info@insidequantumtechnology.com

You’re legally responsible.

The Tale of Vastaamo

You’re legally responsible.
By Brian Siegelwax posted 08 Sep 2026

I normally turn one conversation into one article, but Certes gave me ideas for three distinct dragons. It would be a disservice to you, dear reader, to shove them all into one article, so please enjoy this three-part series.

The Quantum Dragon was feeling entrepreneurial, allowing neighboring villagers to store their valuables near his cave. The prevailing opinion was that no one in their right mind would ever approach a dragon’s cave. Red dragons breathe fire, after all. But what The Quantum Dragon didn’t realize was that he was accepting legal responsibility for their treasures.

You see, when we talk about the threat of quantum computing to modern cryptography, we assume that you want to protect your own data. Realistically, however, you might not physically have your data. If I’m one of your vendors, maybe I have some of your data, and therein lies the problem. I’m now accepting legal responsibility for your data.

But That’s Not All

As an American, I assume that if my company is incorporated, my personal assets are protected. But I was chatting with Simon Pamplin, CTO at Certes, and it turns out that I’m wrong. If your data is breached on my watch, and I’m determined to have been negligent, I can still be held personally liable. There are examples of personal liability involving Google, Meta, and Uber, but one particularly poignant example involves a company called Vastaamo.

A Sobering Case Study

Vastaamo was a privately held Finnish psychotherapy provider that left a highly confidential patient database on the Internet without so much as a password. The data had been breached multiple times and the CEO was determined to have covered it up. The company was eventually blackmailed, and the patients were threatened with publication of their records. The private equity firm that had acquired Vastaamo filed legal action, Vastaamo went bankrupt, and then it ceased to exist a few years ago. The CEO was personally given a three-month suspended prison sentence and had his personal assets frozen. He was ordered to pay approximately EUR 8M in damages to the private equity firm that had acquired the company, and, of course, tens of thousands of individual victims filed class-action lawsuits against him.

Again, that was all personal liability, not corporate liability. When you’re taking ownership of data, financial, operational, regulatory, and personal liability all come into play.

Enter Certes

This is part of the reason why Certes focuses on protecting data, as opposed to infrastructure. Whereas a network breach can be patched, a data breach can end a business. The sovereign encryption keys belong to the actual data owner only and can’t be decrypted by anyone else. In all cases, no data is ever exposed. Furthermore, crypto agility means using NIST’s post-quantum cryptography (PQC) protocols today and staying future-proof for tomorrow.

Data Corruption

Keep in mind that theft is not the only concern. AI lives on data, and if you corrupt it, that’s a problem. By focusing on protecting data, Certes is also protecting against malicious data corruption.

Conclusion

I don’t know why you’d give your valuables to a red dragon anyway. Their alignment is chaotic evil, which means that they’re unconcerned with laws and they’re greedy. I don’t think they can help you with your gold and jewelry, but if you have valuable data, consider reaching out to Certes instead.

Certes’ CTO, Simon Pamplin, will be speaking at PQC+IQT, which is coming to New York City October 25-26.

Categories: The Quantum Dragon with IQT News

Tags: Certes, cybersecurity, data breaches, data protection, NIST PQC, personal liability, post quantum cryptography, Simon Pamplin, Vastaamo case study

0
The Walter Cronkite Dragon