Financial firms harden networks for post-quantum era
European banks and insurers are upgrading encryption, transport visibility and crypto‑agility to protect data in transit under EU post‑quantum guidance, DORA and NIS2.
European banks and insurers are upgrading encryption, increasing transport‑layer visibility and building crypto‑agile network architectures to protect data in transit under EU post‑quantum guidance and the Digital Operational Resilience Act (DORA) and the NIS2 Directive.
Regulators are requiring firms to secure traffic across private networks, cloud platforms and third‑party providers and to submit migration plans for post‑quantum cryptography for high‑risk systems by the end of 2030.
Industry figures show that most financial institutions now run hybrid or multi‑cloud environments and that cloud‑based services and digital payment volumes continue to grow. Cyber incidents affecting finance and insurance accounted for a large share of attacks investigated in 2025.
Operational teams are treating encryption as the baseline protection and adding routing monitoring and stronger transport‑layer controls. Transactions frequently travel through a bank’s data centre, multiple cloud platforms and external processors, which makes tracing data flows harder for network operations teams.
Technical measures being adopted include dedicated private links between critical sites, optical‑layer encryption for bulk transport, enhanced transport‑layer visibility to check link integrity, and crypto‑agile designs that permit algorithm updates without wholesale hardware replacement. Firms are balancing those changes with the need for predictable, low‑latency performance for trading, payment processing and fraud detection.
Industry practitioners describe the transition to post‑quantum cryptography as a long, coordinated process that must align with hardware refresh cycles and wider IT architecture plans. Network teams are prioritising designs that accept new standards and algorithm swaps without disrupting live services to meet the 2030 deadline for high‑risk systems.
Regulatory texts raise expectations for stronger encryption, documented crypto‑agility and oversight of sensitive traffic across the full infrastructure chain. Supervisors expect firms to manage information and communication technology risks beyond individual data centres or cloud instances and to record risk management across internal and third‑party networks.
Financial institutions are expanding tools and controls to monitor routing, detect unusual flows and ensure transport integrity in real time while completing plans for post‑quantum migration.








