top of page

The U.S. Treasury Just Made Quantum Readiness a Financial Infrastructure Issue

By Joel Van Dyk


On August 24, the U.S. Department of the Treasury announced the creation of a Quantum-Readiness Task Force focused on accelerating the financial sector’s transition to quantum-safe technologies (https://home.treasury.gov/news/press-releases/sb0615).


The announcement matters, but perhaps not for the reason people might initially think.


This is not another signal that quantum computing is coming. We already know that. Nor is it primarily an announcement about selecting the right post-quantum cryptographic algorithms. Standards are important, but standards alone do not make an institution quantum-ready.


What matters is where the conversation is moving.


Quantum readiness is becoming a financial infrastructure issue.


That distinction is important because the most difficult part of the post-quantum transition will not be understanding the mathematics behind new cryptographic algorithms. It will be finding, understanding and ultimately replacing cryptography across complex environments that have been built over decades.


For large financial institutions, cryptography is everywhere.


It protects transactions, identities, communications, applications, APIs, certificates, databases, payment systems, third-party connections and long-lived data. Some of those systems are modern. Others are not. Some are controlled directly by the institution. Others depend on vendors, partners, networks and infrastructure outside its immediate control.


Before an organization can migrate its cryptography, it has to know where that cryptography lives, what it protects, how long the protected information must remain secure and what will happen when a component changes.


That is why the post-quantum transition is fundamentally an architecture and operational-resilience problem.


The Treasury initiative follows a broader shift already underway across the financial sector. The G7 Cyber Expert Group has published a roadmap for transitioning the financial sector to post-quantum cryptography. The Bank for International Settlements has similarly emphasized cryptographic inventory, migration planning and crypto-agility as important elements of quantum readiness.


The direction of travel is becoming increasingly clear.


Financial institutions should not wait for a sufficiently powerful cryptographically relevant quantum computer to arrive before addressing the infrastructure that will eventually need to change.


The work begins much earlier.


Organizations need to understand their cryptographic dependencies. They need to identify information that may already be exposed to “harvest now, decrypt later” risk. They need to determine which systems can accommodate new cryptographic standards and which cannot. They need to understand their dependencies on vendors and counterparties.


And, perhaps most importantly, they need to develop crypto-agility.


Crypto-agility is sometimes described simply as the ability to replace one cryptographic algorithm with another. In a large financial institution, it means considerably more than that.


It means building systems, governance and processes that allow cryptographic components to change without requiring an institution to redesign its infrastructure every time the threat environment or cryptographic standards change.


That capability will matter beyond the transition to post-quantum cryptography.


Cryptography changes. Algorithms weaken. Standards evolve. Vulnerabilities emerge. Technology advances.


An institution that understands its cryptographic estate and can change it deliberately is better prepared not only for quantum computing, but for the next cryptographic disruption after it.


This is why I believe the most useful question for financial institutions today is not: when will Q-Day arrive?


It is: if we needed to change a critical cryptographic component tomorrow, would we know where it was, what depended on it and how to replace it without disrupting the business?


For many organizations, answering that question will reveal considerably more about their quantum readiness than predicting the arrival date of a cryptographically relevant quantum computer.


The Treasury’s announcement is therefore important because of what it represents.


Quantum readiness is moving out of the realm of future technology discussion and into the practical world of financial-sector resilience, infrastructure, technology transformation, and risk management.


That is where the work has always needed to happen.


The organizations that begin now will not need to predict precisely when quantum computing crosses the cryptographic threshold.


They will have built the ability to adapt when it does.


And ultimately, that may be the most important measure of quantum readiness of all.

 
 
 

Recent Posts

See All
We Are Still Managing Security Like It’s 2006

And we should be embarrassed about it. Mark Twain once observed that history may not repeat itself, but it sure does rhyme. In information security, we have taken that as a design principle. Let me be

 
 
 

Comments


bottom of page