Business-first cryptographic advisory for financial services. We help you understand risk, build readiness, and transition—without vendor conflicts or tool-first chaos.
Separating hype from evidence. The quantum computing threat to cryptography isn't speculation—it's a documented, measured risk that the world's leading security agencies and standards bodies are actively addressing.
The urgency depends on your data. Mosca's Theorem provides a mathematical framework to understand when you must begin migration to avoid the "Harvest Now, Decrypt Later" threat.
Our CLO, Darren Bender, has developed an enhanced framework combining Mosca's Theorem with the Learned Hand Formula for legal risk assessment—helping you understand not just when to act, but the legal implications of delay.
We're not tool vendors. We're your independent advisors for a complex transition.
Understand which services are truly at risk before committing to discovery tools or migration programmes.
Governance frameworks, policy updates, and team training—so discoveries lead to decisions, not just dashboards.
No product agenda. We recommend only what you actually need, from whichever vendor fits your requirements.
Build systems that adapt to future cryptographic changes—aligned with FS-ISAC best practices.
Quantum computing will break current encryption. Adversaries are already harvesting encrypted data today for future decryption—the "Store Now, Decrypt Later" threat is happening now, not in some distant future.
Tool vendors say "start scanning." But in banking, that's a recipe for chaos—without governance, training, and clear ownership, discovery generates noise, not action.
We start with your organisation—understanding which services matter before any scanning begins.
Organisational Readiness
Value-Stream Mapping
Tool-Assisted Analysis
Roadmap & Investment
Tool vendors start with discovery. We start with your business. That's why our clients achieve actionable outcomes, not just inventory reports.
Comprehensive advisory services across the PQC transition lifecycle.
Evaluate your organisation's current cryptographic posture and readiness for quantum-safe migration.
Identify which services are critical and how they depend on cryptographic infrastructure.
Vendor-neutral guidance for selecting and deploying cryptographic discovery tools.
Build a phased, budgeted roadmap aligned with regulatory timelines and business priorities.
Navigate duty of care, documentation requirements, and liability considerations.
For multinationals navigating different regulatory regimes and migration timelines.
PQC transitions require more than technical knowledge. Our leadership brings complementary perspectives spanning strategy, technology, legal, marketing, and commercial execution.
Olympic Gold Medalist and former World Record Holder (2000 Sydney Olympics, Women's 4×100m Medley Relay). Two-time World Champion and University of Texas Athletic Hall of Fame inductee. BJ brings over 20 years of corporate sales leadership at Nike, LIDS, OtterBox, Atlassian, Pendo, and Graylog in cybersecurity. Her elite athlete background enables powerful connections with stakeholders on discipline, teamwork, and long-term preparation—themes directly applicable to PQC transitions.
Focus Areas
Experienced cybersecurity marketing and communications professional with extensive background at Check Point Software Technologies, leading analyst relations, public relations, and diversity & inclusion initiatives. Co-Lead of Check Point's F.I.R.E Diversity & Inclusion Committee. At ProteQC, Ana focuses on communicating customer trust benefits—particularly the 20-30 year data protection expectations of mortgage customers and long-term financial relationships.
Focus Areas
Originator of the "Post-Quantum Negligence" legal framework. Focused on how duty of care, foreseeability, and liability standards are evolving as quantum threats become quantifiable. Combining legal analysis with business strategy to help organisations document defensible positions.
Focus Areas
Steven has over 25 years of experience helping organisations address their most pressing cybersecurity risk challenges. Founder of Smart Cyber Group and UK Executive Director of IOTSI (IoT Security Institute), he is a recognised expert speaker on Quantum Security and PQC at Quantum Security Defence. Steven has worked at all levels from hands-on operations to defining and implementing cyber and digital strategies across Financial Services, Telecoms, Energy, Healthcare, Retail, and Manufacturing sectors in the UK and Saudi Arabia. With over 10 years as a lecturer and trainer in information security at UK colleges and universities, Steven combines deep technical expertise with exceptional communication skills.
Focus Areas
International cybersecurity educator and practitioner specialising in cryptographic infrastructure, regulatory compliance (DORA, GDPR), and the technical realities of enterprise PQC migration. Contributor to OWASP Top 10:2025 discussions on cryptographic risk prioritisation. Guest lecturer at Ukraine National Academy of Internal Affairs and at several British Universities.
Focus Areas
Our thinking on PQC transitions, legal liability, regulatory compliance, cryptographic risk, and budgeting for cryptographic upgrades.
A groundbreaking analysis of how legal liability is evolving as quantum threats become quantifiable. Applying Mosca's Theorem, the Learned Hand Formula, and duty of care principles to help organisations understand their documentation obligations and defensible positions.
Explore the Series →The timing paradox of HNDL
Quantifying quantum risk
Documentation as duty
Risk to opportunity
Comprehensive answers to the most common questions about post-quantum cryptography, from the basics to implementation challenges.
The UK National Cyber Security Centre has established clear timelines. What this means for financial services organisations.
How regulatory frameworks like DORA and emerging legal standards are creating compliance obligations for financial institutions.
The Financial Services Information Sharing and Analysis Center's recommendations for coordinated industry action.
Banking isn't a start-up. Before any discovery tool touches your infrastructure, you need governance, training, and policy updates in place.
US banks expense everything. European banks may capitalise upgrades. This distinction shapes multi-year planning for quantum transitions.
We still find TLS 1.0 enabled on production banking systems. Before discussing quantum-resistant algorithms, perhaps we need a more fundamental conversation.
Why PQC preparation belongs on the board agenda, not just in the IT department. Executive perspectives on quantum risk.
The Entropy Podcast · Francis Gorman, Bank of Ireland
Steven O'Sullivan discusses the intersection of quantum computing and AI, and how these emerging technologies are reshaping cybersecurity strategy for financial services.
The Entropy Podcast · Episode 39 · December 22, 2025
Tim Williams joins Francis Gorman to discuss the business-first approach to PQC transitions and why tool-first discovery creates more problems than it solves.
"Are EU banks quietly pulling ahead in quantum security? It turns out a surprising factor—accounting rules—is giving Europe a PQC edge. To cut through the noise, we've turned to Tim D Williams, a leading expert in cryptography, risk, and regulatory strategy."
ProteQC submitted Issue #849 arguing against the proposed demotion of Cryptographic Failures from A02:2021 to A04:2025. With NIST PQC standards published, DORA in force, and global migration timelines established, signaling that cryptographic failures are decreasing in importance contradicts the evidence and industry trajectory.
Let's start with a conversation about where you are today, where you need to be, and how to get there without the chaos of tool-first approaches.
Telephone
UK: +44 (0)203 835 5326
US: +1 281-400-3161
Registered Office
71-75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Company Number
16781199 (England & Wales)