Post-Quantum Security Isn't a Someday Topic for Banks - It's a Today Topic
Notes from a workshop on harvest-now-decrypt-later threats and AI's expanding attack surface

🔐 Quantum computing isn't a 'someday' topic for banks. It's a today topic. Yesterday I spent the day on post-quantum security with a bank and Jonathan Jenkyn. One idea reframed the room.
The Harvest-Now-Decrypt-Later Threat
⚠️ 'Harvest now, decrypt later' - attackers can capture your encrypted data today and crack it once quantum hardware matures.
For a bank, that means account records, transactions, and customer data that must stay private for decades. The data you're encrypting today might be vulnerable tomorrow, and adversaries are already collecting it.
Three Key Takeaways
Among all the learnings, three ideas stood out:
🔹 It's a today topic, not a 2030 one. Your longest-lived data is your most exposed - and that clock already started ticking. ⏰
🔹 Your AI footprint just widened the surface. Every LLM and agentic AI workflow might move sensitive data across the wire - prompts, RAG pipelines, agents calling tools and APIs. Post-quantum readiness and your AI roadmap are woven into each other. 🤖
🔹 Know your shared responsibility. AWS uses ML-KEM (the new NIST standard) in a hybrid handshake - already live in KMS, ACM, and Secrets Manager. Some protections are automatic; others need you to update TLS clients and SDKs. Start with a crypto inventory - you can't migrate what you can't see. 🛡️
A Multi-Year Journey That Starts Now
This is a multi-year journey - but the planning starts today. 🚀
The teams starting now will be the calm ones when the timeline tightens. Grateful to the bank's security and engineering team for the sharp questions and discussions. 🙏
Is post-quantum readiness on your 2026 security and AI roadmap yet? I'd love to hear where you are in the journey.
More on AWS's approach: AWS Post-Quantum Cryptography Overview.
#AlwaysDay1 #PostQuantumCryptography #AgenticAI #CyberSecurity #FinancialServices #CloudSecurity #AISecurity
The views and opinions expressed in this post are my own and do not necessarily reflect those of my employer or any organisation I am affiliated with.