Home Our Approach Services Team About Insights Press Contact
Vendor-Independent PQC Advisory

Navigate the Post-Quantum Transition with Confidence

Business-first cryptographic advisory for financial services. We help you understand risk, build readiness, and transition—without vendor conflicts or tool-first chaos.

Where are you in your quantum journey?

Is the Quantum Threat Actually Real?

Separating hype from evidence. The quantum computing threat to cryptography isn't speculation—it's a documented, measured risk that the world's leading security agencies and standards bodies are actively addressing.

  • 🏛️
    NIST Published Standards (August 2024) Three quantum-resistant algorithms finalised after 8 years of global evaluation. ML-KEM, ML-DSA, and SLH-DSA are now official standards.
  • 🇬🇧
    UK NCSC: 2035 Migration Deadline National Cyber Security Centre mandates complete PQC migration by 2035, with high-priority systems by 2031.
  • 🇪🇺
    EU DORA Requires "Crypto-Agility" Article 6.4 explicitly requires financial entities to address "threats from quantum advancements" with cryptographic agility mechanisms.
  • 🏦
    FS-ISAC Global Coordination Financial Services ISAC published migration framework urging banks to begin planning immediately to avoid "crypto-procrastination."

📅 Regulatory Timeline

2024 NIST PQC Standards Published 2025 EU DORA In Force 2028 NCSC: Plans Must Be Complete 2031 High-Priority Systems Migrated 2035 FULL PQC MIGRATION 📍 YOU ARE HERE

⚠️ Mosca's Inequality

If X + Y > Z, then WORRY X = 10 years Y = 5 years X+Y = 15 Z ≈ 9-15? X = How long data must stay secret Y = Time to complete PQC migration Z = Years until quantum computers arrive ⚠️ If your X+Y exceeds Z, adversaries harvesting data TODAY can decrypt it BEFORE it expires.

Is This Urgent for Your Organisation?

The urgency depends on your data. Mosca's Theorem provides a mathematical framework to understand when you must begin migration to avoid the "Harvest Now, Decrypt Later" threat.

X + Y > Z = ⚠️ Act Now
If your data lifespan plus migration time exceeds quantum arrival, you're already behind.
X
Data Lifespan
Y
Migration Time
Z
Quantum Arrival

Our CLO, Darren Bender, has developed an enhanced framework combining Mosca's Theorem with the Learned Hand Formula for legal risk assessment—helping you understand not just when to act, but the legal implications of delay.

The ProteQC Difference

We're not tool vendors. We're your independent advisors for a complex transition.

🎯

Pinpoint risks before you invest

Understand which services are truly at risk before committing to discovery tools or migration programmes.

Audit-ready from day one

Governance frameworks, policy updates, and team training—so discoveries lead to decisions, not just dashboards.

⚖️

Unbiased advice—we don't sell tools

No product agenda. We recommend only what you actually need, from whichever vendor fits your requirements.

🔄

Cryptographic agility, not one-time fixes

Build systems that adapt to future cryptographic changes—aligned with FS-ISAC best practices.

Most banks aren't ready. And standard approaches won't help.

Quantum computing will break current encryption. Adversaries are already harvesting encrypted data today for future decryption—the "Store Now, Decrypt Later" threat is happening now, not in some distant future.

95% of organisations lack a quantum computing strategy
Source: ISACA Quantum Computing Pulse Poll, 2025 View Report

Tool vendors say "start scanning." But in banking, that's a recipe for chaos—without governance, training, and clear ownership, discovery generates noise, not action.

⚠️ Why Tool-First Approaches Fail
  • Discovery tools can't see across SaaS, OT, and shadow IT boundaries
  • Findings aren't mapped to business services or revenue impact
  • No governance framework means no owners, no accountability
  • Risk registers have no taxonomy for cryptographic threats
  • CFOs can't fund what isn't formally classified as risk

Business-First, Then Tools

We start with your organisation—understanding which services matter before any scanning begins.

1

Pre-Discovery™

Organisational Readiness

  • Policy & standards updates
  • Governance framework design
  • Team training & capability
  • Risk taxonomy alignment
  • Stakeholder engagement
Key Outcome

Organisation ready for authorised, purposeful discovery

2

Business Context

Value-Stream Mapping

  • Critical service identification
  • Data classification & lifespan
  • SNDL risk assessment
  • Business impact analysis
  • Application ownership
Key Outcome

Prioritised application list tied to business value

3

Targeted Discovery

Tool-Assisted Analysis

  • Vendor-neutral tool selection
  • Scoped cryptographic inventory
  • Dependency mapping
  • Gap analysis
  • Results interpretation
Key Outcome

Decision-relevant inventory, not just technical artefacts

4

Migration Planning

Roadmap & Investment

  • GAAP/IFRS budget structuring
  • Phased migration roadmap
  • Regulatory alignment (DORA)
  • Board-ready business cases
  • Executive presentations
Key Outcome

Funded, actionable transition roadmap

"Tool vendors start with discovery. We start with your business."

That's why our clients achieve actionable outcomes, not just inventory reports.

How We Help

Comprehensive advisory services across the PQC transition lifecycle—delivered directly or through trusted partners.

📋

PQC Readiness Assessment

Evaluate cryptographic posture and readiness for quantum-safe migration—whether you're a financial institution or an advisory firm supporting client engagements.

  • Cryptographic policy review
  • Governance gap analysis
  • Team capability assessment
  • Risk taxonomy mapping
🗺️

Business Application Mapping

Identify which services are critical and how they depend on cryptographic infrastructure.

  • Value-stream analysis
  • Data lifespan classification
  • Perimeter boundary mapping
  • SNDL exposure assessment
  • Priority application ranking
🔍

Discovery Support

Vendor-neutral guidance for selecting and deploying cryptographic discovery tools—whether you're building internal capability or augmenting partner delivery.

  • Tool evaluation & selection
  • Scoping & configuration
  • Free & Open Source tool integration
  • Results interpretation
  • Dependency analysis
📈

Migration Roadmapping

Build a phased, budgeted roadmap aligned with regulatory timelines and business priorities.

  • Multi-year planning
  • GAAP/IFRS budget structuring
  • DORA alignment
  • Board presentation materials
⚖️

Legal & Governance Advisory

Navigate duty of care, documentation requirements, and liability considerations.

  • Risk documentation frameworks
  • Board governance materials
  • Regulatory response preparation
  • Vendor contract review
🌐

Global Coordination

For multinationals navigating different regulatory regimes and migration timelines.

  • Cross-jurisdiction planning
  • FS-ISAC alignment
  • Regulatory timeline mapping
  • Knowledge transfer

Multi-Disciplinary Expertise

PQC transitions require more than technical knowledge. Our leadership brings complementary perspectives spanning strategy, technology, legal, marketing, and commercial execution—capabilities we extend through collaboration with advisory partners.

BJ Miller

BJ Miller

Chief Executive Officer

MBA, OLY (Olympic Gold Medalist)

🇺🇸

Olympic Gold Medalist and former World Record Holder (2000 Sydney Olympics, Women's 4×100m Medley Relay). Two-time World Champion and University of Texas Athletic Hall of Fame inductee. BJ brings over 20 years of corporate sales leadership at Nike, LIDS, OtterBox, Atlassian, Pendo, and Graylog in cybersecurity. Her elite athlete background enables powerful connections with stakeholders on discipline, teamwork, and long-term preparation—themes directly applicable to PQC transitions.

Focus Areas

Cryptographic Agility Value Security Culture Executive Training Business Development
Ana Perez Quiles

Ana Perez Quiles

Chief Marketing Officer

MBA

🇺🇸

Experienced cybersecurity marketing and communications professional with extensive background at Check Point Software Technologies, leading public relations, and diversity & inclusion initiatives. At ProteQC, Ana focuses on communicating customer trust benefits—particularly the 20-30 year data protection expectations of mortgage customers and long-term financial relationships.

