00:00:02 The IIA
The Institute of Internal Auditors presents All Things Internal Audit Tech.
00:00:07 The IIA
In this episode, Richard Penfield speaks with Corey Misamore about how quantum computing could soon threaten current encryption.
00:00:14 The IIA
They explore why harvest now decrypt later attacks mean organizations need to start preparing today and how internal auditors can evaluate quantum readiness.
00:00:25 The IIA
They also discuss cryptographic inventories and mapping what you have, third-party exposure and vendor risks, crypto agility and building flexible systems, and new regulatory developments on the horizon.
00:00:39 The IIA
Finally, they discuss practical steps organizations can take right now to prepare without overreacting.
00:00:47 Richard Penfil
Thanks Corey for taking the time to explain quantum computing.
00:00:52 Richard Penfil
How would you describe the difference between a regular computer versus a quantum computer?
00:00:58 Cory Missimore
So most computers that we have today from the massive data centers and supercomputers that you think like NSA and others, Amazon, Azure, even to the ones in our laptops, they all work on bits, a combination of zeros and ones.
00:01:13 Cory Missimore
So every time you send an e-mail, play a video,
00:01:16 Cory Missimore
recorded podcasts.
00:01:17 Cory Missimore
It's all just a variation of numbers of zeros and ones put together.
00:01:21 Cory Missimore
And it's a very long string.
00:01:24 Cory Missimore
That's a bit.
00:01:25 Cory Missimore
A bit is a zero or A1.
00:01:27 Cory Missimore
A quantum computer uses quantum bits.
00:01:30 Cory Missimore
Any bit is a coin that's constantly spinning.
00:01:33 Cory Missimore
It's both a zero and A1.
00:01:37 Cory Missimore
So it creates more possibilities of what it can analyze and do because it's not limited to one particular number or set.
00:01:45 Richard Penfil
I've talked to researchers throughout the years, just recently too, about when quantum computing will break the internet as we know it at least.
00:01:56 Richard Penfil
And the answer that I've gotten is always five years into the future.
00:02:01 Richard Penfil
So why should we care now?
00:02:04 Cory Missimore
The moment you describe it as a future technology issue or a future problem, you've kind of basically given every organization the idea to pump this issue.
00:02:14 Cory Missimore
But
00:02:15 Cory Missimore
reality is that it's closer than we think.
00:02:20 Cory Missimore
So the Global Risk Institute, which is based out of Canada, uses a mathematical theorem called Moskov's theorem, which has been globally accepted as the timeframe so when a cryptographically relevant quantum computer or a CRQC will become relevant into today's technology.
00:02:38 Cory Missimore
And what that basically means is the ability to break current encryption
00:02:44 Cory Missimore
and not hours.
00:02:46 Cory Missimore
Their best timeframe, which they really support back in 2025, is that there's a near 49% chance that by 2037, there'll be a CRQC, a cryptographically relevant quantum computer in production.
00:03:02 Cory Missimore
So when you think about that in that sense, 2037, that's less than 10 years from now.
00:03:07 Cory Missimore
Well, it's just a little over 10 years.
00:03:09 Cory Missimore
It's much sooner, I think, and the time to begin prepared for it is obviously now, not 10 years from now from when it actually happens.
00:03:19 Richard Penfil
Yeah, I think there's a quote, we always underestimate the long term, but overestimate the short term.
00:03:25 Richard Penfil
Where have you seen organizations lack visibility or accountability in regards to their encrypted data?
00:03:32 Cory Missimore
So there are three places, and honestly, they kind of compound upon each other.
00:03:36 Cory Missimore
First, almost nobody has what's called a cryptographic build materials, or a CBOM.
00:03:41 Cory Missimore
So based on the research and the maturity of the data that's out there, most organizations haven't documented this at all.
00:03:46 Cory Missimore
And I don't think that's enough on anyone, because until very recently, almost no organization had ever been specifically asked to produce an algorithm inventory.
00:03:56 Cory Missimore
It's legitimately like a new ask.
00:03:58 Cory Missimore
It's a layer to develop an old one, like a software build materials.
00:04:01 Cory Missimore
or even just an asset inventory.
00:04:04 Cory Missimore
It's just that it's now you need to add on another specific layer to it.
00:04:09 Cory Missimore
Second is really ownership.
00:04:10 Cory Missimore
Even where people sort of know where crypto lives, there's really a named person accountable for it, and is that the inventory's never truly kept up to date regularly.
