Composite scenarios grounded in real problems
Modelled case studies for post-quantum decisions.
Each case models a recognisable sector problem, the event that forces a decision, how QNSI would help, the artifact the team should produce, and what must be independently validated. These are composite scenarios, not customer deployments or claimed outcomes.
Source-grounded composite scenarios
Find the situation that resembles yours
The cited primary sources establish the real external problem or obligation. The organisation and QNSI engagement are modelled so no customer or outcome is invented.
01 · AI & data platforms
4 scenariosML Platform · AI Security · Model Risk
Verify an AI model artifact before production loading
Does the model match the approved training run, evaluation, code, and release authority?
Read the modelled case study →Data Governance · ML Engineering · Responsible AI
Trace training data from source agreement to model run
Which dataset version, license, transformation, and approval contributed to a specific model?
Read the modelled case study →AI Governance · Compliance · ML Operations
Protect integrity of logs supporting a high-risk AI review
Can reviewers trust the model version, input context, human intervention, and output recorded for each consequential decision?
Read the modelled case study →AI Platform · Identity Security · Application Owners
Govern credentials used by autonomous AI agents
Which agent instance may call which tool, with what credential, data boundary, and expiration?
Read the modelled case study →02 · Automotive & mobility
4 scenariosVehicle Cybersecurity · OTA Platform · Homologation
Transition vehicle OTA signing across mixed model years
Which vehicles can verify a new signing scheme, and how will older fleets receive trusted updates?
Read the modelled case study →Connected Vehicle Architecture · PKI · Roadside Infrastructure
Measure PKI agility for vehicle-to-everything communications
Can vehicles and roadside units adopt new certificate and signature profiles without losing safety-message interoperability?
Read the modelled case study →Aftersales Security · Dealer Systems · Vehicle Engineering
Replace shared vehicle diagnostic credentials with accountable identities
Which technician, tool, and service action is authorized for a specific vehicle and time window?
Read the modelled case study →Product Cybersecurity · Supplier Assurance · Platform Engineering
Trace cryptographic evidence through automotive tier suppliers
Which supplier component introduces each algorithm, key, certificate, or software signer into the vehicle?
Read the modelled case study →03 · Aviation
4 scenariosAirworthiness · Aircraft Cybersecurity · Configuration Control
Verify the signing chain for aircraft-loadable software
Does each loadable part originate from an approved configuration and authorized release identity?
Read the modelled case study →Airport CISO · Baggage Systems · Airfield Operations
Inventory certificates across airport operational technology
Which safety or continuity functions share issuers, expired trust, or unmanaged vendor certificates?
Read the modelled case study →Continuing Airworthiness · MRO IT · Quality
Prove integrity of digital aircraft maintenance records
Can a reviewer establish who created, changed, approved, and transferred each maintenance record?
Read the modelled case study →Identity Architecture · Airport Partnerships · Crew Systems
Modernize identity trust across an airline partner ecosystem
How can crew, ground handlers, alliance partners, and contractors authenticate without permanent overbroad federation?
Read the modelled case study →04 · Banking & payments
4 scenariosCISO · Head of Payments · Cryptography Lead
Map cryptography across a bank payment rail before migration
Which payment services can move first without breaking clearing, fraud, or settlement dependencies?
Read the modelled case study →PKI Lead · HSM Operations · Payments SRE
Rehearse an HSM-backed signing-key rollover without payment downtime
Can old and new signing trust coexist long enough to rotate safely across every payment participant?
Read the modelled case study →API Security Architect · Open Banking Product Owner
Introduce hybrid post-quantum protection at an open-banking API boundary
Where can quantum-resistant handshakes be introduced while legacy aggregators still require classical interoperability?
Read the modelled case study →Incident Commander · General Counsel · Disclosure Committee
Assemble cryptographic evidence for a bank cyber-incident materiality decision
What cryptographic assets, data paths, and business services were affected, and when was that known?
Read the modelled case study →05 · Cloud & data centres
4 scenariosCloud Platform · Security Architecture · SaaS Assurance
Prove tenant separation in a multi-tenant cloud key service
Can an operator, software defect, or compromised tenant cross the intended cryptographic boundary?
Read the modelled case study →Platform SRE · Service Mesh · PKI
Make service-mesh certificate rotation measurable before PQC change
Can every workload receive, activate, validate, and retire new trust without hidden static certificates?
Read the modelled case study →Data Centre Operations · Network Engineering · Incident Management
Prevent a data-centre certificate expiry from becoming a regional outage
Which internal and external services depend on the expiring chain, and can replacement be rolled back safely?
Read the modelled case study →Security Operations · Regulatory Affairs · Data Centre Management
Prepare incident evidence for a Singapore foundational digital infrastructure operator
Can the operator rapidly identify affected cryptographic services, supplied functions, customers, and containment actions?
Read the modelled case study →06 · Defense & national security
4 scenariosAuthorizing Official · ISSM · Cryptographic Modernization
Scope a CNSA 2.0 transition for a national-security system
Which mission components, interfaces, and data lifetimes fall inside the transition boundary?
Read the modelled case study →Mission Network Architect · Coalition Interoperability · Crypto Custodian
Test post-quantum interoperability for a coalition mission network
Can partners negotiate approved protection without exposing the mission to silent downgrade or incompatible credentials?
Read the modelled case study →DevSecOps · Release Authority · Configuration Management
Modernize signing for defense software delivered into disconnected enclaves
How will an offline enclave verify the release, signer authority, dependency evidence, and revocation state?
Read the modelled case study →Supply Chain Risk · Programme Protection · Contracting
Challenge a defense supplier's cryptographic assurance claims
Which supplier claims are independently evidenced, configuration-specific, inherited, or still unqualified?
Read the modelled case study →07 · Digital assets & fintech
4 scenariosCustody CTO · Wallet Security Lead · Risk Officer
Separate digital-asset custody approval from signing execution
Which people, services, thresholds, and key stores may authorize each class of asset movement?
Read the modelled case study →Wallet Platform Lead · Business Continuity Manager
Design a recoverable wallet-key lifecycle without creating a master-key shortcut
How can the service recover from device loss or operator unavailability without introducing an ungoverned universal recovery secret?
Read the modelled case study →Platform Engineering · Third-Party Risk · Fraud Operations
Contain fintech partner API credentials by product and counterparty
Can one compromised integration credential be prevented from reaching every product, ledger, and partner?
Read the modelled case study →Controller · Treasury Systems · Internal Audit
Preserve authenticity of stablecoin reserve and reconciliation reports
Can a reviewer prove which system produced each reserve snapshot and whether the file changed after approval?
Read the modelled case study →08 · Education & research
4 scenariosUniversity CISO · Registrar · Privacy
Classify quantum exposure in lifetime student records
Which transcripts, identity, disability, conduct, and financial records remain sensitive for decades?
Read the modelled case study →Research IT · Principal Investigator · Data Steward
Preserve provenance across a multi-university research consortium
Can collaborators prove which institution, instrument, pipeline, and researcher produced each dataset version?
Read the modelled case study →Identity Management · Library IT · Research Computing
Rotate federation signing keys across campus and research services
Which relying services will reject a new federation signer, and how quickly can stale metadata be corrected?
Read the modelled case study →Core Facility · Research Integrity · Instrument IT
Authenticate data from shared scientific instruments
Can a result be attributed to the correct instrument, configuration, operator, and acquisition session?
Read the modelled case study →09 · Energy & electric grid
4 scenariosOT Security · Transmission Operations · CIP Compliance
Map cryptography between grid control centres and substations
Which operational links and devices can migrate, and which must be isolated until replacement?
Read the modelled case study →Substation Engineering · PKI · Field Operations
Rotate substation device certificates inside narrow outage windows
Can relay, gateway, and engineering trust change without creating a protection or visibility gap?
Read the modelled case study →Business Continuity · Control Systems · Key Custodians
Test cryptographic key recovery during a grid blackstart scenario
Can essential operators and systems recover credentials when normal identity, network, and key services are unavailable?
Read the modelled case study →OT Access Management · Vendor Risk · Operations
Constrain supplier remote-access trust in electric operations
Which supplier identity can reach which asset, for what task, using which credential and approval?
Read the modelled case study →10 · Government
4 scenariosAgency CIO · Identity Programme · PKI Authority
Pilot a dual-stack post-quantum PIV migration
How can new credentials and services be tested without locking out users or breaking relying applications?
Read the modelled case study →Procurement · Agency Security · System Owner
Require a cryptographic bill of materials in government procurement
Does a proposed product expose enough algorithm, library, certificate, and key-custody detail to plan future transition?
Read the modelled case study →Chief Data Officer · Privacy · Records Management
Protect citizen records with confidentiality horizons longer than system life
Which identity, tax, health, benefits, and justice records need protection beyond the next platform replacement?
Read the modelled case study →API Platform · Mission Owner · Security Authorization
Transition cryptographic trust across an interagency API
Which agency owns issuer trust, version negotiation, revocation, and failure response when algorithms change?
Read the modelled case study →11 · Healthcare providers
4 scenariosHealthcare CISO · Privacy Officer · Clinical Applications
Find ungoverned cryptography around a hospital's ePHI
Where is ePHI encrypted, signed, transmitted, or left dependent on unknown cryptographic components?
Read the modelled case study →Clinical Engineering · PKI Team · Patient Safety
Transition medical-device PKI without interrupting clinical care
Which device cohorts can accept new certificates or algorithms, and which require compensating controls until replacement?
Read the modelled case study →Cloud Security · Privacy Officer · Infrastructure
Evaluate customer-managed key custody for a healthcare cloud workload
Does customer-managed custody materially reduce risk without making recovery or clinical availability fragile?
Read the modelled case study →Incident Response · Privacy · Clinical Operations
Determine cryptographic scope during a healthcare breach
Was compromised ePHI actually protected, were relevant keys exposed, and which records fall inside the incident boundary?
Read the modelled case study →12 · Insurance & asset management
4 scenariosCISO · Records Officer · Chief Actuary
Prioritize quantum exposure in life-policy archives
Which policy, medical, beneficiary, and actuarial records remain sensitive beyond the life of today's public-key protection?
Read the modelled case study →Claims CTO · Fraud Lead · Litigation Counsel
Prove the integrity of claims evidence from intake to settlement
Can the insurer distinguish an original claimant artifact from later transformation, annotation, or fraud-review output?
Read the modelled case study →Third-Party Risk · Enterprise Architecture · Procurement
Measure cryptographic concentration across an insurer's SaaS estate
Which critical business processes depend on the same certificate authority, cloud KMS, identity provider, or unsupported algorithm?
Read the modelled case study →Cyber Underwriting · Risk Engineering · Broker
Replace a PQC underwriting checkbox with measurable evidence
Has the applicant identified material cryptographic exposure and funded a credible transition, or only adopted a policy statement?
Read the modelled case study →13 · IoT & smart cities
4 scenariosSmart City Platform · Device Operations · Procurement
Enroll unique identities for a citywide sensor fleet
Can each camera, meter, light, and environmental sensor be traced to an authorized manufacturing and enrollment event?
Read the modelled case study →IoT Architecture · Network Security · Device Vendor
Prove secure communications from constrained devices through an IoT gateway
Where does end-to-end protection terminate, and which gateway can see or modify device data?
Read the modelled case study →Device Fleet · Firmware Security · Customer Support
Rollover OTA signing trust across a fragmented IoT fleet
Which deployed devices can learn a new signer before the current key or algorithm becomes unsafe?
Read the modelled case study →Product Management · Product Security · EU Compliance
Align IoT cryptographic support with the promised support period
Can the manufacturer maintain keys, certificates, libraries, and update trust for the whole declared support period?
Read the modelled case study →14 · Legal & professional services
4 scenariosLitigation Technology · Records Counsel · CISO
Keep signed legal evidence verifiable after algorithms and firms change
What must be preserved so a future reviewer can validate signer authority and document integrity?
Read the modelled case study →Law Firm CISO · General Counsel · Records
Prioritize harvest-now-decrypt-later exposure in client archives
Which privileged matters retain strategic, personal, or commercial sensitivity beyond current public-key protection?
Read the modelled case study →M&A Technology · Client Security · Deal Counsel
Evaluate customer-controlled keys for a transaction deal room
Can the client revoke provider access without making the deal room unrecoverable during a transaction?
Read the modelled case study →Digital Forensics · Investigations Counsel · Evidence Custodian
Sign forensic evidence at every custody handoff
Can every acquisition, copy, analysis, export, and transfer be linked to an authorized actor and unchanged content?
Read the modelled case study →15 · Manufacturing
4 scenariosOT Architecture · Plant Engineering · Identity
Use machine identity to enforce factory-cell boundaries
Can a machine authenticate only to the controllers, brokers, and services required for its production role?
Read the modelled case study →Automation Engineering · Quality · Plant Cybersecurity
Verify robot firmware and configuration before a line restart
Does the robot image match the approved safety-tested build and cell configuration?
Read the modelled case study →Industrial Data Platform · Process Engineering · Quality
Protect the integrity of data feeding a manufacturing digital twin
Can planners identify which sensors, transformations, and models produced a decision-driving analytical output?
