Hong Kong banks scored just 2.3 out of 10 on the Hong Kong Monetary Authority’s first Quantum Preparedness Index released on July 27. This low rating reveals that most lenders are still in the early stages of defending against quantum computing risks in cybersecurity.

The survey found that 32% of banks haven’t begun addressing post-quantum cryptography challenges or planning migration efforts. While 68% have at least started raising awareness or running pilot programs, only about half have formal strategies in place to adopt quantum-resistant encryption. Governance discussions at the board level outpace actual technical implementation, with roughly half of banks talking about quantum risks but only a third actively exploring solutions.

Why Quantum Security Matters for Banks

Quantum computers have the potential to break the cryptographic systems that currently protect financial data and transactions. Though the timeline remains uncertain, financial institutions need years to identify vulnerable systems and roll out replacements across their networks. The HKMA’s index measures how prepared banks are to spot at-risk systems, develop plans, test new cryptography, and implement it in practice.

A significant worry is the “harvest now, decrypt later” tactic, where attackers collect encrypted data now and wait until quantum hardware can decrypt it in the future. This makes early preparedness vital to safeguard long-term data security.

The HKMA aims for full sector readiness by 2030, supporting banks with toolkits, workshops, and coordinated guidance. The warning comes amid growing concern about quantum threats globally, highlighting the race banks face to stay ahead.

This material is for informational purposes and does not constitute financial advice.