Start now: HSBC’s roadmap to quantum-safe cryptography

 

Key Takeaways

  • Quantum-safecryptographyis becoming a business priority, not a future consideration.
  • Regulators are already setting expectations for post-quantum readiness.
  • Crypto-agilityis essential for long-term resilience.
  • Early planning reduces costs, operational disruption and skills shortages.
  • HSBC’s approach highlights whyorganizations should start now and measure progress over time.

Start now: HSBC’s roadmap to quantum-safe cryptography

Post-quantum cryptography(PQC) isn’t a distant horizon, it’s now a present-day priority nobodyshould ignore.Whileorganizations prepare forquantum-safecryptography,enterprises may still debate timelines for quantum breakthroughs, regulators are already publishing guidance, standards bodies are finalizing algorithms, and forward-looking organizations are moving into execution.

For Will Collison, Interim Global Head of Cryptography at HSBC, the lesson is simple: start now, measure as you go. Waiting for certainty only increases cost, risk, and reputational exposure.

Why quantum-safe cryptography can’t wait

In a recent episode ofShielded: The Last Line of Cyber Defense, Collison joined host Jo Lintzen to share how HSBC, one of the world’s largest banks, is preparing for the quantum era.

With two decades in information security and cryptography, he’s witnessed migrations before, from 1024-bit SSL certificates to stronger PKI, and knows how disruptive they can be when left too late.

His message to peers is clear: treat PQC not as a theoretical concern, but as the next inevitable cryptographic shift.

Q-Day vs. R-Day: why waiting isn’t an option

The industry often frames the threat as Q-Day, the moment a cryptographically relevant quantum computer breaks RSA or ECC. But Collison argues there’s an earlier and more pressing milestone: R-Day, when regulators mandate readiness.

Both are inevitable. Regulators in the UK, EU, Canada, and the U.S. are already signaling timelines, with 2030–2035 as the outer horizon for critical assets.

For financial institutions, waiting for official deadlines is a losing strategy:

“We can’t wait for Q-Day, and we can’t really wait for regulator day,” he cautions. “We should already be on the journey before regulators start to ask what’s going on.”

PQC, QKD, and quantum computing: clearing the confusion

One barrier to action is conceptual. Quantum technologies are often conflated; post-quantum cryptography (PQC), quantum key distribution (QKD), and quantum computing get lumped together.

Collison separates them cleanly: PQC is the universal requirement, QKD addresses niche high-assurance use cases like backbone connections, and quantum computing is the attacker capability looming on the horizon.

“Everybody needs to do PQC,” he stresses, “and there is nothing to stop you from using PQC over a QKD link.”

The key is clarity: invest where the impact is broadest, and don’t let conceptual fog slow down preparation.

Identity at risk: where quantum hits hardest

Quantum computers don’t endanger all cryptography equally. Symmetric algorithms like AES remain resilient, but public-key identity mechanisms, RSA, ECC, and the digital signatures that underpin authentication, are directly vulnerable.

Collison draws the line clearly: the threat is to identity, not bulk data encryption. Once identity is compromised, trust in digital systems collapses.

For organizations, that means prioritizing upgrades in PKI, certificates, and authentication frameworks. The technical roadmap must be designed with this distinction in mind, ensuring resources are directed to where quantum creates the greatest risk.

Crypto-agility: designing for what comes next

Collison is pragmatic about the uncertainty of cryptographic standards. Even post-quantum algorithms, now being standardized, are subject to scrutiny and potential breakage.

That makes cryptographic agility the real long-term goal.

“Assume algorithms can fail,” he explains. “The win is cryptographic agility, being able to change without a rewrite.”

For enterprises, that means engineering modular, pluggable cryptographic architectures that allow algorithms to be swapped quickly. Treating PQC as a one-off migration is shortsighted.Building agility ensures resilience across multiple future transitionsand supports a long-termquantum-safecryptography strategy.

Cost, talent, and regulation: the practical pressures

For Collison, the cost logic is straightforward: if you start now, you can go slowly, achieve quality, and minimize expenses. If you wait, you’ll be forced to move fast, and fast rarely comes cheap.

The same applies to talent. By investing early in graduates and training programs, HSBC is building a workforce fluent in quantum readiness rather than competing for scarce expertise later.

Regulation adds another layer: falling behind peers risks not just technical debt but also public censure.

“Looking at whata regulator might ask and you being shy of that or adrift from that is going to put more pressure on your organization,” he warns.

The takeaway: start now, measure as you go

The message from HSBC’s cryptography leader is blunt: the longer you wait, the harder and more expensive the migration becomes. Organizations need to act before regulators demand it, before attackers exploit it, and before talent and vendor bottlenecks make progress impossible.

Start with awareness and leadership buy-in. Prioritize revenue-critical and internet-facing systems. Build agility into your cryptographic architecture. And measure progress continually, so you can demonstrate posture to regulators, customers, and partners.

Quantum readiness isn’t a theoretical debate. It’s a strategic imperative. As Collison puts it: “Start now. It’s going to look a lot more expensive and a lot more painful in five years.”

Want to learn more about quantum-safe cryptography?

You can hear the full conversation onShielded: The Last Line of Cyber Defense,available now on Apple Podcasts, Spotify,and YouTube Podcasts, or contact PQShield to discover how yourorganization can prepare for the post-quantum transition.

About Will Collison

Will Collison is the Interim Global Head of Cryptography at HSBC, where he leads the bank’s global cryptography strategy across 60 markets.

A CISSP-qualified consultant with two decades of experience, he specializes in public key infrastructure (PKI), cryptography standards, and the automation of trust. Over his seven-plus years at HSBC, Will has served as Technical Director of Cryptography, Global Head ofCryptography Standards and Enforcement, and PKI Specialist, building frameworks for machine and digital identity and driving large-scale remediation programs.

Prior to HSBC, he founded Secmundi Limited, advising international banks on cryptography strategy and operating models, and worked as a Trust Consultant at Barclays, guiding PKI implementations and automation of certificate issuance.

Known for combining deep technical expertise with pragmatic execution, Will has long been a voice forcrypto-agility, helping organizations modernize securely while preparing for future shifts. Today, his focus is clear: ensuring enterprises can meet the challenges of post-quantum cryptography (PQC) and build a quantum-safe future.

Frequently Asked Questions

What is quantum-safe cryptography?

Quantum-safecryptography refers to cryptographic algorithms designed to resist attacks from both classical and quantum computers. Also known as post-quantum cryptography (PQC), these algorithms are beingstandardized to helporganizations prepare for future quantum threats.

Why should organizations start preparing for quantum-safe cryptography now?

Preparing early allowsorganizations to assess their cryptographic assets, prioritise critical systems and migrate at a manageable pace. Waiting until regulatory deadlines or quantum threats become imminent can significantly increase costs and operational risk.

What is crypto-agility and why is it important?

Crypto-agilityis the ability to replace or update cryptographic algorithms without redesigning entire systems. It enablesorganizations to respond quickly to new standards, vulnerabilities and future advances in cryptography.

How is HSBC approaching the transition to post-quantum cryptography?

As discussed by Will Collison, HSBC is focusing on early planning, measuring progress over time, investing in skills and building cryptographic agility to support a smooth transition towardsquantum-safecryptography.

How can PQShield helporganizations prepare forquantum-safecryptography?

PQShield provides quantum-safe cryptographic software, hardware and expert consultancy to helporganizations assess their current cryptographic estate, develop migration strategies and implement standards-based post-quantum security solutions.