
Episode #101
Quantum Computing Risk: What Internal Auditors Need to Know
The Institute of Internal Auditors Presents: All Things Internal Audit In this episode, Richard Penfil talks with Cory Missimore about how quantum computing could threaten current encryption, why "harvest now, decrypt later" attacks require organizations to prepare today, and how internal auditors can assess quantum readiness. They also discuss cryptographic inventories, third-party exposure, crypto agility, regulatory developments, and practical steps organizations can take to prepare without overreacting. HOST: Richard Penfil , Founder, AssureSwarm GUEST: Cory Missimore , CISSP, CDPSE, CISM, CIPP Senior Information Security Compliance Analyst, American Institutes for Research KEY POINTS: Introduction [00:00β00:47] Quantum Computers vs. Traditional Computers [00:47β01:44] Why Organizations Should Prepare Now [01:45β03:18] Cryptographic Inventories and Accountability [03:19β05:27] "Harvest Now, Decrypt Later" Attacks [05:28β07:42] The Emerging Regulatory Landscape [07:43β09:33] Three Questions for Assessing Quantum Readiness [09:34β13:11] Third-Party and Vendor Exposure [13:12β15:01] Integrating Quantum Risk Into Existing Audits [15:02β17:49] Warning Signs and Regulatory Developments [17:50β20:27] How Quantum Computing and AI Could Develop Together [20:28β22:13] Practical Steps Organizations Can Take Today [22:14β24:42] Final Thoughts [24:43β25:36] IIA RELATED CONTENT: Interested in this topic? Visit the links below for more resources: Global Internal Audit Standards Cybersecurity Topical Requirement Cybersecurity Part 3: Cybersecurity Third-Party Risk Management All Things Internal Audit Tech: Quantum Computing All Things Internal Audit Tech: Quantum Is Coming for Your Encryption. Now What? The Big Idea: Quantum Computing Visit The IIA's website or YouTube channel for related topics and more. Follow All Things Internal Audit: Apple Podcasts Spotify Libsyn Deezer




