Post-Quantum Cryptography: The New Risk Finance Teams Need to Track

NIST has finalised post-quantum cryptography standards and the NCSC has set 2028-2035 migration milestones. Why finance teams should care about the 'harvest now, decrypt later' threat.

Learnsignal Education Team
8 min read
Updated

It sounds like science fiction: an encryption-breaking quantum computer that doesn't exist yet, threatening data that's being stolen today. But "harvest now, decrypt later" is a real and specifically acute risk for financial services, and with NIST's quantum-safe standards now finalised and the UK's NCSC publishing firm migration milestones, post-quantum cryptography has moved from theoretical to a genuine item on the risk and compliance agenda.

The problem in plain terms

Modern encryption — the kind protecting bank transfers, custody records and client data in transit and at rest — relies on mathematical problems that are effectively impossible for today's computers to solve in a useful timeframe. A sufficiently powerful quantum computer could solve those same problems far faster, potentially breaking widely used encryption standards like RSA and elliptic curve cryptography. No such computer exists yet at the scale needed to do this. The risk isn't that today's encrypted data is breakable today — it's that an adversary can copy and store encrypted data now, and simply wait until quantum computing matures enough to decrypt it later. This is what the industry calls "harvest now, decrypt later."

Why finance is particularly exposed

Most industries can rotate encryption keys and move on when a standard is deprecated. Financial services is different, because so much of what it protects needs to stay confidential for years or decades after it's created: transaction records, settlement data, and long-lived custody information all retain real sensitivity well beyond the point most other data would have aged out of relevance. Data encrypted today, if harvested and stored by an adversary, could plausibly still be worth decrypting once quantum computing catches up — which is exactly why regulators and standards bodies are pushing migration timelines now, years before a quantum computer capable of the attack is expected to exist.

The standards and timelines now in place

NIST finalised three post-quantum cryptography standards in 2024: ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205), giving organisations concrete algorithms to migrate toward rather than a moving target. NIST's follow-up guidance (NIST IR 8547) sets out a deprecation timeline for current standards — RSA-2048 and ECC-256 are set to be deprecated by 2030 and disallowed after 2035 for federal agencies and regulated sectors handling federal data.

The UK's NCSC has published its own phased migration milestones for critical national infrastructure, a category that includes much of the financial sector:

  • 2028 — complete cryptographic discovery and inventory (knowing exactly where and how cryptography is used across systems)
  • 2031 — migrate high-priority systems to post-quantum algorithms
  • 2035 — complete full transition across all systems

What this means for finance and risk teams

Post-quantum migration isn't primarily a job for the finance function — it's fundamentally a technology and security programme. But finance, risk and audit professionals have real reasons to engage with it now:

  • The 2028 discovery-and-inventory milestone is closer than it looks, and finance teams overseeing technology risk and operational resilience — the same territory covered by NIS2 and broader cyber resilience obligations — should expect post-quantum readiness to become part of standard risk reporting well before full migration is due
  • Custody, settlement and long-dated financial instrument data are exactly the categories most exposed to harvest-now-decrypt-later risk, making financial services a genuine early-mover sector rather than one that can wait for the 2035 deadline
  • Third-party and vendor risk assessments should start asking about post-quantum migration plans, since a firm's own readiness is only as strong as its weakest cryptographically-dependent supplier
  • Budgeting and change-programme planning for the 2028-2031 window should start now, given how long full cryptographic migration typically takes in large, legacy-heavy financial institutions

FAQ

Do quantum computers capable of breaking encryption exist yet?
No — current quantum computers aren't powerful enough. The risk is anticipatory: adversaries can harvest encrypted data now and decrypt it once quantum computing matures, which is why migration timelines start years ahead of the actual threat.

Is this only a concern for very large banks?
No — any organisation holding long-lived sensitive financial data, including smaller financial institutions, asset managers and professional services firms handling client financial data, faces the same underlying exposure, just potentially on a longer timeline for action.

What's the first practical step?
Cryptographic discovery and inventory — understanding exactly where and how encryption is used across systems — which the NCSC has set as its first 2028 milestone for critical infrastructure sectors.

Emerging technology risk is now a core part of the finance and audit skill set, not a niche IT concern. Learnsignal's CPD courses cover the operational resilience and technology risk topics finance professionals increasingly need to understand.

How this compares to a typical technology migration

Most technology upgrades finance teams are used to overseeing — a new ERP system, a cloud migration, an accounting software switch — have a clear before-and-after state and a defined project timeline measured in months. Post-quantum migration is different in a way that makes it easy to under-prioritise: the "why now" isn't a current system failure or a competitive gap, it's a probabilistic future threat with a long lead time. That combination — genuinely serious eventual consequences, but no immediate forcing event — is exactly the profile of risk that tends to get deprioritised against more urgent quarterly pressures, right up until a milestone deadline is suddenly close. Building post-quantum readiness into existing technology risk and audit committee reporting now, well ahead of the 2028 discovery milestone, is the practical way to avoid that trap.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience helping students advance their professional careers.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Learning Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans