25 August 2026
The timeline for quantum computing has always been a moving target. For years, the banking industry treated it as a distant threat, something to monitor but not yet act upon. That mindset is shifting fast. Banks are now pouring serious money into quantum-resistant security, not because quantum computers are here, but because the risk they pose to current encryption is already present in a quieter, more insidious form.
The truth is, the threat is not just about the future. It is about today's data being stolen and stored for later decryption. This is called the "harvest now, decrypt later" attack, and it is the single most compelling reason why banks are moving with urgency. Every piece of encrypted financial data that crosses a network today could be recorded by an adversary with long-term ambitions. When a sufficiently powerful quantum computer arrives, that data becomes readable. For a bank, that means account numbers, transaction histories, wire instructions, and personal identifiers all exposed at once.

Quantum computers, specifically those running Shor's algorithm, can solve both problems in polynomial time. That is a technical way of saying that a sufficiently large quantum computer could break RSA and ECC in hours or days, instead of billions of years. The key phrase is "sufficiently large." Current quantum computers have a few hundred qubits and high error rates. They are nowhere near the scale needed to break real-world encryption. But the trajectory is clear, and the financial incentives for building such machines are enormous.
Banks are not waiting for the machine to exist. They are preparing for the moment it does, because migrating an entire banking infrastructure to new cryptographic standards is not a weekend project. It takes years of planning, testing, and deployment across thousands of systems, from ATMs to core banking platforms to interbank settlement networks.
Consider a wire transfer. It is encrypted in transit, but the ciphertext can be captured by anyone monitoring the network. Today, that ciphertext is useless. In ten years, it is a treasure map. The same applies to stored customer records, internal communications, and even old backup tapes that banks are legally required to keep for years.
This is why banks are not just upgrading new systems. They are also looking at their legacy data archives and asking a hard question: how much of this data will still be sensitive in five or ten years, and is it currently protected in a way that will survive the quantum transition? The answer, for most institutions, is no.

This is not as simple as swapping one algorithm for another. Some post-quantum algorithms have larger key sizes and require more computational overhead. A bank's existing hardware, such as payment terminals or HSMs (Hardware Security Modules), may not have the processing power or memory to handle them. This forces banks to make hard choices about which systems to upgrade, which to replace, and which to phase out.
Hybrid approaches are practical for a simple reason: trust. Banks have spent decades validating RSA and ECC. They know the failure modes, the performance characteristics, and the attack surfaces. New post-quantum algorithms are promising, but they have not been subjected to the same decades of scrutiny. Running both in parallel gives banks a safety net while the new algorithms prove themselves in real-world deployments.
The trade-off is performance. Hybrid encryption requires more bandwidth and more computation. For a high-frequency trading platform or a real-time payment system, this can introduce latency. Banks are testing these hybrid systems in controlled environments to measure the impact before rolling them out across production networks.
QKD is physically secure in a way that algorithm-based encryption can never be. It does not rely on mathematical assumptions. However, it requires dedicated fiber optic links and specialized hardware, making it expensive and impractical for broad deployment. Banks are using it selectively, for example, between data centers or between a central bank and major financial institutions, where the cost is justified by the sensitivity of the data.
The common misconception is that QKD will replace all current encryption. That is not realistic. It is a niche tool for point-to-point links. For general internet traffic, algorithms are the only option. Banks understand this and are investing in QKD only where it provides real value, not as a universal solution.
The process is not just about replacing algorithms. It is about updating protocols, certificates, and key management systems. It involves renegotiating agreements with vendors and partners who also need to upgrade. It requires re-training staff and updating compliance frameworks. This is a multi-year effort even with full commitment.
If a bank waits until a quantum computer is announced, it is already too late. The data that was harvested over the previous years is already compromised, and the migration will be rushed, error-prone, and more expensive. The banks that start now are not just protecting future data. They are protecting the data that is being intercepted and stored today.
In Asia, some central banks are exploring quantum-resistant security for their real-time gross settlement systems, which handle trillions of dollars in transactions daily. These systems are prime targets because a single break could disrupt the entire financial system.
What is notable is that these efforts are not driven by a single event. They are driven by a gradual recognition that the risk is real and the lead time is long. Banks are not reacting to a crisis. They are managing a known risk with a known timeline.
