Home Our Approach Services Team Insights Contact
Vendor-Independent PQC Advisory

Navigate the Post-Quantum Transition with Confidence

Business-first cryptographic advisory for financial services. We help you understand risk, build readiness, and transition—without vendor conflicts or tool-first chaos.

Aligned with:

Is the Quantum Threat Actually Real?

Separating hype from evidence. The quantum computing threat to cryptography isn't speculation—it's a documented, measured risk that the world's leading security agencies and standards bodies are actively addressing.

  • 🏛️
    NIST Published Standards (August 2024) Three quantum-resistant algorithms finalised after 8 years of global evaluation. ML-KEM, ML-DSA, and SLH-DSA are now official standards.
  • 🇬🇧
    UK NCSC: 2035 Migration Deadline National Cyber Security Centre mandates complete PQC migration by 2035, with high-priority systems by 2031.
  • 🇪🇺
    EU DORA Requires "Crypto-Agility" Article 6.4 explicitly requires financial entities to address "threats from quantum advancements" with cryptographic agility mechanisms.
  • 🏦
    FS-ISAC Global Coordination Financial Services ISAC published migration framework urging banks to begin planning immediately to avoid "crypto-procrastination."

📅 Regulatory Timeline

2024 NIST PQC Standards Published 2025 EU DORA In Force 2028 NCSC: Plans Must Be Complete 2031 High-Priority Systems Migrated 2035 FULL PQC MIGRATION 📍 YOU ARE HERE

⚠️ Mosca's Inequality

If X + Y > Z, then WORRY X = 10 years Y = 5 years X+Y = 15 Z ≈ 9-15? X = How long data must stay secret Y = Time to complete PQC migration Z = Years until quantum computers arrive ⚠️ If your X+Y exceeds Z, adversaries harvesting data TODAY can decrypt it BEFORE it expires.

Is This Urgent for Your Organisation?

The urgency depends on your data. Mosca's Theorem provides a mathematical framework to understand when you must begin migration to avoid the "Harvest Now, Decrypt Later" threat.

X + Y > Z = ⚠️ Act Now
If your data lifespan plus migration time exceeds quantum arrival, you're already behind.
X
Data Lifespan
Y
Migration Time
Z
Quantum Arrival

Our CLO, Darren Bender, has developed an enhanced framework combining Mosca's Theorem with the Learned Hand Formula for legal risk assessment—helping you understand not just when to act, but the legal implications of delay.

The ProteQC Difference

We're not tool vendors. We're your independent advisors for a complex transition.

🎯

Pinpoint risks before you invest

Understand which services are truly at risk before committing to discovery tools or migration programmes.

Audit-ready from day one

Governance frameworks, policy updates, and team training—so discoveries lead to decisions, not just dashboards.

⚖️

Unbiased advice—we don't sell tools

No product agenda. We recommend only what you actually need, from whichever vendor fits your requirements.

🔄

Cryptographic agility, not one-time fixes

Build systems that adapt to future cryptographic changes—aligned with FS-ISAC best practices.

Most banks aren't ready. And standard approaches won't help.

Quantum computing will break current encryption. Adversaries are already harvesting encrypted data today for future decryption—the "Store Now, Decrypt Later" threat is happening now, not in some distant future.

86% of financial institutions are unprepared for PQC transitions

Tool vendors say "start scanning." But in banking, that's a recipe for chaos—without governance, training, and clear ownership, discovery generates noise, not action.

⚠️ Why Tool-First Approaches Fail
  • Discovery tools can't see across SaaS, OT, and shadow IT boundaries
  • Findings aren't mapped to business services or revenue impact
  • No governance framework means no owners, no accountability
  • Risk registers have no taxonomy for cryptographic threats
  • CFOs can't fund what isn't formally classified as risk

Business-First, Then Tools

We start with your organisation—understanding which services matter before any scanning begins.

