Finance
Banking and mobile money
Interbank transfer rails, card networks, mobile financial services and the HSM estate behind them. High transaction volume, strict latency budgets, and regulatory retention measured in years.
Post-quantum cryptography
An adversary does not need a quantum computer now. They need your encrypted traffic now, and a quantum computer eventually. For records that must stay secret for a decade — citizen identity, land titles, health, financial and diplomatic data — the deadline has already passed.
The shape of the problem
Encrypted traffic can be recorded cheaply and stored indefinitely. Whenever a cryptographically relevant quantum computer arrives, everything held in that archive is opened at once — retroactively, including data sent today.
The question is not when a quantum computer arrives. It is how long your data must stay secret, plus how long your migration takes. If those two numbers together exceed the time remaining, you are already late. Mosca's inequality, in plain terms
Standards
Status precision matters here. Final, draft, selected and candidate are not synonyms, and a migration plan should say which one it is relying on.
| Standard | Algorithm | Purpose | Status |
|---|---|---|---|
| FIPS 203 | ML-KEM (from CRYSTALS-Kyber) | Key encapsulation — the replacement for RSA and ECDH key establishment. | Final · Aug 2024 |
| FIPS 204 | ML-DSA (from CRYSTALS-Dilithium) | Digital signatures — the general-purpose replacement for RSA and ECDSA signing. | Final · Aug 2024 |
| FIPS 205 | SLH-DSA (from SPHINCS+) | Hash-based signatures — conservative, stateless, useful for firmware and long-lived roots. | Final · Aug 2024 |
| FIPS 206 | FN-DSA (from FALCON) | Compact lattice signatures for bandwidth-constrained protocols and certificates. | In development |
| — | HQC | Code-based backup KEM, chosen for mathematical diversity against ML-KEM. | Selected · Mar 2025 |
We avoid the words unbreakable and future-proof. Post-quantum algorithms are designed and believed to resist known classical and quantum attacks; they remain subject to cryptanalysis, implementation error and revision, like all cryptography. Crypto-agility — the ability to swap an algorithm without rebuilding the system — is the part of this work that keeps paying off.
How we work
Most organisations cannot say where their keys are. That is the first deliverable, and it is the one everything else depends on.
Build a cryptographic bill of materials: every certificate, key store, VPN, HSM, database at rest, signing pipeline and embedded device. Which algorithm, which key length, which expiry, which owner. Automated scanning plus interviews, because the undocumented systems are the risky ones.
Sort assets by how long their contents must stay confidential and how long their signatures must stay trustworthy. A one-hour session token and a citizen's biometric record do not carry the same urgency. This ranking becomes the migration order.
Isolate cryptography behind interfaces so an algorithm can be replaced without touching business logic. In many systems this refactor is the largest piece of work — and it is also the piece that survives the next standards change.
Deploy hybrid key exchange — a classical and a post-quantum KEM together — so security holds if either one fails. Measure the real cost: handshake size, latency, certificate chain growth, HSM support, and what breaks on older clients.
Move the PKI: new roots and issuing certificates with post-quantum signatures, staged re-issuance, and a dated plan to withdraw the classical-only paths. Then keep the inventory alive, because it goes stale in months.
Where it matters here
These are the places where secrecy lifetime, national dependence and cryptographic sprawl all overlap.
Finance
Interbank transfer rails, card networks, mobile financial services and the HSM estate behind them. High transaction volume, strict latency budgets, and regulatory retention measured in years.
Identity
Biometrics cannot be reissued, and a land title must remain provable for generations. Signature longevity, not just confidentiality, is the exposure here.
Infrastructure
Certificate authorities, e-procurement, government service gateways and the long-lived device certificates in telecom and power networks, where firmware signing outlives the hardware refresh cycle.
Engagements
Each one is scoped to produce a document your board, your regulator and your engineers can all use.
Questions we get
The first conversation is short and free. Bring one system you care about, and we will tell you what an inventory of it would involve.