Read the modelled case study →Supplier Quality · Product Security · Procurement
Find certificate concentration across an OEM supplier network
Which products and factories depend on a supplier root, signing service, or unsupported crypto library?
Read the modelled case study →16 · Maritime & ports
4 scenariosFleet CISO · Marine Operations · Communications
Map cryptography across vessel-to-shore communications
Which satellite, radio, VPN, identity, and application paths protect operational and commercial data?
Read the modelled case study →Marine Assurance · Navigation Systems · Fleet IT
Verify navigation-data updates before bridge installation
Can bridge staff prove the update source, content, approval, and target system while offline?
Read the modelled case study →Port OT · Terminal Operations · Automation
Assign rotatable identities to port cranes and gate systems
Can each crane, gate, scanner, and control service be authenticated without shared terminal credentials?
Read the modelled case study →Trade Digitization · Legal · Port Community Systems
Preserve signature provenance for electronic cargo documents
Can parties prove who issued, endorsed, transformed, and presented each cargo record?
Read the modelled case study →17 · Media & digital content
4 scenariosNewsroom Technology · Content Authenticity · Editorial
Sign media provenance from capture through publication
Can audiences and partners verify which device, editor, and publishing system produced an asset?
Read the modelled case study →Archive · Broadcast Engineering · Rights Management
Preserve authenticity of a broadcast archive across format migration
Can the archive prove an asset's origin and editorial state after storage and codec migrations?
Read the modelled case study →Newsroom Security · Investigations Editor · Legal
Protect confidential newsroom sources against future decryption
Which communications and source records remain dangerous if captured now and decrypted years later?
Read the modelled case study →Streaming Platform · Content Protection · Rights Operations
Rotate streaming distribution keys without blacking out licensed audiences
Can origin, CDN, packager, player, and partner trust change within rights and availability constraints?
Read the modelled case study →18 · Medical devices
4 scenariosDevice Security Architect · Firmware Lead · Quality
Qualify post-quantum signing for medical-device secure boot
Can the boot chain verify a new signature scheme within memory, timing, safety, and update constraints?
Read the modelled case study →Product Security · Quality Systems · Regulatory Affairs
Bind a medical-device SBOM to the exact released firmware
Can a hospital or assessor verify that the SBOM, vulnerability status, and firmware image describe the same release?
Read the modelled case study →Fleet Operations · Device Engineering · Customer Support
Rotate field-update trust on devices that cannot all reconnect
How can offline or intermittently connected devices learn a new update key without accepting an attacker-controlled root?
Read the modelled case study →Regulatory Affairs · Product Security · Systems Engineering
Build the cryptography section of a medical-device premarket file
Is every cryptographic claim connected to a design requirement, implementation, verification result, and residual risk?
Read the modelled case study →19 · Oil, gas & pipelines
4 scenariosPipeline Cybersecurity · Control Room · Field Engineering
Inventory cryptographic trust in pipeline remote access
Which human and machine credentials can cross from enterprise access paths into operational pipeline systems?
Read the modelled case study →OT Engineering · Product Security · Maintenance
Verify firmware before it reaches a pipeline controller
Can field staff prove that a controller image is authentic, approved, and compatible before installation?
Read the modelled case study →Field IoT · Production Technology · Asset Integrity
Control identity over the lifetime of remote oilfield sensors
How will each sensor authenticate, rotate trust, and be retired when physical access is costly?
Read the modelled case study →Incident Commander · Pipeline Operations · Regulatory Affairs
Produce a pipeline cyber-incident evidence pack during operations
Which operational assets and cryptographic controls were affected, and what containment is safe while product continues to move?
Read the modelled case study →20 · Pharma & life sciences
4 scenariosClinical Systems · Quality Assurance · Biostatistics
Keep clinical-trial signatures verifiable through the study lifecycle
Will consent, source-data, analysis, and submission signatures remain attributable and verifiable years after systems change?
Read the modelled case study →Laboratory IT · Quality Control · OT Security
Give laboratory instruments distinct, rotatable machine identities
Can each instrument authenticate without shared credentials that outlive ownership or calibration status?
Read the modelled case study →Research CISO · Intellectual Property Counsel · Data Platform
Prioritize harvest-now-decrypt-later risk in drug-discovery data
Which target, compound, genomic, and partnership datasets retain economic value past current encryption assumptions?
Read the modelled case study →Quality Systems · Data Integrity · Validation Lead
Prove provenance of transformed regulated laboratory records
Can an inspector follow a result from instrument output through parsing, normalization, review, and final report?