1

Pre-Discovery™

Organisational Readiness

  • Policy & standards updates
  • Governance framework design
  • Team training & capability
  • Risk taxonomy alignment
2

Business Context

Value-Stream Mapping

  • Critical service identification
  • Data classification & lifespan
  • SNDL risk assessment
  • Business impact analysis
3

Targeted Discovery

Tool-Assisted Analysis

  • Vendor-neutral tool selection
  • Scoped cryptographic inventory
  • Dependency mapping
  • Gap analysis
4

Migration Planning

Roadmap & Investment

  • GAAP/IFRS budget structuring
  • Phased migration roadmap
  • Regulatory alignment (DORA)
  • Board-ready business cases

Tool vendors start with discovery. We start with your business. That's why our clients achieve actionable outcomes, not just inventory reports.

How We Help

Comprehensive advisory services across the PQC transition lifecycle.

📋

PQC Readiness Assessment

Evaluate your organisation's current cryptographic posture and readiness for quantum-safe migration.

  • Cryptographic policy review
  • Governance gap analysis
  • Team capability assessment
  • Risk taxonomy mapping
🗺️

Business Application Mapping

Identify which services are critical and how they depend on cryptographic infrastructure.

  • Value-stream analysis
  • Data lifespan classification
  • SNDL exposure assessment
  • Priority application ranking
🔍

Discovery Support

Vendor-neutral guidance for selecting and deploying cryptographic discovery tools.

  • Tool evaluation & selection
  • Scoping & configuration
  • Results interpretation
  • Dependency analysis
📈

Migration Roadmapping

Build a phased, budgeted roadmap aligned with regulatory timelines and business priorities.

  • Multi-year planning
  • GAAP/IFRS budget structuring
  • DORA alignment
  • Board presentation materials
⚖️

Legal & Governance Advisory

Navigate duty of care, documentation requirements, and liability considerations.

  • Risk documentation frameworks
  • Board governance materials
  • Regulatory response preparation
  • Vendor contract review
🌍

Global Coordination

For multinationals navigating different regulatory regimes and migration timelines.

  • Cross-jurisdiction planning
  • FS-ISAC alignment
  • Regulatory timeline mapping
  • Knowledge transfer

Multi-Disciplinary Expertise

PQC transitions require more than technical knowledge. Our leadership brings complementary perspectives spanning strategy, technology, legal, marketing, and commercial execution.

BJ Miller

BJ Miller

Chief Executive Officer

MBA, OLY (Olympic Gold Medalist)

🇺🇸

Olympic Gold Medalist and former World Record Holder (2000 Sydney Olympics, Women's 4×100m Medley Relay). Two-time World Champion and University of Texas Athletic Hall of Fame inductee. BJ brings over 20 years of corporate sales leadership at Nike, LIDS, OtterBox, Atlassian, Pendo, and Graylog in cybersecurity. Her elite athlete background enables powerful connections with stakeholders on discipline, teamwork, and long-term preparation—themes directly applicable to PQC transitions.

Focus Areas

Cryptographic Agility Value Security Culture Executive Training Business Development
Ana Peres Quiles

Ana Peres Quiles

Chief Marketing Officer

MBA

🇺🇸

Experienced cybersecurity marketing and communications professional with extensive background at Check Point Software Technologies, leading analyst relations, public relations, and diversity & inclusion initiatives. Co-Lead of Check Point's F.I.R.E Diversity & Inclusion Committee. At ProteQC, Ana focuses on communicating customer trust benefits—particularly the 20-30 year data protection expectations of mortgage customers and long-term financial relationships.

Focus Areas

Customer Trust Messaging Stakeholder Awareness Media Relations DEI in Cybersecurity
Steven O'Sullivan

Steven O'Sullivan

Chief Digital Officer

MBA, CISSP, SCCISP, CRISC, CCSK

🇬🇧

Steven has over 25 years of experience helping organisations address their most pressing cybersecurity risk challenges. Founder of Smart Cyber Group and UK Executive Director of IOTSI (IoT Security Institute), he is a recognised expert speaker on Quantum Security and PQC at Quantum Security Defence. Steven has worked at all levels from hands-on operations to defining and implementing cyber and digital strategies across Financial Services, Telecoms, Energy, Healthcare, Retail, and Manufacturing sectors in the UK and Saudi Arabia. With over 10 years as a lecturer and trainer in information security at UK colleges and universities, Steven combines deep technical expertise with exceptional communication skills.

