industry · quantum risk
Is Banking Quantum Proof? Quantum Risk for Banks
Verdict
Banking is not quantum-proof while customer channels, payment networks, and core integrations rely on classical public-key crypto. COBOL longevity multiplies migration windows—not “COBOL breaks under Shor.”
Overview
Banks combine decades-old cores with modern digital channels. Quantum risk sits in TLS, PKI, HSMs, card networks, and wholesale messaging—not in COBOL syntax.
This vertical hub links payments, card, ACH/ISO 20022, core banking, and finance industry pages for a CISO-ready map.
Cross-read Wave 4 COBOL/core-banking and Wave 7c program pages for inventory discipline.
Cryptographic profile
- Signatures: Payment and customer-channel TLS certificates, Core and middleware PKI, Card and ACH network crypto as operated
- Hash: Message authentication and audit hashes (system-dependent)
- Public-key exposure: Long-lived customer data, payment messages, and institutional PKI.
- Vertical: banking
What breaks
Mitigations
- Cryptographic inventory spanning channels, payments, and HSMs
- Hybrid TLS pilots on customer-facing edges
- Board-level multi-year PQC funding with payment partners
FAQ
Is banking quantum-proof?
Not as a sector default. Readiness varies by institution and depends on channel and payment cryptography migration.
Key concepts (technical dictionary)
Terms used on this page — open a definition: