As the global cost of data breaches continues to rise annually and cybercrime ranks among the largest economies worldwide, cyber security leaders and teams are facing escalating and unsustainable stress levels, leading to burnout becoming a significant unspoken threat within the industry. It is imperative to implement strategies for preventing burnout at both the organisational and individual levels. Establishing psychological resilience within teams should commence with leaders developing their own personal psychological resilience, thereby laying the foundation for creating psychologically safe work environments. This paper outlines a people-centric and value-driven leadership framework that employs a polarity mindset to build psychological resilience, fostering innovation and combating burnout. Personal resilience does not imply the avoidance of stress; rather, it equips individuals to adapt to and recover from stress more effectively. The framework serves as a guide to living a value-driven life and career. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The rise of large-scale quantum computing poses a significant threat to traditional cryptographic security measures. Quantum attacks, particularly targeting the mathematical foundations of current asymmetric cryptographic algorithms, render them ineffective. Even standard symmetric key cryptography is susceptible, albeit to a lesser extent, with potential security enhancements through longer keys or extended hash function outputs. Consequently, the cryptographic solutions currently employed to safeguard data will be inadequately secure and vulnerable to emerging quantum technology threats. In response to this impending quantum menace, organizations must chart a course towards quantum-safe environments, demanding robust business continuity plans and meticulous risk management throughout the migration process. This study provides an in-depth exploration of the challenges associated with migrating from a non-quantum-safe cryptographic state to one resilient against quantum threats. We introduce a comprehensive security risk assessment framework that scrutinizes vulnerabilities across algorithmic, certificate, and protocol layers, covering the entire migration journey, including pre-migration, through-migration, and post-migration stages. Our methodology links identified vulnerabilities to the well-established STRIDE threat model, establishing precise criteria for evaluating their potential impact and likelihood throughout the migration process. Moving beyond theoretical analysis, we address vulnerabilities practically, especially within critical components like cryptographic algorithms, public key infrastructures, and network protocols. Our study not only identifies potential attacks and vulnerabilities at each layer and migration stage but also suggests possible countermeasures and alternatives to enhance system resilience, empowering organizations to construct a secure infrastructure for the quantum era. Through these efforts, we establish the foundation for enduring security in networked systems amid the challenges of the quantum era.
The rise of quantum computing presents a significant challenge to the security of asymmetric cryptography, a foundational element of modern digital infrastructure. In order to address this emerging vulnerability, a variety of post-quantum cryptographic algorithms have been proposed. In this study, we conduct a systematic evaluation of the performance and practicality of NIST's selected post-quantum algorithms and 4th round candidates specifically tailored for financial services applications, such as SWIFT Secure Signature Key (3SKey), Europay-Mastercard-VISA (EMV), Secure Electronic Transaction (SET), 3D Secure, Bitcoin Improvement Proposal (BIP) Protocol, and SSL/TLS-based financial application. Our analysis rigorously investigates the time and storage requirements of these post-quantum algorithms to identify the most suitable options for each use-case. The results of our evaluation indicate that Dilithium, SPHINCS, and Falcon display adequate computational efficiency for signature-based algorithms, with Dilithium being particularly well-suited for financial sector applications. In the context of key encapsulation mechanism algorithms, we advocate for Hamming Quasi-Cyclic (HQC) and Kyber, as they provide a favorable balance of time and storage performance, with Kyber being the top-performing candidate. To support informed decision-making, we introduce a robust framework for assessing algorithm suitability, offering essential guidance for organizations aiming to strengthen their systems against the impending quantum computing challenges.
Stablecoins are rapidly transforming digital finance by enabling fast, low-cost transactions, cross-border payments, and greater financial inclusion in remittance-dependent Commonwealth economies. However, their pseudonymous nature, integration with decentralised finance, and global accessibility introduce significant vulnerabilities to money laundering, terrorist financing, and proliferation financing. Illicit actors increasingly exploit stablecoins to bypass traditional financial controls, sanctions, and oversight. This chapter evaluates these emerging risks and advances a coherent regulatory response anchored in the Commonwealth Model Law. It recommends risk-based supervision, stronger licensing and enforcement for issuers and intermediaries, Travel Rule compliance, enhanced due diligence, and mandatory transparency in reserves and governance. It also calls for improved data sharing, cyber-resilience standards, and capacity building for smaller jurisdictions. Case studies from across the Commonwealth illustrate both challenges and successful approaches.
We examine actively managed equity portfolios that incorporate venture capital (VC). VC investments carry a high expected return and likely diversification benefits. However, access to the best deals may be reserved for investors with specialized business knowledge to assist target-firm management. Based on PSN data from 2000 to 2022, we document that funds incorporating VC trail their benchmarks and matched non-VC counterparts on a variety of investment-performance metrics. This underperformance suggests that traditional equity portfolio managers fail to access value-enhancing VC opportunities, and their investors do not gain from the excursion into that adjacent asset class.