Focus Areas

PQC Strategy Enterprise Cyber Leadership Smart Cyber & IoT/IIoT Digital Transformation Industry 4.0
Tim D Williams

Tim D Williams

Chief Technology Officer

Chartered IT Fellow (BCS), 30+ years experience

🇬🇧

International cybersecurity educator and practitioner specialising in cryptographic infrastructure, regulatory compliance (DORA, GDPR), and the technical realities of enterprise PQC migration. Contributor to OWASP Top 10:2025 discussions on cryptographic risk prioritisation. Guest lecturer at Ukraine National Academy of Internal Affairs and at several British Universities.

Focus Areas

DORA Compliance Pre-Discovery™ Cryptographic Hygiene OWASP Risk Taxonomy

Thought Leadership

Our thinking on PQC transitions, legal liability, regulatory compliance, cryptographic risk, and budgeting for cryptographic upgrades.

Blog Steven O'Sullivan

PQC FAQ: All You Wanted to Know But Were Afraid to Ask

Comprehensive answers to the most common questions about post-quantum cryptography, from the basics to implementation challenges.

🇬🇧
Blog Steven O'Sullivan

UK NCSC Sets 2035 Deadline for Quantum-Safe Transition

The UK National Cyber Security Centre has established clear timelines. What this means for financial services organisations.

⚖️
Blog Steven O'Sullivan

Legal Imperatives Drive EU and UK PQC Compliance

How regulatory frameworks like DORA and emerging legal standards are creating compliance obligations for financial institutions.

🏦
Blog Steven O'Sullivan

FS-ISAC Calls for Global Banking Coordination on Post-Quantum Migration

The Financial Services Information Sharing and Analysis Center's recommendations for coordinated industry action.

🔍
Blog Tim D Williams

PQC Pre-Discovery: Why Banks Can't Just "Deploy and Discover"

Banking isn't a start-up. Before any discovery tool touches your infrastructure, you need governance, training, and policy updates in place.

💰
Blog Tim D Williams

PQC Budgeting: The Hidden GAAP vs. IFRS Challenge

US banks expense everything. European banks may capitalise upgrades. This distinction shapes multi-year planning for quantum transitions.

🔐
Blog Tim D Williams

What Does PQC Actually Mean? Are You Ready for Pre-Quantum Computing?

We still find TLS 1.0 enabled on production banking systems. Before discussing quantum-resistant algorithms, perhaps we need a more fundamental conversation.

👔
Blog Steven O'Sullivan

Post-Quantum Cryptography: A Strategic Imperative for the C-Suite

Why PQC preparation belongs on the board agenda, not just in the IT department. Executive perspectives on quantum risk.

Podcasts & Media

🎙️

Quantum Computing & AI: Implications for Cybersecurity

The Entropy Podcast · Francis Gorman, Bank of Ireland

Steven O'Sullivan discusses the intersection of quantum computing and AI, and how these emerging technologies are reshaping cybersecurity strategy for financial services.

🎙️

Defense Stack: Business-First PQC Transitions

The Entropy Podcast · Episode 39 · December 22, 2025

Tim Williams joins Francis Gorman to discuss the business-first approach to PQC transitions and why tool-first discovery creates more problems than it solves.

Industry Recognition

📰 Industry Citation

Venari Security: GAAP vs IFRS Shaping PQC Roadmaps

"Are EU banks quietly pulling ahead in quantum security? It turns out a surprising factor—accounting rules—is giving Europe a PQC edge. To cut through the noise, we've turned to Tim D Williams, a leading expert in cryptography, risk, and regulatory strategy."

📅 December 2025 👤 Venari Security 🏷️ GAAP vs IFRS
🛡️ Standards Contribution

OWASP Top 10:2025 - Cryptographic Failures Ranking

ProteQC submitted Issue #849 arguing against the proposed demotion of Cryptographic Failures from A02:2021 to A04:2025. With NIST PQC standards published, DORA in force, and global migration timelines established, signaling that cryptographic failures are decreasing in importance contradicts the evidence and industry trajectory.

📅 November 2025 👤 Tim D Williams 🏷️ OWASP Top 10

Ready to discuss your PQC transition?

Let's start with a conversation about where you are today, where you need to be, and how to get there without the chaos of tool-first approaches.

Send us a message

By submitting this form, you agree to our Privacy Policy. We do not use cookies on this website.