Most organisations can say that their data is encrypted. Far fewer can say where their keys are, who can use them, when they were last rotated, or which certificates will expire next month. In practice, encryption rarely fails because of a broken algorithm. It fails because a key sits in a configuration file, a certificate expires on a payment gateway at midnight, or an old protocol version was left enabled for a legacy system that nobody dared to touch. For banks and government bodies, these operational gaps are the real exposure.
Algorithms and TLS hygiene
Start with a cryptographic standard inside your organisation: a short, approved list of algorithms, key lengths and protocol versions, based on current guidance such as NIST SP 800-57 and the recommendations in PCI DSS v4.0.1 where cards are involved. Then enforce it:
- Allow only current TLS versions and strong cipher suites on all external and internal services, and disable obsolete protocols and weak ciphers.
- Scan your own estate regularly, including internal applications, APIs, mail servers, VPN gateways and management interfaces, not just the public website.
- Avoid home-made cryptography and hard-coded secrets. Use vetted libraries and platform services.
- Keep an inventory of where cryptography is used, because you cannot change what you cannot find.
Key lifecycle and HSMs
A key has a life: generation, distribution, storage, use, rotation, backup, revocation and destruction. Each stage needs an owner and a documented procedure.
- Generation: use approved random sources, ideally inside a hardware security module (HSM) for high-value keys.
- Storage: keep keys out of source code, scripts and shared drives. Use a KMS or HSM, and restrict access by role.
- Separation of duties and dual control: key ceremonies should require more than one authorised person, and administrators of the key system should not be able to read the data it protects.
- Rotation: define lifetimes by risk and test rotation in advance, including the ability to re-encrypt or roll back.
- Backup and recovery: protect key backups as carefully as the keys themselves and rehearse recovery.
- Destruction: retire keys formally and record it, so that decommissioned data is truly unreadable.
An HSM is not required for every key, but it is a sound choice for root and signing keys, payment keys and the master keys that protect other keys. Whichever model you choose, log every key operation and send those logs to your monitoring platform.
Certificate management
Certificates are keys with an expiry date, and expiry is the most common cause of avoidable outages. Maintain a central inventory of every certificate, its owner, issuing authority and expiry date. Automate issuance and renewal wherever the platform allows, alert well before expiry, and define who is accountable for each one. Keep your internal certificate authority hierarchy protected, with the root kept offline, and document how you would revoke and replace certificates quickly after a compromise.
Planning for post-quantum change
NIST has standardised the first post-quantum cryptography algorithms. You do not need to panic, but you should plan. The sensible first steps are not replacing everything today but building the ability to change: maintain the cryptographic inventory, identify systems that protect data with a long confidentiality lifetime, require crypto-agility in new procurement so that algorithms can be swapped without redesign, and follow your vendors and regulators as guidance matures. Organisations that already manage keys and certificates well will find this transition far easier than those that do not.
How Wethaq ICT helps
Wethaq ICT helps banks and government bodies review how cryptography is actually used. We build the cryptographic inventory, assess TLS and certificate posture, review key-management design and HSM or KMS options, and define policies and processes aligned with recognised standards, so that strong algorithms are backed by disciplined operations and a clear path for future change.
Let’s build a secure foundation for your digital future
It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.

