Operational Risk Advisory

Specialist risk investigations in: Advanced Cyber Risk

Many operational resilience problems are symptoms of deeper issues.

I help leadership teams understand the implications of quantum technologies and advanced AI for the security and sustainability of their business operations. I identify underlying weaknesses and model the likelihood and impact of potential outcomes to inform board decisions.

Our approach combines established root cause analysis with forward-looking risk modelling, grounded in operational and financial data. The result is clearer foresight and a stronger basis for investment decisions.

Cause Dependency Failure Propagation Exposure Decision

Why

You might need me when.

The quantum risk is real, but nobody can agree how serious it is

Different teams have different views of the same exposure. The risk register contains it, but there is no shared understanding of what is causing it, how material it is or what happens if assumptions fail.

A post quantum migration programme looks healthy on paper, but confidence is in question

Milestones are being reported, yet dependencies are slipping, suppliers are creating friction, decisions are being deferred and management cannot see where failure is most likely to emerge.

A critical supplier or dependency feels more fragile than it appears

A service depends on one provider, technology, counterparty or hidden chain of dependencies, but nobody has established how far failure would propagate or what the real concentration risk is.

Post Quantum Resilience plans exist, but nobody is sure they would work under stress

Critical services have recovery plans and tolerances, yet it is unclear whether those assumptions hold when multiple systems, suppliers or operational dependencies fail together.

Advanced technology is moving faster than governance can keep up

AI, quantum, automation or another emerging technology is changing the operating environment faster than existing policies, controls and assurance processes can adapt.

The Board is being asked to make a decision without enough certainty

The decision is material, the consequences are significant and the available information is fragmented, overly technical or influenced by vendors and internal interests.

Something is already going wrong, but the true cause is still unclear

Teams are treating symptoms, incidents keep recurring or remediation is not fixing the problem because the underlying causal structure has not been properly identified.

Problems keep returning after they were supposedly fixed

Incidents recur, remediation programmes close without resolving the underlying issue, or one failure is replaced by another because the organisation is addressing visible symptoms rather than the causal structure behind them.

Approach

Causal Risk Analysis

Understand why the risk exists before deciding how to manage it.

Operational risk is not simply a list of controls, incidents or red ratings. It is the combined effect of dependencies, decisions and failure paths across technology, suppliers, operations and governance.

Most risk assessments begin with a list of risks. My approach begins one step earlier: what causes the exposure?

The analysis follows the relationships between business objectives, critical services, operational processes, technology, data, people, suppliers, counterparties and infrastructure, identifying root causes, shared dependencies, concentration, correlation, failure propagation and business consequences.

Only then should the organisation decide how the risk should be treated.

Cause Dependency Failure Propagation Exposure Decision

The value I bring is simple: clearer causality, better decisions and faster action on complex risk.

Not every risk needs a full investigation. Sometimes the most valuable outcome is knowing whether the exposure is material at all.

Discuss a Risk or Programme

Services

Advisory Services

Independent investigations and advisory engagements for Boards, executives and programme leaders.

Entry point

Executive Risk Diagnostic

A tightly scoped independent investigation of a specific operational, technology or emerging-risk question. Suitable where management suspects an exposure but does not yet know whether it justifies a larger programme.

1–2 weeks · Executive diagnostic and management briefing

Discuss a Diagnostic

Complex exposures

Systemic Risk Analysis

For complex exposures involving multiple business services, technologies, counterparties, suppliers or shared dependencies. Multi-layer dependency analysis, cascading scenarios, financial exposure, Board/ExCo briefing.

6–12+ weeks · Systemic analysis and senior briefing

Discuss a Systemic Risk Engagement

In Practice

What this work has looked like in practice

From visible issue to underlying cause

Control, resilience and delivery problems traced back to hidden dependencies, concentration, governance gaps and incorrect assumptions.

Risk identified to decision supported

Analysis has progressed into prioritised remediation, programme decisions, executive recommendations and clearer ownership of material exposure.

The evidence changes, conclusions change

Findings are challenged against operational reality, stakeholder evidence and system behaviour, with conclusions revised where the facts require it.

Complex environments to clarity of decision

Work has spanned banking infrastructure, telecommunications, critical systems, technology programmes, third parties and emerging technology risk.

Industries

Industries That I Work With

Most of my work is concentrated around international financial networks, with growing engagements in telecommunications, government and other critical infrastructure teams. My focus right now is handling the increased risk and disruption from agentic AI and a potential AGI, but this also extends into cryptographic risk and opportunities from new modalities of computation, including quantum.

