Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Commvault: Crypto Agility for Post-Quantum Readiness

Commvault
08/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


differentiate ourselves, right? Unlike traditional algorithms where it's like, okay, you increase the cipher sizes, change the cipher, crypto agility allows us to switch. And the reason why that's super important, and you mentioned ML, when NIST was going through and validating and making recommendations for FIPS 203, 204, and 205, there was an algorithm called Psyche. And it's really easy to remember, because if anyone was growing up in the 90s, we were all like Psyche, when you used to like fake someone out. It's really easy to remember, Psyche made it through three rounds, and then they were able to actually crack it with like a single core CPU. Oh, you just never know. And if we trace that philosophy back to Psyche, what we're even seeing today with HQC, which is another algorithm that uses a different mathematic computation. So KEM uses lattice, whereas HQC uses error correcting codes. NIST understands that if these mathematical calculations somehow get cracked, there needs to be a failsafe. So that's why crypto agility is super important. So when we were implementing PQC, we kind of saw the writing on the wall, even though HQC was one of those things that was still kind of not completely approved, and it's still not. It's probably going to end up being approved this year, or maybe early next year. They understood that when Psyche got cracked, they probably need a failsafe, and it needs different mathematical proofs. NIST is kind of doing the work to do that. And then if you've been watching the news, there's even another nine algorithms that they're kind of going through and putting them through its paces. So NIST is going to continually do that. So fast forward to what we implemented. We implemented MLKEM. We implemented MLDSA. And then we have a couple other algorithms that are not super optimized, but they're possibilities for us to switch to. And then we even have the ability to switch to HQC, just in case. So again, as these algorithms are being used to protect our pipelines and making sure that if data was exfiltrated, they are completely quantum resistant to today's standards. If those were to get cracked at some future point, for us, it's a flip of the switch. We can switch algorithms. Because of crypto agility and the way our encryption framework works, you would be able to re-encrypt the data with the new ciphers right out the gates. We're looking at that as fully protecting our customers' base, not only for today, but also for tomorrow. And then keep a close eye on what NIST is doing, so that as these changes in the landscape happen, whether they be more secure, or maybe there's optimizations that are made. Because again, you're going to need some compute, you're going to need some networking package changes like MTUs. Those things are going to happen. We continue to keep a finger on the pulse, just so that we can provide not only that optionality, but the best balance of security and performance for our customers to meet all their different needs.

TL;DR

  • Crypto agility means building the ability to swap cryptographic algorithms quickly, rather than committing permanently to a single post-quantum standard.
  • SIKE, a NIST PQC finalist, was broken by a single-core CPU after three evaluation rounds — proving that no algorithm should be treated as permanently secure.
  • Commvault has implemented MLKEM and MLDSA with the flexibility to switch to HQC and other algorithms as NIST's standardization process continues to mature.

Summary

In this short clip from Commvault's STRIVE series, Michael Fasulo makes the case for crypto agility as the cornerstone of any serious post-quantum cryptography strategy. Rather than treating quantum readiness as a one-time migration to a single approved algorithm, Fasulo argues that organizations must build encryption frameworks capable of switching algorithms on demand as the threat landscape and NIST standards continue to evolve. He illustrates the risk of static cryptographic approaches by referencing SIKE (Psyche), a post-quantum candidate that survived three rounds of NIST evaluation before being broken by a single-core CPU — a stark reminder that no algorithm is permanently safe. Fasulo also highlights HQC, an error-correcting-code-based alternative to lattice-based KEM schemes, which NIST is advancing as a mathematical failsafe. Commvault's implementation of MLKEM and MLDSA, alongside the ability to switch to HQC and other candidates, is presented as a practical embodiment of crypto agility — enabling customers to re-encrypt data with new ciphers at the flip of a switch. The segment closes with a commitment to tracking NIST's ongoing evaluation of nine additional algorithms, balancing security strength with real-world performance considerations such as compute overhead and network MTU changes.

Chapters

0:00 - Why Crypto Agility Matters
0:27 - The SIKE Cautionary Tale
0:46 - HQC and NIST's Failsafe Strategy
1:50 - Commvault's PQC Implementation

Key Quotes

0:35 "Psyche made it through three rounds, and then they were able to actually crack it with like a single core CPU."
1:05 "NIST understands that if these mathematical calculations somehow get cracked, there needs to be a failsafe."
2:19 "If those were to get cracked at some future point, for us, it's a flip of the switch. We can switch algorithms."

FAQ

What is crypto agility and why does it matter for quantum readiness?

Crypto agility is the architectural capability to adopt, replace, or transition between cryptographic algorithms without redesigning the underlying security framework. It matters because post-quantum standards are still evolving — NIST continues to evaluate new algorithms and previously approved candidates can be broken, as happened with SIKE.

Which post-quantum algorithms has Commvault implemented?

Commvault has implemented MLKEM and MLDSA, both aligned with NIST FIPS standards, and has also built in the ability to switch to HQC and other candidates as they receive approval — providing a mathematical failsafe if lattice-based approaches are ever compromised.


Categories:
  • » Webinar Library » Commvault
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Zero Trust
  • AI & Machine Learning
  • Technical Deep Dive
  • Thought Leadership
  • Compliance & Governance
  • Post-Quantum Cryptography
  • Crypto Agility
  • NIST PQC Standardization
  • MLKEM and MLDSA
  • HQC Algorithm
  • Quantum Readiness
  • Encryption Framework Design
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Commvault: Crypto Agility for Post-Quantum Readiness

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version