Europol has warned that the transition of European financial services to quantum-safe cryptography must be prioritised, as the risks posed by ‘store now, decrypt later’ (SNDL) attacks continue to grow.
The EU’s international law enforcement agency has issued an urgent call to action, with its Quantum Safe Financial Forum (QSFF) imploring firms in the financial sector to act now in order to combat future quantum-related threats.
According to Europol, despite estimates suggesting that quantum computers capable of such threats will emerge within the next ten to fifteen years, the time required to transition to more secure cryptographic methods could put financial firms at significant risk of quantum attack methods.
The agency warned that in order to successfully transition to post-quantum cryptography financial institutions, technology providers, policymakers, and regulators must collaborate quickly, a formidable challenge in the face of a fractured technology ecosystem where the goals of these groups are often misaligned.
Pointing to a 2023 survey of 200 financial sector leaders found that 86% of organisations feel unprepared for post-quantum cybersecurity, Europol urged governments and regulatory bodies worldwide to take the lead to ensure the financial sector does not fall behind in the quantum arms race.
Without swift action, Europol said that sensitive financial information, including long-term investment strategies and confidential agreements, could be compromised by malicious actors that are collecting encrypted data today with the intention of decrypting it in the future using quantum techniques.
Among the QSFF’s recommendations is that financial institutions and policymakers should actively support the implementation of quantum-safe cryptography; that there should be more coordination among different stakeholders to align planning, roadmaps and common goals; and that a framework around cryptography management should be established.
However, the agency also argued that there’s no need for additional legislation, as a voluntary framework between regulators and the private sector could be sufficient in setting guidelines for quantum-safe cryptography and promoting standardisation.
The fresh warning builds on work the agency has already undertaken to anticipate the threat quantum tech might pose. In 2023, Europol published what it called a ‘first of its kind’ report, outlining the potential applications of quantum computing, as well as its impact on law enforcement practices.
Recommended reading
- UK Government Steps Up Interest in Quantum Technologies
- Heriot-Watt’s DeepTech LaunchPad Drives Prosthetic Innovation
- Are Satellites the Solution to Quantum-powered Threats?
That study, The Second Quantum Revolution, also highlights the danger that quantum computing could have on stolen databases, protected files, or communications data, with Europol’s executive director, Catherine De Bolle, saying at the time: “Quantum computing and quantum technologies hold significant potential to strongly impact law enforcement.
“From the analysis of large and complex data sets, to improved forensics capabilities and new ways of secure communication, the future promises significant opportunities to strengthen the fight against crime.
“Nevertheless, malicious actors could equally try to profit from such advancements and we have to prepare accordingly.”
The financial sector has also been growing acutely aware of the threat posed by quantum technology, with UK Finance publishing its own report in 2023 that noted the sector’s vulnerability to quantum-enabled attacks, and provided a roadmap for financial firms to transition to ‘quantum safe’ environments.





