The government has directed banks to develop a sector-wide strategy for adopting quantum-resistant technology, alongside an artificial intelligence (AI) resilience framework. The move aims to protect banking systems, customer information and financial transactions against emerging cyber threats.
The initiative follows growing concerns that advances in quantum computing could eventually weaken encryption systems currently used to secure financial information.
Banks have begun internal discussions, while a working group under the State Bank of India (SBI) is examining the proposed transition.
What Is Quantum Computing?
Quantum computing is an advanced technology that uses quantum physics to solve certain complex problems much faster than traditional computers. Unlike regular computers, which use bits (0 or 1), quantum computers use qubits that can represent multiple states simultaneously. While this technology could improve scientific research and financial services, it could also threaten existing encryption systems used to protect banking transactions and sensitive data.
Why Are Banks Preparing for Quantum Threats?
Quantum computing could create new cybersecurity risks because sufficiently powerful quantum computers may eventually break some encryption methods used to protect digital communications and financial data.
Unlike conventional computers, which process information using bits, quantum computers use quantum bits, or qubits. These can operate using principles such as superposition and entanglement, allowing certain calculations to be performed differently from conventional computing systems.
Although quantum computers capable of breaking widely used encryption are not yet available, financial institutions are being encouraged to prepare before the technology becomes powerful enough to pose a serious threat.
The banking sector is particularly exposed because it handles large volumes of confidential information, including customer records, transaction details and financial communications.
A successful attack against encryption systems could compromise sensitive information and undermine confidence in digital banking.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
What Is the ‘Harvest Now, Decrypt Later’ Threat?
One of the government’s main concerns is a cyberattack technique known as ‘harvest now, decrypt later’ (HNDL).
Under this approach, attackers collect encrypted information today and store it with the intention of decrypting it in the future, when more powerful quantum computers become available.
This means that information stolen now could remain at risk even if criminals cannot immediately read it.
Financial institutions may therefore need to protect not only current transactions but also sensitive information that must remain confidential for many years.
The Department of Science and Technology has identified this threat in its assessment of India’s quantum-safe ecosystem.
The concern is that attackers could accumulate encrypted banking data long before the technology required to break its protection becomes available.
This makes early preparation important, particularly for organisations responsible for long-term financial records and sensitive customer information.
What Has the Government Asked Banks to Do?
The finance ministry has asked banks to assess vulnerabilities that could arise from advances in quantum computing and begin developing measures to reduce those risks.
Banks are expected to identify weaknesses in their existing encryption systems and examine how they can gradually move towards quantum-resistant security.
The government has also encouraged public sector banks to explore advanced encryption methods as an additional security layer under their existing cybersecurity improvement programmes.
A working group under SBI is examining the issue, while individual banks are preparing internal strategies.
However, the government has emphasised that the transition should not remain limited to individual institutions.
A coordinated approach is considered necessary because banks, payment systems and other financial organisations operate through interconnected digital infrastructure.
The proposed sector-wide framework would help financial institutions prepare for emerging risks while maintaining consistency in cybersecurity planning.
What Is the AI Resilience Framework?
Alongside quantum security, the government is developing a common framework to address cybersecurity risks associated with artificial intelligence.
AI is increasingly being used in financial services, but its growing adoption also introduces new security concerns.
The proposed framework is intended to help banks identify and manage threats involving AI systems and AI-driven cyberattacks.
The Reserve Bank of India (RBI) has already introduced an AI cybersecurity and technology-resilience framework for commercial banks.
In August, the Securities and Exchange Board of India (SEBI) introduced an IT Resilience Index for market infrastructure institutions to assess the effectiveness of their critical technology systems.
These measures reflect a broader effort to strengthen the financial sector against emerging technology risks.
The government is now considering how banks and other financial institutions can adopt a more coordinated approach to AI security.
The focus includes preparing institutions for new cyber threats while ensuring that the growing use of AI does not create additional weaknesses in financial infrastructure.
How Will India Become Quantum-Safe?
India has begun developing a phased roadmap to move its digital infrastructure towards post-quantum cryptography.
Post-quantum cryptography refers to encryption methods designed to resist attacks from both conventional computers and future quantum computers.
The Department of Science and Technology’s quantum-safe roadmap outlines a transition for critical sectors, including banking, financial services and insurance.
Under the proposed timeline, foundational work is expected by 2027, followed by the migration of high-priority systems by 2028.
The roadmap envisages broader adoption of post-quantum cryptography by 2029.
An expert committee under the RBI’s Quantum Secure and Adaptive Financial Ecosystem initiative has also examined the implications of quantum technology for financial institutions.
Its recommendations include preparing the sector for the transition to quantum-resistant systems.
The international financial sector is taking similar steps.
The United States National Institute of Standards and Technology has finalised post-quantum cryptography standards and encouraged organisations to begin migration.
The G7 has developed a roadmap for transitioning financial institutions towards quantum-resistant security.
The European Union has also called for member states to begin the transition by the end of 2026, with high-risk systems moving to quantum-resistant cryptography as soon as possible and no later than the end of 2030.
These developments indicate that quantum cybersecurity is becoming an important part of long-term financial security planning.
Why Does This Matter for Banking Customers?
For ordinary banking customers, the immediate concern is the long-term protection of their personal and financial information.
Modern banking depends heavily on encryption to protect online transactions, account information and communications between financial institutions.
If existing encryption systems become vulnerable to future quantum attacks, information that is secure today could face risks later.
Moving towards quantum-resistant technology is intended to reduce that possibility.
However, the transition will require banks to examine their existing systems, identify vulnerable technology and introduce stronger encryption without disrupting essential financial services.
Quantum computing also presents opportunities for the financial sector.
India’s technology roadmaps identify financial modelling, fraud detection and encryption among the potential applications of quantum technology.
The challenge is therefore not simply to defend against quantum computing but also to develop capabilities that could benefit the financial system.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics