Kaysec is the post-quantum practice of Spinsphere, a New Zealand quantum technology company.
We are independent. Kaysec is tied to no vendor and earns nothing from the products you end up choosing, so our recommendations answer to your risk, not to a partner quota. Where we help implement, we do it vendor-neutrally.
We help New Zealand organisations work out which of their systems actually carry quantum risk worth acting on, and in what order to move, on measured evidence rather than manufactured urgency.
1. Readiness snapshot
A measured, evidence-led baseline of your quantum exposure. We identify which systems and datasets carry potential post-quantum risk, benchmark your posture against NZISM and frameworks, and characterise the threat honestly, including where there is no threat worth acting on. You finish with a clear picture and a defensible priority order.
Exposure snapshot, NZ$4,500 + GST. An external read of every public domain, mail exchanger and certificate you run, a discovery session, a shelf-life inventory of your most important datasets, an NZISM 2.4 gap check, and a short written report with a priority order. About two weeks.
Full readiness snapshot, NZ$12,500 + GST. Everything above, plus an inside cryptographic inventory of the systems that protect your long-lived data (keys, certificates, libraries, protocols), a supplier readiness check industry-standard vendor questions, a frozen point-in-time baseline for future re-scans, a board-ready report, and a leadership briefing. About three to four weeks.
See what the internet already sees
A one-minute external read of your website and email encryption for post-quantum readiness. It touches nothing internal and gives you a plain characterisation, not a score: hybrid post-quantum, classical, or older than that.
2. Migration roadmap & implementation
A phased, costed transition plan for the systems that warrant it. We sequence the work against your operational constraints, supplier dependencies and regulatory timeline, using hybrid strategies that keep you interoperable throughout. This is the organisational programme, not a cryptographic parts swap. The hard part of PQC migration is the coordination, and coordination is what the roadmap manages. From there we work the plan together, staying agile as new or unexpected challenges arise. Our flexibility and transparency keep the migration fluid.
3. Continued advising and monitoring
Standards move, suppliers ship, and your own systems change. A regular re-scan and review keeps your baseline current, tracks your suppliers’ readiness, and flags what has shifted since the last point of reference. This way quantum risk stays a managed line item rather than an ad hoc audit. We keep up to date with the frameworks, standards, regulatory policies and guideline updates and will advise you when action or change is recommended or necessary.
The world has agreed on the maths of post-quantum cryptography. It has not agreed on how to use it — and the traffic on the wire has already changed shape. Four developments from the past fortnight, and what they mean for New Zealand. There is a comfortable version of the post-quantum story in which the…
Standfirst: A validated hardware security module, a bill aimed at the electricity grid, and a Finnish research programme pointing at the certificate layer. Three developments in one week say the same thing: the hard part of the post-quantum transition is no longer cryptographic. A fourth — a vendor blog doing the rounds again — is…
What “harvesting” encrypted data really costs an adversary, what it would take to read the stockpile, and where the actual threat is hiding. This article walks a five-gate framework (physical access, storage economics, decryptability, data shelf life, and adversary motive) from first principles, and grounds it in an original internet-wide scan of what post-quantum cryptography…
On 28 July, Anthropic published two cryptanalysis results produced with its Claude Mythos Preview model. One improved an attack on a reduced-round variant of AES — theoretically interesting, practically irrelevant, and not our subject here. The other is a genuine problem for HAWK, a post-quantum signature scheme that NIST advanced to a third round of…
Three weeks in June and July produced hard US deadlines for post-quantum cryptography, a blunt statement from the US military about which quantum-safe technologies don’t count, and a machine-checked paper on what it actually costs to break RSA-2048 and P-256. New Zealand remains the only Five Eyes member with no migration deadline at all. For…
Our read of a sweeping new survey of quantum computing and security keeps circling back to one under-addressed problem. Two specialist papers from the same week show why getting your organisation quantum-safe is becoming harder, not easier. Three papers landed on arXiv in the space of a fortnight in late May and early June, and…
On 2 June 2026 we re-ran our post-quantum cryptography (PQC) readiness scanner against the same 118 New Zealand critical infrastructure entities we assessed on 14 April 2026. Seven weeks is a short interval for a cryptographic migration story — and the headline number reflects that: the overall PQC rate moved from 52.6% to 52.2%, essentially…
Three papers published in the second week of May 2026 cover different parts of the post-quantum migration stack: a new NIST report on the next generation of digital signature candidates, a proof-of-concept PQC deployment inside a production bank, and a working FN-DSA implementation on Raspberry Pi hardware. Read together, they deliver the same message from…
6G standardisation is still years away, but the cryptographic choices that will shape it are being made now. Every Five Eyes PQC migration deadline falls before the first commercial 6G radios are expected. A new paper from Toshiba’s Bristol research lab benchmarks how the NIST-standardised primitives behave on actual telecom-relevant hardware — desktop-class, ARM-class edge,…
A new arXiv preprint runs the numbers on something every Australian bank — and by extension every NZ subsidiary of one — should already have answered: can post-quantum signatures actually run inside a real-time payments SLA? Reference: arXiv 2605.02276v1, 4 May 2026. The simulation covers Australia’s real-time retail payments rail at production volume — 5.2…