5 min read
Is Quantum Computing a Cybersecurity Risk for Community Banks?
Andrew Hernandez
:
October 9, 2026
What quantum computing could mean for bank encryption, what is realistic today, and what community financial institutions should do now
A first-person look at why quantum risk is real, why it is not an emergency, and why the smartest first step is a conversation with your vendors.
The Short Answer
Yes, quantum computing is a cybersecurity risk for community banks. It is also not an emergency, which is the part that tends to get lost between the headline and the second paragraph. The honest answer is a future threat with a present-day deadline, and a problem that has far more to do with vendor management than with physics.
I should confess a bias up front. I have a long-standing fascination with quantum mechanics, the kind that has me reading about superposition for fun, a hobby that has never once improved a dinner party. So when client questions started arriving, especially after Treasury announced its Quantum-Readiness Task Force in August, I was delighted and slightly obligated in equal measure. The science is remarkable. It is also remarkably easy to oversell.
What Quantum Computers Could Actually Break
A classical computer stores information as bits, and each bit is a zero or a one. A quantum computer uses qubits, which can exist in a blend of both states at once until they are measured. That is real physics, not a metaphor, and it lets certain algorithms explore enormous numbers of possibilities in a way a conventional machine cannot.
The important phrase is certain algorithms. A quantum computer is not a faster laptop, and it will not make your core system run any quicker. Unfortunately, one problem it is well suited to is the math underneath much of modern public key cryptography. In 1994, Peter Shor showed that a sufficiently large, error-corrected quantum computer could factor huge numbers efficiently. RSA and elliptic curve cryptography depend on that being hard, and they protect secure web connections, digital certificates, VPNs, and digital signatures.
Not everything breaks equally, though. Symmetric encryption such as AES-256 holds up far better, because the best-known quantum attack offers only a modest speedup that larger keys can absorb. So can quantum computers break the encryption banks use today? Not today, and not all of it. But the part used to establish trust and exchange keys is the part in the crosshairs.
What Is Realistic Today
Today's quantum machines are impressive and nowhere near ready for this job. The largest chips hold roughly a thousand physical qubits, which are noisy, fragile, and in many designs kept colder than deep space. Useful work requires error correction, which bundles many physical qubits into one reliable one. Estimates for breaking RSA-2048 have fallen from tens of millions of physical qubits to under a million, which is real progress and still orders of magnitude beyond anything that exists. Google's 2024 demonstration that error correction can improve as a system scales was a genuine milestone, but not a countdown clock.
Most credible estimates place a cryptographically relevant quantum computer somewhere in the 2030s, with real uncertainty in both directions. Almost nobody will own one, either. Building them takes rare, interdisciplinary talent, so access will largely come through the cloud, and the realistic adversary is a nation-state, not someone in a garage. No one is decrypting your bank's traffic with a quantum computer today. I am comfortable saying that out loud.
Why Harvest Now, Decrypt Later Changes the Timeline
If the threat is a decade away, why is Treasury forming task forces? The answer is a phrase that deserves to be better known: harvest now, decrypt later. An adversary can capture encrypted data now, store it cheaply, and wait. For information with a long confidentiality shelf life, such as Social Security numbers, loan files, and account records, the exposure begins when the data is intercepted, not when the machine arrives.
The second reason is lead time, because cryptographic migrations are slow and tangled. The G7 Cyber Expert Group's January 2026 roadmap points to 2035 as a general target for the financial sector, with the most critical systems addressed around 2030 to 2032. Executive Order 14412, signed in June, sets federal deadlines of 2030 for post-quantum key establishment and 2031 for digital signatures on the government's highest-value systems. Those deadlines bind federal agencies, not community banks, but the direction of travel is hard to miss. So when should community banks start preparing? Now, with the emphasis on preparing rather than deploying.
The Good News Is Mostly Math
In August 2024, NIST finalized its first post-quantum cryptography standards, FIPS 203, 204, and 205. They rest on different hard problems, built largely from linear algebra and high-dimensional geometry, that no known quantum algorithm cracks, and they run on ordinary hardware. We do not have to out-build quantum computers. We get to out-math them. I will spare you the lattice lecture, though hiding a secret in a few hundred dimensions of geometry is the kind of thing I find quietly beautiful. That is the quantum-nerd portion of this article, and it is now over.
Your Vendors Hold Most of the Keys
Here is where this gets practical. Most of a community bank's cryptography lives in products you buy, not code you write: your core processor, online banking, Microsoft 365, your firewall and VPN, and the certificates holding it all together. Each will transition on its own timeline, which makes your job over the next one to three years about visibility and accountability rather than engineering. Treasury's task force includes a dedicated workstream on third-party and vendor readiness, which tells you where the real work is expected to be.
What To Do Now
-
Start a cryptographic inventory. Learn where encryption, certificates, and keys live across your systems and vendors. A spreadsheet is a fine beginning, and the executive order directs CISA to publish minimum elements for a cryptographic bill of materials by early 2027, a useful yardstick.
-
Add quantum questions to vendor management. Ask critical vendors for their post-quantum roadmaps, how easily their algorithms can be swapped, and whether they will notify you of changes. Build those questions into due diligence and renewals.
-
Prioritize by data shelf life. Information that must stay confidential for ten years or more deserves attention first.
-
Make it a standing governance item. Add quantum readiness to your risk assessment, review it annually with management and the board, and keep a short written plan. I would not be surprised if examiners begin asking for one.
-
Be skeptical of quick fixes. The goal is crypto-agility, the ability to swap algorithms without rebuilding everything, not a rushed purchase of something labeled quantum-safe.
Quantum computing is often described as overhyped in the short term and underestimated in the long term, and I think both halves are fair. The banks that handle it well will not be the ones that panic, or the ones that wait for a deadline. They will be the ones that start asking good questions now, while there is plenty of time to hear the answers.
Quick Answers: Quantum Computing and Community Bank Cybersecurity
Is quantum computing a cybersecurity risk for community banks?
Yes, but a long-term one. Quantum computing could eventually undermine the public-key cryptography banks use to secure connections and verify identity. It is a risk to plan for now, not an emergency today, and most of the exposure sits with vendors.
Can quantum computers break the encryption banks use today?
Not today. A large, error-corrected quantum computer could break widely used public key methods such as RSA and elliptic curve cryptography, but no such machine exists. Symmetric encryption such as AES-256 is far more resilient.
What is "harvest now, decrypt later"?
It is the practice of capturing encrypted data today and storing it until a future quantum computer can decrypt it. It makes quantum risk relevant now for any data that must stay confidential for many years.
When should community banks start preparing for post-quantum cryptography?
Now, starting with inventory and vendor conversations rather than deployment. Industry guidance points to roughly 2030 to 2032 for critical systems and 2035 for broader migration, and cryptographic transitions take years.
What should community banks do now to prepare for quantum computing?
Inventory where cryptography is used, add post-quantum questions to vendor due diligence, prioritize long-lived sensitive data, make quantum readiness a standing governance item, and avoid rushed purchases of products labeled quantum-safe.
Is your information security program keeping pace with emerging risks? If the answer is no, we can help. Learn more about our vCISO services here.