Introduction
QSD helps organisations integrate quantum-related cryptographic risk into enterprise risk, operational resilience and crisis management. We focus on scenarios that matter to critical services: compromised trust anchors, unsupported algorithms, supplier failure, emergency certificate rotation, cryptographic service outage and accelerated migration triggered by new intelligence or standards.
2026 Risk Context
Quantum risk increasingly belongs in mainstream resilience management rather than a distant technology register. The EU roadmap explicitly points to “Harvest Now, Decrypt Later” exposure and long device lifetimes as reasons to start transition now. For risk owners, the relevant scenario is not only a future Q-Day; it is also a forced cryptographic change caused by cryptanalysis, supplier withdrawal, certificate ecosystem change or emergency deprecation. Scenario planning should test how quickly the organisation can identify affected services, make risk decisions, coordinate suppliers, activate compensating controls and execute controlled rollback.
Why It Matters
- Quantum transition risk is not limited to confidentiality; it can affect identity, signatures, software trust and availability.
- Accelerated algorithm retirement can create a compressed change window across PKI, applications and suppliers.
- Resilience requires pre-agreed decision paths, fallback patterns and communication routines—not only technical controls.
Our Approach
- Build quantum and cryptographic risk scenarios.
- Map critical services, dependencies, recovery constraints and decision owners.
- Define crisis playbooks, fallback controls and escalation thresholds.
- Run tabletop or simulation exercises and convert lessons into remediation actions.
What You Receive
- Quantum-risk scenario catalogue
- Critical dependency map
- Cryptographic incident / crisis playbooks
- Tabletop exercise package
- Improvement plan
- Executive resilience briefing
Relevant Standards & Context
NIS2 · DORA · ISO 22301 concepts · ISO/IEC 27001 · NIST security and PQC guidance