Hong Kong's banks

HKMA Survey Finds Hong Kong’s Banks Unprepared for Quantum Computing Threat to Encryption

The Hong Kong Monetary Authority (HKMA) says Hong Kong’s banks are years behind where they need to be on a cybersecurity threat that doesn’t exist yet, but might soon.

According to a new HKMA white paper, produced with support from KPMG and Quinlan & Associates, the more urgent threat isn’t quantum computers becoming powerful enough to optimize portfolios or price derivatives faster. It’s quantum computers becoming powerful enough to break the encryption that keeps the entire banking system’s secrets safe.

The 56-page report lays out a sobering assessment. The HKMA surveyed all authorized institutions, or AIs, operating in the city and found that the sector’s overall readiness score for the coming cryptographic transition sits at just 2.3 out of 10. Retail banks scored slightly better, at 2.6. Non-retail banks trailed at 2.2. Whichever way the numbers are sliced, Hong Kong’s banks remain, the analysts state, “at an early stage of transition.”

According to the paper, Cryptographically Relevant Quantum Computer, or CRQC, are machines powerful enough to run an algorithm published by mathematician Peter Shor in 1997 and break the RSA and elliptic curve encryption that underpins nearly all secure banking communication today. No such machine exists yet. But the report stresses, quoting a 2026 survey by the Global Risk Institute, that experts consider it “quite possible” a CRQC could emerge within a decade and “likely” within 15 years, based on likelihood estimates ranging from 28% to 87% across different time horizons.

That uncertainty is a significant problem, according to the paper, which was developed under the HKMA’s Fintech Promotion Blueprint. Hong Kong’s banks cannot wait for a firm date before acting, because of a concept the report calls Mosca’s Theorem, named for cryptographer Michele Mosca. The theorem is simply that if the number of years data needs to stay confidential, plus the number of years it takes to migrate to quantum-safe encryption, exceeds the number of years until a CRQC arrives, then sensitive information is already exposed before its protection period ends.

The report also describes a more immediate concern — the “Harvest Now, Decrypt Later” attacks. In these attackes, adversaries intercept and store encrypted data now, banking on the ability to crack it open once quantum hardware matures. For financial institutions holding decades-long client records, mortgage documents and trade data, the clock on that risk started ticking long ago.

The stakes, in dollar terms, are enormous. Citing a 2023 Hudson Institute study, the paper reports that a single-day quantum attack on one of the five largest U.S. financial institutions could cost the American economy between $2 billion and $3.3 trillion, or roughly HK$15.6 trillion to HK$25.9 trillion. Separately, the report cites Citi Institute research estimating that trillions of dollars in data globally could be exposed by a quantum-enabled breach.

A Sector That Knows the Problem but Hasn’t Moved

The survey shows that the industry is aware of the danger but institutionally unprepared to confront it. Some 68% of surveyed AIs report at least a basic awareness of quantum computing, and half say the topic has reached board-level discussion, whether formally or informally. Yet 68% also report having no quantum-related initiatives in place at all, and 61% have allocated no budget whatsoever to the space.

The gap widens further when the paper turns specifically to post-quantum cryptography, or PQC, the suite of new encryption algorithms designed to resist both classical and quantum attacks. Governance structures score 2.8 out of 10. Funding scores 2.0. Training and education score just 1.9. Only 18% of institutions report having a formal quantum readiness steering committee, and just over half say quantum risks are managed informally, folded into existing cybersecurity forums without dedicated attention.

Pilot testing tells a similarly uneven story with nearly three-quarters of surveyed institutions, 71%, report having neither conducted nor planned any proof-of-concept testing of PQC algorithms. Among the minority that have experimented, the report highlights examples from unnamed institutions, including a completed pilot applying post-quantum protections to websites, APIs and legal document signatures, and another testing whether cloud-based key management systems could accommodate a future PQC transition.

According to the report, cryptographic inventories, sometimes called a Cryptographic Bill of Materials, catalog where and how encryption is used across an institution’s technology systems. They are, according to the report, “the foundation for assessing exposure, prioritizing remediation activities, and tracking transition progress.” Yet 45% of surveyed AIs report having no such inventory at all, and 36% describe having no formal process even to identify where cryptographic assets exist within their own systems.

Why the Fixes Are Harder Than They Sound

The barriers cited by Hong Kong’s banks themselves help explain the slow pace. Asked to rank their top obstacles, 79% of respondents point to the sheer technical complexity of mapping cryptography across legacy IT environments. Some 87% cite dependencies on critical third parties, saying there is no clear pathway to coordinate PQC transition work with vendors, cloud providers and financial market infrastructure operators. Another 85% report that key technology vendors themselves lack clear timelines for delivering quantum-safe products.

Complicating matters even more, the paper indicates that the underlying science keeps shifting. Theoretical estimates of how many qubits a CRQC would need to break RSA-2048 encryption have fallen sharply in recent years, from hundreds of millions down to as few as 10,000 under certain assumptions, according to research the paper cites from a 2026 paper by Cain et al. That trend, the HKMA writes, suggests the quantum threat’s timeline “could potentially be earlier than previously expected,” even as physical hardware roadmaps from companies including IBM, Google and IonQ continue to climb toward hundreds of thousands of qubits within the next decade.

Global regulators aren’t waiting to find out. The report catalogs a wave of international deadlines, noting that the United States government has mandated migration of high-value assets to quantum-safe key establishment by the end of 2030 and digital signatures by the end of 2031, under a June 2026 executive order. The European Union, United Kingdom, Canada, Singapore and Australia have all published guidance or mandatory timelines clustering around 2030 to 2035. Google, meanwhile, announced in March 2026 that it aims to complete its own PQC migration by 2029, according to the report.

What the HKMA Wants Banks to Do Now

Rather than prescribing a single technical fix, the paper lays out a four-stage roadmap, moving institutions from Awareness through Planning and Pilots to what it calls Practical Preparedness. The immediate, low-cost steps get particular emphasis. Banks should engage their boards and frame quantum risk as an enterprise concern, the report advises. They should name an accountable executive owner with a mandate crossing departmental lines. They should commission a cryptographic inventory, even an imperfect one, and start pressing vendors for their own post-quantum roadmaps.

For its part, the HKMA commits to building supervisory infrastructure of its own. The authority plans to develop a PQC toolkit in partnership with academic institutions, expand training workshops already underway, and host industry forums bringing together banks, vendors and financial market infrastructure providers, according to the report. The stated goal is full sectoral readiness by 2030, a target the paper repeatedly frames not as a prediction but as a discipline the industry must impose on itself given how far behind current preparation levels sit relative to the multi-year migration effort ahead.

The report’s authors are careful not to cast the transition as purely defensive. Quantum computing also carries genuine promise for banking, the paper notes, pointing to pilots by HSBC, Citi, Barclays and mainland Chinese lenders exploring quantum-assisted fraud detection, portfolio optimization and trade clearing. HSBC’s work with IBM, for instance, reportedly produced a 34% improvement in predicting the odds of winning customer bond inquiries. But those upside use cases, the report makes clear, remain years from commercial maturity, while the cryptographic threat is a liability the sector is already living with, whether it has built the tools to see it or not.

Leave a Comment

Your email address will not be published. Required fields are marked *