance & Governance
  • Post-Quantum Cryptography
  • Crypto Agility
  • NIST PQC Standardization
  • MLKEM and MLDSA
  • HQC Algorithm
  • Quantum Readiness
  • Encryption Framework Design
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Commvault: Crypto Agility for Post-Quantum Readiness

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  The Automation Escalation: Discovering the AI-Driven Underground Revolution

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Invisible Data: Understanding What You Can't Safeguard

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      The Automation Escalation: Discovering the AI-Driven Underground Revolution
                      https://www.truthinit.com/index.php/channel/2108/the-automation-escalation-discovering-the-ai-driven-underground-revolution/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: Understanding What You Can't Safeguard
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-you-cant-safeguard/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhancing Visibility and Control in Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhancing-visibility-and-control-in-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version