Over the years, one lesson has become impossible for me to ignore: organisations spend heavily on keeping attackers out, yet often give too little attention to what protects the data after an attacker gets in.

That is where cryptography becomes indispensable. It is not the first line of defence, and it is certainly not the only one. Identity, access control, monitoring, DLP, cloud security and incident response all matter. But if those controls fail and sensitive data leaves its intended boundary, cryptography may be the final thing standing between an attacker and usable information.

There is one uncomfortable truth, however: encryption is only as strong as the keys behind it. A powerful algorithm protected by a poorly managed key gives us the appearance of security, not the assurance of it. In practice, the real security boundary is often not the encrypted database or application. It is the key.

The Crypto Heart

At CREDO, we believe every serious enterprise should build what we call a Crypto Heart: one governed cryptographic capability sitting deep inside the organisation and establishing trust for everything around it.

At its centre is an HSM based root of trust. The Hardware Security Module protects the organisation’s most sensitive root, master, signing and certificate authority keys inside a hardened cryptographic boundary. Not every operational encryption key needs to live directly inside the HSM; that would be impractical at enterprise scale. The HSM anchors the hierarchy, while central key management platforms and digital vaults securely manage the larger population of downstream keys.

The Crypto Heart must also manage digital trust. PKI and certificate lifecycle tools discover certificates, assign ownership, automate renewals and enable rapid revocation. Cryptographic discovery provides visibility into algorithms, libraries, keys, certificates and protocols scattered across data centres, clouds, applications, APIs and devices. Without that inventory, an organisation cannot protect, or replace, what it cannot see.

And this platform must be crypto agile. NIST has already finalised its first post quantum cryptography standards. The immediate job is not to replace every algorithm tomorrow. It is to identify where vulnerable cryptography exists, understand dependencies and build the ability to change algorithms and keys without disrupting the enterprise. The quantum transition is as much an orchestration challenge as it is a mathematical one.

When one trusted key opened the wrong doors

The 2023 Microsoft Storm-0558 incident shows why this matters. Microsoft disclosed that the threat actor had acquired a consumer signing key and used it to forge authentication tokens. Combined with a token validation weakness, those forged tokens enabled access to email accounts through Outlook Web Access and Outlook.com. Microsoft reported that approximately 25 organisations, including government agencies, were affected, and its technical analysis confirmed email access and exfiltration for targeted users.

The public evidence did not conclusively establish how the key was obtained, so we should not invent certainty where none exists. But the lesson is clear: a trusted signing key is a Tier 0 asset. When it is compromised, an attacker may no longer need to break through every door; trusted systems can accept the attacker’s forged proof as legitimate.

Protection therefore cannot stop at placing a key inside secure hardware. Organisations need strict separation of duties, continuous monitoring of key use, tested rotation and revocation, resilient backup and recovery, strong validation logic and a rehearsed compromise response. A key that cannot be replaced quickly and safely under pressure is already an operational risk.

Start with discovery, not procurement

The first step in building a Crypto Heart is not buying another product. It is answering four questions honestly: Where is our cryptography? Who controls our most powerful keys? How quickly can we revoke or replace trust? Can we change algorithms without interrupting the business?

From there, an organisation can design the HSM root of trust, centralise key and certificate lifecycles where appropriate, assign accountable ownership and create a practical crypto agility roadmap. The outcome should not be another set of isolated cryptographic tools. It should be one continuously operated enterprise capability.

Applied cryptography has always been one of CREDO’s core engineering strengths. Our conviction is simple: data protection is incomplete until the cryptography beneath it is discoverable, governed, protected and ready to evolve. When those elements work together, the enterprise has more than encryption. It has a Crypto Heart, and a last line of defence worthy of the data it protects.

Sources

Microsoft Security: Storm-0558 mitigation

CISA Cyber Safety Review Board report

NIST: Post quantum cryptography standards