ESPNDodgers dispatch Braves, advance to third straight NLCSESPN DeportesEN VIVO: interferencia de aficionado crea polémica, Volpe remolca una y acerca a YankeesLa NaciónLa agenda de la TV del jueves: el Masters 1000 de Shanghai y la acción del básquetbol한겨레대구로페이 오프라인 물량 130억 남아…아이엠뱅크서 충전 가능Daily MaverickBarn owls, bees, puffins and hedgehogs to feature on UK banknotesZDF heuteEntdecken Sie das ZDF-NachrichtenstudioUOLSão Paulo perde no Mineirão, e Cruzeiro salta para o quarto lugar no BrasileiroThe Jerusalem PostProtesters overrun Israeli peace vigil marking October 7 attended by MamdaniEl ComercioTemblor en México EN VIVO HOY, 07/10/2026 - hora exacta, magnitud y epicentro del último sismo vía SSNNew Straits TimesMcTominay cleared to return, Napoli sayESPN CricinfoWeatherald subbed out with concussion after fielding incident경향신문‘장보기는 옛말’…충북 청주지역 전통시장, 주·야간 복합문화공간 됐다
The Daily Newsstand · Free, Always
Thursday, October 8, 2026

From ‘quantum-enhanced’ to ‘quantum-safe’: Why banks are preparing in advance for the new big threat

Translate

The banking sector is moving its focus towards cybersecurity as artificial intelligence (AI) poses threats to financial systems. But regulators have also stepped up, mandating cyber preparedness across the sector.

The Reserve Bank of India (RBI) issued a new cybersecurity and technology-resilience framework for commercial banks in July, setting requirements for IT governance, cyber-risk management and incident response, while the Securities and Exchange Board of India (SEBI) introduced an IT Resilience Index for market infrastructure institutions in August to measure the robustness of their critical IT systems and identify weaknesses early.

While these measures may help address the threats confronting the sector today, a new type of threat is beginning to emerge — one that could challenge the mathematical foundations of some of the encryption used to protect digital systems: quantum computing.

What is quantum computing?

Traditional computing stores and processes data in a unit called a bit, which can have a value of either 0 or 1. In quantum computing, the unit is called a quantum bit, or qubit.

Unlike a classical bit, a qubit can exist in a combination of 0 and 1, a property known as superposition. Quantum systems can also exploit another property called entanglement, in which the states of different qubits become closely correlated.

Quantum algorithms are designed to manipulate these quantum states so that the probability of useful answers is amplified, and that of the incorrect answers is reduced. This can give quantum computers a significant edge over traditional computers for certain types of problems.

Their significance comes from particular problems for which quantum algorithms can provide a major computational advantage. They have the potential to solve certain problems in minutes or hours that would take conventional machines millennia to complete.

Story continues below this ad

While this could have striking use cases, it also opens the door to a whole new set of threats. The cybersecurity concern stems from the fact that sufficiently powerful quantum computers could solve some mathematical problems that underpin widely used public-key cryptographic systems much more efficiently than classical computers can.

Why does quantum computing threaten banks’ encryption?

“Right now, we are talking about AI threats, right? In a couple of years, we will be talking about cryptographic threats due to quantum computing. We will be talking about a lot of other things that are not even there in the market yet,” Sarthak Dubey, Co-founder and COO of Mitigata, a full-stack cyber resilience firm, told The Indian Express. “What people have been talking about quantum becomes a very major risk starting, say, 2030,” he added.

Modern cryptography protects digital communications by relying on mathematical problems that are extremely difficult for conventional computers to solve. Some widely used public-key systems, such as RSA (Rivest–Shamir–Adleman) and elliptic-curve cryptography, rely on problems related to integer factorisation and discrete logarithms.

India’s financial ecosystem is heavily digitised through the Unified Payments Interface (UPI), Aadhaar, real-time gross settlement (RTGS), and national electronic funds transfer (NEFT).

Story continues below this ad

The quantum threat is not that a quantum computer would hack a payment system. Rather, it could undermine cryptographic building blocks used across the digital infrastructure for functions like authentication, secure communication, key exchange, and digital signatures.

However, cybersecurity and traditional computing in general are based on a particular set of mathematical logic.

For example, RSA relies on the difficulty of factoring very large numbers, while elliptic-curve systems rely on the difficulty of solving certain discrete-logarithm problems. These problems are computationally difficult for classical machines, but could be much easier for a sufficiently capable quantum computer.

