

IBM
Quantum Safe Posture Management

My Role
Research Plan
Discussion Guide
User Interviews
Data Analysis
Insights Report
Research Readout
Stakeholder Management

Timeframe
Two Months

Tools
Box Notes
Mural
Figma
WebEx
The Challenge
In recent years, quantum technology has gained rapid advancement. With production quantum computers on the horizon, there's been a growing concern about current cryptography standards - which are vulnerable to quantum-powered attacks.
As one of its New Product Introductions (NPI), IBM set out to build a Quantum Safe Posture Management product as part of its Guardium data security portfolio. The company needed to understand how customers viewed post-quantum cryptography, and determine if this new tool would help them defend their data.
As somone who is incredibly interested in futures work, I was beyond excited to jump into this new frotier and lead our discovery efforts.
Research Approach
Goals:
- Determine user's understanding of post-quantum cryptography (PQC)
- Identify barriers to entry in the PQC market
- Identify barriers to user adoption
- Evaluate the design of the product, including terminology
Method: User interviews.
Participants: Nine customers with job responsibilities that involve dealing with cryptography.
Research Insights
We met wtih customers to conduct discovery and to concept test our initial designs. Considering the high-stakes situation of an NPI, many stakeholders attended our sessions to observe, including executives.
Product Insights
These insights are categorized at the product level.
Quantum is considered theoretical
Among interview participants, awareness about the threat posed by the advancement or eventual adoption of quantum computers is high but there's a lack of urgency to this problem.All participants stated that there's no plan for taking concrete action to secure the organization's encrypted data from post-quantum attacks.
No participants mentioned a concern about the "harvest now, decrypt later" concept, that allows threat actors to collect sensitive data now and decrypt it later when they obtain quantum capabilities.Recommendations
Embark on educating customers about quantum-powered attacks and the criticality of the threat, which could help create urgency for the product.
Create awareness around the upcoming changes in NIST compliance standards relating to post-quantum cryptography.
"I'm not initially concerned. I mean there's certain algorithms that are
quantum resistant, but you know, to a degree, we're all in the same boat."Quantum safe is the key differentiator rather than the focus
The perceived value of Guardium QSPM is high as an observability tool for the entire cryptographic health across an organisation, not just to protect against post-quantum threats.
Protection from quantum-powered attacks can be the key differentiator and a value-add of the product, rather than the basis of the product. This will help with market penetration and adoption right now, as organizations are not willing to invest in a tool solely focused on protecting them from quantum-powered threats.IBM's brand value and industry reputation made the participants feel that this will be a reliable product and that it will perform well.
Recommendations
Consider updating the value proposition of Guardium QSPM as a broad cryptographic observability tool, with protection against quantum-powered attacks as a key differentiator for IBM in the market.Leveraging IBM's strong brand reputation during launch and upsell will aid in successfully introducing the product.
"This would really give me insight into all of my encryption. Quantum-safe is great for when it gets here, but this could help me with my encryption now."
The product name isn't aligned with its value
The name Guardium Quantum Safe Posture Management received mixed reviews. A close contender for the name was Cryptographic Posture Management.
Those who understood that the product focus was on protecting organizations from quantum-powered attacks, thought the word quantum should be used in the name. Others, who viewed it as a tool that monitors their organization’s cryptographic health, preferred using the word cryptography.
All agreed that the name Guardium Quantum Safe Posture Management was lengthy. Some mentioned the usage of the word safe is misleading, as the tool is not keeping their organization safe, but rather providing a bird’s eye view of all the cryptographic risks that are present.Others mentioned the term quantum seemed like a buzz word for marketing.
Recommendations
Consider using a shorter name for the product.
Consider using a name aligned to the product's identified greater value proposition of an overall cryptographic observability tool."You know quantum - it's a gimmick word. People are using it. It's just like, oh,
okay, what's the latest ingredient? And a lot of people don't even know what
that really means."Delivery preference varies based on data storage setup
Organizations use on-premises, cloud, or a hybrid of on-premises and cloud infrastructure for storing their data.Participants varied in their preferred delvery method of either on-premises or SaaS for QSPM, mainly depending on their existing data infrastructure setup, along with some ofther factors, such as type of industry, solution cost, and effort requried to maintain.
There was a slight edge amonst participants for it to be delivered as a SaaS product because it is considered flexible, convenient and there's an industry trend with cloud migration.Recommendation
Consider a hybrid deployment model to cater to different needs in the industry.
"Personally, I would say it probably should be provided as a SaaS solution. Flexibility being one of the reasons. Cost model as well."
Security Architects are likely the primary user
The personas targeted for research were cybersecurity professionals with experience in cryptography, such as SecOps Manager and Data Security Specialist.
Participants indicated that various job roles would find value in QSPM, with Security Architects being the likely primary user of the tool.
Recommendation
Additional research with Security Architects and various administrators to bring more clarity around primary use of the tool.
"Mostly it would be the technical people like architects, administrators and so on."
Remediation is table stakes
Participants expected the tool to provide remediation measures as well and not only highlight the risk factors, in order for it to be considered an end-to-end soultion.
Participants also listed various integrations as desireable, including ServiceNow, SIEM tools, and AI for search and resolution.
Recommendations
Consider evaluating Guardium QSPM Explorer-Advisor-Remediator as a package to gauge user reaction and perceived value in future research.Consider OOTB integrations with ServiceNow, SIEM tools, and AI co-pilots.
"Like from that is there a thing that when I click into it, it would show me
here's what you need to do to fix that? Like how to remediate?"Design Insights
These insights are related to the design of Guardium QSPM.
Dashboard: General
Insights
- Participants appreciated the "single pane of glass" view provided by the dashboard and its "clean" design.
- Most were appreciative of the dark mode but expected to have the ability to switch between dark and light modes.
- Some expected the colors used to be adjusted when they shift between dark and light modes.
Recommendations
Maintain the minimalist design going forward.
Consider giving users the option to toggle between dark and light modes.

