HomeMalware & ThreatsTreasury Initiates Quantum Task Force for Financial Sector

Treasury Initiates Quantum Task Force for Financial Sector

Published on

spot_img

Finance & Banking,
Industry Specific,
Next-Generation Technologies & Secure Development

Banks Face a Migration With No Deadline and No Regulator Behind It

Treasury Initiates Quantum Task Force for Financial Sector
Image: Michael R. Bresnahan/Shutterstock

The U.S. Department of the Treasury is initiating the formation of a public-private task force aimed at accelerating the transition to quantum-safe encryption across banks, market infrastructure operators, and their respective technology vendors. This initiative is seen as a necessary step to ensure the financial sector’s resilience against the potential threats posed by quantum computing.

On August 28, 2026, the Treasury unveiled the Quantum-Readiness Task Force, directly correlating this effort with a recent executive order from former President Donald Trump. In June, this order mandated that all federal systems integrate post-quantum cryptography as part of a broader strategy to secure the nation from advanced cryptographic attacks.

Through the executive order, each agency categorized as a sector risk management agency was instructed to collaborate with the Cybersecurity and Infrastructure Security Agency (CISA) in developing migration strategies intended to protect critical infrastructure. The Treasury functions as the sector risk management agency specifically for financial services.

As the discussion surrounding quantum computing intensifies, analysts are expressing concerns that future quantum computers could render existing public-key cryptography obsolete, thereby jeopardizing payment systems, digital identities, and overall market infrastructure. Experts underline that adversaries may currently intercept and store encrypted data, which could later be decrypted once powerful quantum systems become operational.

At this juncture, U.S. financial regulators have not issued any requirements concerning post-quantum computing for the institutions they supervise, and the Treasury’s announcement has not indicated that this will change in the near future.

According to Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group, the shift towards post-quantum cryptography readiness necessitates organizations to give priority to critical systems and processes. She emphasized the importance of managing dependencies within the financial ecosystem while addressing the substantial challenges associated with implementation.

At present, the Treasury has not disclosed the specific members of the task force, its inaugural meeting date, nor the anticipated outcomes of the group. Requests for further comment from the department went unanswered.

Research indicates that the level of readiness concerning quantum security varies significantly throughout the financial sector. Prominent banks have allocated substantial resources to quantum risk over the years, establishing dedicated teams and budgets to address potential vulnerabilities. In contrast, smaller banks, asset management firms, and fintech companies tend to rely heavily on external vendors with fewer internal resources focused on quantum-related issues.

Utkarsh Ahuja, founder and managing partner at Moon Pursuit Capital, which invests in quantum-security enterprises, noted that it would be misleading to equate the progress made by a few sophisticated institutions with the overall market readiness.

Treasury officials expressed that the newly formed group will bring together financial institutions, market infrastructures, and technology providers to work on critical areas such as cryptographic inventory, agility, and interoperability. Luke Pettit, Treasury Assistant Secretary for Financial Institutions, described the initiative as a “financial sector quantum readiness task force,” with an overarching goal of facilitating a transition that is coordinated, risk-based, and operationally resilient.

This initiative is envisioned as a continuation of the roadmap laid out by the Group of Seven (G7) cyber expert group regarding post-quantum migration.

Inventory First, Migration Later

Most frameworks for achieving cryptographic readiness emphasize the importance of creating a comprehensive cryptographic inventory as the initial step. However, many institutions have found this task to be particularly challenging. Financial organizations often utilize cryptography embedded in products developed by third parties, operating on infrastructures that may predate the algorithms that are currently being deprecated.

Ahuja explained that the scope of a cryptographic inventory encompasses legacy systems, APIs, cloud infrastructure, acquired technologies, and third-party software, some of which may have been embedded in an institution for decades. If a financial institution is unable to pinpoint the locations of its encryption systems, it cannot adequately prioritize which elements to transition.

A white paper released in September 2025 by the Financial Services Information Sharing and Analysis Center echoed similar findings concerning migration timelines, co-developed by its post-quantum cryptography working group alongside Canadian and European counterparts. The paper cautioned against what it termed “crypto-procrastination,” attributing it to firms underestimating the magnitude of necessary efforts and framing quantum threats as a long-term concern.

Many analysts point out that a typical bank’s reliance on cryptography often comes through technology acquired from third-party vendors. This reliance implies that migration schedules are largely governed by those suppliers rather than by the banks themselves.

Ahuja highlighted the risk that even if an institution executes a comprehensive strategy internally, it may still rely on payment processors, cloud service providers, custodians, software suppliers, and counterparties that are not aligned with the same speed of advancement. This discrepancy is particularly problematic in payments and settlement sectors, where successful interoperability is crucial to operational integrity.

Source link

Latest articles

Android 17 Introduces Enhanced Network Security Protections

Google Enhances Network Security in Android 17 In a significant move to bolster user privacy,...

Unit 42 Observes AI Transforming Enterprise Security Practices

Human Oversight in AI-Driven Cybersecurity: Insights from Unit 42 As artificial intelligence (AI) continues to...

The Balance of Healthcare Research Potential and Privacy in the Age of AI

The Impact of AI on Healthcare Research: Navigating Innovation and Privacy Concerns The advancement of...

ServiceNow Addresses Three Critical Vulnerabilities Posing Risks to Enterprise Data

In a recent analysis, cybersecurity expert Seker highlighted significant changes in the landscape of...

More like this

Android 17 Introduces Enhanced Network Security Protections

Google Enhances Network Security in Android 17 In a significant move to bolster user privacy,...

Unit 42 Observes AI Transforming Enterprise Security Practices

Human Oversight in AI-Driven Cybersecurity: Insights from Unit 42 As artificial intelligence (AI) continues to...

The Balance of Healthcare Research Potential and Privacy in the Age of AI

The Impact of AI on Healthcare Research: Navigating Innovation and Privacy Concerns The advancement of...