On 17 October 2024, the G7 Cyber Expert Group (G7 CEG) issued a public statement (dated 25 September 2024) highlighting the potential cybersecurity risks associated with developments in quantum computing and recommending steps for financial authorities and institutions to take to address those risks.
The statement notes that an initial set of quantum-resilient encryption standards was released by the National Institute of Standards and Technology (NIST) last month. Additional standards from NIST and other standard-setting bodies are expected in the future.
- Developing a better understanding of the issue, the risks involved, and strategies for mitigating those risks. Financial entities may consider outreach to vendors, third parties, and other subject matter experts to better understand the risks of quantum computing and potential technology solutions, with a particular focus on cryptographic risks. Issues they may want to focus on include the timelines for quantum technology development, the evolution of the threat landscape, and existing and emerging quantum resilience technologies and approaches. Financial entities should consider processes to track developments in these areas as they change over time.
- Assessing quantum computing risks in their areas of responsibility. Financial entities should develop a sound understanding of quantum computing risks to their particular areas of responsibility, whether that is an individual company or a jurisdiction. The intention is to identify the level of effort the entity should dedicate toward the issue and the specific area(s) where it should focus.
- Developing a plan for mitigating quantum computing risks. Financial entities should consider establishing governance processes, identifying key stakeholders and their roles and responsibilities, and establishing milestones for key actions based on the anticipated deployment of a cryptographically relevant quantum computer.
