
David Balbás
David holds a PhD in cryptography and is a postdoctoral researcher at a prestigious university. His work covers cryptographic protocols, privacy-preserving systems, and secure messaging.
LinkedInWorkshop · English
Inspect your cryptography. Run controlled tests. Turn the evidence into migration priorities.
Two days of hands-on cryptographic inspection, post-quantum experiments, and migration planning for technical teams.
A two-day, English-language workshop for professionals who need to turn post-quantum risk into practical engineering decisions. Four modules build from applied cryptography and the quantum threat to post-quantum constructions and real-world protocols. Concepts are paired with guided tests, architecture reviews and reusable templates. Work through a sample stack, inspect its cryptographic dependencies, compare implementations, and prepare a migration plan that accounts for interoperability and operational constraints. Exercises use controlled environments rather than production systems. The program is designed for security engineers, IT architects, developers, CTOs, founders and technical risk teams. You do not need to be a cryptographer; familiarity with software systems, networking and a command line will help you participate in the hands-on sessions. Exact daily hours and the software setup instructions will be confirmed before the event.
Build a working model of symmetric-key and public-key cryptography, separating confidentiality, integrity and authentication. Follow key exchange and Key Encapsulation Mechanisms (KEMs), then connect them to TLS and the hybrid post-quantum handshake. Introduce the NIST standardization process, ML-KEM and ML-DSA before studying them in depth on day two.
Explore side-channel attacks, constant-time implementations and the role of open-source cryptographic libraries. Distinguish an algorithm from its implementation and the protocol that uses it.
Practical work: inspect a certificate chain and a TLS connection in a controlled environment; identify the key exchange and signature algorithms; compare a classical connection with a supported hybrid configuration. Record what the test proves and what remains outside its scope.
Takeaway: a first cryptographic inventory showing the algorithms, protocols, libraries and dependencies in a sample stack.
Understand what Shor’s and Grover’s algorithms change, what they do not change, and why a quantum computer is not simply a faster classical machine. Separate post-quantum cryptography from quantum cryptography and quantum key distribution. Read security parameters and NIST security levels without treating them as interchangeable guarantees.
Examine harvest-now, decrypt-later exposure for confidential data, and distinguish it from the separate risk of future signature forgery. Compare data lifetimes, migration lead times and uncertain quantum timelines. Consider the operational cost of larger keys, ciphertexts and signatures, alongside mathematical problems believed to remain hard for quantum computers.
Practical work: classify sample services by confidentiality and authentication exposure; build risk-register entries; rank migration priorities using data sensitivity, retention periods and dependency constraints.
Takeaway: a 1–2 page quantum-risk checklist and an initial list of systems to investigate or migrate first.
Explore lattice-based hardness assumptions, ring and module lattices, and how they lead to encryption schemes and ML-KEM. Compare lattice-signature approaches, including hash-and-sign and rejection sampling through Falcon and ML-DSA. Introduce code-based cryptography through McEliece and HQC, and examine the standardization path rather than assuming every candidate has the same deployment status.
Learn how to read guidance from NIST, BSI and ANSSI and translate it into questions about algorithm selection, interoperability, implementation assurance and cryptographic agility.
Practical work: use established libraries to run KEM encapsulation/decapsulation and signature generation/verification in a local test environment. Compare key, ciphertext and signature sizes and basic runtime measurements. Discuss why a small benchmark is not a security audit or a production-readiness guarantee.
Takeaway: an algorithm comparison sheet and vendor questions covering supported standards, hybrid modes, implementation review, performance constraints and upgrade paths.
Study the difficulties of deploying advanced cryptography at scale. Distinguish forward secrecy from post-compromise security, and examine secure messaging through the Signal protocol, post-quantum handshakes and Messaging Layer Security (MLS). Compare the protection of data in transit with data at rest through a cloud-storage case study.
Connect protocol choices to certificate lifecycles, key management, library dependencies and interoperability. Explore hybrid deployment and the ability to change algorithms without rebuilding the entire system.
Practical work: review a messaging or cloud-storage architecture, identify where encryption and authentication terminate, and develop a staged migration plan. Define pilot scope, compatibility checks, operational ownership, rollback conditions and the evidence required before a wider rollout.
Takeaway: a migration playbook combining inventory, prioritized risks, hybrid testing, vendor evaluation and the next actions for your team.

David holds a PhD in cryptography and is a postdoctoral researcher at a prestigious university. His work covers cryptographic protocols, privacy-preserving systems, and secure messaging.
LinkedIn
Founder of QuantaKrypto, Leon brings a background in infrastructure, cybersecurity, and blockchain. His work connects cryptographic decisions to production systems, security reviews, and post-quantum migration.
LinkedInYour event materials will include:
Turn what you learn into a plan for your systems, from assessing exposure to testing a migration.