Read the modelled case study →21 · Rail & public transit
4 scenariosRail Cybersecurity · Signalling Engineering · Safety Assurance
Stage a PKI transition for rail signalling support systems
Which support, management, and communications components can change trust without affecting safe train movement?
Read the modelled case study →Fare Systems · Payments Security · Station Operations
Rotate fare-system keys across gates, validators, and mobile wallets
Can new keys become active across every channel without rejecting riders or extending old trust indefinitely?
Read the modelled case study →Asset Management · Maintenance Control · Safety
Sign rail maintenance work orders at safety-critical handoffs
Can the operator prove which technician completed, inspected, and released work on a specific asset?
Read the modelled case study →Fleet Engineering · Vendor Management · Security Operations
Time-bound supplier remote diagnostics for rolling stock
Can a supplier diagnose one fleet subsystem without retaining access to other trains or depots?
Read the modelled case study →22 · Retail & ecommerce
4 scenariosRetail CISO · Payments · PCI Programme
Find cryptography that actually touches a retailer's card-data environment
Which terminals, gateways, token services, applications, and vendors are inside or connected to the cryptographic scope?
Read the modelled case study →Store Technology · Payment Security · Vendor Management
Verify point-of-sale firmware before store deployment
Does each terminal image come from the authorized vendor release and match the approved device model?
Read the modelled case study →Privacy · Loyalty Platform · Data Governance
Assess quantum exposure in loyalty and customer-profile data
Which behavior, identity, location, and preference records remain exploitable long after collection?
Read the modelled case study →Marketplace Platform · Seller Risk · Fraud
Contain seller-app credentials in an ecommerce marketplace
Can one compromised seller application be prevented from reading other merchants, orders, payouts, or customer data?
Read the modelled case study →23 · Software & SaaS
4 scenariosProduct Security · Engineering · EU Compliance
Create the cryptography evidence index for a CRA product technical file
Can every material cryptographic design claim be traced to implementation, test evidence, lifecycle support, and residual risk?
Read the modelled case study →PSIRT · Legal · Product Operations
Connect a product cryptography incident to the CRA reporting clock
Does an exploited vulnerability or severe incident meet reporting criteria, and what is known at each deadline?
Read the modelled case study →Release Engineering · Product Security · Customer Trust
Give SaaS customers verifiable release-signing provenance
Can a customer verify which build produced an artifact and which authorized identity approved it?
Read the modelled case study →Application Security · Platform Engineering · Architecture
Find hidden cryptography in a SaaS dependency graph
Which libraries, runtimes, services, and managed dependencies will block a cryptographic transition?
Read the modelled case study →24 · Telecommunications
4 scenariosMobile Core Security · Network Architecture · PKI
Inventory PKI dependencies across 5G network functions
Which network functions, vendors, and interfaces depend on shared trust anchors or non-agile certificate profiles?
Read the modelled case study →eSIM Platform · Device Certification · Roaming Security
Plan long-lived signature agility for eSIM provisioning
How will profile-signing and trust anchors evolve across devices that remain deployed for a decade?
Read the modelled case study →Privacy · Data Governance · Telecom CISO
Reduce long-term quantum exposure in telecom subscriber records
Which call-detail, location, account, and network records remain sensitive long enough to justify early re-protection?
Read the modelled case study →Network Cloud · Vendor Assurance · Change Authority
Verify network-function software before carrier rollout
Does the candidate image originate from the approved vendor build and match the tested configuration?
Read the modelled case study →25 · Water & wastewater
4 scenariosUtility Manager · SCADA Engineering · Cybersecurity
Establish a cryptographic baseline for a water SCADA network
Where does cryptography protect control, telemetry, engineering, and business interfaces-and where is it absent?
Read the modelled case study →SCADA Operations · Field Maintenance · PKI
Rotate certificates on remote water PLC gateways
Can trust be replaced across unmanned sites without losing telemetry or control?
Read the modelled case study →Emergency Management · SCADA · Infrastructure
Recover treatment-system keys during a flood or facility loss
Can an alternate control location authenticate and decrypt essential systems when the primary site is inaccessible?
Read the modelled case study →Maintenance Manager · Procurement · Cybersecurity
Expire vendor cryptographic access after water-system maintenance
Does each vendor credential terminate when the approved service task ends?
Read the modelled case study →Customer evidence status
A modelled case study is not deployment evidence.
QNSI has not published a verified customer deployment case study. Every modelled case separates QNSI's potential contribution from customer testing, legal applicability, accreditation, integration, production evidence, and independent assurance still required.