Session

Enterprise Shadow Cryptography - Why visibility matters now more than ever

Enterprises run on cryptography — but hardly anyone can say where it actually lives. TLS gets terminated somewhere in the infrastructure, the container base image decides which OpenSSL you run, algorithms come from library defaults. Everything works, and that’s exactly the problem: healthy cryptography is invisible.

We term this „shadow cryptography”. It’s the functional crypto that nobody sees/manages end to end. Pressure is now building from several directions at once — shrinking certificate lifetimes (browser forum), faster vulnerability discovery (AI), tightening regulation, the post-quantum transition. Different storms, same weakness: not knowing your cryptographic landscape.

This talk shows a pragmatic way out. Start with what you can already see, follow the connections across team and vendor boundaries, assign ownership, build agility, modernise by priority. Step by step, the landscape lights up.

About the speaker

Yannik Goldgräbe

Yannik Goldgräbe

Security Architect at Swisscom
As a security architect and cryptographic protocol expert, he drives innovation topics in B2B application security such as certificate automation, post-quantum readiness and the future of digital identity. His roots are in early-stage startups, where he built cryptographic systems from the ground up: a web3 consensus protocol enabling code collaboration for engineers, and a decentralised identity provider for the regulated German health market with every key, algorithm and protocol under one team’s control. He has published on zero-knowledge proofs and holds a patent on the decentralised, encrypted provision of user data. „Enterprise Shadow Cryptography” is his field report from both sides of the divide between full cryptographic control and enterprise reality.
Read more …
Copyright © 2026
 
Swiss Cyber Storm
Hosting graciously provided for free by Nine