Hong Kong’s Banks Are Watching the Quantum Clock. Few Are Racing It
No bank in Hong Kong has been broken by a quantum computer, because no quantum computer can yet do the breaking. A new white paper backed by the Hong Kong Monetary Authority says the city’s banks understand that day is coming. What it also says, in three blunt words the report uses to describe the sector’s readiness, is where you should pause.
“Uncertain. Uneven. Unready.”
That verdict sits at the center of the paper. Awareness of quantum computing is climbing across Hong Kong’s banking industry, and a handful of institutions have set up governance, run pilots, and started migration planning. Most have not. The paper, prepared with KPMG and Quinlan & Associates from a survey of authorized institutions in the city, describes an industry that knows the threat by name and has mostly filed it under ‘later.’
It’s worth saying plainly that this is a sponsor-backed survey of self-reported readiness, not an independent audit, and the sponsors sell some of the services the report recommends. That doesn’t make the core argument wrong. It makes the argument the interesting thing, because the logic holds regardless of who paid for the paper.
Why the real deadline comes before Q-Day
The instinct in most boardrooms is to wait. Build quantum-safe systems once a cryptographically relevant quantum computer, a CRQC, actually exists and can run Shor’s algorithm against the RSA and elliptic-curve encryption that guards online banking. The report’s central point, and the reason it pushes banks to move now, is that this instinct gets the deadline wrong.
The tool it reaches for is Mosca’s inequality, which sets three clocks side by side: how long your data must stay secret, how long a full migration takes, and how many years remain before a CRQC arrives. Add the first two. If the sum runs past the third, you are already exposed, and you were exposed the day you did the math. For a bank sitting on records that must hold their confidentiality for decades, and facing a cryptographic migration that the report itself calls a years-long project, the margin is thin before anyone builds anything.
This is what turns “harvest now, decrypt later” from a slogan into a line item. An adversary doesn’t need a working quantum computer today to hurt you. They need a hard drive and patience, copying encrypted traffic now to decrypt once the hardware catches up. The mechanics of that attack are why the threat is present-tense, and why it’s the same warning the Bank for International Settlements aimed at pension funds and sovereign wealth funds earlier this year. Q-Day was never going to be a single morning. The exposure starts long before the machine does.
Uncertainty is the argument, not the excuse
Nobody can tell you the CRQC’s arrival date. The paper leans on a Global Risk Institute expert survey that calls such a machine reasonably possible within a decade and likely inside fifteen years, and it notes recent theory has cut the estimated qubit count needed to attack RSA, though the engineering to get there remains unsolved. It adds a caution that deserves repeating: published vendor roadmaps show only what companies choose to disclose, and say nothing about classified programs.
Banks read all that and hear permission to wait. The paper reads it the other way. When the arrival time is a wide range rather than a fixed date, and the migration is slow, uncertainty becomes the reason to start, because you cannot compress a multi-year cryptographic overhaul into the final quarter before a deadline you can’t see.
There’s a quieter complication too. A bank can’t migrate alone. Its encryption lives inside payment networks, vendor software, and shared market infrastructure, so readiness has to be coordinated across the whole chain, tested for interoperability, and pulled along at the speed of the slowest partner. That dependency is already spawning a services market, from migration-focused reseller channels to the tooling covered in this enterprise migration deep dive.
What the HKMA report recommends banks do now
The roadmap is deliberately unglamorous. Put quantum risk on the board’s agenda and give it an executive owner. Inventory every cryptographic system you run, which for a large bank is harder than it sounds, given legacy infrastructure and technical debt. Map where long-life data could be exposed, press vendors on their post-quantum timelines, train people, and fold quantum readiness into the cybersecurity and resilience programs you already have. The HKMA says it will help with supervisory guidance, workshops, and PQC toolkits built with academic partners.
None of that requires a quantum computer to exist. Which is the whole point. The banks that treated this as a hardware milestone are the ones the paper found flat-footed, and the ones that treated it as a governance project are the small group already moving.
On the upside case, the report is careful, and so should anyone quoting it be. It lists financial uses quantum computing might eventually unlock, in portfolio optimization, fraud detection, and risk modeling, and cites live experiments to match. Read those as they are. Citi’s portfolio-optimization test with Classiq showed no quantum advantage over classical methods. Huaxia Bank’s ATM-optimization result with SpinQ is the bank’s own experimental claim. The work at HSBC, Barclays, and Ping An sits at proof-of-concept. The report’s own word for the sector’s quantum-computing maturity is exploratory, and the commercial payoff stays speculative.
The security clock does not. That asymmetry is the reason a regulator has put its name on a paper telling banks to start work on a threat no machine can yet carry out. Uncertain, uneven, and unready describes where the industry is. Whether it stays a description or becomes a warning depends entirely on what the banks do with the years they have left.