Home Finance Why Financial Institutions Need Quantum-Safe Encryption Now

Why Financial Institutions Need Quantum-Safe Encryption Now

0
37
Financial Institutions

Banks and insurers hold some of the most valuable and longest-lived data on the planet: account details, transaction histories, mortgages, pensions, and identity records that must stay confidential for decades. A new breed of computer is being built that could unlock all of it, which is why quantum safe encryption has climbed to the top of the financial risk agenda. A 2025 ISACA survey of more than 2,600 professionals found that 62% expect quantum machines to break current encryption, yet only 5% work somewhere with a plan to respond. For an industry built on trust, that gap is a serious exposure. Here is why finance cannot wait, and how to begin.

Key Takeaways

  • Quantum safe encryption uses algorithms designed to resist attacks from both classical and quantum computers.
  • Financial data has a long shelf life, so records stolen today can be decrypted once quantum hardware matures.
  • Payment systems, card networks, and messaging all rely on encryption that quantum machines can break.
  • Regulators and central banks have already begun the shift, making early preparation a compliance issue, not just a technical one.
  • A cryptographic inventory and crypto-agility are the practical first steps for any institution.

What Quantum-Safe Encryption Means for Finance

Quantum safe encryption is a family of algorithms built to withstand attacks from quantum computers while running on the systems banks already operate. It replaces the maths that a quantum machine could crack with problems it cannot solve efficiently. For risk teams weighing their options, planning for quantum safe encryption for banks has shifted from a research topic to a boardroom priority.

You will also see it called post-quantum or quantum-resistant cryptography. All three describe the same goal: keeping financial data private long after powerful quantum computers arrive. In plain terms, it upgrades the locks before anyone builds the key that opens them.

Worth knowing: the technology needs no quantum computer to run. It works on the servers and networks a bank already owns, which is why the migration can start now rather than someday.

Why Banks Are the Prime Target

Financial institutions are attractive precisely because their data stays sensitive for so long. A mortgage file or pension record is still valuable in fifteen years, and much of what a bank holds must remain confidential far longer than a quantum computer is likely to take to arrive.

The problem is scale. That cryptography is woven through core banking platforms, payment gateways, and decades of archived records, so replacing it is a multi-year programme rather than a quick upgrade.

That longevity makes the sector especially exposed to one particular tactic.

Warning: in a harvest now, decrypt later attack, criminals copy encrypted financial data today and store it, ready to unlock the moment a capable quantum machine exists. Long-life records such as account histories and identity files are effectively at risk right now.

Nearly every part of a bank leans on the cryptography now under threat, from online banking to payment messaging.

Where it is usedCryptographyWhat quantum does
Online and mobile bankingRSA and ECC in TLSBroken by Shor’s algorithm
Payment messagingDigital signaturesBroken by Shor’s algorithm
Card networksRSA and ECCBroken by Shor’s algorithm
Stored recordsAES-256Weakened, safe with longer keys

Mapping those dependencies is the same discipline behind guarding against identity theft and fraud, applied at institutional scale.

The Regulatory Clock Is Already Ticking

Preparation is no longer purely voluntary. In the European Union, the Digital Operational Resilience Act, known as DORA, came into force in January 2025, raising the bar for how financial firms manage technology risk. In the UK, the national cyber authority has singled out banking and financial services as sectors that should prioritise an early migration to quantum-resistant encryption.

The wider timeline is tightening too. Analysts at Gartner expect conventional public-key cryptography to become unsafe by 2029 and fully breakable by 2034, while government roadmaps target completion by 2035. The maths is unforgiving: when the years your data must stay secret plus the time to migrate exceed the runway before capable quantum machines arrive, you are already behind.

Concern is widespread across the sector; concrete preparation is not.

Waiting carries a hidden cost. Protecting sensitive documents and messages, as covered in guidance on keeping business email secure, becomes far harder once the underlying encryption is in doubt.

Central Banks Are Already Moving

If any doubt lingers that this is real, the world’s central banks have themselves run the experiment. Through a programme called Project Leap, an international group of central banks and a global payments network tested post-quantum cryptography inside operational payment systems, swapping traditional digital signatures for quantum-resistant ones while moving genuine liquidity transfers. In an earlier phase, the same partners had already sent protected payment messages through a quantum-resistant tunnel between servers in Paris and Frankfurt.

Two phases of live testing have shown the migration is feasible.