“Essentially, when we talk about the existing ways of security, there are encryption mechanisms that keep systems safe and secure in certain ways, that keeps your data secure in certain ways. And there are ways to decrypt them, which requires a significant amount of compute, and a significant amount of hardware power to make sure that you are able to decrypt those particular encryptions and get into that particular system,” said Dubey.

Story continues below this ad

“Now, with quantum, and what people call the quantum deadline, is that by 2029 or 2030 the quantum computers would be smart enough to decrypt any of the historical encryptions that are present,” he explained. Several technology companies and governments have been working towards transitioning their systems well before such a capability emerges, although there is no universally agreed date for when a cryptographically relevant quantum computer will arrive.

Why banks cannot wait for the quantum computer

One reason why financial institutions can’t just wait for quantum computers to become powerful enough is a threat called Harvest Now, Decrypt Later, or HNDL.

Under this model, an attacker can intercept and store encrypted information today, with the expectation of decrypting it once sufficiently powerful quantum computers arrive. This makes data that needs to remain confidential for many years particularly vulnerable.

According to the Digital Threat Report 2025-26 by CERT-In, CSIRT-Fin and SISA, the broader quantum threat has yet to reach full-scale realisation, but HNDL strategies are already active.

Story continues below this ad

This is why the transition to post-quantum cryptography (PQC) — encryption algorithms resistant to attacks from quantum computers — has to begin before the threat materialises.

The more immediate task in preparing for the quantum era involves identifying where vulnerable cryptography is being used, and replacing it before sufficiently capable quantum systems emerge.

This involves creating an inventory of cryptographic systems, identifying the most sensitive and critical data, testing quantum-resistant algorithms, working with technology vendors and ensuring that systems can switch between cryptographic standards without requiring a complete rebuild. This last capability, known as crypto-agility, is the ability of an organisation to replace cryptographic algorithms and protocols as security requirements change.

For banks, this is crucial because their technology infrastructure is spread across legacy systems, cloud environments, third-party vendors, payment platforms and multiple layers of security infrastructure.

Story continues below this ad

How imminent is the threat?

While the new threat sounds scary, it is at least a few years away. India has only a handful of quantum computers, though the technology is rapidly developing through startups, academics, and government initiatives such as the National Quantum Mission launched in 2023 with an outlay of Rs 6,003.65 crore.

The mission aims to develop indigenous quantum-computing capabilities in stages, moving from 20-50 physical qubits in the initial phase towards systems with larger numbers of qubits over the longer term. Despite this, most projects are either under development or under small-scale testing.

“We’re currently seeing only a handful of such systems being developed. This is led mainly by institutes like the IISc (Indian Institute of Science, Bengaluru), or through startups like QpiAI. Most are under 10-qubit and are still under development, so it may take a few more years to undergo testing and be operational,” said the executive from the Bengaluru-based startup cited earlier. Others remotely access such systems developed by bigger names such as IBM and Amazon Web Services for research and developmental purposes.

Globally, too, quantum threats have not become widespread yet but remain an active concern, as suggested by Big Tech’s endeavours to bulk up security systems. They are researching on, and have started deploying post-quantum cryptography algorithms into their products, as well as stepping up protection against HNDL strategies.

Story continues below this ad

Governments and financial regulators are taking similar steps. In the US, the National Institute of Standards and Technology (NIST) has already finalised post-quantum cryptography standards and is urging organisations to begin the migration process.

The G7 has also developed a roadmap for transitioning the financial sector towards post-quantum cryptography, while the European Union has called for member states to begin the transition by the end of 2026, with high-risk use cases moved to quantum-resistant cryptography as soon as possible and no later than the end of 2030.

India’s quantum-safe roadmap

India has begun building a policy framework around this transition as well.

The Department of Science and Technology’s quantum-safe roadmap sets out a phased approach for moving the country’s digital ecosystem towards post-quantum cryptography. For critical sectors such as banking, financial services and insurance, it envisages foundational work by 2027, migration of high-priority systems by 2028 and full adoption of post-quantum cryptography by 2029.

Story continues below this ad

The expert committee under RBI’s Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) initiative released in May aims to examine the implications of quantum technology for the financial sector, and recommend a roadmap to quantum-secure it.

NITI Aayog’s roadmap for transforming India into a quantum-powered economy released in 2025 also identifies financial modelling, fraud detection and encryption among potential applications of quantum technology in finance.

This creates a two-sided policy challenge for India: the country has to protect its digital infrastructure from a technology that could eventually disrupt existing cryptography, while simultaneously building the domestic capabilities that could make quantum computing economically useful.

View the original on The Indian Express →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.