Focus Areas

Customer Trust Messaging Stakeholder Awareness Media Relations DEI in Cybersecurity
Steven O'Sullivan

Steven O'Sullivan

Chief Digital Officer

MBA, CISSP, SCCISP, CRISC, CCSK

🇬🇧

Steven has over 25 years of experience helping organisations address their most pressing cybersecurity risk challenges. Founder of Smart Cyber Group and UK Executive Director of IOTSI (IoT Security Institute), he is a recognised expert speaker on Quantum Security and PQC at Quantum Security Defence.

Focus Areas

PQC Strategy Enterprise Cyber Leadership Smart Cyber & IoT/IIoT Digital Transformation Industry 4.0
Tim D Williams

Tim D Williams

Chief Technology Officer

Chartered IT Fellow (BCS), 30+ years experience

🇬🇧

International cybersecurity educator and practitioner specialising in cryptographic infrastructure, regulatory compliance (DORA, GDPR), and the technical realities of enterprise PQC migration. Contributor to OWASP Top 10:2025 discussions on cryptographic risk prioritisation.

Focus Areas

DORA Compliance Pre-Discovery™ Cryptographic Hygiene OWASP Risk Taxonomy

Who We Are

Understanding our mission and why vendor-independence defines everything we do.

🎯

Our Mission

ProteQC exists to help financial institutions navigate the most significant cryptographic transition in 25 years—without the conflicts of interest that plague vendor-led approaches.

We believe that successful PQC migration requires business understanding before technical discovery. Our Pre-Discovery™ methodology ensures organisations are governance-ready, audit-compliant, and strategically positioned before any scanning tools are deployed.

We serve regulated financial entities and their extended supply chain across the EU, UK, USA, Australia, Singapore, Hong Kong, and Israel—bringing together legal, technical, and strategic expertise to transform quantum risk into operational resilience. We work directly with clients and alongside advisory partners who share our commitment to vendor-independent guidance.

⚖️

Why Vendor-Independence Matters

Most PQC guidance comes from organisations selling discovery tools or cryptographic products. Their advice inevitably starts with "deploy our scanner"—because that's where their revenue begins.

This creates a fundamental conflict: tool vendors benefit from complexity, extended timelines, and comprehensive (expensive) scanning. Your organisation benefits from targeted, efficient migration that addresses actual business risk.

Tool Vendor Approach
  • Scan everything first
  • Generate comprehensive inventory
  • Recommend their products
  • Extended engagement timelines
ProteQC Approach
  • Understand business context first
  • Target high-value systems
  • Recommend best-fit solutions
  • Efficient, outcome-focused delivery

We recommend tools when you need them—from whichever vendor fits your requirements. Whenever we use technologies to help facilitate your vendor selection decisions or to make delivery of our services more efficient, this is without obligation and at no additional cost. Our only "product" is independent, expert, vendor-neutral advice you can trust.

Thought Leadership

Our thinking on PQC transitions, legal liability, regulatory compliance, cryptographic risk, and budgeting for cryptographic upgrades.

Feature Articles

Thought Leadership

In-Depth Analysis
Feature Article Research Preview Tim D Williams 📖 Deep Dive

Why PQC Migration Is Different: Technological Momentum and the Perfect Storm

Why is this cryptographic transition so much harder than previous ones? The answer lies in technological momentum—a concept from Science and Technology Studies that explains why mature systems resist fundamental change. PQC is the first paradigm shift since the system acquired momentum in the late 1990s, facing all of Anderson's perverse incentive categories simultaneously.

Read the Analysis

Key Concepts

  • Hughes' technological momentum framework
  • 1995–1999: The critical lock-in window
  • Previous transitions stayed within paradigm
  • PQC: First fundamental change since lock-in
  • All perverse incentives operating simultaneously
  • Why governance before tools matters
Feature Article New Tim D Williams 🔗 Plain English

The Elephant in the Room: Why Has No One Been Charging for Cryptography?

Why is it so hard for banks to respond to cryptographic threats? We've found a surprising answer: nobody has been charging for the value cryptography delivers. No charges means no accounting, no budgets, and no maintenance plans. Quantum computing may be the forcing function that finally changes this—at a cost of around 20% higher IT spending for five years.

