News

The Top Ten things to know about Quantum Computing

Authored by Sybille Mueller, Director, Streets Consulting 


The era of quantum computing is imminent. Throughout our blog series this month, we have looked at what Quantum Mechanics is, what quantum computers could do, and why the technology is important to financial services and FinTechs. We have examined the threats and opportunities the technology poses, and explored the developing regulatory landscape, which is mandating the global financial industry’s move to post-quantum cryptography.

What has become clear is that the quantum era is likely to descend on everyone involved in the financial markets at the same time, and the markets will have to move jointly, as quickly as the technology does. 

‘Q-day’ (the expected date when a Cryptographically Relevant Quantum Computer (CRQC) becomes operational with the ability to crack modern cryptography) is looking likely to materialise sooner than many expect. Here we summarise the top ten quantum computing takeaways for the financial services sector.

1. The Imminent Obsolescence of Public-Key Cryptography

Quantum computing fundamentally threatens the security architecture of the global financial system. A Cryptographically Relevant Quantum Computer (CRQC) is defined as a machine capable of running Shor’s algorithm, developed by Peter Shor in 1994, which can solve the mathematics underpinning current industry-standard cryptography, problems previously considered computationally impossible to crack at scale. The specific standards facing this quantum threat include RSA and Elliptic Curve Cryptography (ECC), which currently protect trillions of dollars in daily transactions, digital signatures, and secure web browsing. For FinTechs, this threat extends directly to the elliptic curve cryptography securing blockchain networks, digital assets, and smart contracts, making quantum readiness a business-critical priority, not merely an IT security concern.

2. The Immediate Threat of ‘Harvest Now, Decrypt Later’

The quantum threat to data confidentiality is not a future problem; it is active today, regardless of when quantum hardware achieves full capability. Adversaries, including state-sponsored actors and criminal syndicates, are currently executing ‘Harvest Now, Decrypt Later’(HNDL)  attacks. This strategy involves intercepting and storing encrypted data today with the intent to decrypt it once quantum capabilities mature. Long-lived sensitive data, corporate trade secrets, financial records, and medical data, such as those held by the insurance industry, is immediately vulnerable to this interception tactic. It is worth noting that the precise scale of active HNDL campaigns is difficult to confirm publicly, as much of the evidence is held by intelligence agencies; however, the threat model is treated as credible and live by governments and regulators worldwide, and that consensus alone should compel action.

3. The Standardisation of Post-Quantum Cryptography 

The primary defence against quantum threats at the software layer is Post-Quantum Cryptography (PQC): new cryptographic algorithms based on mathematical problems that are theoretically hard for both classical and quantum computers to solve. In August 2024, the United States National Institute of Standards and Technology (NIST) finalised and published the first three post-quantum standards (FIPS 203, FIPS 204 and FIPS205). These algorithms are designed to interoperate with existing networks and classical hardware, but PQC will require meaningfully more compute power than current encryption, placing a significant burden on infrastructure providers, and, ultimately, on the financial institutions that depend on them.

4. The Mathematics of System Compromise (Mosca’s Theorem)

Financial institutions must calculate their cryptographic risk window using Mosca’s Theorem, formulated by cryptographer Michele Mosca. The theorem states that if the time data must remain confidential (X), plus the time required to migrate IT systems to quantum-safe alternatives (Y), exceeds the time remaining until a CRQC is developed (Z), then the system is already compromised. Because financial and insurance records often require 25 to 50 years of confidentiality, data encrypted today using classical methods may be effectively vulnerable right now. When organisations work through Mosca’s Theorem honestly, accounting for the multi-year complexity of enterprise cryptographic migrations, the uncomfortable conclusion for many institutions may be that the risk window has already opened.

5.  Hardware-Level Defense via Quantum Key Distribution

While Post-Quantum Cryptography (PQC) secures the application layer, Quantum Key Distribution (QKD) addresses security at the physical network layer. QKD uses the principles of quantum mechanics to distribute encryption keys in such a way that any interception attempt alters the quantum state of the key, immediately alerting both parties to the presence of an ‘eavesdropper’. JPMorgan Chase, working with Toshiba and Ciena, has demonstrated a first-of-its-kind QKD research prototype network connecting two data centres over deployed fibre, validating the full viability of quantum-secured infrastructure in a real-world environment. HSBC has also conducted a world-first trial with Toshiba, BT, and Amazon Web Services, using QKD to protect AI-driven FX trading infrastructure. It is important for financial institutions evaluating QKD to understand its constraints: it requires dedicated fibre infrastructure, carries significant cost, and does not scale with the same flexibility as PQC. The most resilient institutions are likely to pursue a layered strategy, deploying both PQC and QKD where appropriate.