00:04:21 Cory Missimore
You know, IT assumes security owns it, security assumes it's an IT operations question, and it falls into the gap between them.
00:04:27 Cory Missimore
And the single most revealing question you can ask isn't, do you know where your crypto is?
00:04:32 Cory Missimore
Everyone says yes to that.
00:04:34 Cory Missimore
It's, can you send me the document, the documentation?
00:04:36 Cory Missimore
That's actually what separates real governance versus a verbal assurance.
00:04:42 Cory Missimore
And third, and this is where a lot of people also miss too, is most organizations, cryptography doesn't live inside the organization.
00:04:50 Cory Missimore
It's in your core processor, your payment gateway, your cloud provider, your managed service providers.
00:04:56 Cory Missimore
So you can have an incredibly pristine internal inventory and still be fully exposed through a vendor who has not.
00:05:04 Cory Missimore
So if I had to take a signal at the lighting spot, that's it because we live in such an integrated and supply chain risk environment that is not just you need to be aware of and be confirmed on, it's all your third party vendors.
00:05:17 Cory Missimore
And so what I really think is the main issue is that quantum opinion isn't a mathematical problem saying that crypto agilic problem, it is a governance documentation and really a third party risk management problem.
00:05:28 Richard Penfil
To follow up on that, can you give us an example of a gap that you've seen and what exposure that organization might have?
00:05:36 Cory Missimore
Make sure an organization running a customer-facing platform.
00:05:39 Cory Missimore
Could be a bank, could be a hospital portal, could be an insurer.
00:05:43 Cory Missimore
using an old type of encryption to protect account numbers or personal records.
00:05:47 Cory Missimore
So that data have been legally retained for seven years, and nobody at that organization has been deemed the owner of the encryption that manages and protects it.
00:05:57 Cory Missimore
There's no documentation to take care of it.
00:06:01 Cory Missimore
Now, for managing that data from a quantum risk, you're going to really need a time to look at the Harvard's down to decrypt later approach.
00:06:07 Cory Missimore
So for those who are not familiar with Harvard's down to decrypt later is a
00:06:12 Cory Missimore
current ongoing persistent attack that the states in the world is where adversaries, be it from rogue nation states, be it from rifle leading companies, are collecting and managing data in a cold storage.
00:06:29 Cory Missimore
So they are collecting data being encrypted or unencrypted.
00:06:32 Cory Missimore
It doesn't matter to them.
00:06:33 Cory Missimore
They're trying to get as much data as possible so that when that CRQC computer is available,
00:06:39 Cory Missimore
they can break that information and collect all that data.
00:06:42 Cory Missimore
So we think about that then, the retention period becomes a crux for how much at risk of a gap or exposure backs or second basis.
00:06:54 Cory Missimore
It's that data that say that insurer a hospital or bank is having its personal and it's regulated.
00:07:01 Cory Missimore
And now that's meaningful retention.
00:07:03 Cory Missimore
Then with that,
00:07:05 Cory Missimore
high probability of a quantum computer being viable by 2037, that puts that potentially exposed data at risk and therefore that company's requirements to protect that data and the cost for that breach or exposure is exponential.
00:07:21 Cory Missimore
Then that's because the retention period alone puts any kind of records at risk if it breaches that period when a CRQC is potentially made viable.
00:07:31 Richard Penfil
So essentially it doesn't matter if we get to useful quantum computers within the next 5 or 10 years or next year.
00:07:38 Richard Penfil
It's what you're doing today with your data to protect it from that future state.
00:07:43 Cory Missimore
Absolutely.
00:07:43 Cory Missimore
Because again, so the Harvard's metric replator is actually now deemed a national security threat by the United States government.
00:07:51 Cory Missimore
They recently put out an executive order 14412
00:07:56 Cory Missimore
to address this risk.
00:07:58 Cory Missimore
For federal agencies and for fellow contractors, there is now strict deadlines to begin a migration to post-quantum encryption.
00:08:08 Cory Missimore
And the US is not alone in this.
00:08:11 Cory Missimore
The UK's NCSC board, ENISA, EU, and others have put out migration plans and requirements to migrate to a post-quantum encryption algorithm.
00:08:26 Cory Missimore
for a set period of time to address this prevailing draft horizon of the group later.
00:08:31 Richard Penfil
Is there current data that shows either nation states or attackers doing the harvesting?
00:08:36 Cory Missimore
So while there's no official publicized confirmations of set number of attacks being successful for a horizon of the group later, because there's no real way to endpoint that.
00:08:48 Cory Missimore
Because when you harvest data, particularly if it's encrypted,
00:08:51 Cory Missimore
There's no breach, notification, there's no instant or alert.
00:08:55 Cory Missimore
It's just captured data.
00:08:57 Cory Missimore
It could be a high, somebody got into our own system and they downloaded the data, that would be instant and notifiable.
00:09:03 Cory Missimore
But whether that's a nation state or external company or competitor, that information has not always necessarily made available or public.
00:09:14 Cory Missimore
But it is understood that it's a active attack being used by a lot of
00:09:20 Cory Missimore
various nations have the world against all of its competitors in various forms and areas of activity.
00:09:26 Cory Missimore
So it's understood, but I'll call a two or four having distinct number of say attacks by explanation to explanation.
00:09:34 Richard Penfil
So how as internal auditors, like what should we be looking for when assessing our organization and how they manage anything related to cryptography?
00:09:44 Cory Missimore
I boil it down to like 3
00:09:47 Cory Missimore
testable questions.
00:09:49 Cory Missimore
And nice thing again about all these three is that none of these require understanding quantum mechanics or the algorithm supporting it.
00:09:55 Cory Missimore
First, does a C-BOM exist, a cryptographic bill of materials?
00:10:00 Cory Missimore
If the answer is no, do you know, but we know roughly where crypto is, request the actual documentation.
00:10:07 Cory Missimore
If there's no documentation, that's the finding, full stop.
00:10:11 Cory Missimore
If there is a C-BOM or some kind of asset inventory that captures
00:10:17 Cory Missimore
the encryption link, the protocol, the algorithm being used, then validate that it's still accurate and current.
00:10:26 Cory Missimore
Because an adequacy bomb has a named owner, the bind scope, a completion date, and it uses a standard schema.
00:10:33 Cory Missimore
OWASP, the second one, DX, has a...
00:10:38 Cory Missimore
viable template that is acceptable worldwide.
00:10:42 Cory Missimore
So for those looking for a free template, I recommend to go to a loss model, because it's a great one to base off of, though again, you don't need to use it.
00:10:50 Cory Missimore
You need to have a preference inventory that has that cryptographic data attached to that.
00:10:56 Cory Missimore
Second thing I ask is, can algorithms be swapped without a full system rebuild?
00:11:02 Cory Missimore
That does go to the topic of what's like crypto agility.
00:11:05 Cory Missimore
It's a
00:11:06 Cory Missimore
really a third party question to disguise because for most systems, the honest answer depends on your vendor's architecture, not necessarily yours.
00:11:13 Cory Missimore
Because again, too, if the encryption being used is a configuration, that's a parameter you can change.
00:11:20 Cory Missimore
However, if it's hard coded into some more legacy systems, say 70 bits of encryption, then by default, post quantum encryption objects are just far larger than
00:11:33 Cory Missimore
you can simply just reconfigure that parameter for that system, get to do a complete full rebuild to add on that new encryption algorithm.
00:11:43 Cory Missimore
So you have first to see which one required the rebuild versus which is more of a creation change.
00:11:49 Cory Missimore
Thirdly is, does your migration plan actually pass the math test?
00:11:53 Cory Missimore
Again, going back to that hard percent of decrypt later map, was the substitute the data, was our attention period, and then what is the
00:12:02 Cory Missimore
probability you're using for when a CRQC computer is made viable.
00:12:07 Cory Missimore
So again, the GRI Institute in their report had a 27 to 49% chance within by between 2030 to 2037.
00:12:17 Cory Missimore
So if you are more risk adverse, you want to have as a higher probability of it being sooner than later.
00:12:25 Cory Missimore
But if you are a little more risk accepting, you can push that to almost 2037.
00:12:31 Cory Missimore
I personally use 2035 probabilities, which is our ground.
00:12:35 Cory Missimore
I think that like 38, 39% for your analysis because that date and percentage is tied to the executive order once more for 12, which provides a timeline to migrate to encryption, your digital signatures, and remove all legacy encryption algorithms from your environment 2035.
00:12:57 Cory Missimore
So it's a good benchmark to use.
00:13:00 Cory Missimore
PCI 4.0, control 12.33, actually requirements to have in cryptographic inventory.
00:13:07 Cory Missimore
So you're already halfway through the process if you're part of that regulation.
00:13:12 Richard Penfil
You mentioned third-party providers.
