Wall Street Races to Adopt Quantum-Safe Encryption
Fearing a future in which quantum computers crack today's cryptography, major New York financial firms are quietly overhauling how they protect data.
By Priya Nair · July 11, 2026 · 5 min read

NEW YORK — Inside the data-security teams of several large New York financial institutions, an unusual long-range worry has moved to the top of the agenda: the possibility that a sufficiently powerful quantum computer could one day break the encryption that protects trillions of dollars in transactions. In response, firms across the city's financial sector have begun a quiet, years-long migration to so-called post-quantum cryptography, a new class of algorithms designed to resist attacks that would defeat today's standards.
The threat is not immediate. No existing quantum machine can break the widely used encryption underpinning modern finance, and experts disagree on how many years — or decades — remain before one might. But security officials say the danger of waiting is subtler than it appears. "The concern is 'harvest now, decrypt later,'" one bank security executive explained. "An adversary can steal encrypted data today, sit on it, and unlock it the moment the technology catches up. For records that stay sensitive for decades, that's a problem right now."
The migration is enormous in scope. Encryption is woven into virtually every layer of a financial firm's operations, from customer logins to interbank settlement systems, much of it running on legacy software that is difficult to inventory, let alone replace. Security teams describe the effort as a multiyear archaeology project, first cataloging every place cryptography is used and then swapping in new algorithms without disrupting live systems. "You can't just flip a switch," one engineer said. "You have to find every lock in the building before you can change them."
The push has accelerated since federal standards bodies finalized a first set of post-quantum algorithms, giving firms concrete targets to build toward. Vendors that sell security software have raced to add support, and a small ecosystem of New York consultancies has sprung up to advise banks on the transition. Some firms have set internal deadlines to complete the most critical migrations within a few years, treating the effort as a compliance imperative rather than a distant research curiosity.
Regulators are watching closely. Officials at agencies overseeing the financial sector have signaled that they expect firms to have credible transition plans, and some have begun asking institutions to report on their progress. "We don't want the industry sleepwalking into a crisis it could see coming," one regulatory official said, framing the shift as basic operational resilience rather than speculative futurism.
For all the technical complexity, security leaders stress that the goal is invisibility: if the migration succeeds, customers will never notice anything changed. "Success looks like nothing happening," one executive said. "No breach, no headline, no panic — just the quiet knowledge that when the day comes, we were already ready." The firms declined to detail their specific timelines, citing security concerns, but several acknowledged the work is now among their largest ongoing technology projects.