Quantum risk overview

Northwind Financial Group · last full scan Oct 03, 02:41 UTC

Velar Quantum Risk Score

68/ 100 risk

↓ 6 pts improvement vs. last month

Critical23
High61
Medium148
Low212

Crypto assets discovered

4,308

+17 this week

Quantum-vulnerable

3,774

87.6% of inventory

HNDL-exposed systems

214

−9 since last scan

PQC-protected

96

+38 this quarter

Risk score history

12 months · lower is better

Prioritized remediation

All findings
98
CriticalHNDLs3://nw-archive-7y

RSA-2048 key exchange protecting 7-year retention archive

Re-wrap data keys with ML-KEM-768 (FIPS 203) via KMS hybrid key wrapping; rotate within 30 days.

96
CriticalHNDLswift-connector

SWIFT connector uses RSA-2048 TLS without PFS

Enable TLS 1.3 with X25519MLKEM768 hybrid; coordinate with SWIFT Alliance Gateway upgrade.

94
CriticalHNDLvpn.corp.northwind.com

Corporate VPN negotiates classic DH Group 14

Upgrade IKEv2 to RFC 9370 multiple key exchanges with ML-KEM; disable Group 14.

91
CriticalHNDLpayments-gateway

Payments API signs tokens with ECDSA P-256

Plan dual-signing with ML-DSA-65 (FIPS 204); introduce crypto-agile JWS header negotiation.

90
CriticalHNDLapi.northwind.com

Public API terminates TLS with RSA-2048 certificate

Move edge termination to hybrid PQ TLS; issue ECDSA P-384 interim cert, ML-DSA when CA supports.

Algorithm distribution

  • RSA-20481,842
  • ECDSA P-2561,206
  • RSA-4096512
  • ECDH X25519438
  • ML-KEM hybrid96
  • Other214

Open findings trend

Assets by type

Migration roadmap

Open
Discover100%
Assess100%
Prioritize72%
Migrate18%
Verify0%
Monitor0%

Live monitoring

View stream
02:24:11MediumNew RSA-2048 certificate issuedstaging-api.northwind.com
02:19:47LowTLS downgrade to classical KEX observededge.northwind.com (legacy client)
02:11:02HighDependency added: node-rsa@1.1.1customer-portal PR #4182
01:58:30LowHybrid PQ handshake enabledlb-prod-eu-2