Applied Cryptography & Quantum-Safe Readiness

Your exposure started before the machine exists.

Encrypted traffic captured today can be decrypted years from now, by an adversary who only has to wait. That makes quantum readiness a question about the data you are protecting right now, not about a machine that arrives later. Most organisations cannot answer the first question that follows: where does our cryptography actually live?

2Doctorate-level applied cryptographers in the practice
6Weeks to a board-ready readiness assessment
4Cryptographic jobs your estate depends on — each affected differently
The uncomfortable truth

A report that treats encryption as one thing cannot say anything useful.

Cryptography does four separate jobs in your estate. It keeps content secret, detects alteration, proves origin, and makes that proof undeniable — the last being the property your contracts, audit trails and financial records actually rest on.

Those jobs use different mathematics, and quantum computing affects them very differently: some are barely touched, others structurally broken. So a report that says “we assessed your encryption” has already collapsed four distinct exposures into one word. You cannot sequence a migration from that, cost it, or defend it to a regulator.

Ask any vendor which of the four jobs they assessed. The answer tells you whether you bought an assessment or a template.
The discovery problem

Nobody knows where their cryptography is. That is the normal finding.

Ask an engineering organisation to inventory its cryptographic dependencies and you get a document listing the places people remember. It omits the certificate embedded in a device fleet, the signing key in a build pipeline nobody has touched in four years, the library three layers down a dependency tree, and the protocol that silently falls back to something older at runtime.

That is not incompetence — cryptography is deliberately invisible when it is working, configured once by someone who has since left. Which is why discovery has to be tooled: a questionnaire returns the estate people can recall, instrumentation returns the estate that exists. The gap between the two is the most uncomfortable finding in any assessment, and the reason it is worth commissioning at all.

The inventory your team can produce from memory is not wrong. It is just not the estate.
Method

Five stages, each producing evidence rather than opinion.

01

Discover

Instrumented inventory of cryptographic assets, dependencies and protocol behaviour across the estate — including the inherited and forgotten.

Produces: An evidenced inventory, with an explicit record of what could not be reached and why.

02

Assess

Risk-ranking against the four cryptographic jobs, the data’s required confidentiality lifetime, and the obligations that actually bind you.

Produces: A prioritised exposure register a board can read and an engineer can act on.

03

Plan

Sequenced migration with dependency ordering, cost analysis and the decisions that must be made before anything is changed.

Produces: A costed, ordered plan with the trade-offs stated.

04

Migrate

Execution, including running old and new schemes together through the transition, which is where most of the operational risk actually sits.

Produces: Working systems, and the evidence that they work.

05

Adapt

Cryptographic agility, so the next transition is a configuration change rather than a programme.

Produces: The capability to do this again without repeating the cost.

Existing frameworks cover parts of this competently. They stop at the points where a general framework cannot help — the determinations, the conflicts, the estate-specific trade-offs. Those stages need an applied cryptographer, and that is where we work.

Engagement

Six weeks, fixed fee, a defensible artefact at the end.

Stages 01 and 02 as a defined engagement: fixed fee, fixed duration, and no discovery phase to scope the discovery phase.

What you get

  • An evidenced inventory of cryptographic assets and dependencies — including what discovery could not reach
  • A risk-ranked exposure register, mapped to the four jobs and to your data’s confidentiality lifetime
  • A determination of which published obligations actually bind you, with reasoning
  • The decisions you must make before migration begins, and what each forecloses

Why the artefact matters beyond the findings

Boards, auditors and regulators are beginning to ask what you have done about this. An evidenced assessment is a defensible answer; an internal spreadsheet is not. A vendor report that overclaims is worse than either — it creates a documented position you may not be able to sustain.

Book a readiness conversation
The team

Cryptographers, not generalists with a checklist.

In applied cryptography, the practitioners are the credential. This practice is led by two applied cryptographers, both holding doctorates in the field, who work in production alongside the rest of our engineering practice — on systems where cryptographic failure has consequences, not in an advisory function separated from delivery.

We maintain cryptographic components in production on public blockchain infrastructure, where the code is open and the review is adversarial by default.

Start here

Start with the question you cannot currently answer.

Tell us what you are protecting and how long it has to stay protected. We will come back with an honest view of your exposure — and of what an assessment would not establish.

  • Evidenced cryptographic inventory & exposure register
  • A determination of what actually binds you
  • Sequenced migration — we can own it end to end

Want the field guide? Ask for it here — we’ll send it with the readiness conversation.

Book a readiness conversation

We’ll only use your details to respond to your enquiry. Prefer email? info@icangroup.co.uk

Let’s talk

The clock started when the traffic was captured.

Quantum readiness is about the data you hold today. Find out where your cryptography actually lives — and what to do about it, in what order.