ComputerWeekly

US Treasury sets up quantum readiness unit


The United States Department of the Treasury has officially launched a Quantum Readiness Task Force, supporting wider efforts to secure innovation, strengthen supply chains, and ensure the US remains a leading voice at the post-quantum table.

The new unit fulfils a key obligation imposed by president Trump in an Executive Order (EO), Securing The Nation Against Advanced Cryptographic Attacks, which was signed in June. The EO set out a series of guidelines to strengthen cryptographic protections for sensitive data, critical infrastructure, and America’s wider digital economy in the face of the much-discussed advent of workable quantum computers, and their likely impact on current cyber standards, particularly cryptographic tools.

“America must lead in securing the technologies that power our economy,” said treasury secretary Scott Bessent. “This Task Force will help ensure our financial system remains strong, secure, and competitive as new technologies reshape the global landscape.”

The Task Force takes the form of a public-private initiative, and will focus on helping the financial services sector through the transition to quantum-safe technology in an “orderly and operationally resilient manner”. Its work will build on a roadmap drawn up at the start of the year by the G7 Cyber Expert Group. According to the US government, it also advances Trump’s cyber agenda by “supporting the adoption of post-quantum cryptography and strengthening protections for critical financial infrastructure.”

Working through three workstreams – Sector Alignment and PQC Transition, Third-Party and Vendor Readiness, and Digital Assets and Emergency Technology Risk – the Task Force will align government officials, financial institutions and market infrastructures, technology suppliers, and other private sector stakeholders to coordinate preparation for quantum-related cyber risk.

Some early areas of focus are likely to include identifying critical dependencies, improving cryptographic agility, promoting interoperability, strengthening operational resilience, and addressing implementation challenges related to third-party dependencies and digital assets.

“The creation of the Quantum-Readiness Task Force highlights the growing importance of post-quantum cryptography as a financial-sector resilience issue,” said David Tao, vice president of the Financial Institutions Group at Moody’s Ratings.

“While cryptographically relevant quantum computers are not yet available, organisations may need to act well before they arrive because the transition to post-quantum cryptography is likely to be lengthy, costly and operationally complex. Delaying preparation also increases exposure to ‘harvest now, decrypt later’ risks, where attackers collect encrypted data today with the intention of decrypting it once sufficiently powerful quantum capabilities become available.

“We view large banks, payment processors and critical infrastructure operators as among the issuers facing the steepest transition burden,” Tao told Computer Weekly via email.

“These organisations often operate complex, legacy-dependent technology environments with extensive third-party dependencies and long technology refresh cycles. In many cases, vulnerable systems cannot simply be updated and may require physical replacement, creating significant planning, procurement and execution challenges. That makes early planning, cryptographic inventories and vendor coordination particularly important.”

Quantum guard

Meanwhile, earlier in August two US senators introduced legislation, the Quantum Grid Utility Assurance and Resilient Defence (Quantum-GUARD) Act designed to strengthen the resilience of America’s electrical grid.

Should it become law, the Act will direct federal agencies, such as the Federal Energy Regulatory Commission (Ferc) to evaluate quantum vulnerabilities, assist utility operators in the transition to post-quantum cryptogaphy, and mandate collaboration between grid operators, the government, and the cyber security community.

“Quantum computing may seem like science fiction, but it’s only a matter of time before an operationally relevant quantum computer arrives,” said Cyber Threat Alliance president and CEO Michael Daniel.

“The cyber security impacts of quantum computing will be immense, and the Quantum-GUARD Act would help both government and industry tackle this problem. Prompting Ferc to consider the reliability risks associated with quantum computing and directing the Department of Energy to create a sandbox to test technology and implementation strategies against quantum capabilities are good steps to take,” he said.



Source link