Another mistake is assuming that all data needs the same level of protection. Not all data is created equal. A bank's internal cafeteria menu does not need quantum-resistant encryption. Its customer authentication system does. A risk-based approach is essential, but many banks are treating the problem as a blanket upgrade, which wastes resources and creates unnecessary complexity.
A third mistake is ignoring the supply chain. Banks rely on third-party vendors for everything from cloud services to payment processing to security software. If a vendor does not upgrade its own systems, the bank's efforts are worthless. Banks need to contractually require their vendors to meet quantum-resistant standards and to verify that compliance through regular audits.
Next, prioritize by risk. Focus on systems that protect long-lived data, such as customer records, and systems that are critical to daily operations, such as authentication and payment processing. These should be migrated first. Systems with short-lived data, such as temporary session tokens, can be migrated later.
Then, adopt a hybrid approach for the transition period. Run both traditional and post-quantum algorithms in parallel, but have a clear plan for when to drop the traditional one. Do not let the hybrid state become permanent, as that defeats the purpose of reducing reliance on broken algorithms.
Finally, treat this as a continuous process, not a one-time project. Quantum computing is not the end of the story. New algorithms will be developed, new attacks will be found, and the standards will evolve. Banks need a flexible cryptographic framework that can adapt to new threats without requiring a complete overhaul each time.
However, regulation is a double-edged sword. If regulators set unrealistic deadlines, banks may rush implementations and introduce new vulnerabilities. If they set no deadlines, banks may procrastinate. The ideal approach is for regulators to set clear expectations and timelines, but also to provide flexibility for banks to implement solutions in a way that suits their specific infrastructure.
Industry standards bodies are also playing a role. The financial industry is heavily reliant on global standards, such as those from ISO and the Payment Card Industry Security Standards Council. Updating these standards to include post-quantum algorithms is a slow process, but it is essential for ensuring interoperability between banks and across borders.
Banks are investing in training programs, hiring specialists, and partnering with academic institutions to build internal expertise. They are also creating cross-functional teams that include not just cryptographers, but also network engineers, application developers, and risk managers. The migration touches every part of the bank, so the team needs to be equally broad.
Another human factor is resistance to change. Bank IT departments are notoriously conservative, and for good reason. A failure in a core banking system can be catastrophic. Adding new cryptographic algorithms, especially ones that are less familiar, creates anxiety. Banks are addressing this through rigorous testing, pilot programs, and clear communication about the risks and benefits.
The challenge is that the entire ecosystem needs to move together. A bank can have the best quantum-resistant security in the world, but if it sends a payment to a smaller institution that still uses weak encryption, the data is exposed at the weakest link. This is why industry-wide coordination is so important, and why banks are pushing their partners and counterparties to adopt quantum-resistant standards as well.
There is also a geopolitical dimension. Some countries are investing heavily in quantum computing research, while others are focusing on quantum-resistant defense. Banks that operate internationally need to be aware of these differences and ensure that their security measures work across all jurisdictions in which they operate.
At the same time, expect to see new challenges. The larger key sizes of post-quantum algorithms will strain networks and storage systems. The transition will create new attack surfaces, as attackers target the migration process itself. And the standards will continue to evolve, meaning that what is considered quantum-resistant today may not be sufficient in a decade.
Banks that take a measured, proactive approach will come through this transition stronger. Those that wait will face a chaotic scramble, with higher costs, greater risk, and the possibility of significant data loss. The investment in quantum-resistant security is not just about technology. It is about preserving trust, which is the most valuable asset a bank has.
Once you have those answers, you can build a roadmap. Start with a cryptographic inventory, then move to a risk assessment, then to a pilot project, and then to a phased deployment. Do not try to do everything at once. The banks that are most successful are the ones that treat this as a journey, not a destination.
The most important thing is to start now. Not because the quantum computer is coming tomorrow, but because the data being stolen today might be decrypted tomorrow. The banks that understand this are not just protecting themselves. They are setting the standard for the entire financial industry. And in a world where trust is the currency, that is the best investment they can make.
all images in this post were generated using AI tools
Category:
Banking SecurityAuthor:
Yasmin McGee