Insider Brief
- A Hong Kong Monetary Authority-supported white paper found that most banks in Hong Kong recognize the strategic importance of quantum computing but remain in the early stages of preparing for post-quantum cryptography (PQC).
- The report identifies quantum-enabled cyber threats, including “Harvest Now, Decrypt Later” attacks, as an immediate concern and recommends that banks begin migration planning well before cryptographically relevant quantum computers become available.
- The paper calls for banks to establish governance, inventory cryptographic assets, engage technology vendors on PQC roadmaps and integrate quantum readiness into long-term cybersecurity and operational resilience programs.
Uncertain. Uneven. Unready.
Hong Kong’s banking sector has begun preparing for quantum computing, but most institutions remain in the early stages of protecting their systems against future quantum-enabled cyber threats, according to a new white paper supported by the Hong Kong Monetary Authority (HKMA).
The report concludes that awareness of quantum computing is growing across Hong Kong’s banking industry, yet practical implementation of post-quantum cryptography (PQC) remains limited. While a small number of banks have established governance structures, pilot projects and migration planning, most are still building foundational capabilities needed for what the report describes as a years-long transition.
The study was prepared with support from KPMG and Quinlan & Associates. It surveyed authorized institutions operating in Hong Kong to evaluate both their interest in quantum computing and their readiness to defend against future quantum attacks.
According to the report, banks increasingly view quantum computing as both an opportunity and a cybersecurity challenge. Future quantum computers could eventually accelerate financial modeling, portfolio optimization, fraud detection and risk analysis. At the same time, sufficiently powerful quantum machines could break many of today’s public-key encryption systems that protect online banking, payment networks and financial infrastructure.
The paper reports that cybersecurity risks require more immediate attention than commercial quantum computing applications because migrating encryption across large banking organizations will likely take many years.
Uneven Preparation
The survey found that most participating institutions have at least some awareness of quantum computing, and a smaller group has begun evaluating potential business applications or conducting pilot projects.
However, according to the report, most banks still consider quantum computing a long-term technology because of uncertain commercial value, limited internal expertise and the immature state of current quantum hardware.
Preparation for post-quantum cryptography presents a different picture with the report assessing readiness across awareness, planning, pilots and practical preparedness. It found that many institutions have not yet established formal governance, dedicated budgets, workforce training programs, cryptographic inventories or migration plans.
Researchers report that the industry’s preparedness varies considerably. A relatively small group of organizations has already established governance frameworks, begun structured planning and launched pilot projects, while much of the sector remains at earlier stages.
Banks cited uncertainty surrounding standards and regulatory timelines, the technical difficulty of identifying every cryptographic system across large organizations, legacy infrastructure, technical debt and shortages of internal expertise.
External dependencies also complicate planning as financial institutions rely heavily on software vendors, payment networks, common infrastructure providers and business partners, meaning migration cannot occur independently. Organizations must coordinate upgrades and interoperability testing across the broader financial ecosystem.
Quantum Promises Beyond Cybersecurity
Although cybersecurity dominates current planning, the report also outlines several ways quantum computing could eventually improve financial services.
Unlike conventional computers, which store information as binary bits representing either 0 or 1, quantum computers use quantum bits, or qubits. Qubits can exist in combinations of states through a phenomenon known as superposition and can also become linked through entanglement. These properties may eventually allow quantum computers to solve certain optimization and simulation problems more efficiently than classical systems.
The report emphasizes that current quantum computers remain limited by hardware errors and relatively small numbers of qubits. Multiple hardware approaches — including superconducting circuits, trapped ions, neutral atoms, photonic systems and silicon-based devices — are under active development, with no clear winner emerging.
Even so, financial institutions worldwide have begun experimenting with quantum algorithms.
The paper highlights several industry examples.
For example, Citi and quantum software company Classiq tested quantum portfolio optimization using historical stock data. According to the report, the work did not demonstrate a quantum advantage over classical methods but showed how algorithm tuning may become important as hardware improves.
Huaxia Bank collaborated with SpinQ to optimize ATM placement and cash replenishment using a quantum neural network trained on operational data from more than 2,200 ATMs. The report states that the experimental system improved accuracy while reducing computation time compared with a conventional algorithm.
Other examples include Ping An Insurance’s work on quantum machine learning for fraud detection, HSBC‘s experimental quantum-assisted trading research with IBM, and Barclays‘ proof-of-concept work exploring quantum algorithms for securities transaction clearing.
Most of these projects remain experimental, and the report characterizes the industry’s overall quantum computing maturity as exploratory or in the pilot stage.
Uncertain Cybersecurity Timeline
The report devotes significant attention to the uncertainty surrounding when quantum computers may become capable of breaking today’s encryption.
Such a machine is commonly referred to as a Cryptographically Relevant Quantum Computer, or CRQC.
Current public-key encryption methods, including RSA and elliptic curve cryptography, depend on mathematical problems that are computationally impractical for today’s classical computers to solve. According to the report, a sufficiently capable quantum computer running Shor’s algorithm could eventually solve those problems efficiently enough to compromise existing encryption.
One concern already affecting long-term planning is the “Harvest Now, Decrypt Later” scenario.
In this type of attack, adversaries collect encrypted information today and store it until future quantum computers become powerful enough to decrypt it. Information requiring confidentiality for decades—including financial records, customer information and government data—could therefore be vulnerable long before practical quantum computers arrive.
The report discusses this concept using Mosca’s Theorem, which compares three timelines: how long data must remain confidential, how long organizations need to migrate to quantum-safe encryption and when quantum computers become capable of breaking existing cryptography. If migration takes too long, sensitive information could become exposed before its required confidentiality period expires.
The paper cites expert surveys from the Global Risk Institute indicating that specialists consider it reasonably possible that a cryptographically relevant quantum computer could emerge within the next decade and likely within 15 years. The report also notes that recent theoretical research has reduced estimates for the number of qubits required to attack encryption under certain assumptions, although many engineering challenges remain unresolved.
The researchers caution that published company roadmaps represent only publicly available information and may not reflect undisclosed advances or classified research programs.
Roadmap Points to Immediate Action
Rather than waiting for quantum computers to mature, the report recommends that financial institutions begin organizational preparations now.
Its proposed roadmap starts with board-level engagement and treating quantum risk as an enterprise-wide issue. Banks are encouraged to assign executive ownership, develop inventories of cryptographic systems, assess where sensitive data could face long-term exposure and engage technology vendors about their post-quantum migration plans.
The report also recommends building workforce expertise, conducting controlled pilot programs and incorporating quantum readiness into existing cybersecurity, operational resilience and third-party risk management processes.
According to the researchers, industry-wide support will also be necessary. Banks participating in the survey requested clearer supervisory guidance, practical implementation frameworks, knowledge-sharing programs and testing environments.
The HKMA reports that it plans to support those efforts through supervisory guidance, workshops, training initiatives, post-quantum cryptography toolkits developed with academic partners and industry collaboration programs.