"I've seen some solutions of Microsoft, but they weren't this clear. It's a similar
idea, but I think the execution here at the IBM side is much better"Dashboard: Detail
Insights
- Participants wanted to be able to click on the tiles Cipther strength, TLS versions, and Cryptographic libraries.
- The font size used in the legends for the tiles was too small and difficult to read for the participants.
- Some participants were unable to understand the labels Cipher suites and Cryptographic libraries.
- For some participants, it was difficult to differentiate between the red and orange tones in the donut chart at a first glance.
- It was confusing to most as to why there were two tiles – TLS versions and Endpoints - showing the same data of 4.55k Endpoints.
- In the Cryptographic libraries tile, the legends reading BouncyCastle, JCA, and Inferred made no sense to most – it lacked context.
- In the Cypher strength tile, all participants noted that the use of yellow to represent Secure didn't make sense to them. They would associate being secure with a different shade of green or blue.
- In the Cypher strength tile, most stated that the term Recommended didn't seem consistent with the other labels on the legend, like Insecure, Weak and Secure, which cause confusion.
Recommendations
Consider making the tiles clickable.
Using a different color than yellow to denote secure would bring clarity.
Increasing the font size on the legend will increase readability.
Add a content designer to the team to upate lables and terminology.

"I think the color usage is good but I think it's a little bit odd that
secure is in yellow. I don't know what color I'd pick, but yellow is a little
interesting because yellow kind of means caution."Cryptographic posture
Insights
- The graph label of Cryptographic posture was not understood by most participants.
- Participants expected the graph to be interactive, with more information available on hover.
- All participants did not understand what the un-labeled y-axis represented.
- Most participants did not understand what the dotted line repreented, and most struggled to even see it with it being the same gray color used for the other lines.
Recommendations
Consider providing some kind of affordance to help customers understand what Cryptographic posture means.
Provide a lable for the y-axis.
Utilize a different color for the dotted line on the graph and a way to understand what it represents.
Consider making the graph interactive to provide more information to customers.

"I see a dotted trend line in there between 30 and 50. So, maybe if you hover
your mouse over that trend line, I would expect it to give you the exact
number. I really have to lean close to the screen to try to gauge whether it's
around 35 or 40. So yeah, I would expect the number to be shown there."Policy compliance
Insights
- Participants wanted the ability to filter each column on the basis of open/closed status, number of issues, and severity level.
- Participants expected the accordians to have more information regarding the TLS policy.
- Participants questioned how Weak TLS is different from TLS 1.1 - they wanted to know on what basis are we making these distinctions. They mentioned since TLS 1.1 is not the latest and updated version of TLS it should lack in both performance and security and hence be considered weak TLS in itself.
- The term Policy compliance was confusing for some, as organizations can be compliant with various mandates, regardless of the risks identified in this tool.
- Participants wanted the ability to export the data for review and sharing.
Recommendations
Provide filtering options for all of the columns: status, total issues, and severity.
Provide more information in the accordians.
Consider rephrasing the label Policy compliance.
Reconsider the rationale behind using both the labels TLS 1.1 and Weak TLS.

"So, on the right hand side for policy compliance, I might want to sort by severity
and by total issues and then kind of take a two-pronged approach on where
we need to be focusing our efforts for what has the most issues that's the
highest severity."Cryptographic inventory
Insights
- After viewing the dashboard, nearly all found it confusing that the scale used for Cipher strength was different than in the Cryptographic inventory. The Dashboard is using severity levels of Insecure, Weak, Secure and Recommended whereas in the Cryptographic inventory page
is using High, Medium, and Low. - The information provided on the screen was considered adequate.
- Participants wanted the ability to filter content and export the data as well.
- Participants wanted to be able to add and remove columns of information.
Recommendations
Consider using consistent labels for severity levels across the screens.
Provide a way to filter and export data.
Explore whether the ability to add and remove columns makes sense.

"Nowadays if you use data tables, they're very advanced. This table looks like it's a
nineties table, right? Nowadays data tables are so advanced on the each column
you can filter them directly. "Final Thoughts
Working with customers on Quantum Safe Posture Management was a fantastic experience. Not only were we launching an NPI, we were operating in unchartered territory. There's something incredibly exciting about learning how customers feel about an emerging technology that is going to change their way of life.
The most striking thing about working on QSPM was seeing our team initially miss the forest for the trees. While the team was centering the product around being quantum safe, customers explained that the real value was much broader as a cyrptographic observability tool. That single insight crystalizes why discovery and listening to customers is so important.
I brought this insight to the attention to our VP of Product Management, along with my thoughts that we had the potential to develop QSPM into a next-gen encryption tool to replace our legacy (OEM-ed) encryption product. She fully agreed and asserted that we would be heading in that direction.
© 2016









