InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Deutschland GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Deutschland GmbH
Am Gierath 20A
40885 Ratingen
Germany
InfoGuard GmbH
Kohlmarkt 8-10
1010 Vienna
Austria
Quantum computing was long considered the technology of the future. Today, it is emerging as a strategic challenge for financial institutions. Powerful quantum computers could one day break widely used cryptographic algorithms such as RSA and ECC. Post-quantum cryptography refers to methods designed to protect sensitive data and digital communications even under these conditions.
The need for action arises even before the technology achieves a breakthrough. Attackers can already intercept and store encrypted information today, then decrypt it later using more powerful tools (“harvest now, decrypt later,” or HNDL). At the same time, artificial intelligence is automating existing attack methods, accelerating their movement through IT environments, and shortening the available response time. In its Supervisory Circular 05/2026 issued in July 2026, FINMA specified how financial institutions should address the cyber risks posed by cryptographically relevant quantum computers and prepare for the migration to quantum-secure encryption.
The pressure to act is increasing now for several reasons simultaneously. Some risks are already having an impact today, while others require preparations that will take years.
The following developments are particularly critical for financial institutions:
According to a FINMA survey, two-thirds of the institutions surveyed expect to be directly affected by the cyber risks of quantum computing within seven years. Just as many assume that a quantum computer could crack RSA 2048-bit encryption within 24 hours within ten years at the latest.
The greatest perceived risks are: data security, incomplete migration, lack of expertise, “harvest-now-decrypt-later” (HNDL) attacks, and interoperability with legacy systems.
The threat is already a reality today: widely used algorithms such as RSA and ECC will be broken, making services like online banking, encrypted communication, and payment systems insecure. The HNDL risk is real: It must be assumed that certain countries are already actively collecting data today with the intention of decrypting it later.
Regulatory Assessment: Forecasts regarding the availability of quantum computing vary widely and can quickly become outdated—therefore, swift action is essential, regardless of the exact timeline.
In its Supervisory Notice 05/2026, FINMA explicitly identifies six areas of action. A robust migration plan should cover all of them:
Strategy and Roadmap: Define objectives, priorities, milestones, and responsibilities for the PQC migration.
Risk Analysis: Identifycritical data and systems; assess vulnerability to HNDL attacks.
Cryptographic inventory: Document the algorithms, keys, certificates, protocols, applications, and dependencies in use.
Protection of Critical Data: Prioritize data with a long confidentiality period and reduce the risk of subsequent decryption.
External Service Providers: Incorporatedependencies and PQC roadmaps from cloud, technology, and other service providers.
Crypto-Agility: Design systems so that cryptographic methods can be replaced with reasonable effort.
To turn these six measures into an actionable plan, clear responsibilities, governance approved by the board, and sufficient personnel and financial resources are required. The CISO bears overall responsibility, IT management oversees technical implementation, and the compliance team ensures compliance with FINMA regulations. The budget should account for external consulting as well as targeted training for security teams.
AI-enabled attacks require immediate investment in detection and response, while PQC is a long-term migration. Both budgets should shift over time:
| Time Period | AI Defense | PQC Preparation or PQC Migration |
| 2026–2027 | Approx. 70% of the budget | approx. 30% of the budget |
| 2028–2030 | approx. 50% of the budget | Approx. 50% of the budget |
| Starting in 2030 | approx. 30% of the budget | approx. 70% of the budget |
Crypto-agility creates the technical foundation for quickly and in a controlled manner replacing cryptographic methods in response to new threats, standards, or regulatory requirements.
Three elements are particularly important for this:
Modular, API-based architecture: Design systems so that cryptographic algorithms can be dynamically swapped out.
Regular audits: Check annually to ensure your encryption is state-of-the-art.
External service providers: Require all partners (e.g., cloud providers) to provide a PQC roadmap and adopt crypto-agile design.
Based on the concepts outlined in NIST NCCoE SP 1800-38A, the following structured, multi-step approach is recommended:
Establish governance and accountability: Appoint executives as sponsors and a PQC program manager; establish a cross-functional committee (security architecture, risk, legal, procurement, compliance); define a formal migration charter specifying scope, objectives, and reporting to the executive board.
Create a cryptographic inventory: Identifyprotocols (TLS, VPN, databases, APIs, SSH keys, S/MIME, PGP, DKIM, etc.), public-key usage, cryptographic libraries, PKI resources, applications/firmware, and third-party providers; document each resource with its algorithm, key size, confidentiality period, and owner.
Classify data and identify HNDL risks: Categorize business processes and data sets according to required retention periods; identify points where data traffic and archives can be intercepted; prioritize high-impact data sets.
Reduce HNDL risks in the short term: Use strong symmetric cryptography (AES-256, SHA-384/512 in accordance with NSA CNSA 2.0/NIST), prioritize forward secrecy, limit the retention of decrypted data, improve key rotation, and shorten certificate validity periods.
Embed crypto-agility: Design systems so that cryptographic algorithms can be swapped out without extensive code changes.
Involve vendors and the supply chain: Identify dependencies, request PQC roadmaps from vendors, adapt contracts and requests for proposals, and coordinate timelines with industry associations.
Conduct pilot and interoperability tests: Set up lab environments and test the impact on performance and interoperability. Start with Kyber (FIPS 203) and Dilithium (FIPS 204), which are prioritized by FINMA and NIST.
Prioritize, monitor, and report on migration: Implement a phased rollout starting with the highest HNDL risks (development/testing, limited pilot projects, gradual rollout); Maintain dashboards on asset coverage, HNDL remediation, and migration status for regulatory authorities and audits.
Lateral movement occurring in minutes rather than days.
Anomalous API usage, such as sudden spikes in credential harvesting.
Customized attack vectors with every new access attempt.
Exploitation of known, unpatched vulnerabilities instead of complex zero-day exploits.
Multi-factor authentication: for all critical systems, especially admin access and cloud consoles.
Least Privilege: minimal, time-limited permissions for user and service accounts.
Network segmentation: Isolate critical systems such as databases and payment processing.
Secret rotation: Automatically renew credentials every 30–90 days (weekly for critical credentials).
EDR/XDR solutions: with real-time detection and automated response playbooks for common attack scenarios.
| Measure | Benefits for PQC | Benefits for AI-Based Defense |
| Cryptographic inventory | Identifies systems for PQC migration | Reveals vulnerabilities to AI attacks |
| Zero-Trust Architecture | Protects against “harvest-now-decrypt-later” attacks | Limits lateral movement of AI agents |
| Secret rotation | Prevents long-term data compromise | Stops automated credential harvesting |
Without timely preparation, the risks to data, compliance, reputation, and business operations increase. A structured approach helps proactively manage cryptographic risks, address regulatory requirements, and respond to technological disruptions.
For decision-makers: Develop a board-approved PQC migration plan by 2026, including a risk analysis, roadmap, and budget.
For security teams: Start with a cryptographic inventory and test Kyber and Dilithium in pilot projects; adapt incident response playbooks to machine-speed attacks.
Take action now. Assess your current needs with a PQC gap assessment. Our experts will guide you on your journey to quantum-secure cryptography.
Don’t miss out on important developments anymore. Our blog updates keep you regularly informed about current threats, new security risks, and relevant cybersecurity trends.
Caption: AI-generated image