Post-Quantum advisory  /  The workshop
The executive briefing

A half-day that ends in a decision your board can defend.

Roughly three hours, on-site with your leadership team. We turn the EU and Romanian regulatory picture into a clear obligation, an honest read of the quantum threat, and a first move your audit committee can adopt on the record.

~3 hours
Half-day, single session
On-site
At your premises, in Romania
5–10 people
Board & C-suite
EN / RO
Your choice of language
What it is

A decision-making session. Not a training course, and not a full assessment.

Most quantum briefings leave a room more informed but no closer to a decision. This one is built backwards from the decision your board actually has to make: whether, when, and how to begin the post-quantum transition and how to document that choice for a supervisor.

Everything in the three hours serves that outcome. We spend no time on quantum physics for its own sake, and we don't sell a product at the end. You leave with a shared understanding across the room and a written position you can take to the audit committee.

The agenda in full

How the three hours run.

A single working session with two short breaks. Timings flex to the room.

00:00–00:40

The regulatory forcing function

We start where the urgency actually comes from: the stack of EU and Romanian obligations, and which of them apply to your institution specifically.

  • DORA, NIS2 (OUG 155/2024, Legea 124/2025), eIDAS 2.0 and the DNSC roadmap — mapped to your entity type
  • What "essential" or "important" entity status means for your cryptographic obligations
  • The near-term dates that matter, separated from the longer 2030–2035 horizon
00:40–01:20

The quantum threat, calibrated

An honest read of where quantum hardware actually is — neither dismissive nor alarmist — so the room decides on facts rather than headlines.

  • What current hardware trajectories do and do not imply for RSA and ECC
  • The peer-reviewed resource estimates, and what remains genuinely uncertain
  • "Harvest now, decrypt later" — where it is a real concern for a bank, and where it is overstated
01:20–02:00

Your cryptographic surface

A structured walk through where vulnerable cryptography lives in a banking estate — the surface any migration has to cover.

  • Where RSA and ECC sit across payments, PKI, TLS, signing, backups and third parties
  • Which systems are long-lived enough that today's data is tomorrow's exposure
  • How exposure is prioritised — by risk and data longevity, not by convenience
02:00–02:35

The migration roadmap

A phased plan aligned to the DNSC, EU and NIST timelines — sequenced so the highest-risk, longest-lived systems move first.

  • The phases, and what a credible first phase looks like for your institution
  • Crypto-agility and cryptographic inventory (CBOM) as the foundation
  • Where a deeper technical assessment is the right next step — stated plainly
02:35–03:00

The 90-day commitment & board statement

We close by agreeing the immediate moves and drafting the position your audit committee can adopt as its documented decision.

  • The concrete first steps: inventory, ownership, governance
  • A board-ready statement template, filled in together
  • Open Q&A — no fixed script
Who should be in the room

Built for the people who own the decision.

The session works best small and senior. The five to ten people who can actually commit the institution to a direction.

  • CISO or head of information security
  • COO and / or CTO
  • Audit-committee chair or board risk lead
  • DORA / NIS2 compliance lead
  • Head of architecture or cryptography, where you have one
What you leave with

A decision, not a reading list.

The value is in the room and on the page by the time you finish. Nothing waits on a follow-up report.

  • A shared understanding of the obligation across leadership
  • A regulatory map specific to your institution
  • A calibrated view of the threat and its real timeline
  • A phased migration direction, sequenced by risk
  • A drafted board statement your audit committee can adopt
What you take away

Three things, in your hands afterwards.

01

The briefing pack

The full slide material, tailored to your institution, including the regulatory map and the cryptographic-surface view. Yours to circulate internally.

02

The board statement

A written position on quantum-safe readiness, drafted with you in the session, ready for your audit committee to review and adopt.

03

The 90-day plan

A short, concrete list of first moves with suggested ownership. The inventory, governance and next steps to begin without delay.

Format & logistics

Everything you need to plan the session.

Duration
Half a day, ~3 hours

A single working session with two short breaks. We can run morning or afternoon.

Location
On-site, at your premises

Delivered in person anywhere in Romania. In-person keeps a board-level conversation candid and focused.

Language
English or Romanian

Your choice. The session and the board statement are delivered in whichever your leadership prefers.

The room
5–10 senior people

Kept deliberately small and senior. All we need is a room, a screen, and your leadership team's attention.

Preparation
A short pre-call

A 30-minute call beforehand lets us tailor the regulatory map and surface view to your institution.

What we need
Very little from you

No documents or system access required. The session works from your entity type and business profile.

The honest scope

This is an executive briefing, not a full cryptographic assessment. That boundary is deliberate. A credible half-day gives your leadership the regulatory map, a calibrated threat picture, and a defensible first move. It does not inventory every system or produce an implementation plan.

Where a deeper technical assessment is the right next step, we say so plainly in the session rather than overreaching. You leave knowing exactly what you have decided and what, if anything, comes next.

Book the briefing

Put quantum-safe readiness on your board's record.

Tell us your institution and a rough timeframe, and we'll arrange the pre-call and confirm a date.