6. Offensive Value Generation in Portfolio Optimisation

Beyond defensive security, quantum computing offers substantial revenue-generating opportunities for capital markets. Quantum algorithms are designed to simultaneously evaluate vast numbers of investment scenarios and constraints, enabling asset allocation optimisation that minimises risk and maximises returns in volatile environments. Quantum computing also holds significant near-term promise for derivatives pricing, credit risk modelling, and liquidity optimisation, areas where classical computing reaches practical limits. The potential economic value of quantum computing across the finance industry is estimated at between $400 billion and $600 billion by 2035. Vanguard has already collaborated with IBM, using 109 qubits on IBM’s Heron processors, to explore sampling-based variational quantum algorithms for ETF portfolio construction under real-world constraints, a demonstration that quantum advantage in finance is moving from theory towards practice.

7. Hard Regulatory and Compliance Deadlines (2030–2035)

Whilst Q-day remains a matter of ongoing academic debate, governments and regulatory bodies are not waiting; they are establishing hard compliance mandates now. 

The United States National Security Memorandum 10 (NSM-10) establishes a 2035 deadline for the complete migration of federal systems to Post-Quantum Cryptography (PQC), with deprecation of vulnerable algorithms beginning in 2030. The European Union’s Digital Operational Resilience Act (DORA) imposes binding requirements on financial entities to maintain cryptographic agility and defend against evolving cyber threats, with quantum attacks falling within scope. The G7 Cyber Expert Group published a formal roadmap in January 2026 recommending that financial institutions prioritise the migration of critical systems within a 2030 to 2032 window. In the UK, the National Cyber Security Centre has published official guidance setting milestones to complete high-priority migrations by 2031 and full transition by 2035. The Financial Conduct Authority is actively engaged in international coordination on quantum resilience, though UK-specific formal mandates are still developing, firms should not mistake the absence of a domestic deadline for the absence of urgency.

8. Quantum Machine Learning for Fraud Detection

The financial sector relies heavily on machine learning for anti-money laundering (AML) and fraud detection, but classical models face well-documented limitations when processing highly imbalanced transaction datasets, generating false positives that create significant operational burden and investigator fatigue. Quantum Machine Learning would map data into high-dimensional quantum feature spaces, allowing algorithms to detect hidden, non-linear correlations across massive transaction datasets that classical models may miss. Early research suggests quantum and quantum-hybrid models can meaningfully outperform classical counterparts on precision and false positive reduction in fraud classification tasks, though this remains an active and evolving area of research rather than a deployed commercial reality. Financial institutions should monitor this space closely: firms that move early to build quantum ML capability for financial crime compliance may secure a significant competitive and regulatory advantage as the technology matures.

9. The Necessity of Cryptographic Agility and Asset Inventories

The transition to quantum safety is a multi-year, enterprise-wide overhaul, and it must begin now with systematic discovery. Financial institutions need to execute exhaustive cryptographic asset inventories, mapping vulnerabilities across legacy infrastructure, third-party vendor dependencies, and payment networks. Equally important is building “cryptographic agility”: the architectural capability to rapidly swap out outdated encryption algorithms for new standards as the threat landscape evolves, without disrupting underlying financial operations. This is not a small undertaking. Enterprise-wide PQC migrations in large financial institutions are expected to be among the most complex and costly technology programmes of the coming decade, comparable in scale to Y2K or the transition to cloud infrastructure. Institutions that begin their inventories and agility assessments today will be meaningfully better positioned, operationally and in terms of regulation, than those that defer.


10. Capital Concentration and Vendor Dependency

The quantum technology market is experiencing rapid capital inflows and significant consolidation. Global investment in quantum technology reached $12.6 billion in 2025, representing more than a six-fold increase from 2024. Despite this surge, capital remains heavily concentrated with a small number of firms capturing the majority of investment, with the top three companies alone raising approximately $3.5 billion in 2025. This concentration creates a strategic risk that financial services firms should be cognisant of. Institutions could become deeply dependent on a small, concentrated supply chain of quantum hardware and software providers for their future computational and cryptographic infrastructure. Vendor selection, contractual resilience, and supply chain diversification should already be on the agenda of any financial institution developing a quantum strategy, the firms that forge the right partnerships now will have a structural advantage over those scrambling to catch up when Q-day does arrive.