9/11/26

From Q-Day to SolarWinds: Can Security Certification Keep Up?

Cybersecurity threats are evolving faster than the certification programs designed to provide assurance. So can programs like Common Criteria and FIPS keep pace? In this episode of Trust and Turbulence, I’m joined by Alicia Squires, Industry Principal for FIPS at AWS, and Kevin Micciche, Chief Technologist at HPE, two long-time practitioners in security certification and cryptography.

We start with SolarWinds and a deceptively simple question: could a security evaluation have caught it?

From there, the conversation moves to the tension between rigorous assurance and getting products to market, and why developing the next generation of security evaluators matters. Then we turn to Q-Day and post-quantum cryptography: crypto inventories, cryptographic agility, migration challenges, and what vendors and governments should be doing now.

We also explore an increasingly important wildcard: AI. Could AI change the cryptographic threat? Can it find vulnerabilities that previously weren't practical to exploit? And can the same technology be used to make security certification faster without sacrificing trust?

Finally, we look ahead at a world where security requirements are multiplying rather than converging—and ask whether AI, automation, and better reuse of security evidence can help certification keep up. Disclaimer: Views expressed are the guests' own and do not represent their employers.

About the Guests

Kevin Micciche is Chief Technologist for HPE Networking Platform Trust, where he leads work in cryptography, platform security, and the transition to post-quantum cryptography. A longtime security certification practitioner, Kevin has certified more than 150 products spanning 16 years against Common Criteria and FIPS requirements.

Alicia Squires is the FIPS Security Industry Principal on AWS's Cryptography team, with more than 25 years of experience in security certification, cryptography, and international compliance. Previously, she spent 15 years at Cisco, including leading its Global Certifications Team. Alicia is also a founding member of the Common Criteria Users Forum and served as its Chair for seven years.

Next

From Paperwork to Proof: Automating Cyber Compliance