Board & Risk Committee Briefing
For Non-Executive Directors, Audit Chairs, and Chief Risk Officers, quantum computing represents a dual fiduciary challenge: understanding long-term technology risk without being misled by sensationalist vendor marketing.
Executive Summary for Board Packs
- The Real Threat is Immediate (HNDL): Adversaries are harvesting encrypted transactions today. Data requiring 10+ years of confidentiality (mortgages, trade finance, wire transfers) is already exposed if encrypted with RSA-2048.
- The Transition Takes 5–7 Years: Upgrading core banking ledgers, HSM clusters, and SWIFT rails cannot be completed in a single fiscal year. Starting discovery in 2026 is necessary to complete migration before 2031–2033 deadlines.
- Regulatory Scrutiny is Active: European supervisors (under DORA) and US examiners are requesting cryptographic transition plans during annual supervisory reviews.
Five Critical Questions for the CISO / CTO
"Do we have an automated Cryptographic Bill of Materials (CBOM)?"
If the security team relies on manual spreadsheets rather than automated discovery across payment rails, the inventory has significant blind spots.
"Which payment gateways still depend on RSA-2048 or ECDSA?"
Identify high-value settlement rails (SWIFT, Fedwire, CHAPS) and establish prioritized migration milestones.
"Are our Hardware Security Modules (HSMs) FIPS 140-3 ready?"
Ensure hardware refresh budgets account for the September 2026 NIST FIPS 140-2 sunset.
"What are our critical fintech vendors doing about PQC?"
Require third-party software vendors to submit cryptographic agility roadmaps during procurement renewals.
Download the Executive Board Briefing (PDF)
Six-page executive summary formatted for board risk committee packs, refreshed quarterly.
Request Board Briefing Pack →