News

Offence vs Defence: The Dual Nature of Quantum Computing

Authored by Andrew Dunn, Practice Lead, Streets Consulting 

The Quantum Revolution is Happening Now

For those out there who think that quantum computing is some far-off future tech, the reality is that it is much closer than you think.

Let’s look at some current statistics: The financial services industry is anticipated to see quantum computing use cases generate between $400 billion and $600 billion in economic value by 2035. Global financial sector spending on quantum computing capabilities is projected to increase from $80 million in 2022 to $19 billion by 2032, representing a compound annual growth rate of 72%. Approximately 80% of the 50 largest banks worldwide are presently exploring quantum applications, and there are many initiatives already being run by the largest financial institutions.

This development is being driven by a looming and perhaps ominous deadline. 

The financial markets are wary of ‘Q-day: the time when Cryptographically Relevant Quantum Computers – CRQCs – are fully operational.

Why the Urgency?

In a nutshell, the cryptography that currently protects everything we do in financial services and beyond, and is the foundation for our trust in the global modern economy, will eventually be broken.

A CRQC (Cryptographically Relevant Quantum Computers) running on something called Shor’s algorithm, which was developed in 1994, will be able to solve the mathematical heavy lifting involved in breaking modern cryptography standards. These standards, such as RSA and Elliptic Curve Cryptography, currently secure global financial transactions and digital signatures and were safe in the knowledge that the best supercomputers in the world would take decades to crack the code. Current thinking is that a CRQC would be able to beat most modern cryptographic puzzles in 24 hours or less.

Whilst the timeline of delivery itself remains a matter of academic debate, the global consensus among experts and institutions is that the arrival of a CRQC is a matter of time rather than a mere possibility. Which means that the cryptography which currently protects us needs a serious overhaul. The United States and the European Union have issued mandates for the completion of a transition to quantum-safe cryptographic standards (Post-Quantum Cryptography (PQC)) by 2035. The National Cyber Security Centre in the UK has provided its own guidance targeting a 2035 transition completion date. 


Institutions and Financial Market Infrastructures are Building a Solid Defence

One of the reasons for this urgency stems from the rise of ‘Harvest Now, Decrypt Later’ cyber attacks. Foreign adversaries and criminal organisations are currently intercepting and storing encrypted financial data with the intention of decrypting it once quantum computers reach sufficient maturity. The risk of inaction is severe. A study by the Hudson Institute estimates that a quantum attack disrupting the Fedwire Funds Service could decrease the United States real GDP by 10 to 17%, causing up to  $3.3 trillion in cascading economic losses.

Post-Quantum Cryptography (PQC) involves new cryptographic algorithms designed to run on existing classical hardware while remaining secure against both classical and quantum computer attacks. These algorithms rely on even harder mathematical problems that lack known quantum shortcuts. Throughout 2024 and 2025, the United States National Institute of Standards and Technology finalised three post-quantum encryption standards and continues to explore others. These first recommended standards are called FIPS 203, FIPS 204, and FIPS 205.

Further defensive measures require physical hardware. Quantum Key Distribution (QKD) is a hardware-based secure communication method using the counterintuitive laws of quantum physics to distribute encryption keys. By encoding keys in quantum states, typically using photons, QKD ensures that any interception attempt alters the quantum state (explained in the first blog) and is therefore immediately detected by the communicating parties. Quantum Random Number Generation (QRNG) improves cryptographic security by using fundamental quantum processes to produce genuinely unpredictable random numbers. This eliminates the vulnerabilities associated with classical pseudo-random number generators.

Institutions are also looking at Hybrid Cryptography, which involves deploying classical algorithms alongside post-quantum algorithms. This dual-layer approach ensures that if a newly developed post-quantum algorithm contains unforeseen vulnerabilities, the classical algorithm maintains the current baseline of security. 

The integration of these defensive quantum technologies dictates a comprehensive architectural overhaul for the financial sector. Organisations must execute exhaustive cryptographic asset inventories to map vulnerabilities across legacy infrastructure and third-party vendor dependencies. Achieving cryptographic agility will allow institutions to rapidly swap encryption algorithms as standards evolve.


Institutions Are Also Building Offensive Capabilities

Quantum Computing is a double-edged sword, and there is a much brighter side. 

The properties of quantum computing provide financial institutions with ‘offensive’ applications that drive computational and commercial advantages, too.

Quantum technology has the power to enhance financial performance, optimise operations, and generate revenue. Financial services institutions are looking to use quantum computers for complex mathematical operations that are computationally expensive or practically impossible for classical systems.

Key offensive applications include:

  • Portfolio Optimisation: Quantum algorithms can simultaneously evaluate numerous investment scenarios and constraints to maximise returns and minimise risk in volatile markets.
  • Risk Modelling: Quantum-enhanced Monte Carlo simulations provide quadratic speedups for pricing complex financial derivatives and evaluating credit risk.
  • Fraud Detection: Quantum Machine Learning integrates quantum feature mapping to identify hidden, non-linear correlations in massive transaction datasets, operating in microseconds to reduce false positives in financial crime detection.

Current Trends in Market Adoption

Despite heavy investment across the sector, a recent analysis found that only 3% of banking websites currently support post-quantum cryptography. However, specific institutional testing and deployment are already underway across diverse financial applications, and quantum innovations are closer than you might think. Here are a few examples.

HSBC partnered with Quantinuum to pilot quantum-safe cryptography for tokenised gold transactions. The institution also successfully worked with IBM quantum computers to achieve up to a 34% improvement in predicting European corporate bond trade fills. JPMorgan Chase has deployed a quantum-secured crypto-agile network in Singapore and achieved milestones in Certified Quantum Randomness. They are also partnering with OQC and AMD to test hybrid workflows for portfolio optimisation and risk analysis.

Vanguard collaborated with IBM using variational quantum algorithms to optimise exchange-traded fund portfolio construction under real-world constraints. Additionally, Lloyds Banking Group tested IBM quantum hardware for graph-based anomaly detection to identify money mule networks. CaixaBank utilised D-Wave systems to reduce compute time for investment portfolio hedging, and Danske Bank completed a live Quantum Key Distribution data transfer between simulated data centres.

The Quantum Future is Now

Governments, regulators and financial institutions are looking into this technology with increasing urgency because, whilst a CRQC has not yet materialised, consensus is that it is firmly on its way, and the pace of development continues to quicken. With threats already emerging, and regulators and governments setting deadlines for transition to the post-quantum era, quantum computing is a present reality rather than science fiction. 

The emerging picture suggests that those who ignore the technology now may well be obsolete later, whether they fall foul of quantum attacks on cryptography, or fail to keep up with leading institutions as they use their new quantum powers to capture additional revenues and market share.

Neither race is a good one to lose.