industry · quantum risk
Core Banking & Quantum Risk: Inventory, Channels, and Migration
Verdict
Core banking platforms—often COBOL-heavy on mainframes or hybridized with modern channels—are not quantum-proof while classical public-key cryptography protects identities and confidentiality. Programs should inventory crypto, prioritize high shelf-life data, and pilot hybrid TLS without waiting for a full core rewrite.
Overview
Core banking is where accounts, balances, and many payment instructions ultimately settle. Cryptography is everywhere around that core even when business rules are expressed in COBOL or packaged products: operator authentication, channel encryption, batch file integrity, and partner federation.
A cryptographically relevant quantum computer changes the timeline for public-key algorithms that still dominate enterprise PKI and TLS. Harvest-now-decrypt-later means data exported from cores today can be valuable to adversaries for decades. That urgency is about data and keys—not about scaring boards with “quantum hacks COBOL.”
This industry page is the program lens. Technical COBOL pages explain the language and banking usage. System pages on this site cover TLS, PKI, databases, and compliance drivers in more depth.
What breaks
- Unmapped certificates and mutual-TLS service identities
- Long-lived customer and payment data protected only by classical key exchange (HNDL)
- Vendor cores with no crypto-agility roadmap
- PQC workstream owned only by “innovation” with no mainframe change calendar
Mitigations
- Stand up a crypto bill of materials for core-adjacent systems
- Classify data by confidentiality shelf life
- Engage vendors on hybrid TLS, HSM algorithms, and dual-sign options
- Link digital-asset custody programs separately (different threat surfaces) via /industries/finance/digital-assets
- Use /guides/migration-roadmap and the free assessment for a baseline
FAQ
Is core banking quantum-proof?
Not while classical public-key cryptography is the default for authentication and key exchange on its channels. Exact exposure is estate-specific—inventory is mandatory.
How does this relate to crypto assets?
On-chain assets have their own signature models (see /crypto). Core banking is traditional ledgers and rails. Institutions may need both programs under one risk committee.
What is a sensible first 90 days?
Crypto inventory of gateways and certificates, data classification for extracts, vendor questionnaires on PQC roadmaps, and a pilot hybrid TLS path—documented owners and change windows.
Key concepts (technical dictionary)
Terms used on this page — open a definition:
Related on this site
- /tech/cobol
- /tech/cobol/banking
- /is-quantum-proof/cobol
- /industries/finance/core-banking
- /industries/finance/digital-assets
- /is-quantum-proof/pki-certificates
- /is-quantum-proof/tls-https
- /is-quantum-proof/databases
- /standards/compliance-nsm10-cisa
- /guides/migration-roadmap
- /assessment
- /learn/what-is-pqc
- /industries/finance/digital-assets
- /blog/pqc-compliance-policies-cisa-nsm10
- /standards/compliance-nsm10-cisa