8.1 The Quantum Threat to Encryption
Quantum computing represents a paradigm shift in computational capability with profound implications for cybersecurity. Unlike classical computers that process information sequentially using bits representing 0 or 1, quantum computers employ quantum bits (qubits) that can exist in superposition—representing 0, 1, or both simultaneously . This property enables quantum machines to solve certain mathematical problems exponentially faster than classical computers.
The threat to current encryption systems arises from the fact that most modern cryptography relies on mathematical problems—such as integer factorization and discrete logarithms—that are difficult for classical computers to solve but may be tractable for sufficiently powerful quantum computers . The anticipated moment when quantum computers become capable of breaking existing encryption is sometimes referred to as “Q-Day” . Two separate papers, including one from Google, have discovered that the threshold for a quantum computer to threaten encryption is far lower than expected . Google now plans to transfer its services to post-quantum cryptography by 2029 .
Researchers have found approximately a 20-fold reduction in the number of physical qubits needed to solve the fundamental math puzzle that underpins elliptic curve cryptography (ECC) . This is particularly concerning because most blockchain technologies and cryptocurrencies currently rely on ECC for critical aspects of their security .
8.2 The “Harvest Now, Decrypt Later” Threat
One of the most significant risks is that attackers do not need a quantum computer today to compromise data. They can intercept and store encrypted information now and hold onto it until they have a quantum computer capable of breaking that encryption . This “harvest now, decrypt later” strategy poses an immediate threat to data that must remain confidential for years or decades into the future .
According to NIST’s Andrew Regenscheid, “Even though the quantum computers that could break today’s encryption don’t exist yet, data is being exposed to that future risk the moment it’s sent or stored today” . Cybersecurity experts warn that there is already evidence that some actors, particularly states and espionage groups, are capturing large volumes of encrypted data to decrypt later once quantum computing matures . This includes medical records, trade secrets, financial information, and national security documents that must remain confidential for decades . The average time needed to infiltrate and steal data has fallen to just 25 minutes .
8.3 The Regulatory and Compliance Landscape
The quantum threat has prompted a range of regulatory responses globally, creating compliance obligations that are particularly relevant to central banks. The UK Information Commissioner’s Office (ICO) has signaled that quantum computing falls squarely within the obligation to ensure the security of personal information . Organisations must take “appropriate technical and organisational measures” to protect personal data, having regard to the “state of the art” . This obligation is not static and requires safeguards to evolve as new threats emerge .
The G7 Cyber Expert Group has identified “store now, decrypt later” attacks as a significant concern . The original EU Network and Information Systems (NIS) Directive and its successor, NIS 2, impose cybersecurity risk-management obligations on essential entities that explicitly encompass “policies and procedures regarding the use of cryptography and, where appropriate, encryption” . NIS 2 further hardens accountability by requiring management bodies to approve and oversee risk-management measures, with the possibility of personal liability for infringements . One proposed amendment would explicitly require Member States to adopt national policies to cover the transition to post-quantum cryptography . A group of seven financial regulators are urging early action, with many governments setting 2035 as the target year for a full migration to quantum safety .
8.4 Building a Quantum-Safe Migration Strategy
Building resilience starts with understanding an organisation’s cryptographic landscape. A complete inventory of cryptographic assets helps identify where they’re used, their properties and vulnerabilities, and how critical they are to the business . This visibility delivers immediate benefits, such as spotting outdated or non-compliant assets, and can support operational efficiency over time .
Cryptographic agility—the ability to quickly update cryptography—is becoming increasingly necessary in a world of fast-changing technologies, threats, and standards . Agility alone cannot fully mitigate certain threats, such as “store now, decrypt later” attacks. A comprehensive strategy pairs agility with complementary measures, such as defence-in-depth . Cryptography defence-in-depth leverages multiple layers of cryptography to mitigate the risk of relying on a single solution . By containing the impact of breaches, this approach helps ensure critical systems remain secure even if one layer fails .
8.5 Technical Aspects of Post-Quantum Cryptography
NIST has released three final post-quantum encryption standards developed through an open and transparent process that involved researchers worldwide . For more than a decade, NIST solicited ideas for algorithms from experts, and the worldwide cryptographic community subjected those algorithms to intense public analysis . The standards are built on mathematical problems with over three decades of research behind them, giving continued confidence in their security .
Practical Considerations for Post-Quantum Cryptographic Migration in Financial Systems examines the practical and operational challenges associated with migrating financial systems to PQC . It emphasises that real-world adoption remains constrained by legacy infrastructure, regulatory and compliance requirements, performance trade-offs, and limited cryptographic agility in existing deployments . The paper proposes an adaptive and self-healing migration framework designed to support incremental adoption of PQC while preserving availability, compliance, and risk tolerance .
8.6 The Convergence of AI and Quantum Computing
While the quantum threat to encryption is serious by itself, an increasingly urgent concern is its convergence with advances in AI . Individually, each technology poses distinct risks to cybersecurity; together, they threaten to create a compounding effect that could overwhelm current defences far more quickly than either could alone . Threat actors are using machine learning models to automate vulnerability discovery in software code, identifying weaknesses far more rapidly than manual methods allow . AI-driven tools can also craft highly convincing phishing emails and deepfake audio or video for impersonation attacks, reducing the skill barrier for sophisticated social engineering campaigns .
The timeframe in which current defences become inadequate may be shorter than quantum computing progress alone would suggest . Organisations should consider incorporating quantum risk into their Data Protection Impact Assessments (DPIAs), identifying systems that rely on current encryption techniques, recording transition plans, and evaluating supplier readiness . Maintaining a comprehensive inventory of algorithms, protocols, and certificates in use will be increasingly important for demonstrating compliance to regulators .
8.7 Practical Challenges for Central Banks
Central banks face unique challenges in quantum-safe migration. The migration of legacy systems to quantum-safe cryptography presents many challenges due to their limited cryptographic agility, outdated infrastructure, and regulatory constraints . These legacy environments, even though they rely on aging technologies and constrained hardware, are still vital to critical sectors such as finance and government . Hard-coded cryptographic functions, outdated programming languages, hardware limitations, vendor lock-in, and interoperability constraints all complicate the transition . The CSIRO’s Quantum Safe Transition project has developed a structured, practical approach to help organisations prepare for and manage the transition, providing guidance, tools, and frameworks to identify critical assets, assess cryptographic dependencies, and plan migration pathwaysÂ