The results were encouraging but sobering. The migration is workable, yet it demands careful testing, because post-quantum algorithms perform differently from the ones they replace. That is why supervisors increasingly frame this as a resilience issue, not merely an IT upgrade.

“Migrating payment systems to quantum-safe solutions is a complex and high-stakes process that affects the entire financial ecosystem.”  Bank for International Settlements, 2025

For the full technical account, the international body behind the work has published its findings on quantum-proofing payment systems.

[Video: “Quantum-safe cryptography available now” by ZDNet: https://www.youtube.com/watch?v=GE1Nb7Gslw0]

This short interview with a working cryptographer explains why the switch matters and how the new algorithms differ from what they replace.

How Financial Institutions Can Prepare

Preparation begins with visibility. A cryptographic inventory maps every place encryption lives, across online banking, payment rails, databases, applications, and outside suppliers such as processors and clearing networks. You cannot protect what you have never catalogued.

After that, rank the inventory by how long each dataset must stay confidential. Long-life, high-value records move to the front, since they meet the harvest threat first. Payment partners and messaging networks deserve special attention, since a bank is only as quantum-safe as the weakest link in its chain.

Key stat: a late 2025 industry study found that 81% of security professionals believe their cryptographic tools and hardware are not yet ready for the switch, so most of this groundwork remains undone.

Practical steps worth starting now:

  • Build and maintain a living cryptographic inventory across the whole estate.
  • Classify data by its required secrecy lifespan, then protect the oldest first.
  • Deploy hybrid encryption so services keep working throughout the transition.
  • Favour crypto-agile systems for anything new you build or procure.
  • Demand a clear quantum-safe roadmap from every critical supplier and payment partner.

The same rigour that supports cloud security and compliance and sound layered security controls makes a quantum-safe migration far smoother. Any institution that has felt the fallout from a data breach already knows how quickly hard-won trust can drain away.

Pro tip: treat the move as an ongoing programme, not a one-off project. Fold it into the operational-resilience reviews you already run, so progress stays funded and tracked as the standards keep maturing.

Frequently Asked Questions

What is quantum safe encryption?

It is encryption that keeps working against quantum computers while operating on the systems firms use today. The approach swaps vulnerable methods such as RSA for quantum-resistant standards that protect financial data over the long term.

Why must banks act before quantum computers arrive?

Because attackers can steal encrypted records today and unlock them once quantum machines are ready. Given how long banking data stays sensitive, any delay leaves that information exposed for years to come.

Can quantum computers break banking encryption today?

Not yet. No public quantum computer can crack strong encryption at present. The risk is future hardware combined with data stolen now, which is why regulators urge financial firms to prepare well ahead of the threat.

Are there rules forcing financial institutions to prepare?

Increasingly, yes. The EU’s DORA rules took effect in 2025, and UK guidance flags finance as a priority sector for early migration. Government roadmaps target a completed transition by 2035.

How should a bank begin the migration?

Start with a cryptographic inventory that maps where encryption is used. Then prioritise long-life data, adopt hybrid and crypto-agile systems, and ask each supplier and clearing partner to share their quantum-safe plan.

Trust Is the Asset Worth Protecting

The quantum era will test the one thing finance cannot afford to lose: trust. The encryption protecting today’s transactions and records was never built to survive it, and the migration will take years to complete across payment rails, applications, and suppliers. Quantum safe encryption offers a proven route through, and central banks, regulators, and standards bodies have already lit the path. Institutions that map their cryptography, protect their longest-lived data, and build in crypto-agility now will keep that trust intact. Those who wait may not get a second chance.

References

Bank for International Settlements, Project Leap: Quantum-proofing Payment Systems, 2025. https://www.bis.org/about/bisih/topics/cyber_security/leap.htm

NIST, NIST Releases First 3 Finalized Post-Quantum Encryption Standards, 2024. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards

Gartner, Postquantum Cryptography: The Time to Prepare Is Now, 2024. https://www.gartner.com/en/documents/6199155

ISACA, 2025 Quantum Computing Pulse Poll (reported by The Quantum Insider), 2025. https://thequantuminsider.com/2025/04/28/organizational-quantum-readiness-remains-low-poll-finds-only-5-of-organizations-have-a-quantum-computing-roadmap/

Trusted Computing Group, State of PQC Readiness, 2025. https://trustedcomputinggroup.org/91-of-businesses-do-not-have-a-roadmap-in-place-to-protect-against-quantum-threats-finds-new-industry-survey/