Connect with us

Cybersecurity

AI and Cyber Liability Insurance: Protecting Businesses from 22-Second Ransomware

Published

on

a paper beside a person typing on a laptop

Cyber insurance underwriting was built for a threat model measured in hours: an attacker gains access, explores manually, identifies a target, and hands off to a ransomware operator over a window that averaged more than 8 hours as recently as 2022. That model is now obsolete. Mandiant’s M-Trends 2026 report confirms that the median handoff time between initial access brokers and ransomware operators collapsed to 22 seconds in 2025 — a compression that has forced the cyber insurance industry into one of the fastest coverage redesigns in its history.

Key Takeaways

  • Median attacker handoff time collapsed from more than 8 hours in 2022 to 22 seconds in 2025, per Mandiant’s M-Trends 2026 report — faster than any human-staffed security operations center can realistically detect and respond.
  • The first confirmed agentic ransomware operation (“JadePuffer”) was disclosed in July 2026, involving an LLM-orchestrated attack that exploited a critical Langflow vulnerability (CVE-2025-3248, CVSS 9.8) to autonomously conduct reconnaissance, credential theft, lateral movement, and encryption of AI artifacts and databases.
  • “AI & Emerging Technology Liability” is the fastest-growing new cyber insurance coverage category in 2026, with insurers increasingly asking about AI governance and unbundling AI-specific risk from standard policies at renewal.
  • Global cyber insurance premiums are forecast to rise 15–20% in 2026, reversing a recent decline, driven by a 47% surge in initial ransomware demands in 2025 and an 800% increase in infostealer-driven credential theft over a similar period.
  • Average ransomware payments now exceed $400,000 in 2026, with total event cost (ransom, recovery, business interruption, and legal) reaching $1M–$5M for mid-size businesses — and 27% of data breach claims face exclusions leading to partial or zero payouts.

The 22-Second Benchmark: Why It Changes Everything

The scale of the shift documented in M-Trends 2026 is difficult to overstate. In 2022, the gap between an initial access broker establishing a foothold and handing that access off to a ransomware operator averaged more than 8 hours — a window that, while tight, at least theoretically allowed a well-staffed security operations center to detect anomalous activity, investigate, and respond before catastrophic damage occurred. By 2025, that median window had collapsed to 22 seconds.

The operational sequence behind this compression, as documented by threat researchers tracking agentic AI attacks, looks roughly like this:

  • Second 0: Agentic AI agent gains initial access (credential theft, phishing)
  • Second 4: Agent autonomously maps the network environment
  • Second 11: Agent identifies the highest-value lateral movement target
  • Second 22: Access is handed off; secondary payload is deployed

No human-staffed security operations center can meaningfully respond to an attack that completes within that window. This single fact is reshaping both cybersecurity defense architecture and cyber insurance underwriting simultaneously.

JadePuffer: The First Confirmed Agentic Ransomware Case

In early July 2026, cloud security firm Sysdig disclosed what researchers describe as the first documented, fully agentic ransomware operation, tracked as JadePuffer. The threat actor exploited CVE-2025-3248 — a critical missing-authentication vulnerability (CVSS score 9.8) in Langflow, a Python-based, LLM-agnostic open-source framework used for building AI agent workflows — to gain access to an internet-exposed instance. From that foothold, an LLM-driven, largely autonomous process conducted reconnaissance, discovered credentials, moved laterally, and proceeded to encrypt AI model artifacts, training data, and production databases, deleting tables as part of the extortion mechanism.

This case matters specifically for AI cyber liability underwriting because it demonstrates a new category of exposure: AI infrastructure itself — model artifacts, training data, and agent orchestration frameworks — is now a high-value, directly targetable asset class, distinct from traditional file servers and databases that legacy cyber policies were designed around.

Why Standard Cyber Policies Are Being Unbundled

Insurance industry analysis in 2026 has identified “AI & Emerging Technology Liability” as the fastest-growing new coverage category, driven by carriers recognizing that standard cyber policies were not actuarially designed for AI-specific loss scenarios. A notable trend documented by insurance agents in 2026: AI coverage is being quietly carved out of standard commercial general liability and cyber bundles at renewal, with new ISO forms treating AI-related exposure as a distinct risk category requiring separate underwriting, separate sublimits, and often separate premium calculation.