Read the Analysis

Key Takeaways

  • Cryptography has been "free" for decades
  • No charging means no accounting systems
  • No accounting means no maintenance budgets
  • Quantum threat will force the change
  • Expect ~20% IT cost increase for ~5 years
  • Detailed budgeting guidance coming soon
Feature Article Tribute Tim D Williams 📖 Deep Dive

Standing on the Shoulders of Giants: Ross Anderson's Security Economics and the PQC Migration Challenge

Professor Ross Anderson (1956–2024) founded Security Economics—the discipline that examines how incentives, rather than technology alone, determine security outcomes. His seminal work anticipated the very obstacles that make PQC migration so difficult today: liability dumping, the tragedy of the commons, and perverse vendor incentives. This tribute applies Anderson's framework to help financial institutions understand why governance, understanding and strategy must precede tools.

Read the Tribute

Key Concepts Applied

  • Liability Dumping in SNDL attacks
  • Tragedy of the Commons in shared infrastructure
  • Network Externalities in vendor markets
  • Protocol Maintenance across 20-year cycles
  • Asymmetric Information and "lemons"
  • Certification Theatre in PQC products
Feature Article 4-Part Series Darren Bender, CLO 📖 Technical

Post-Quantum Negligence: A Legal Framework for the Quantum Era

A groundbreaking analysis of how legal liability is evolving as quantum threats become quantifiable. Applying Mosca's Theorem, the Learned Hand Formula, and duty of care principles to help organisations understand their documentation obligations and defensible positions. This series establishes the legal foundations for treating PQC migration as a governance imperative.

Explore the Series
1

Introducing the Concept

The timing paradox of HNDL

2

Foreseeability

Quantifying quantum risk

3

Reasonable Care

Documentation as duty

4

Creative Destruction

Risk to opportunity

Industry News

ProteQC Commentary
Industry News Bank of Israel Tim D Williams 📕 Professional

The Israel Model: One Year On from the Most Prescriptive PQC Banking Directive in the World

In January 2025, Israel's Supervisor of Banks issued a directive requiring banking corporations to submit quantum preparedness plans within twelve months. That deadline has now passed. We examine what makes this directive unique, how it compares to DORA and G7 approaches, and what multinational financial institutions should learn from the most prescriptive PQC regulatory model yet published.

Read Analysis

Three Regulatory Models Compared

  • Israel: Prescriptive mandates with hard deadlines
  • EU DORA: Capability requirements, flexible timing
  • G7 CEG: Coordinated targets, non-binding
  • Board discussions mandated at minimum biennially
  • Supply chain quantum readiness required
  • Preparedness plan deadline: January 2026
Industry News QSFF Tim D Williams 📕 Professional

Europol QSFF Publishes PQC Prioritisation Framework: Why Governance Before Tools Is Becoming Industry Consensus

The Quantum Safe Financial Forum's new prioritisation framework confirms what we've been advocating: successful PQC migration requires understanding business risk and migration complexity before reaching for discovery tools. The methodology published today provides financial institutions with a structured approach to answer the board-level question: "Where do we start?"

Read Analysis

Framework Highlights

  • Business use cases first, not systems
  • Quantum Risk Score (Shelf Life, Exposure, Severity)
  • Migration Time Score (Availability, Cost, Dependencies)
  • Priority matrix for resource allocation
  • Cryptographic antipatterns as "no-regret" actions
  • Endorsed by major financial institutions
Industry News G7 CEG Tim D Williams 📕 Professional

G7 Cyber Expert Group Sets 2035 Target for Financial Sector PQC Migration

The G7 CEG—co-chaired by the US Treasury and Bank of England—has released a coordinated roadmap establishing 2035 as the target date for completing post-quantum cryptography migration across global financial systems. Critical systems should migrate by 2030-2032 to limit downside risk from "harvest now, decrypt later" attacks already underway.

