Simon Pamplin, CTO at Certes, on how Quantum computing will eventually force a reckoning with the cryptographic assumptions on which the financial system is built.

Financial institutions hold some of the most sensitive and long-lived data of any sector. Customer identities, decades of transaction records, credit histories, and proprietary trading information must be kept confidential, not just today, but far into the future. The cryptographic systems guarding that data, however, were built for a different era; one in which quantum computing was purely theoretical. That era is ending.

Recent guidance from both the G7 Cyber Group and the UK’s National Cyber Security Centre has made the stakes explicit: financial organisations should complete their transition to post-quantum cryptography by 2035. For institutions managing sprawling, decades-old technology estates, that deadline is less reassuring than it might first appear. Ten years sounds like breathing room. In practice, for organisations of this complexity, it is barely enough.

Quantum Risk: The Threat Doesn’t Wait for the Technology

The most common mistake in discussions about quantum risk is treating it as a problem for tomorrow. The assumption is that until a quantum computer powerful enough to crack modern encryption actually exists, there is no immediate danger. That assumption is dangerously flawed.

Sophisticated adversaries are already operating on a longer time horizon. The strategy, widely referred to as “harvest now, decrypt later,” involves systematically collecting encrypted data today and storing it until quantum computing capabilities catch up. No quantum computer is needed to execute this phase of the attack, only patience and storage.

For the financial sector, the implications are particularly serious. The data being harvested now, customer records, transaction histories, and commercially sensitive communications, could have a useful life measured in decades. By the time it is decrypted, the individuals and organisations it concerns will still be very much affected by its exposure. This is not a theoretical future liability. It is a risk quietly accumulating in the background of every financial institution that has not yet begun to act on it.

Why Updating Financial Systems Is So Hard

The cryptographic methods underpinning most financial infrastructure today, primarily RSA and elliptic curve cryptography, derive their security from mathematical problems that are extraordinarily difficult for conventional computers to solve. Quantum computing threatens to render those problems tractable, potentially dismantling encryption that currently appears robust.

Responding to that threat, however, means working through some of the most technically complex environments in any industry. Core banking platforms were often built 20, 30, or 40 years ago. Cryptographic functions are frequently embedded deep within application logic, firmware, or hardware, in payment terminals, ATMs, and proprietary systems that were never designed with replaceability in mind.

Replacing or updating these components is not a software patch. It can mean recertifying devices, replacing physical infrastructure, or undertaking large-scale application rewrites, all while maintaining continuous service to customers and satisfying stringent regulatory requirements. Progress is possible, but it is measured in years, not quarters.

Rethinking Security from the Data Outward

The quantum threat is also accelerating a broader rethink of how financial institutions approach security architecture. Perimeter-based defences, firewalls, VPNs, and network segmentation have consistently shown their limitations when attackers can move laterally through systems using legitimate credentials or compromised access. Relying on the boundary to keep data safe has a poor track record.

A more resilient approach centres protection on the data itself. By applying strong controls directly to information as it moves across systems, organisations can maintain security even within legacy environments that cannot be immediately upgraded. Sensitive data remains protected regardless of where it travels or which network it traverses.

Alongside this, crypto agility, the ability to swap out cryptographic algorithms and rotate keys without overhauling entire systems, is becoming a fundamental requirement rather than a nice-to-have. The transition to post-quantum standards will not be a one-time event. Cryptographic best practice will continue to evolve, and institutions that have built flexibility into their architecture will be far better positioned to keep pace.

The Cost of Inaction

The financial sector has a well-established capacity to absorb and adapt to technological change. It has navigated the transition to digital banking, the rise of real-time payments, and successive waves of cybersecurity threats. The quantum challenge is different in one important respect: the timeline for harm is already running.

Regulatory expectations are being set now. Adversaries are collecting encrypted data now. And the internal processes required to modernise a major financial institution’s cryptographic infrastructure take years to complete. The gap between when action is needed and when it can realistically be delivered is not wide, and it is narrowing.

Preparation does not demand panic or the immediate replacement of every system. It demands a clear-eyed audit of where sensitive data lives, an honest assessment of which information carries long-term confidentiality requirements, and a commitment to building security architectures that can evolve as the threat landscape does.

Financial institutions that move early will not simply reduce their quantum exposure. They will emerge with stronger, more adaptable security postures and with the trust of customers, regulators, and partners intact.

Quantum computing will eventually force a reckoning with the cryptographic assumptions on which the financial system is built. The question is no longer whether that reckoning is coming. It is whether institutions will be ready when it arrives.

Learn more at certes.ai

  • Artificial Intelligence in FinTech
  • Blockchain & Crypto
  • Cybersecurity in FinTech
  • Data & AI
  • Digital Strategy
  • Fintech & Insurtech