Post-quantum migration readinessFor regulated institutions. Inventory, exposure, roadmap, board briefing.Technical due diligenceFor investors. Architecture, security and regulatory exposure, reported to the IC.InsightsWriting on cryptography, energy and verificationAbout and evidenceThe record, and what you can checkStart a conversation
Engagement for regulated institutions

Post-quantum migration readiness

You end with an inventory of what you actually run, an exposure measured against how long your data has to stay secret, a sequenced roadmap with cost bands, and a briefing your risk committee can act on without a translator.

Duration4–8 weeks
FeeFixed, scoped first
Reports toCTO, CISO, board risk
AfterOptional retainer

Why this is harder than it looks

The standards question is settled. NIST published the algorithms, and any competent firm can tell you which are approved. That part is a reading exercise.

What is difficult sits underneath it. Which HSMs in your estate will not hold the new key sizes. Which counterparty integration silently stops negotiating when a cipher suite changes. Which certificate chain nobody has owned since 2019. What happens to handshake latency on the payment path when signatures grow an order of magnitude, and whether your SLA survives it.

I have made those choices with a network in production and customers on it, and got some of them wrong the first time. That is the difference between a roadmap that survives contact with your estate and one that does not.

How it runs

Four phases, and you see the shape of the answer by week two

Week 0

Scope

A twenty-minute call, then a one-page written scope: what I examine, what you receive, what I need from your team, and the fixed price. Free, and yours to take elsewhere.

Weeks 1–3

Inventory

The part nobody enjoys and everyone skips.

  • Algorithms, key sizes, protocol versions and certificate authorities in use
  • Where each is terminated: HSMs, load balancers, service meshes, payment rails, archives
  • Counterparty and vendor dependencies, including the integrations nobody owns
  • Data classes mapped to the confidentiality lifetime each actually needs
Weeks 3–6

Exposure and roadmap

Shelf-life against migration time, system by system, so sequencing follows risk rather than convenience.

  • What is exposed today under harvest-now-decrypt-later, ranked
  • Crypto-agility: what can be swapped, what has to be rebuilt
  • Sequenced roadmap with dependencies, effort bands and decision points
  • The next ninety days, separated from what waits
Weeks 6–8

The briefing, and the room

A board-level document, then a session presenting it to whoever has to act on it. Questions answered live, including the ones that come after the slides.

Start a conversation

Tell me what you are dealing with

Three short steps, about ninety seconds. It means the first call opens on your situation rather than on introductions.

Which of these is closest?

This decides what I ask next, and what I read before we speak.

What happens next

A twenty-minute call on your situation, then a one-page written scope with a fixed price. Both free, and the scope is yours to take elsewhere.

Response time

Two working days, from me rather than an assistant.

Confidentiality

What you send stays between us. An NDA before the first call is fine, and I will sign yours rather than send mine.