Carriers in 2026 increasingly require, as baseline conditions for any cyber policy:

  • Multi-factor authentication (MFA) across all privileged access points
  • Endpoint detection and response (EDR) or extended detection and response (XDR)
  • Offline, immutable backups
  • Documented AI governance frameworks covering model access, agent permissions, and audit logging

Organizations with weak controls in these areas face either coverage denial or premiums 3–5 times higher than well-controlled peers.

The Pricing Picture: What 2026 Premiums Actually Look Like

Business Size2026 Typical Annual PremiumCoverage Limit
Small business$750–$5,000Often $1M aggregate
Mid-size company ($5M–$10M revenue)$3,500–$15,000+ (varies by industry)$1M–$5M aggregate
Large enterprise$75,000–$350,000+Varies significantly

S&P Global Ratings has forecast a 15–20% premium increase across 2026, reversing a brief recent decline, citing three converging pressures: successful attacks now cost roughly 17% more per incident than in 2024, ransomware incidents rose 126% in Q1 2025 alone, and infostealer-driven credential theft surged 800% over a comparable period. Global cyber insurance premiums, which rose roughly 7% in 2025 to approximately $15.3 billion, are forecast by some analysts to double by 2030, with other projections putting the market at roughly $29 billion by 2027.

Coverage Gaps Businesses Should Scrutinize

Several structural coverage gaps recur across 2026 cyber policies and warrant specific attention during renewal negotiations:

  • Social engineering / funds transfer fraud sublimits. Most policies include only a modest sublimit — commonly $100,000 — for this category by default, even though real-world losses from business email compromise and voice-based fraud regularly exceed $50,000–$300,000 per event and can run far higher.
  • AI-related exclusions. As AI liability is unbundled into its own coverage category, businesses relying on legacy cyber policies purchased before this shift may find AI-related incidents — including agentic ransomware events like JadePuffer — explicitly excluded from coverage.
  • Ransom payment exclusions tied to sanctioned entities. With 86% of businesses refusing to pay ransom in 2025 (a record high, per Coalition’s 2026 Cyber Claims Report), sanctions-related payment restrictions are increasingly relevant to claims outcomes even for businesses willing to pay.
  • 27% of data breach claims face exclusions leading to partial or zero payouts, according to NAIC-referenced data — underscoring that policy language review, not just premium comparison, should drive purchasing decisions.

A Practical Underwriting Checklist for 2026

  • Confirm whether AI/agentic-AI incidents are explicitly included or excluded under the current policy language, not assumed to be covered under general “cyber incident” definitions
  • Verify MFA, EDR/XDR, and offline backup requirements are met and documented, since these increasingly function as coverage preconditions rather than discount qualifiers
  • Increase social engineering and funds transfer fraud sublimits beyond default levels given real-world loss data
  • Request telemetry-based or on-site underwriting assessment rather than relying solely on self-reported security questionnaires, which security researchers note frequently produce unreliable risk pricing

Frequently Asked Questions

What is the “22-second ransomware” threat?

It refers to Mandiant’s M-Trends 2026 finding that the median handoff time between initial access brokers and ransomware operators has collapsed to 22 seconds, down from more than 8 hours in 2022, driven by agentic AI tools that autonomously conduct reconnaissance and lateral movement.

Does standard cyber insurance cover AI-related ransomware attacks?

Increasingly, no — by default. “AI & Emerging Technology Liability” is being unbundled into its own coverage category in 2026, meaning businesses should explicitly verify whether agentic AI incidents are covered rather than assuming standard cyber policies apply.

How much does cyber liability insurance cost in 2026?

Small businesses typically pay $750–$5,000 annually, mid-size companies $3,500–$15,000+, and large enterprises $75,000–$350,000+, with premiums broadly forecast to rise 15–20% in 2026.