Read Analysis

Key Timelines

  • 2030-2032: Critical systems migration target
  • 2035: Complete financial sector transition
  • Six-phase migration journey defined
  • Cryptographic agility emphasised
  • Vendor dependency management critical
  • Non-prescriptive but directionally clear

Perspectives

By Author:
Reading Level:
No insights found for this category. Show all insights
🎯
Blog Tim D Williams 📕 Professional

Risk Taxonomy Blindness: Why Your Risk Register Can't See Quantum Threats

Where does quantum computing risk appear in your enterprise risk register? Under which category? With which owner? If your team struggled to answer, you've encountered risk taxonomy blindness.

🔍
Blog Tim D Williams 🔗 Accessible

PQC Pre-Discovery™: Why Banks Can't Just "Deploy and Discover"

Banking isn't a start-up. Before any discovery tool touches your infrastructure, you need governance, training, and policy updates in place.

💰
Blog Tim D Williams 📖 Technical

PQC Budgeting: The Hidden GAAP vs. IFRS Challenge

US banks expense everything. European banks may capitalise upgrades. This distinction shapes multi-year planning for quantum transitions.

🔍
Blog Tim D Williams 🔗 Accessible

What Does PQC Actually Mean? Are You Ready for Pre-Quantum Computing?

We still find TLS 1.0 enabled on production banking systems. Before discussing quantum-resistant algorithms, perhaps we need a more fundamental conversation.

Blog Steven O'Sullivan 🔗 Accessible

PQC FAQ: All You Wanted to Know But Were Afraid to Ask

Comprehensive answers to the most common questions about post-quantum cryptography, from the basics to implementation challenges.

👔
Blog Steven O'Sullivan 📖 Deep Dive

Post-Quantum Cryptography: A Strategic Imperative for the C-Suite

Why PQC preparation belongs on the board agenda, not just in the IT department. Executive perspectives on quantum risk.

Industry Updates

🇬🇧
Update Steven O'Sullivan 📕 Professional

UK NCSC Sets 2035 Deadline for Quantum-Safe Transition

The UK National Cyber Security Centre has established clear timelines. What this means for financial services organisations.

⚖️
Update Steven O'Sullivan 📕 Professional

Legal Imperatives Drive EU and UK PQC Compliance

How regulatory frameworks like DORA and emerging legal standards are creating compliance obligations for financial institutions.

🏦
Update Steven O'Sullivan 📕 Professional

FS-ISAC Calls for Global Banking Coordination on Post-Quantum Migration

The Financial Services Information Sharing and Analysis Center's recommendations for coordinated industry action.

🏠
New Blog Ana Perez Quiles 📗 Plain English

Digital Trust: What Long-Term Mortgages Mean for Data Security

If you've taken out a 20 or 30-year mortgage, you're already at risk from harvest now, decrypt later attacks. Nearly half of all home loans involve data that must stay protected for decades.

Podcasts & Media

🏙️
⭐ Featured

When Quantum Risk Becomes Legal Risk

Shielded: The Last Line of Cyber Defense · PQShield · February 19th, 2026

Darren Bender joins host Johannes Lintzen on PQShield’s flagship podcast to discuss Post-Quantum Negligence, fiduciary duty, and why the absence of private-sector regulation does not remove legal responsibility. Darren argues that quantum risk has already crossed the threshold of legal foreseeability — and that organisations delaying action are accumulating legal exposure, not preserving optionality.

PQShield’s cryptographers authored or co-authored all of the PQC algorithms evaluated by NIST, including the approved algorithms announced in August 2024 — making this a landmark validation of Darren’s globally original legal framework.

🎙️

The Urgency of Quantum Readiness

The Entropy Podcast · Episode 18 · July 17th, 2025

Steven O'Sullivan discusses the intersection of quantum computing and AI, and how these emerging technologies are reshaping cybersecurity strategy for financial services.

🎙️

Defense Stack: Business-First PQC Transitions

The Entropy Podcast · Episode 39 · December 23rd, 2025

Tim Williams joins Francis Gorman to discuss the business-first approach to PQC transitions, why tool-first discovery creates more problems than it solves, and the importance of Pre-Discovery™ activities for cryptographic readiness.