00:13:14 Richard Penfil
Can you go into more detail about how they could create a quantum exposure?
00:13:19 Cory Missimore
Data doesn't really just, you're one organization, the entire game of its life cycle.
00:13:24 Cory Missimore
You are utilizing third-party tools to
00:13:28 Cory Missimore
package and manage data to transfer to one party to the next into your business processes.
00:13:35 Cory Missimore
So while you may have a complete C-bottom, your inventory, and you're transferring data securely, if your third-party provider doesn't have that same level of rigor or support, they're the weak link.
00:13:52 Cory Missimore
Very similar concepts to, now again, if I want to get into the primary target, I may necessarily go through the front door, I'm going to go through the back door through one of your providers and compromise them, and in that way then I'll also get access to all this data I want to with less effort.
00:14:10 Cory Missimore
And that's again, the concept of this is that quantum technology is an amazingly cool technology.
00:14:16 Cory Missimore
It has promises to
00:14:18 Cory Missimore
revolutionize market analysis, making capabilities, so much more.
00:14:24 Cory Missimore
But what it boils down to is to say new technology that can be governed, documented, and managed through party risks.
00:14:31 Cory Missimore
So to how you manage any other kind of contract reviews or acquisitions, you would encryptions they're using put into your contracts, you will have post-call encryption utilized for your environment at rest and in transit.
00:14:45 Cory Missimore
and we will reserve the right to audit and you will provide us your updated CBOM or validations that these controls are put into place.
00:14:53 Cory Missimore
So there are already standard processes used for other risks.
00:14:58 Cory Missimore
Quantum technology and the risk opposed it is just another one added to that list.
00:15:02 Richard Penfil
It seems like these controls fit into some existing audits.
00:15:06 Richard Penfil
Is that the case?
00:15:07 Cory Missimore
The concept of creating a cryptographic bill of materials doesn't exist right now for PCI.
00:15:13 Cory Missimore
That is the only
00:15:14 Cory Missimore
specific regulation or framework that calls out the need to have this kind of activity or to have this information to prepare for the migration to post-colonal encryption.
00:15:26 Cory Missimore
Now, again, with the recent EO, if you are a federal agency or a fellow contractor, then you are not beholden to this timeline.
00:15:32 Cory Missimore
However, though, let's say you are a hospital.
00:15:35 Cory Missimore
So within HIPAA, there's this language that says reasonable technology and
00:15:41 Cory Missimore
actively pursue to protect information.
00:15:44 Cory Missimore
So, this goes back into managing that risk and that governance.
00:15:49 Cory Missimore
If your organization has deemed quantum technology as a risk that needs to be mitigated, then reasonable technology would be to create the C-BOM.
00:15:57 Cory Missimore
We did have a migration plant, begin to migrate into the various post-climate algorithms that have been repeated and.
00:16:06 Richard Penfil
Validated by NIST.
00:16:08 Richard Penfil
From the internal auditor's perspective, how would you recommend proceeding and providing value?
00:16:16 Richard Penfil
Are we supposed to be just monitoring these risks at this point?
00:16:19 Richard Penfil
Are we supposed to be advising?
00:16:21 Richard Penfil
What are your suggestions?
00:16:23 Cory Missimore
So it depends upon your industry.
00:16:25 Cory Missimore
One, first and foremost, an auditor should always advise.
00:16:28 Cory Missimore
100% we can advise.
00:16:30 Cory Missimore
Here is the new
00:16:33 Cory Missimore
regulatory landscape that we're aware of here is what we're seeing in the industries as best practices as peers or there again specific times or requiredness here's what we should be doing and here's where we should be finding validation in this control or just trying to find it and what to begin to mitigate and create problems to track it.
00:16:52 Cory Missimore
But beyond again to my knowledge of the payments and fintech industry with the PCI compliance,
00:16:58 Cory Missimore
or in the federal agencies and their contractors, there isn't anything binding framework or regulation that requires the direct application.
00:17:09 Cory Missimore
Unless, of course, you have business in the EU, of course, many nations, because again, in the EU, both with DORA and NIS2, there are actually specific call-outs to cryptography as a risk that needs to be managed.
00:17:24 Cory Missimore
So if you have business activities or processes,
00:17:28 Cory Missimore
that involve the EU, then you are now beholden to those regulations, which does require more of an emphasis internationally.
00:17:37 Cory Missimore
Singapore as well, New Zealand, Australia, they have also have post-qualification migration plans in place.
