Strategies Before the Clock Runs Out
In Part 1, we examined how attackers are already exploiting a “harvest now, decrypt later” strategy—quietly stockpiling today’s encrypted financial data in the expectation that tomorrow’s quantum computers will unlock it. The threat is real, and recent breaches show how quickly sensitive records can slip beyond a bank’s control.
The Quantum Finance Security Series. This three-part series explores how quantum computing will reshape cybersecurity in the financial sector. Part 1 examines the immediate threat of “harvest now, decrypt later” attacks. Part 2 outlines practical steps financial institutions can take to prepare for post-quantum cryptography. Part 3 looks beyond algorithms to the broader challenge of building quantum-resilient finance.
But awareness without action is useless. The good news is that financial institutions are not powerless. A growing body of regulatory guidance, emerging standards, and practical security measures can help reduce exposure and prepare systems for a post-quantum world. The real challenge is timing: preparation must begin now, because the migration away from vulnerable cryptography will be measured in years, not months.
From Awareness to Action
Quantum-resistant security is no longer an academic exercise. Governments, standards bodies, and industry groups are all signalling that financial institutions must begin the transition now. The window for “wait and see” has already closed.
Regulators Are Raising the Stakes
Central banks and regulators are sharpening their focus on quantum risk:
- The Bank for International Settlements (BIS) has warned that quantum computing could undermine the confidentiality and integrity of financial data if institutions delay adopting quantum-safe cryptography.¹
- The European Central Bank (ECB) has flagged post-quantum readiness as part of its broader cyber-resilience agenda, urging banks to assess cryptographic dependencies in their systems.²
- In the US, the National Institute of Standards and Technology (NIST) finalised its first set of post-quantum cryptography (PQC) standards in 2024,³ and regulators expect financial institutions to begin planning migrations well before deadlines are imposed.
- The EU’s Digital Operational Resilience Act (DORA), coming into effect in 2025, requires financial entities to maintain cryptographic agility as part of their resilience planning.⁴
For banks and insurers, the regulatory message is clear: quantum preparedness is shifting from “best practice” to an emerging compliance requirement.
Post-Quantum Cryptography: Preparing for the Transition
NIST’s chosen PQC algorithms—CRYSTALS-Kyber for key establishment and CRYSTALS-Dilithium for digital signatures—will form the backbone of future cryptographic standards.³ Migration, however, is not a simple patch:
- Financial institutions must inventory their cryptographic assets, identifying where vulnerable algorithms like RSA and ECC are embedded in infrastructure.
- They need to design systems with crypto-agility, the ability to swap algorithms without major disruption.
- Testing and pilot deployments should begin early, as PQC algorithms are larger and more resource-intensive than their classical predecessors, with implications for performance in high-volume trading and payments systems.
The transition will take years—hence the urgency to start now.
Third-Party and Supply Chain Weaknesses
Recent breaches highlight another weak point: vendors and suppliers. Allianz’s breach originated in a third-party CRM system, while UBS, Santander, and DBS were all exposed through supplier compromises.⁵
This raises a crucial lesson: quantum readiness cannot stop at the institutional perimeter. Banks must require their service providers—cloud platforms, payment processors, CRM vendors—to adopt crypto-agile practices and align with PQC standards. Otherwise, the weakest link in the supply chain could become the entry point for harvested data that survives well into the quantum era.
Zero Trust and Beyond
Preparing for the quantum future also means re-evaluating broader security architectures:
- Zero-trust models—where no user or system is implicitly trusted—help limit the blast radius of a breach.
- Data minimisation reduces the volume of information that could be harvested in the first place.
- Continuous monitoring and incident detection help identify breaches earlier, shortening the window during which adversaries can extract data unnoticed.
Quantum risk adds urgency to these practices, but the benefits are immediate regardless of the quantum timeline.
The Cost of Delay vs. the Cost of Action
IBM reports that the average global cost of a data breach in 2025 is US $4.88 million.⁶ For financial institutions, the figure is consistently higher. At the same time, industry forecasts suggest cybercrime will inflict US $10.5 trillion in damage globally this year.⁷
The cost of preparing for PQC—assessing cryptographic assets, enabling crypto-agility, testing new algorithms—will be substantial. But compared to the risk of systemic data exposure in a post-quantum future, it is a fraction of the potential loss. For boards and regulators alike, the business case is clear: quantum-proofing is not an IT expense; it is risk management.
Conclusion: Securing Tomorrow, Starting Today
Financial institutions cannot control when a quantum breakthrough will occur. What they can control is their preparedness. The harvest-now, decrypt-later threat is already reshaping the risk landscape, and the time required for migration leaves no room for complacency.
The institutions that act now—mapping cryptographic assets, engaging suppliers, and planning for PQC—will be positioned to protect their data into the quantum era. Those that wait may discover that their most valuable assets have already been stolen, stored, and queued for decryption.
Sources
- Bank for International Settlements — Financial Stability Risks from Quantum Computing (2024).
- European Central Bank — Cyber resilience oversight expectations for financial market infrastructures (2025 update).
- NIST — Post-Quantum Cryptography Standards: First Algorithms Finalized (2024).
- European Union — Digital Operational Resilience Act (DORA) (effective 2025).
- DeepStrike — Data breach at financial institutions: Santander, DBS and supply-chain risk (2025); Financial News London — UBS hit by cyber attack on external supplier with data stolen (2025).
- IBM Security — Cost of a Data Breach Report 2025.
- Cybersecurity Ventures — Official Cybercrime Report 2025.





Leave a Reply