What we solve ·What is unaccounted for, and what am I missing?
Taskforce · Sustain
Where does your organization encrypt, and what happens when that encryption expires?
The cryptography is spread across twenty years of systems.
Where your organization uses cryptography, what each scheme protects and how many years that data must stay secret, with the roadmap of what to migrate first.
Post-quantum inventorySend this page to whoever decides
Use this today, without hiring anyone
The right order for thinking about this, which is not the obvious one. The question is not which algorithm you use: it is how many years what it protects has to stay secret, because data captured today gets decrypted tomorrow.
- List your data categories by useful life. Medical records, contracts, customer information, intellectual property. Write next to each how many years it has to stay confidential. Ten, twenty, forever.
- Now mark which ones travel or are stored encrypted. If a long life category is not encrypted, you have a problem that predates quantum and is more urgent.
- For the long life ones, ask with what scheme. You do not need to be a cryptographer: you need someone able to answer. That nobody can answer is already the finding.
- Review your certificates and their expiry dates. It is the easiest inventory to pull and it is usually the first thing that has to move.
The entire priority of the migration comes from one line. The data with the longest useful life is what has to be migrated first, even if its system is the least important. The typical roadmap gets ordered the other way, by system criticality, and that is the expensive way to be wrong.
This sounds like you if
- A query about post quantum readiness arrived and the starting point is still to be defined.
- You protect data that has to remain confidential in ten years.
- The use of cryptography is spread across twenty years of systems and was never inventoried.
How we solve it
The method, not the promise.
- The use of cryptography gets discovered in code, configurations, certificates and channels, with analysis at scale and not with interviews.
- It gets inventoried with algorithm, key length, location, owner and dependent system.
- It gets classified by the useful life of the protected data, which is the criterion that orders the migration.
- Third party dependence gets mapped: who encrypts on your behalf and what plans they have.
- The roadmap goes through the cryptography specialist before being delivered. That step is not optional.
What you receive
- The cryptographic inventory with algorithm, location and owner.
- The classification by useful life of the protected data.
- The map of dependence on third parties who encrypt on your behalf.
- The prioritized roadmap and the one-page note for the committee, with coverage declared area by area.
The proof that applies here
- Asset and dependency inventory over an infrastructure of 60,000 servers.
- The separation of two banks' data in one of the largest bank divestitures in Latin America, with zero regulatory findings.
- Eight years under supervision where the inventory was the reviewer's first question.
Before you hire
The firm inventories and prioritizes; the cryptographic judgment is issued by a specialist, and that is written into the scope and not into a footnote.
There is no pretending to be a cryptographer here, and that is why the specialist is a condition for accepting the engagement. What does get contributed is the half that decides the result: inventorying what nobody has inventoried and ordering it by what actually matters, which is how many years the data has to stay secret.
Which of your data has to remain confidential fifteen years from now, and do you know what protects it today?
If the problem is a different one
We have service accounts with privileges and nobody knows who answers for them.
Non-human identity governance
The vendor's dashboard shows green and the operation keeps going down.
Vendor contract and performance audit
They no longer ask whether we have controls. They ask whether I can prove it holds.
Operational resilience readiness
