Discover
Instrumented inventory of cryptographic assets, dependencies and protocol behaviour across the estate — including the inherited and forgotten.
Produces: An evidenced inventory, with an explicit record of what could not be reached and why.
Applied Cryptography & Quantum-Safe Readiness
Encrypted traffic captured today can be decrypted years from now, by an adversary who only has to wait. That makes quantum readiness a question about the data you are protecting right now, not about a machine that arrives later. Most organisations cannot answer the first question that follows: where does our cryptography actually live?
Cryptography does four separate jobs in your estate. It keeps content secret, detects alteration, proves origin, and makes that proof undeniable — the last being the property your contracts, audit trails and financial records actually rest on.
Those jobs use different mathematics, and quantum computing affects them very differently: some are barely touched, others structurally broken. So a report that says “we assessed your encryption” has already collapsed four distinct exposures into one word. You cannot sequence a migration from that, cost it, or defend it to a regulator.
Ask any vendor which of the four jobs they assessed. The answer tells you whether you bought an assessment or a template.
Ask an engineering organisation to inventory its cryptographic dependencies and you get a document listing the places people remember. It omits the certificate embedded in a device fleet, the signing key in a build pipeline nobody has touched in four years, the library three layers down a dependency tree, and the protocol that silently falls back to something older at runtime.
That is not incompetence — cryptography is deliberately invisible when it is working, configured once by someone who has since left. Which is why discovery has to be tooled: a questionnaire returns the estate people can recall, instrumentation returns the estate that exists. The gap between the two is the most uncomfortable finding in any assessment, and the reason it is worth commissioning at all.
The inventory your team can produce from memory is not wrong. It is just not the estate.
Instrumented inventory of cryptographic assets, dependencies and protocol behaviour across the estate — including the inherited and forgotten.
Produces: An evidenced inventory, with an explicit record of what could not be reached and why.
Risk-ranking against the four cryptographic jobs, the data’s required confidentiality lifetime, and the obligations that actually bind you.
Produces: A prioritised exposure register a board can read and an engineer can act on.
Sequenced migration with dependency ordering, cost analysis and the decisions that must be made before anything is changed.
Produces: A costed, ordered plan with the trade-offs stated.
Execution, including running old and new schemes together through the transition, which is where most of the operational risk actually sits.
Produces: Working systems, and the evidence that they work.
Cryptographic agility, so the next transition is a configuration change rather than a programme.
Produces: The capability to do this again without repeating the cost.
Existing frameworks cover parts of this competently. They stop at the points where a general framework cannot help — the determinations, the conflicts, the estate-specific trade-offs. Those stages need an applied cryptographer, and that is where we work.
Stages 01 and 02 as a defined engagement: fixed fee, fixed duration, and no discovery phase to scope the discovery phase.
Boards, auditors and regulators are beginning to ask what you have done about this. An evidenced assessment is a defensible answer; an internal spreadsheet is not. A vendor report that overclaims is worse than either — it creates a documented position you may not be able to sustain.
Book a readiness conversationIn applied cryptography, the practitioners are the credential. This practice is led by two applied cryptographers, both holding doctorates in the field, who work in production alongside the rest of our engineering practice — on systems where cryptographic failure has consequences, not in an advisory function separated from delivery.
We maintain cryptographic components in production on public blockchain infrastructure, where the code is open and the review is adversarial by default.
Tell us what you are protecting and how long it has to stay protected. We will come back with an honest view of your exposure — and of what an assessment would not establish.
Want the field guide? Ask for it here — we’ll send it with the readiness conversation.
Quantum readiness is about the data you hold today. Find out where your cryptography actually lives — and what to do about it, in what order.