Print-ready copy — print it or save it as PDF
Back
Dubai 5 October 2026
Training Programme

Harvest Now, Decrypt Later: A Post-Quantum Cryptography Readiness Training Course

1Summary

An attacker does not need a working quantum computer today to threaten your data tomorrow — encrypted traffic captured now can simply be stored and decrypted later, once the technology catches up. This "harvest now, decrypt later" risk is the practical starting point of the Post-Quantum Cryptography Readiness course from Arab British Fellowship Training Academy, and it is why organisations with long-lived sensitive data cannot afford to treat post-quantum migration as a distant problem.

Delivered under Cybersecurity and Digital Security, the course builds from that threat toward a practical response: a refresher on how modern cryptography actually protects enterprise systems today, followed by the post-quantum mechanisms designed to replace the parts of it that quantum computing will eventually break.

Two standardised algorithms anchor the technical core of the programme — Kyber for key encapsulation and Dilithium for digital signatures — alongside the broader lattice-based cryptography they are built on and the NIST standardisation process that gives organisations a defensible basis for their migration decisions. The course also keeps established technologies such as elliptic curve cryptography in view, since most organisations will run hybrid, coexisting systems for years rather than switching overnight.

The second half of the programme is deliberately organisational rather than purely technical: building a cryptographic inventory, assessing which systems are actually at risk, and turning that assessment into a realistic migration roadmap, governance framework, and long-term resilience strategy.

Arab British Fellowship Training Academy designed the course for security leaders and technical teams who need to move from awareness of quantum risk to a defensible, prioritised action plan.

2Objectives and target group

The course moves from threat awareness to a defensible migration plan, in the order a security team would actually need to act.

Understanding the risk

  • Explain the "harvest now, decrypt later" threat and why long-lived sensitive data is exposed today, not just in the future.
  • Assess the limitations of conventional public-key cryptography against emerging quantum computing capabilities.
  • Evaluate business implications of cryptographic disruption and build organisational awareness of quantum risk.

Understanding the replacement mechanisms

  • Explain the principles of lattice-based, hash-based, code-based, and multivariate post-quantum cryptography.
  • Examine Kyber's role in key encapsulation and Dilithium's role in post-quantum digital signatures.
  • Analyse the NIST standardisation process and its implications for enterprise cryptographic planning.
  • Assess where elliptic curve cryptography remains in use and what that means for coexistence during migration.

Turning assessment into action

  • Build a cryptographic inventory across applications, networks, certificates, and infrastructure.
  • Prioritise systems for migration according to risk and business impact.
  • Develop a migration roadmap, including hybrid cryptographic approaches during the transition period.
  • Address integration, performance, interoperability, and key-management requirements during implementation.

Governing the transition

  • Establish cryptographic governance frameworks, ownership, and policy standards.
  • Measure post-quantum readiness and maintain cryptographic agility for future algorithm changes.
  • Build a long-term cryptographic resilience strategy connected to enterprise security architecture.

Target Audience

Chief information security officers, cybersecurity and information security managers, and security architects will find the course directly relevant to strategic planning, alongside cryptography professionals, security engineers, and network, cloud, and application security specialists handling implementation.

Identity and access management professionals, IT risk and compliance managers, and IT auditors reviewing cryptographic controls can use the course to strengthen risk assessment and governance work.

The programme also supports digital transformation leaders, technology managers responsible for security modernisation, software engineers building secure applications, and consultants supporting cybersecurity transformation programmes — as well as senior technology and business stakeholders who need to understand the organisational implications of post-quantum migration without handling implementation directly.

3Course Content

Modules

Module 1: Harvest Now, Decrypt Later — Why Quantum Risk Is Already Here

  • Quantum computing concepts relevant to cybersecurity
  • Potential impact of quantum algorithms on established cryptographic systems
  • Identifying information requiring long-term protection today

Module 2: Modern Cryptography Refresher for Enterprise Security

  • Symmetric and asymmetric mechanisms, public-key infrastructure
  • Cryptographic dependencies across enterprise applications, identity, and secure communications

Module 3: Post-Quantum Foundations — Lattice, Hash, Code and Multivariate Approaches

  • Objectives of quantum-resistant cryptographic mechanisms
  • Lattice-based, hash-based, code-based, and multivariate approaches compared
  • Selecting appropriate mechanisms for corporate environments

Module 4: Kyber and Modern Key Encapsulation

  • Key generation, encapsulation, and decapsulation concepts
  • Implementation, integration, and key lifecycle management

Module 5: Dilithium and Post-Quantum Digital Signatures

  • Digital signing and verification processes
  • Certificate considerations and integration with existing public-key infrastructure

Module 6: NIST Standardisation and What It Means for Your Roadmap

  • Standardised algorithm families and security levels
  • Technology procurement, vendor evaluation, and cryptographic agility

Module 7: Elliptic Curve Cryptography — What Stays, What Changes

  • Existing dependencies and identifying systems that use elliptic curve mechanisms
  • Compatibility, interoperability, and migration challenges for legacy applications

Module 8: Building a Cryptographic Inventory and Risk Assessment

  • Mapping certificates, keys, protocols, applications, and infrastructure
  • Prioritising systems by risk and business impact, and building a risk register

Module 9: Migration Strategy — From Roadmap to Hybrid Implementation

  • Establishing migration priorities and planning technology replacement cycles
  • Hybrid cryptographic approaches, integration, and operational security after deployment

Module 10: Cryptographic Governance and Corporate Readiness

  • Governance frameworks, ownership, policy, and compliance considerations
  • Measuring post-quantum readiness and building a practical roadmap

Module 11: Strategic Cryptographic Resilience

  • Maintaining cryptographic agility as standards evolve
  • Connecting post-quantum security to long-term enterprise architecture and investment planning

FAQs

1. What does "harvest now, decrypt later" actually mean?

It means encrypted data captured today can be stored and decrypted once quantum computing matures — Module 1 explains why this makes long-lived sensitive data a present-day risk, not a future one.

2. Does the course cover Kyber and Dilithium in depth?

Yes — Module 4 covers Kyber for key encapsulation and Module 5 covers Dilithium for digital signatures, including implementation and integration considerations.

3. Will elliptic curve cryptography become obsolete after this course?

No — Module 7 explains why most organisations will run elliptic curve and post-quantum mechanisms side by side for years, and what that coexistence requires.

4. Is this course only for cryptography specialists?

No — Modules 8 through 11 are built for risk, governance, and leadership audiences who need to plan and oversee migration without necessarily implementing it themselves.

5. Who provides this training?

Arab British Fellowship Training Academy, under the Cybersecurity and Digital Security category.

Please enter your details to download the file

Harvest Now, Decrypt Later: A Post-Quantum Cryptography Readiness Training Course