Photos: Havarhen, Lotus Head, Bidgee, Stefan Andrej Shambora (CC BY-SA/CC BY via Wikimedia Commons); Harland Quarrington/MOD (Open Government Licence); Library of Congress and public domain sources.

About

I help Boards, executives and leadership teams understand what is actually driving complex technology and operational risk. This matters most where risk spans multiple systems, suppliers, functions or critical infrastructure.

In complex environments, the visible problem is often not the real problem. Risk can sit in hidden dependencies, concentrated suppliers, weak interfaces, fragmented ownership or assumptions that no longer hold. Conventional risk assessments can identify the exposure without explaining what is causing it, how a failure could propagate, or where intervention will have the greatest effect.

That is the problem I help solve.

I work with leadership teams to identify the underlying causes of complex risk, map the dependencies that matter, understand how failures could develop and propagate, and determine where action will most effectively reduce exposure. The objective is not simply to produce another risk assessment. It is to give leadership the clarity needed to decide what to fix, what to prioritise and where to invest.

I have worked with successful international leadership teams for more than 30 years, across both technical, product management and senior commercial leadership roles on both vendor and end user sides of the table.

My particular strength is bridging two worlds: I can speak fluently to the Board and just as fluently to the engineering team. I can work deeply with technical teams while translating complex dependencies, emerging risks and technical uncertainty into issues that leadership can understand and act upon.

My approach draws on established disciplines including root-cause analysis, systems thinking, dependency analysis, causal modelling, failure-mode analysis, scenario analysis, risk propagation and resilience assessment, applied selectively depending on what the specific risk actually requires.

Through QSECDEF and Applied Quantum, my work focuses on the operational and systemic risks emerging from advanced computational technologies, including quantum computing and AI. I work alongside specialists across innovation, cryptography, cybersecurity, operations, policy and compliance to understand how emerging technologies translate into real operational and strategic risk.

The outcome is a clearer understanding of what is changing, what could fail, how failure could propagate and where intervention matters most. That gives leadership the clarity to make better decisions, prioritise effectively and act before a complex risk becomes a costly failure.

Steve Vaile

“The outcome is a clearer understanding of what is changing, what could fail, how failure could propagate and where intervention matters most. That gives leadership the clarity to make better decisions, prioritise effectively and act before a complex risk becomes a costly failure.”

Find me working with international financial clients at Applied Quantum. Read more about Applied Quantum ↗

Find me engaged with the wider user community at QSECDEF, which provides specialist services for post-quantum migration. Read more about QSECDEF ↗

Find me on LinkedIn

Insights

Latest insights

All insights

Resources

What I have been working on..

Over the past three years I have been focused on understanding and helping to categorise Post Quantum and Advanced Technology operational risk within critical infrastructure environments, with a focus on international finance and government. The published research below is licensed under CC BY 4.0, free to use, adapt and share, including for commercial purposes, with relevant attribution and without the need to engage my services.

The tools below are free directional analysis tools built on the same compliance models, risk and impact data, and generate a directional report instantly.

AQ Cryptographic Concentration Framework cover

Cryptographic Concentration Framework

The Applied Quantum Cryptographic Concentration Framework (CCF) is a second-line method for measuring cryptographic concentration and contagion risk. It includes a global payments extension.

Read More →
AQ CBOM Framework cover

CBOM Profile with Payments and Financial Services Extension

CBOM Profile is a property taxonomy layered on CycloneDX (ECMA-424) for cryptographic bills of materials. It defines the registered appliedquantum namespace: 50 properties across eight subnamespaces, covering post-quantum migration governance, financial-sector and custody context, and the inputs a cryptographic concentration computation needs. It serves the PQC Migration Framework and the Cryptographic Concentration Framework.

Read More →
QSECDEF Quantum Migration Index cover

QSECDEF Migration Index

The QSECDEF Migration Index gives organisations a single number that answers a question every board is starting to ask but few CISOs, innovation leads or project heads can yet answer cleanly: are we actually going to be ready in time?

Read More →
AQ PQC Migration Framework and Methodology cover

PQC Framework

An open-access, practitioner-grounded methodology covering the complete 8-phase PQC migration lifecycle, from securing executive mandate and building cryptographic inventories through CBOM documentation, risk-prioritised roadmaps, hybrid pilots, infrastructure modernisation, and vendor governance. Published by Marin Ivezic of Applied Quantum.