Press Coverage

📰 News Coverage

Quantum Zeitgeist: New Consultancy Helps Firms Meet EU DORA Crypto Agility Rules

"ProteQC launched today as a cryptographic resilience advisory firm to help banks and financial institutions prepare for the post-quantum cryptography transition. The firm offers vendor-independent guidance, addressing pressures from EU DORA regulations and finalized NIST post-quantum standards."

📅 December 22nd, 2025 👤 Quantum Zeitgeist 🏷️ Original Coverage
Read Article → Quantum Tech News
📡 Syndicated Coverage

ProteQC Launch Covered by US Broadcast Networks & Fintech Media

ProteQC's launch announcement was syndicated across major US broadcast network websites and fintech publications, including CBS and FOX affiliates and Global Fintech Series, reaching audiences across the United States with our message on crypto-agility and quantum readiness for financial services.

📅 December 22nd, 2025 📺 CBS, FOX & Fintech Media 🏷️ Press Release Syndication

Industry Recognition

📰 Feature Article

Cybr.Sec.Media: Quantum Security Spending Hits a Tipping Point

Award-winning journalist George V. Hulme extensively cites Tim D. Williams on why 5% of security budgets now belong to post-quantum migration. Key insights include: "The SHA-1 to SHA-2 transition took over twelve years... we don't have the luxury of that leisurely pace for post-quantum computing."

📅 December 18th, 2025 👤 George V. Hulme 🏷️ PQC Budgets
Read Article → Cybr.Sec.Media
📰 Industry Citation

Venari Security: GAAP vs IFRS Shaping PQC Roadmaps

"Are EU banks quietly pulling ahead in quantum security? It turns out a surprising factor—accounting rules—is giving Europe a PQC edge. To cut through the noise, we've turned to Tim D Williams, a leading expert in cryptography, risk, and regulatory strategy."

📅 December 2025 👤 Venari Security 🏷️ GAAP vs IFRS
🛡️ Standards Contribution

OWASP Top 10:2025 - Cryptographic Failures Ranking

ProteQC submitted Issue #849 arguing against the proposed demotion of Cryptographic Failures from A02:2021 to A04:2025. With NIST PQC standards published, DORA in force, and global migration timelines established, signaling that cryptographic failures are decreasing in importance contradicts the evidence and industry trajectory.

📅 November 2025 ✏️ Tim D Williams 🏷️ OWASP Top 10

Technical Research

🔄 Research Paper
In collaboration with Oxford Scientifica

QuStream-OTP: Structural Performance Advantages Over AES at Scale

This peer-contributed technical paper presents a formal 18-dimension analysis comparing One-Time Pad (OTP) streaming encryption with AES for ultra-high-speed, low-latency secure communications. The analysis demonstrates that structural performance advantages of OTP-based encryption — including sub-nanosecond latency at 100+ Gbit/s — cannot be matched by AES optimisation alone, with particular implications for latency-sensitive financial infrastructure such as high-frequency trading networks. Importantly, the paper positions OTP as complementary to Post-Quantum Cryptography rather than a replacement, offering a pathway to information-theoretic security alongside algorithmic quantum resistance.

18
Performance Dimensions
2-6ns
Latency @ 100Gbit/s
35
Pages
📅 October 2025 👤 Adrian Neal (Oxford Scientifica) & Tim D. Williams (ProteQC) 🏷️ Cryptographic Architecture

Press Releases

🚀 Company Launch

ProteQC Launches to Help Organisations Build Crypto-Agility for the Quantum Era

ProteQC Limited announces its official launch as a specialist Post-Quantum Cryptography (PQC) consultancy, helping financial institutions and enterprises prepare for the most significant cryptographic transition in 25 years.

📅 December 22nd, 2025 📍 London, UK 🏷️ EIN Presswire
Read Press Release → via EIN Presswire

Ready to discuss your PQC transition?

Let's start with a conversation about where you are today, where you need to be, and how to get there without the chaos of tool-first approaches.

Send us a message

By submitting this form, you agree to our Privacy Policy. We do not use cookies on this website.