Set up the cryptographic infrastructure
in accordance with standards PQC, Before Q-Day Arrives
Cybercriminals„ "Harvest Now, Decrypt Later” (HNDL) strategy is based on a simple premise: attackers are already massively exfiltrating and storing your organization’s encrypted network traffic. They cannot decrypt it yet, but they will be able to do so in a few years, once they have a quantum computer (CRQC) capable of breaking asymmetric algorithms such as RSA or ECC using Shor’s algorithm.
Learn how to transition from reactive security to native crypto-resilience and prepare your infrastructure for post-quantum cryptography standards before Q-Day arrives.
Attendance is free, but space is limited. See you there.
A workshop designed for three groups of organizations
The program combines the migration of your current HSM infrastructure with preparations for post-quantum standards—regardless of what stage your organization is at.
Regulated Sector
Banks, financial institutions, and other entities subject to DORA and NIS2/UKSC that are required to present a structured inventory of cryptographic assets and devices to an auditor.
Thales Luna Users
Teams using HSM Luna 5.x/6.x that are facing an end-of-sale migration to Luna 7 or 8—and the decision of which path and method to choose.
Organizations outside the Thales ecosystem
Companies looking to take their first step toward crypto-agility: a cryptography inventory, CBOM, and a model for coexistence with existing vendors.
The data you encrypt today may be decrypted in a few years
Attackers using the „Harvest Now, Decrypt Later" do not need to break encryption right now—all they need to do is intercept and archive network traffic and PKI material today, and they will be able to decrypt it once a cryptographically relevant quantum computer (CRQC) becomes available.
Data with a long sensitivity period is most at risk: insurance policies, contracts, project documentation, and signing keys. The reference standards for the new generation of cryptography are now ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205).
Agenda – September 29, 2026, 12:15–16:25
Four hours of in-depth content: from the market context, through HSM migration and cloud key management, to PQC readiness and the first step toward crypto-agility.
Registration
Registration of participants.
Introduction and Market Context
- „Harvest Now, Decrypt Later" Attacks as the No. 1 Threat to Companies in the Regulated Sector
- Key Findings from the „Thales Data Threat Report 2026"
- Regulatory Pressure: DORA and NIS2/UKSC
- The debut of the HSM Luna 8, unveiled by Thales at the Black Hat conference
Cryptographic Hardware Migration: End-of-Sale HSM
- Device Lifecycle: End-of-Sale vs. End-of-Life – How to Plan Your Budget and Schedule in Advance
- Luna 5.x/6.x → Luna 7 Path: Backup and Restore, Cloning, and Cloning via a Temporary HA Group—When to Choose Which Method
- Obstacles to projects: FIPS migration requiring an intermediate firmware version before updating to 7.7.1 or later; cloning domain compatibility; transition from PED to password-based authentication
- Migration between vendors (e.g., from Entrust nShield): inventory of keys and applications; exportable vs. non-exportable keys
- Luna 8 Outlook: Backward Compatibility and Maintenance of Existing Applications via the Luna HSM Universal Client—Migrate to Version 7 or Go Directly to the New Platform
CipherTrust Manager and CCKM: Key Management in the Cloud
- CipherTrust Manager as a central management hub, with HSM as the root of trust
- Key ownership models: native CSP keys, BYOK, HYOK – CCKM centralizes their management across multiple clouds, regions, accounts, and subscriptions
- Data Sovereignty: Microsoft Double Key Encryption for Microsoft 365—Sharing Control Between CipherTrust and Azure, Scope of Data, and Limitations of Application
Lunch
Lunch amidst the exclusive gardens of Fort Mokotów.
Thales in the Post-Quantum Era
- The Anatomy of HNDL Risk: Long-Term Sensitivity Data—Policies, Contracts, Documentation, and PKI Materials
- Reference Standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), and hybrid modes
- Luna 8 in practice: native PQC support (ML-DSA and ML-KEM operations) while maintaining support for traditional workloads, entropy options from QRNG, multi-tenancy architecture with isolated HSM containers, FIPS 140-3 Level 3 and EU Common Criteria certifications pending
- Data Protection in Transit: FPGA-Based Network Encryptors with Over-the-Air Updates, Integration with QKD and QRNG
- Testing Without Disrupting Production: PQC Starter Kit – an environment that combines PQC algorithms in the Luna HSM with Quantum Origin, PKI scenarios, code signing, and TLS
Starting Point: An Assessment of Cryptography and Crypto-Agility for Organizations Outside the Thales Ecosystem
- The first step isn't buying equipment, but answering the question „where exactly do we find cryptography?": keys, certificates, libraries, firmware, vendors
- CBOM as a program artifact and evidence for the auditor—DORA requires structured inventories of ICT assets, including their dependencies, as well as a registry of certificates and devices for critical functions
- The role of specialized tools (e.g., the PostQuantum platform) in automating this process
- A Model of Coexistence Rather Than Revolution: PKCS#11, KMIP, and JCE Standards, and the Division of Roles Among Platforms from Different Manufacturers
- Moving to the Cloud: Luna Cloud HSM / Data Protection on Demand as a PoC Environment Without Hardware Investment
Summary and Dedicated Advisory Sessions
- Open Q&A Session
- Overview of Next Steps: Inventory Workshop, PQC Readiness Assessment, CipherTrust/CCKM PoC, HSM Migration Plan
- The opportunity to consult with ISCG and Thales engineers regarding a specific environment
Materials summarizing the individual session will be sent by email after the meeting.
Experts from ISCG, Thales, and Clico

Mateusz Bukowski-Matz
ISCG · Business Development ManagerBusiness Development Manager with many years of experience in building mature and secure IT environments. He supports organizations in their digital transformation by adapting their strategies to current market challenges and provides daily cybersecurity consulting using automation and system integration.
LinkedIn
Stanisław Wawszczak
ISCG · System ArchitectSystem Architect with over 10 years of experience in building systems for the banking sector and military organizations. At ISCG, he serves as the lead architect for HSM solutions and the Thales portfolio.
LinkedIn
Piotr Majek
Clico · IT Security ConsultantCybersecurity Engineer at CLICO since 2018. He specializes in solutions from Thales, Entrust (formerly nCipher), and Trend Micro, combining consulting services in the areas of endpoint, user, and data protection. He is a certified trainer in HSM (Hardware Security Module) and KMS (Key Management System) technologies, as well as an experienced implementation specialist who supports integrators and clients in Poland and abroad.
LinkedInGardens by Fort Mokotów, Warsaw
Gardens by Fort Mokotów
Warsaw · September 29, 2026 · 12:15–16:25
The substantive session and lunch will take place amid the exclusive gardens of Fort Mokotów—an intimate venue well-suited to a workshop format featuring advisory sessions.
Check out the venue at fortmokotow.pl →Join PQC's expert community and help us develop the best cryptographic standards
September 29, 2026, Warsaw – Gardens by Fort Mokotów, 12:30–16:30.
Admission is free; space is limited.
Registration is done through a Microsoft Forms form.