Conclusion

The compression of ransomware attack timelines from hours to 22 seconds represents a genuine inflection point, not incremental threat evolution — and the insurance industry’s rapid unbundling of AI liability coverage in 2026 is a direct, rational response to that shift. Businesses that treat cyber insurance renewal as a routine annual exercise, without specifically confirming AI-related coverage and reviewing sublimits against current loss data, are carrying risk exposure that their policies were never actuarially designed to cover.


Discover more from The Economy

Subscribe to get the latest posts sent to your email.

AI

Voice Phishing (Vishing) on the Rise: How AI is Forcing Banks to Rewrite Security Protocols

Published

on

close up photo of toy robot

The reliable “tells” that once let a wary consumer spot a scam call — bad grammar, robotic cadence, obvious accent mismatches — have largely disappeared. In 2026, an AI-generated voice can convincingly clone a real person from as little as three to ten seconds of audio, adapt its script in real time under questioning, and pass through a spoofed number that appears to originate from a legitimate bank fraud line. The result is a category of fraud that has moved from a nuisance to a board-level risk, forcing financial institutions to rewrite verification protocols that have gone essentially unchanged for a decade.

Key Takeaways

  • Financial institutions reported a 32% rise in deepfake-related fraud attempts in 2025, with over 10% of banks reporting individual deepfake vishing losses exceeding $1 million per case.
  • Fraudsters need as little as 3–10 seconds of audio to clone a voice convincingly, with deepfake audio now achieving over 90% accuracy in mimicking real voices, according to multiple 2026 fraud research compilations.
  • Vishing now accounts for over 60% of phishing-related incident response engagements, and in more than 80% of voice phishing attacks, attackers use spoofed caller IDs to make calls appear to originate from legitimate numbers.
  • The 2024 Arup case remains the reference incident for enterprise risk: an employee at the UK engineering firm authorized 15 wire transactions totaling $25.6 million after joining a video call featuring convincing real-time deepfakes of the company’s CFO and several executives.
  • Verizon’s 2026 Data Breach Investigations Report tracks pretexting (synchronous voice or chat manipulation) at 6% of initial access vectors, with phone-based phishing simulations showing a median click rate roughly 40% higher than email-based simulations.

Why Deepfake Vishing Broke the Old Verification Model

Voice-based identity verification has historically relied on a simple, largely unstated assumption: that a familiar voice, speaking in a familiar and contextually appropriate way, is a reasonably reliable signal of identity. That assumption depended on voice cloning being expensive, technically demanding, and largely confined to research labs and high-budget production environments. That constraint dissolved in 2024 and 2025, as open-source models, real-time inference, and cheap, abundant compute closed the technical gap — reducing the cost of a convincing voice-cloning attack from what industry practitioners describe as a “research lab” undertaking to a “weekend project.”

The critical architectural failure this exposes: any verification process that depends on a human listening to a voice and confirming it “sounds right” can now be defeated by AI, because the voice only needs to be convincing under pressure — not indefinitely, and not against forensic scrutiny, just long enough to complete a transaction.

First-Generation vs. Second-Generation AI Vishing

The evolution of AI voice phishing across 2025 and 2026 illustrates why static defenses have consistently fallen behind:

  • First-generation (pre-rendered audio): Attackers scripted a short call, generated the audio in advance, and played it through a SIP gateway. Defenders could reliably defeat this by throwing the call off-script — asking an unexpected question, requesting a callback, or changing the topic — because pre-rendered audio could not adapt.
  • Second-generation (real-time inference, 2025–2026): Real-time inference services now synthesize responses inside the call itself, with end-to-end latency low enough to feel like a normal conversation. The off-script defense that worked reliably against first-generation attacks is substantially weaker against a system that can adapt its responses live.

This progression matters directly for bank security protocol design: verification procedures built around the assumption that unpredictable questioning defeats vishing are now defending against a threat model that no longer exists in its original form.

