Sibos 2026: financial sector nears quantum tipping point
At Sibos 2026 in Miami, QuSecure CEO Rebecca Krauthamer warned migration to post‑quantum cryptography may take longer than the time before operational quantum computers arrive.
At Sibos 2026 in Miami, QuSecure CEO Rebecca Krauthamer warned the financial sector is approaching a “quantum tipping point.” She described it as the moment when the time required to move to post‑quantum cryptography exceeds the time left before a working quantum computer appears, creating long‑term exposure for encrypted data.
Krauthamer explained that certain quantum algorithms can solve the mathematical problems behind current public‑key systems such as RSA and ECC. That capability would threaten confidentiality, identity verification and message integrity across banking systems and communications.
She outlined two linked risks: the eventual arrival of quantum capability able to break widely used cryptography, and the accumulation now of encrypted data that can be harvested and decrypted later. Krauthamer used the terms “harvest now, decrypt later” and a signature equivalent, “trust now, forge later,” to describe those tactics.
The tipping point is reached, she said, when the remaining time before a quantum‑capable machine is shorter than the time an institution needs to finish migration. “We don’t know when the quantum computer arrives, whether it’s two years or 30. We have to be ready well in advance. The knowable date is how long your migration takes,” Krauthamer told delegates.
To underline the changing technical picture, she cited shifts in qubit estimates: projections in 2019 suggested as many as 20 million qubits might be required to break encryption; by March of this year some estimates had fallen to about 26,000 qubits. She also referenced forecasts that put the probability of a nation‑state quantum computer being ready by 2030 at roughly 75%.
Krauthamer proposed cryptographic agility as the practical response. That involves redesigning systems so cryptographic algorithms can be replaced without changing the underlying assets or data flows. She noted agility is difficult because encryption is embedded in hardware, software and vendor services.
She pointed to standards work already under way, including NIST’s August 2024 release of three post‑quantum cryptography standards intended to support migration of existing systems.
Krauthamer said the main barrier is inaction and urged firms to prioritise migration planning and execution. “We’re late, but for once the answer arrived before the attack… What’s left is the decision,” Krauthamer added.
Industry bodies and standards authorities have begun defining migration paths, while large financial institutions face operational, vendor and legacy challenges when updating cryptographic infrastructure.