00:17:43 Cory Missimore
So there are other frameworks internationally as well to be aware of based on how you direct with other nations outside the US.
00:17:50 Richard Penfil
As things continue to progress, what should we be looking for?
00:17:54 Richard Penfil
Are there any signals
00:17:56 Richard Penfil
or warning signs that need to be on our radar.
00:17:58 Cory Missimore
A couple of things that we want to look for is first, watch for other algorithms failing.
00:18:03 Cory Missimore
So what I mean by that is, so NIST has for years now been evaluating some post-quantryption algorithms and they got the user testing, rounds for review, and we now have FIPS 203, 204, 205, which are very specific post-quantryption algorithms that people can begin to utilize and migrate to.
00:18:25 Cory Missimore
Now,
00:18:26 Cory Missimore
Two other encryptions being are Hawk and Falcon.
00:18:30 Cory Missimore
Hawk was recently broken by a classical computer powered by an AI Mythos.
00:18:37 Cory Missimore
I think that Mythos broke this encryption that had gone for two years of reviews and analysis within like 60 hours and just a little over, I think, $100,000 worth of tokens.
00:18:49 Cory Missimore
So for relatively low cost, this potential algorithm
00:18:54 Cory Missimore
was broken.
00:18:54 Cory Missimore
So that highly need that technology is potentially outpacing our capabilities to manage if we don't begin process sooner than later.
00:19:03 Cory Missimore
Now to get not too far into the mathematics behind it, the other algorithms are still secure because they use a different mathematical theorem to create their encryption.
00:19:13 Cory Missimore
So those are still secure, still viable.
00:19:15 Cory Missimore
But I'd be able to look out for as technology and capabilities increase, they are more algorithms becoming more susceptible.
00:19:22 Cory Missimore
Or are they bringing a student you've anticipated?
00:19:24 Cory Missimore
That's back into your live test, and that seemed like my research is that cyber insurers are starting to actually move on this more and more.
00:19:34 Cory Missimore
are taking this as a risk for an issue.
00:19:36 Cory Missimore
DAOs will provide this like, this is a issue that needs to address sooner or later.
00:19:39 Cory Missimore
There have been public statements this year from underwriters and major insurers that have to start asking about cryptographic inventories and migration plans directly as part of the underwriting.
00:19:49 Cory Missimore
When your insurance broker starts asking for a document, that uses a moment that it needs to become a formal audit engagement rather than an advisory one.
00:19:57 Cory Missimore
And again,
00:19:58 Cory Missimore
I also look for more regulatory guidance coming out.
00:20:01 Cory Missimore
Right now, there is a NIST IR 8547, which is in draft, that does provide guidance for migrating to those FIPS algorithms.
00:20:12 Cory Missimore
And once it's finalized, that has provided greater force and purpose to win it from the advisory to more to the audit engagement.
00:20:21 Cory Missimore
Now we have this NIST IR, we need to migrate, here's the guidance, let's go forth with what is a formal audit engagement.
00:20:28 Richard Penfil
Going back to mythos breaking one of the post-quantum algorithms.
00:20:33 Cory Missimore
Yeah, he was a pretty impressive.
00:20:35 Richard Penfil
I've always been optimistic that quantum computing would advance and help AI, but it seems like now we've already reached the point where AI is hardening some components to this post-quantum world.
00:20:49 Richard Penfil
So do you see like this compounding effect where they both feed off each other and grow together?
00:20:56 Cory Missimore
I completely agree.
00:20:57 Cory Missimore
I think quantum and AR are actually going to be really a powerful combination.
00:21:00 Cory Missimore
Because again, what AI can do is analyze most the outputs of all the quantum information.
00:21:07 Cory Missimore
Because again, quantum is that 01 simultaneously.
00:21:11 Cory Missimore
And we add on, and that's 1 qubit.
00:21:13 Cory Missimore
And you got to keep adding more more qubits.
00:21:14 Cory Missimore
But I think right now we're on like around like 1300 qubits.
00:21:18 Cory Missimore
And the goal potentially, according to Peter Schwartz algorithm in 1984 of breaking encryption is
00:21:26 Cory Missimore
to have around 4,000 qubits to our fault tolerant or error correction.
00:21:30 Cory Missimore
So we're getting closer and closer to that threshold.
00:21:33 Cory Missimore
So all those qubits working together will be able to figure out all those possibilities and do this all of analysis and have all this like raw data for that AI to kind of say, okay, now I have even more data to analyze, I have more possibilities to review, now I'm a good pile more.
00:21:48 Cory Missimore
So it's going to
00:21:49 Cory Missimore
basically give AI a supercharge and a ton more data and possibilities, then we now can create ourselves naturally.
00:21:56 Cory Missimore
So it's going to be a really interesting combination.
00:22:00 Cory Missimore
And excited Harvey is like, this is the possibilities are truly in my mind endless what this combination should really do and achieve.
00:22:07 Richard Penfil
Because things aren't moving fast enough already.
00:22:10 Cory Missimore
It definitely keeps you up at night, but at least it's exciting times too.
00:22:14 Richard Penfil
Without overreacting to the hype, what can we do to start preparing today?
00:22:21 Cory Missimore
Reasonable prep is actually the opposite of dramatic.
00:22:23 Cory Missimore
It's not a crash migration program.
00:22:25 Cory Missimore
It's an inventory.
00:22:26 Cory Missimore
I've always felt that for all these different technologies, anytime there's a new emergency technology, the core concept of like cyber hygiene, the basics.
00:22:34 Cory Missimore
still needs to be honored and completed and those are truly held to and maintained, then really any new add that technology is just a positive rather than a cost center or unknown risk and can't truly manage.
00:22:50 Cory Missimore
So start with your certification managers, you know, your DG search, your they'll have a ton of the material for your CBOM and it's pullable.
00:23:02 Cory Missimore
It's your gated to pull.
00:23:04 Cory Missimore
Then the overreacting, so you have to pull your data and start building out your CBOM.
00:23:10 Cory Missimore
You also then identify a owner of that CBOM of that friction fan.
00:23:16 Cory Missimore
I recommend somebody at like the CISO or equivalent level, someone with the authority to actually carry out the activity because not only do you want to have this information, you'll be to migrate appropriately based on
00:23:28 Cory Missimore
what the risks are.
00:23:29 Cory Missimore
Because again, the CPOM, it will capture all those algorithms and data per each system.
00:23:34 Cory Missimore
And then we add on, like, the harvest and interpolated score of that, which is the sensitivity times the retention times the probability of when a quantity will be in existence.
00:23:44 Cory Missimore
That gives you a risk factor to tie to that system that gives you an actual migration plan.
00:23:49 Cory Missimore
And so you do not say, oh, where should we migrate?
00:23:52 Cory Missimore
You now have
00:23:54 Cory Missimore
a targeted approach of most vulnerable systems or high-value systems for your company, you should migrate over to.
00:24:01 Cory Missimore
So again, use the method to prioritize and standard between everything that is equally urgent.
00:24:06 Cory Missimore
Not everything needs to be direct attention right away.
00:24:09 Cory Missimore
And again, be precise to your earlier question about what's really advice versus what's binding.
00:24:16 Cory Missimore
Again, right now, to my knowledge, there's only the EEO and PCI requirements that are explicitly calling for
00:24:23 Cory Missimore
in the US.
00:24:25 Cory Missimore
For international again, you added NIS2 and DORA.
00:24:29 Cory Missimore
And of course, for other international nations, there are other relations as well, Singapore, China has some, Australia, New Zealand.
00:24:37 Cory Missimore
So I don't know where you work, see what is the impetus that it has and have a virtual regulations.
00:24:43 Richard Penfil
Yeah, thank you again for the time.
00:24:46 Richard Penfil
Do you have any closing remarks or anything that you want to leave us with?
00:24:49 Cory Missimore
The future is really bright, and don't be scared by this because it's not a futuristic concept or future problem.
00:24:57 Cory Missimore
It is a problem that's coming, but it's a manageable problem.
00:25:00 Cory Missimore
It is something that can be governed and be documented and be managed to current risk frameworks we have right now.
00:25:08 Cory Missimore
So despite all the dazzling headlines or this scary announcements, it is a fascinating new technology
00:25:18 Cory Missimore
that can be folded into current auditing and GRC frameworks with, in my opinion, minimal effort.
00:25:26 Cory Missimore
We need to help each other and much other up, whether it's saying we're better than we're doing things differently and let's work as a team versus as individuals.
00:25:33 Cory Missimore
So thank you for having me here and sharing this topic.
00:25:37 The IIA
If you like this podcast, please subscribe and rate us.
00:25:40 The IIA
You can subscribe wherever you get your podcasts.
00:25:42 The IIA
You can also catch other episodes on YouTube or at theia.org.
00:25:47 The IIA
That's THEIA.org.