The Arup Case: What $25.6 Million Bought as a Lesson

The 2024 Arup incident remains the most frequently cited case study in 2026 vishing analysis, and for good reason: it demonstrates the failure mode at enterprise scale. An employee at the UK engineering firm joined what appeared to be a routine video conference featuring the company’s CFO and several senior executives — everyone looked right, and everyone sounded right. The employee authorized 15 separate transactions totaling $25.6 million to Hong Kong bank accounts before the fraud was identified. The case has become the reference point specifically because it defeated not just voice verification but visual verification simultaneously, illustrating that multi-channel deepfake attacks — voice plus video plus contextually accurate scripting — represent the frontier threat model banks and enterprises must now defend against, not single-channel voice calls in isolation.

How Banks Are Rewriting Security Protocols in 2026

Several concrete protocol shifts are emerging across financial institutions in response to this threat environment:

  • Out-of-band verification as a hard requirement. The consistent recommendation across 2026 fraud research is to verify any high-risk request on a channel the caller does not control — for example, calling back through an independently sourced phone number rather than a number provided during the suspicious call itself, or confirming through a separate app-based channel.
  • Behavioral and telephony metadata analysis over voice recognition alone. Since caller identity and voice familiarity are no longer sufficient trust signals in high-risk workflows, leading practitioners now emphasize behavioral detection and telephony metadata analysis — call origination patterns, timing anomalies, SIP routing irregularities — as stronger risk signals than voice identity checks.
  • Mandatory delay windows for high-value transfers. Given that wire recall success rates drop sharply after the first six hours following a fraudulent transfer, banks are increasingly building mandatory cooling-off periods for large or unusual transfers specifically to create a window for after-the-fact verification.
  • Pre-established fraud team relationships. Practitioner guidance increasingly recommends that businesses establish a relationship with their bank’s fraud team before an incident occurs, since wire recall procedures, session revocation, and credential rotation all move faster when a pre-existing escalation path exists.
  • No-blame reporting culture. Because deepfake vishing has higher success rates than traditional email phishing due to its emotional-manipulation component, organizations that punish employees for falling victim risk delayed incident discovery; a no-blame reporting culture surfaces incidents in real time rather than days later.

The Data Gap: Where Awareness Training Is Misallocated

A notable finding from 2026 security awareness research is a significant mismatch between actual risk and training prioritization: while 73% of security leaders prioritize phishing reporting training, only 10% prioritize deepfake recognition training specifically — despite 35% of organizations having already experienced a deepfake incident, according to Gartner’s 2025 AI Risk Management Survey. Phone-based phishing simulations show a median click rate roughly 40% higher than email-based simulations, according to Verizon’s 2026 Data Breach Investigations Report, suggesting that voice-channel vulnerability is measurably higher than email-channel vulnerability even as training investment remains skewed toward the latter.

A Practical Vishing Incident Response Framework

  • Pre-written wire recall playbook, covering bank fraud-team contact procedures, session revocation, credential rotation, and forensic capture of call metadata
  • Mandatory callback verification through independently sourced contact information for any request involving funds transfer, credential reset, or access changes
  • Layered channel verification for high-risk requests — requiring confirmation through at least two independent channels (e.g., a callback plus an internal messaging system confirmation) rather than relying on any single channel, however convincing
  • Regular, realistic vishing simulation exercises modeled on actual scenarios (bank fraud alerts, executive impersonation, SaaS support calls) rather than generic phishing awareness content alone, given the roughly 40% higher click-through vulnerability documented on phone-based channels

Frequently Asked Questions

How much audio does it take to clone someone’s voice in 2026?

As little as 3 to 10 seconds of audio is sufficient to produce a convincing voice clone using current AI tools, with resulting deepfake audio achieving over 90% accuracy in mimicking the real voice.

What was the Arup deepfake case?

In 2024, an employee at UK engineering firm Arup authorized 15 wire transactions totaling $25.6 million after joining a video call featuring real-time deepfakes of the company’s CFO and several executives — a case widely cited as the reference incident for enterprise multi-channel deepfake fraud risk.

How are banks defending against AI voice phishing in 2026?

