Quantum Risk — The CISO’s Assessment
As a CISO, you need more than an awareness briefing. You need to assess quantum exposure against your specific risk profile, determine whether and when to launch a migration program, design the program’s governance structure, frame the budget conversation, and communicate the risk to your board in terms that drive appropriate action without creating panic.
This course is built for that conversation. It goes deeper than the executive briefing into threat modeling, regulatory analysis, program design, and budget framing — the specific competencies a CISO needs to own the quantum risk decision.
Who Should Take This Course
CISOs, deputy CISOs, CSOs, VPs of information security, heads of cybersecurity, and senior security leaders who are accountable for their organization’s quantum risk posture. Also appropriate for security directors at consulting firms who advise CISOs on quantum readiness.
What You Will Learn
- Conduct a CRQC timeline assessment using published research, error correction progress, and hardware roadmaps — producing a defensible position for your risk register
- Apply the HNDL and TNFL threat models to your specific organizational context: which data assets have sensitivity windows that extend into the CRQC era, which signing systems could be targeted for retroactive forgery
- Map every relevant regulatory requirement to your organization and assess compliance gaps
- Design a PQC migration program structure: governance, phasing, resourcing, and vendor strategy
- Build a migration budget that leadership will approve: cost modeling, ROI framing, and the comparison to the cost of not migrating
- Brief your board on quantum risk in a way that drives appropriate action: the evidence-based case for urgency, the honest acknowledgment of timeline uncertainty, and the concrete ask
Course Outline
Module 1 — Threat Assessment for Your Organization (60 minutes)
CRQC timeline analysis: how to build a defensible assessment from published research rather than vendor timelines or media predictions. Mapping HNDL exposure across your data estate: which data has sensitivity windows (regulatory, contractual, competitive) that extend 10, 15, or 20+ years. Mapping TNFL exposure: which signing systems (software updates, legal documents, financial transactions) could be targeted. Risk quantification approaches for quantum exposure. Integrating quantum risk into your existing enterprise risk management framework.
Module 2 — Regulatory and Compliance Assessment (60 minutes)
Every regulatory requirement that touches your organization, mapped to specific actions. CNSA 2.0 implications for government contractors and suppliers. EU directives and NIS2 crypto-agility requirements. DORA for financial services. Sector-specific mandates. Insurance questionnaire trends. Client and partner contractual expectations. Building a compliance calendar that keeps migration on track.
Module 3 — Program Design and Budget (60 minutes)
Designing a PQC migration program: governance structure, phasing (discovery → planning → implementation → verification → operations), resourcing, and vendor strategy. The vendor dependency problem and how to mitigate it. Budget construction: what each phase costs, what drives cost variation, and how to build contingency. ROI framing: quantified risk reduction, regulatory compliance value, insurance premium implications, and competitive positioning. The budget conversation: presenting to CFOs and boards.
Module 4 — Board Communication and Ongoing Governance (60 minutes)
Structuring board-level quantum risk communication: the threat, the exposure, the plan, the ask. Avoiding both fear-based messaging and dismissive minimization. The board-briefing toolkit: templates, metrics, and reporting frameworks. Setting expectations for migration milestones and reporting cadence. Ongoing governance: how quantum risk monitoring changes as the CRQC timeline evolves and as migration progresses. Peer benchmarking: what CISOs at comparable organizations are doing.
Format and Delivery
Online (self-paced) — US$499. Approximately 4 hours. 90-day access.
Live online (instructor-led) — US$499. Half-day session with peer discussion.
In-person (instructor-led) — US$799. Half-day. Ideal for CISO peer groups or security leadership teams.
Prerequisites
None. Designed for experienced security leaders.
Pricing
| Option | Price |
|---|---|
| Online (self-paced) | US$499 |
| Live online (instructor-led) | US$499 |
| In-person (instructor-led) | US$799 |
All prices are in US dollars.