# Topics, Shujaatali Badami

The list of topics with on-record positions. Each one has a deep-dive page on the site if you want background before reaching out.

---

## Post-quantum cryptography (PQC)

- **Position**: NIST FIPS 203/204/205 are the migration target. Hybrid PQC is the right transition pattern. The deadline is sooner than the consensus says.
- **Background**: `/topics/post-quantum-cryptography/`
- **Best for**: NIST PQC adoption stories, harvest-now-decrypt-later explainers, ML-KEM/ML-DSA practitioner views.

## ICS and IEC 62443 security

- **Position**: ICS PQC migration is a decade-long capital programme. SOC-style detection on PLC traffic is the missing layer.
- **Background**: `/topics/ics-62443-security/`
- **Best for**: water/power utility breaches, ICS-focused vendor news, IEC 62443 certification stories.

## Quantum kernels on NISQ hardware

- **Position**: Quantum kernels are the most plausible near-term ML use of NISQ. The headline result is anomaly detection on ICS telemetry, validated cross-testbed on ibm_fez.
- **Background**: `/topics/quantum-kernels-nisq/`
- **Best for**: IBM Quantum, Google Quantum, quantum advantage stories with a "but does it work on real hardware" angle.

## Post-quantum IoT (EDHOC, OSCORE)

- **Position**: ML-KEM-512 fits a Cortex-M4 IoT handshake. ML-DSA fits with care. The IETF LAKE working group is the venue.
- **Background**: `/topics/iot-pq-edhoc/`
- **Best for**: IoT security, smart home, IETF standards stories.

## 6G cognitive radio security

- **Position**: 6G makes cognitive radio foundational. The attack surface is the controller policy. PQC has to be in from day one.
- **Background**: `/topics/6g-cognitive-radio-security/`
- **Best for**: 6G, telecom security, adversarial RL stories.

---

## What I will NOT comment on

To save your time and mine, I will decline questions on:

- Cryptocurrency price predictions or investment advice.
- Vendor-specific marketing claims I cannot independently verify (the relevant question is "what does the data show", not "what does the vendor say").
- Geopolitical attribution for cyber incidents (outside my expertise; refer to MITRE ATT&CK or US-CERT).

---

## Geographic specialisation

- Primary: Chicago, US Midwest. See `/chicago/` and `/midwest/`.
- Secondary: US national, IEEE-region 4.

Last reviewed: 2026-04-27.