Banks are shifting toward out-of-band verification on channels the caller cannot control, behavioral and telephony metadata analysis instead of voice-identity checks alone, mandatory delay windows for high-value transfers, and pre-established fraud-team relationships to speed wire recalls.

Conclusion

The 2026 vishing threat landscape reflects a broader pattern seen across AI-enabled fraud: the technology did not create a new category of crime so much as it removed the practical constraints — cost, technical skill, adaptability — that previously kept an old category of crime in check. Financial institutions rewriting security protocols around out-of-band verification, behavioral metadata, and multi-channel confirmation are responding to a threat model where “it sounded right” and “it looked right” have both stopped being reliable signals of anything at all.


Discover more from The Economy

Subscribe to get the latest posts sent to your email.

Continue Reading

Analysis

ICE Airport Detentions 2026: Know Your Rights as an Asylum Seeker

Published

on

The Indi Veitia case shows ICE is detaining asylum seekers with pending applications and work permits at airports. Learn your legal rights, documentation requirements, and when to call an immigration attorney.

Key Takeaways

  • Indi Veitia, a 47-year-old Venezuelan asylum seeker with a pending application and valid work permit, was detained for 21 days after ICE officers stopped her while boarding a flight home from Atlanta.
  • Having a pending asylum application, work authorization, or a valid-looking receipt does not guarantee protection from detention — DHS has stated that a pending application “does not confer legal status” in the United States.
  • ICE has jurisdiction to interview passengers at airports and has expanded enforcement activity at points of domestic and international travel throughout 2026.
  • Legal representation matters immediately — an immigration attorney can help distinguish between lawful presence, pending status, and expired documentation before a detention becomes a deportation risk.
  • Immigration attorneys are now advising some clients not to fly domestically given the pattern of airport-based enforcement actions.

What Happened to Indi Veitia?

Indi Veitia, a Venezuelan national who arrived in the United States in 2019 on a work visa and later filed for asylum, was detained by Immigration and Customs Enforcement (ICE) officers as she attempted to board a flight home to Indiana from Hartsfield-Jackson Atlanta International Airport. Despite holding a valid work permit and a receipt for her pending asylum application — documentation that stated she was permitted to remain in the country until a final decision was reached — Veitia was detained for 21 days at a facility in Lumpkin, Georgia, over allegations that she had overstayed her visa.

Her attorney, a partner at the Kuck and Baxter law firm in Atlanta specializing in immigration law, has since said he now advises clients not to fly domestically and urges asylum seekers to “take extra care everywhere.” A Department of Homeland Security spokesperson clarified the government’s position in response to inquiries: a pending application does not confer legal status within the United States, even for individuals who have complied with every requirement asked of them, including obtaining work authorization and a driver’s license.

The Core Legal Contradiction

Veitia’s case highlights what immigration attorneys describe as a “legal no-man’s land.” As her attorney put it: the government provides individuals with the means to work and integrate into society while their case is pending, “only to later target them for detention.” Someone can simultaneously:

  • Hold a valid Employment Authorization Document (EAD) allowing them to legally work
  • Have a driver’s license issued based on that same status
  • Be not unlawfully present in a technical sense
  • Still be detained and placed into deportation proceedings at any point, including at an airport

This Is Not an Isolated Incident

Immigration advocacy organizations have documented a broader pattern of ICE arrests at airports throughout 2026, targeting a range of individuals with less secure or unresolved immigration status, including:

  • People who entered through humanitarian parole programs such as CHNV (Cuban, Haitian, Nicaraguan, and Venezuelan parole)
  • Participants in the Uniting for Ukraine (U4U) program
  • Individuals who used the CBP One app for entry
  • People with expired visas, even if they have since applied for a change or extension of status
  • Individuals with pending immigration applications of any kind

According to community alerts from immigration legal organizations, reporting has confirmed that federal transportation security screening data has been shared with ICE, enabling agents to identify and intercept individuals at security checkpoints and gates — not just at the immigration court or ICE office level.

