Learning Objectives:

  • Understand the threat posed by quantum computing to current encryption standards.

  • Explain the “harvest now, decrypt later” strategy and its implications.

  • Identify the key encryption standards vulnerable to quantum attacks.

  • Recognise the urgency of quantum-safe migration.

4.1 The Quantum Threat to Encryption

Quantum computing represents a paradigm shift in computational capability with profound implications for cybersecurity. Quantum computers, should they reach sufficient size and power, may be able to break the encryption schemes widely used today to secure financial transactions, communication, and data . This makes quantum computing one of the most significant cybersecurity threats facing the financial system, potentially exposing financial transactions to attack .

The threat to current encryption systems arises from the fact that most modern cryptography relies on mathematical problems—such as integer factorization and discrete logarithms—that are difficult for classical computers to solve but may be tractable for sufficiently powerful quantum computers . IBM has warned that quantum computers capable of breaking today’s encryption algorithms are no longer a distant risk; they’re an approaching reality, with a “cryptographically relevant” quantum computer likely by the early 2030s .

Payment data in these systems has long-term value. Compromised transaction histories, customer profiles, and authentication data can be exploited years after capture . This underscores the need for proactive preparation.

4.2 The “Harvest Now, Decrypt Later” Threat

Malicious actors can intercept and store confidential, classically encrypted data with the intention of decrypting it later when quantum computers become powerful enough to do so . This means that data stored or transmitted today are, in fact, exposed to “harvest now, decrypt later” attacks by a future quantum computer .

This “harvest now, decrypt later” strategy poses an immediate threat to data that must remain confidential for years or decades into the future. For central banks, this includes transaction histories, customer profiles, authentication data, and confidential policy communications . Data that is captured today could be decrypted in the future, potentially causing significant reputational damage and undermining public trust in the financial system.

4.3 Encryption Standards at Risk

The mathematical problems that make RSA and ECC secure today will be trivially solvable by quantum computers sometime in the next few years . The BIS has noted that most payment systems rely on public key cryptography and require long-term data confidentiality, making them vulnerable to the quantum threat . At the same time, as the backbone of modern economies, payment systems are critical to the smooth functioning of commerce, finance, and daily life—protecting them is essential to preserving financial stability .

Specific encryption standards at risk include:

  • RSA: Widely used for digital signatures and key exchange.

  • ECC: Widely used for digital signatures and key exchange.

  • Diffie-Hellman: Widely used for key exchange.

4.4 Urgency of Quantum-Safe Migration

Experts have given a five to ten year estimated timeframe for when quantum computing could break existing encryption techniques, and the transition to quantum-safe practices will take time . “It is certainly not too early to make serious preparations,” the MAS managing director has stated .

The World Federation of Exchanges (WFE) has noted that post-quantum cryptographic (PQC) solutions are not simple upgrades . Encryption is often embedded within legacy platforms and vendor products, making discovery and inventory a necessary first step in any transition . Third-party dependencies—including cloud services, market data providers, and software vendors—can complicate readiness efforts .

The BIS has warned that a significant gap exists between regulatory expectations for early preparation and the industry’s current prioritisation of nearer-term threats such as generative AI (GenAI) and cyber resilience . However, the BIS’s Project Leap has demonstrated the feasibility of migrating payment systems to post-quantum cryptography .