Quantum Academy begins operations on September 1, 2026. Enrollment opens soon.
Skip to content

Executive & awareness

Quantum Risk for CISOs

Deep-dive quantum risk assessment for CISOs and senior security leaders. Covers CRQC timeline analysis, HNDL and TNFL threat models, regulatory drivers, migration program design, budget framing, and board communication.

4 hours Executive Online On-Demand / Live Online / In-Person US$499–999

Quantum Risk — The CISO’s Assessment

As a CISO, you need more than an awareness briefing. You need to assess quantum exposure against your specific risk profile, determine whether and when to launch a migration program, design the program’s governance structure, frame the budget conversation, and communicate the risk to your board in terms that drive appropriate action without creating panic.

This course is built for that conversation. It goes deeper than the executive briefing into threat modeling, regulatory analysis, program design, and budget framing — the specific competencies a CISO needs to own the quantum risk decision.

Who Should Take This Course

CISOs, deputy CISOs, CSOs, VPs of information security, heads of cybersecurity, and senior security leaders who are accountable for their organization’s quantum risk posture. Also appropriate for security directors at consulting firms who advise CISOs on quantum readiness.

What You Will Learn

  • Conduct a CRQC timeline assessment using published research, error correction progress, and hardware roadmaps — producing a defensible position for your risk register
  • Apply the HNDL and TNFL threat models to your specific organizational context: which data assets have sensitivity windows that extend into the CRQC era, which signing systems could be targeted for retroactive forgery
  • Map every relevant regulatory requirement to your organization and assess compliance gaps
  • Design a PQC migration program structure: governance, phasing, resourcing, and vendor strategy
  • Build a migration budget that leadership will approve: cost modeling, ROI framing, and the comparison to the cost of not migrating
  • Brief your board on quantum risk in a way that drives appropriate action: the evidence-based case for urgency, the honest acknowledgment of timeline uncertainty, and the concrete ask

Course Outline

Module 1 — Threat Assessment for Your Organization (60 minutes)

CRQC timeline analysis: how to build a defensible assessment from published research rather than vendor timelines or media predictions. Mapping HNDL exposure across your data estate: which data has sensitivity windows (regulatory, contractual, competitive) that extend 10, 15, or 20+ years. Mapping TNFL exposure: which signing systems (software updates, legal documents, financial transactions) could be targeted. Risk quantification approaches for quantum exposure. Integrating quantum risk into your existing enterprise risk management framework.

Module 2 — Regulatory and Compliance Assessment (60 minutes)

Every regulatory requirement that touches your organization, mapped to specific actions. CNSA 2.0 implications for government contractors and suppliers. EU directives and NIS2 crypto-agility requirements. DORA for financial services. Sector-specific mandates. Insurance questionnaire trends. Client and partner contractual expectations. Building a compliance calendar that keeps migration on track.

Module 3 — Program Design and Budget (60 minutes)

Designing a PQC migration program: governance structure, phasing (discovery → planning → implementation → verification → operations), resourcing, and vendor strategy. The vendor dependency problem and how to mitigate it. Budget construction: what each phase costs, what drives cost variation, and how to build contingency. ROI framing: quantified risk reduction, regulatory compliance value, insurance premium implications, and competitive positioning. The budget conversation: presenting to CFOs and boards.

Module 4 — Board Communication and Ongoing Governance (60 minutes)

Structuring board-level quantum risk communication: the threat, the exposure, the plan, the ask. Avoiding both fear-based messaging and dismissive minimization. The board-briefing toolkit: templates, metrics, and reporting frameworks. Setting expectations for migration milestones and reporting cadence. Ongoing governance: how quantum risk monitoring changes as the CRQC timeline evolves and as migration progresses. Peer benchmarking: what CISOs at comparable organizations are doing.

Prerequisites

None. Designed for experienced security leaders.

Enroll

Book this course

Online On-Demand

Start immediately and learn at your own pace, with full access to every lesson, exercise, and reference you keep.

US$499

Enrollment opens soon.

Private Team Training

Bring this course to your organization: online or at your location, on your schedule, tailored to your environment.

Custom quote

Contact us about private training

Live Online

Join a scheduled instructor-led cohort over video, with real-time exercises, discussion, and direct Q&A.

US$749

Includes 180 days of access to the online on-demand course.

Dates coming soon.

In-Person

Attend a scheduled classroom session: immersive, hands-on, and away from the distractions of a working day.

US$999

Includes 180 days of access to the online on-demand course.

Dates coming soon.

Online on-demand courses are delivered through the Quantum Academy learning platform. Live online, in-person, and private team sessions are scheduled separately. Prices are shown in US dollars.

← All courses & certifications