Legal Rights for Asylum Seekers and Immigrants at Airports

What ICE Can Do

  • ICE agents have jurisdiction in airports and the legal right to interview passengers, including U.S. citizens, though citizens are not obligated to answer questions beyond confirming identity in most circumstances.
  • Officers can detain individuals based on visa status, expired documentation, or even a pending application if the agency determines removal proceedings are warranted.

What You Are Entitled To — Regardless of Citizenship Status

  • The right to remain silent beyond providing basic identification, in most circumstances.
  • The right to decline a warrantless search — a search without a judicial warrant is not mandatory, and you do not have to consent to one.
  • The right to contact an attorney before signing any documents. Immigration attorneys strongly advise never signing anything without legal review, as some documents can waive rights to a hearing or expedite removal.
  • The right to have your immigration attorney’s contact information available immediately — carrying a physical card or document with your lawyer’s name and number is considered a best practice by immigration law practitioners.

Documentation Immigration Attorneys Recommend Carrying at All Times

  • Any receipt notice or documentation related to a pending asylum case (Form I-589 receipt, if applicable)
  • Valid Employment Authorization Document (EAD), if issued
  • Contact information for your immigration attorney
  • Any court dates, notices to appear, or prior case documentation

Actionable Guidance for Asylum Seekers and Work-Visa Holders

  • Consult an immigration attorney before any domestic or international travel, even for short trips, if your status involves a pending application, expired visa, or any parole-based entry category.
  • Understand the specific limits of your documentation. An EAD or asylum-application receipt is not the same as a grant of legal permanent status — know precisely what protections your paperwork does and does not provide.
  • Consider the risk calculus of air travel specifically. Given documented information-sharing between transportation security screening and ICE, air travel — even domestic — currently carries elevated enforcement risk for individuals with unresolved status.
  • If detained, exercise your right to counsel immediately and avoid signing any document, including what may be presented as a routine form, without attorney review.
  • Monitor Board of Immigration Appeals (BIA) rulings and advance parole guidance closely — recent BIA changes have altered the consequences of traveling on advance parole, including new 3- and 10-year reentry bar risks for some travelers.

Why Legal Representation Is Critical in This Environment

Immigration law in 2026 has become significantly more complex and enforcement-focused, with agencies exercising broad interpretive authority over what constitutes lawful presence versus mere procedural compliance. An experienced immigration attorney can:

  • Assess whether your specific documentation creates any detention risk before you travel
  • Represent you immediately if detained, potentially shortening custody duration
  • File emergency motions or habeas petitions in cases of prolonged or unlawful detention
  • Advise on the evolving landscape of parole program terminations and advance parole reentry bars

Frequently Asked Questions

Can ICE detain someone with a pending asylum application at an airport? Yes — current enforcement practice, as illustrated by the Indi Veitia case, shows that ICE can and does detain individuals with pending asylum applications, valid work permits, or other pending immigration paperwork, since the Department of Homeland Security maintains that a pending application does not by itself confer legal status.

What should I do if ICE tries to detain me while traveling? Immigration attorneys generally advise remaining calm, exercising your right to remain silent beyond identifying yourself, declining any warrantless search, and requesting to contact your attorney immediately before signing any documents presented to you.

Is it safe for asylum seekers to fly domestically in the United States right now? Some immigration attorneys are currently advising clients with pending or uncertain immigration status to avoid domestic air travel where possible, given documented patterns of airport-based ICE enforcement; anyone with concerns about their specific status should consult a licensed immigration attorney before booking travel.


Discover more from The Economy

Subscribe to get the latest posts sent to your email.