Read More →
BIP-361 Post Quantum Migration and Legacy Signature Sunset cover

BIP-361: Post Quantum Migration and Legacy Signature Sunset

A Bitcoin Improvement Proposal for a phased, pre-announced sunset of ECDSA/Schnorr signatures: new sends to quantum-vulnerable addresses are disallowed first, those addresses become unspendable at a fixed flag-day roughly five years later, with a possible future mechanism to recover frozen funds via zero-knowledge proof of seed-phrase ownership. Co-authored with Jameson Lopp, Christian Papathanasiou and others.

Read More →
Executive (5)
Security Team (9)

Security Team

Quantum Security Risk Assessment

Map your current cryptographic assets against quantum threat vectors and receive a prioritised risk profile for your security architecture.

Open Tool ↗

Security Team

Harvest Now Decrypt Later Risk Calculator

Calculate your exposure to store-now-decrypt-later attacks based on data sensitivity classifications and estimated Q-Day timelines.

Open Tool ↗

Security Team

Cryptographic Algorithm Deprecation Timer

Track the remaining operational lifespan of your current cryptographic algorithms against published deprecation schedules and emerging standards.

Open Tool ↗

Security Team

NIST Post-Quantum Algorithm Selector

Match your use case requirements to the appropriate NIST-standardised post-quantum algorithm across key encapsulation and digital signature functions.

Open Tool ↗

Security Team

Cryptographic Asset Migration Prioritiser

Rank your cryptographic assets by migration urgency, factoring in data sensitivity, algorithm lifespan, and operational dependency.

Open Tool ↗

Security Team

Blockchain Quantum Exposure Scanner

Score your blockchain deployment across six quantum exposure dimensions: signing algorithm, address reuse, smart contracts, protocol upgrade feasibility, key management, and data sensitivity.

Open Tool ↗

Security Team

Blockchain Quantum Exposure Assessment

Dual-vector assessment scoring both signing key exposure (authentication threat) and encrypted data vulnerability (harvest now, decrypt later). Produces a composite quantum exposure profile for your blockchain infrastructure.

Open Tool ↗

OT Security

OT Cryptographic Asset Prioritisation Matrix

Score OT assets across five dimensions: lifecycle, cryptographic vulnerability, operational impact, migration feasibility, and regulatory exposure. Produces a ranked migration register with Mosca analysis and PDF report.

Open Tool ↗

OT Security

OT Protocol Quantum Vulnerability Scanner

Select the OT communication protocols deployed in your network. Identifies which use classical asymmetric cryptography a quantum computer would break, maps the specific vulnerable functions, and returns the available migration pathway for each protocol.

Open Tool ↗
Sales (2)
Defence / SATCOM (1)

Need help gauging quantum risk based on your organisation’s unique circumstances? An initial risk assessment brings clarity and urgency to teams evaluating cryptographic risk, with a full report delivered within 7 days.

Discuss a Risk or Programme

Upcoming Events

Suggested events and Workshops

Catch me at the following events as a speaker or a panellist. It's always great to meet people who share an interest in the topic.

PQC - Cryptographic Concentration Risk in Financial / Payment Networks

Event by Quantum Security Defence · Event Link

Live Training

Training

Here are some of the training courses and resources that I recommend for those new to Quantum Technologies.

Quantum Academy Training

Quantum-Safe Financial Services Intensive

Live Group Online · 1 Day · 8 Hours

October 2026

Register

QSECDEF

Quantum Business Bootcamp

Self Study Online · 10 days · 2 hours a day

Find out more

Working with advanced technology risk is not as depressing as it may sound. The process can, and often does, uncover commercial opportunities for innovation, cost savings and process improvements that lead to competitive advantage, better security and a more robust organisation.

If you are a CRO, COO, Head of TPRM, Programme Director or a Board member carrying the quantum or AI risk question nobody else seems to own, I am happy to help. Drop me a line.

Discuss a Risk or Programme

Contact

Discuss a Risk or Programme

Use this form to start a conversation. All enquiries are treated in confidence.

What to expect

All enquiries are treated in confidence.

I personally review every message. If your question is within scope, I’ll respond within two working days.

There is no obligation and no sales team. A first conversation is simply a conversation.

30+ years causal analysis experience in defence, banking, and enterprise at C-Level. Dual MBA · Rome Business School · VIU · Oxford · Yale

Tell me what you’re trying to understand. I’ll tell you whether it’s something I can help with.