Leonardo Spreafico

nd24034@bristol.ac.uk

Year 2 Student - 2024 Cohort - Cohort 6

After graduating cum laude in Mathematics from University of Milano, I took part in an international master’s program (joint Universities: Milano-Concordia, Canada) with focus on algebra, geometry and number theory.  Before that, I completed an internship in an associated law firm.

Throughout my studies, I have worked as a tutor, providing both private and curricular support to an ample spectrum of students, including adults returning to education and individuals with learning and attention disorders, affirming my belief in explainability and inclusivity.

The common ground of these experiences is my longstanding passion for interdisciplinarity and linking, which initially led me to Mathematics - as a universal, unifying sense-making effort - and eventually here, at the CDT.

PhD Project 

Secure Post-Quantum Era for Everyone: Migration to Post-Quantum Cryptography in Small and Medium Enterprises

The quantum computing industry is expected to produce sufficiently powerful machines to threaten most of the widely deployed cryptosystems in the proximate future. While predictions on whether and when this will happen are probabilistic and non-unanimous, governments mandating transition to new, supposedly quantum-resistant, cryptographic algorithms have turned what could seem an anticipatory caution against an hypothetical threat into a tangible compliance requirement.

In particular, the UK National Cyber Security Centre (NCSC) expects all enterprises to develop a detailed migration plan by 2028 and fully transition their high-priority assets by 2031. It is not a matter of 'if', nor 'when': it is a matter of 'how'.


While some transitions will happen straightforwardly, others will not - requiring a massive holistic effort: technical, economical, and organizational.
A suite of Assured Cyber Security Consultancy (ACSC) companies will assist UK enterprises in this migration endeavour, but the accessibility limitations for some organizations caused by the cost of these high-profile services and the non-exhaustiveness of use-cases of current standardized protocols, requires ongoing case-based research.

This research project, aware of the limitations of the "pipeline approach" of cryptographic design patterns - which falsely assume that cryptographic artifacts will naturally trickle down to satisfy every needs - commences where the migration effort is supposed to terminate: with small and medium enterprises. In particular, the technical cryptographic research of protocol design is subordinated and instructed upon a socially-driven elicitation and study of concrete barriers to migration.

Events Attended

CONFERENCES

"Post-Quantum Cryptography Conference" - PKI Consortium, Oct 2025, Kuala Lumpur, Malaysia (in-person attendance) https://pkic.org/events/2025/pqc-conference-kuala-lumpur-my/

"LatinCrypt" - iacr & Universidad Nacional de Colombia & EAFIT, Sept 2025, Medellin, Colombia https://ciencias.medellin.unal.edu.co/eventos/latincrypt/

"Workshop on Tackling the Quantum Threat: How to Migrate the Digital Ecosystem?" - PQCSA, Sept 2025, Athens, Greece https://www.esat.kuleuven.be/cosic/events/standardization-pqc-fundamentals/


SCHOOLS

"ASCrypto" - Advanced School on Cryptology and Information Security, Sept 2025, Medellin https://ascrypto.org/

"CatioCrypto" - Introductory School on Cryptology, Sept 2025, Medellin https://www.octavio.pk/catiocrypto/2025/

"Resilient Cybersecurity: Anticipate, Resist, Recover, and Rebuild" - joint CDT summer school, June 2025, UCL London https://www.ucl.ac.uk/cybersecurity-cdt/conferences


LOCAL EVENTS

"Gloucestershire tech week - Secure Futures Series" - CyNam, Oct 2025, Cheltenham https://cynam.org/

"FinTech West Conference" - FinTech West, Oct 2025

"BSides Bristol" - Community-led series of events, Sept 2025 https://www.bsidesbristol.org.uk/

"Festival of Digital Health - Leadership Summit", LEAP, June 2025

Academic and Industry Placements completed - Year 1

Academic Placement - University of Bristol with Chloe Martindale: advanced cryptographic protocols and preliminary identification of venues of engagement.

Industry Placement - Vodafone Business: participation in SafeAgile Ceremonies within the cybersecurity team and presentation of the white paper "Quantum-safe Market Opportunity Quantification: Potential Products and Services with relative time horizon".

Social Media 

https://www.linkedin.com/in/leonardo-spreafico-760809296