Continue Reading

Cybersecurity

Post-Quantum Encryption in Banking: The Next Frontier in Cybersecurity Investments

Published

on

Key Takeaways

  • NIST finalised its first three post-quantum cryptography standards in August 2024, ending an eight-year global evaluation process; a fifth backup algorithm, HQC, was selected in March 2025.
  • The post-quantum cryptography market is projected to exceed $15 billion by 2030, and industry voices including the Boston Consulting Group warn that “starting in 2030 will already be too late.”
  • The “harvest now, decrypt later” threat is active today: adversaries are already capturing encrypted financial data at scale, banking on future quantum decryption capability — meaning banks’ current encryption choices carry decades-long risk exposure.
  • Three regulatory deadlines converge in late 2026/early 2027: NIST’s FIPS 140-2 to Historical transition (September 21, 2026), the EU’s national PQC strategy milestone (December 31, 2026), and NSA CNSA 2.0 acquisition requirements.
  • JPMorgan Chase is directly engaged in NIST’s Migration to Post-Quantum Cryptography project, signalling that large financial institutions are treating this as a present-tense operational priority, not a future contingency.

Why Banking Is Ground Zero for the Quantum Transition

Every major cybersecurity upgrade cycle has a sector that moves first because it has the most to lose. For post-quantum cryptography, that sector is banking. Every RSA key, every ECC certificate, every TLS handshake, every VPN tunnel, every digitally signed document, every encrypted database was built on mathematics that quantum computers will break — not might break, will break.

Industry analysts project the post-quantum cryptography market will exceed $15 billion by 2030 as governments and enterprises execute mandated migration timelines, with the “harvest now, decrypt later” threat already active: adversaries are capturing encrypted data at scale today, banking on future quantum decryption capability. For a bank, that threat model is uniquely severe — financial records, account credentials, and transaction histories captured today remain sensitive for decades, well past any reasonable estimate of when a cryptographically relevant quantum computer will exist.

The Standards Are No Longer Theoretical

NIST finalized the first three post-quantum cryptography standards in August 2024, ending an eight-year global evaluation process. A fifth algorithm, HQC, was selected as a backup in March 2025, and NIST is not finished: FIPS 206 (FN-DSA), designed specifically for bandwidth-constrained applications, is expected to be finalised sometime between 2026 and 2027. The message from standards bodies has shifted decisively from research to implementation. Since NIST standardised its first post-quantum cryptographic algorithms in 2024, governments and cybersecurity agencies worldwide have shifted focus from research to implementation, with organisations now expected to assess their cryptographic exposure, define migration strategies, and begin preparing critical systems for a quantum-resistant future.

The Regulatory Deadline Convergence

What makes 2026 the genuine inflection year — rather than another year of PQC discourse without action — is the simultaneous arrival of several binding deadlines. Three independent dates converge in late 2026 and early 2027: NIST’s FIPS 140-2 to Historical transition on September 21, 2026, the EU NIS Cooperation Group’s national strategy milestone on December 31, 2026, and the NSA CNSA 2.0 acquisition requirement timeline.

US federal policy has also hardened. Urgency increased in 2026 when the United States issued an Executive Order accelerating the transition to post-quantum cryptography for high-value assets and calling for faster validation of PQC modules, with similar guidance from NIST, Germany’s BSI, and the UK’s National Cyber Security Centre reinforcing the same message across regions. EO-14412 mandates an accelerated, government-wide migration to PQC for federal systems, establishing binding deadlines for high-value assets and directing the Federal Acquisition Regulatory Council to require contractor compliance with NIST PQC standards — a provision with direct implications for any bank holding federal contracts or processing government-linked payment flows.

The EU framework, published by the NIS Cooperation Group in June 2025, calls for member states to publish national PQC strategies and initiate cryptographic inventories by the end of 2026. Banks operating across US and EU jurisdictions now face two parallel, binding compliance clocks rather than one.

Banks Are Already at the Table

This is not a theoretical exercise for the financial sector — major institutions are directly embedded in the standards-development process. JPMorgan Chase Bank, N.A. is listed among the participating organisations in NIST’s Migration to Post-Quantum Cryptography project at the National Cybersecurity Center of Excellence, alongside firms including Samsung SDS and Thales. That level of direct engagement from a systemically important bank is a strong signal of how seriously the sector is treating implementation timelines.

Comparative Table: Classical vs. Post-Quantum Cryptography Migration for Banks

DimensionClassical Cryptography (RSA/ECC)Post-Quantum Cryptography (NIST-standardised)
Mathematical basisFactoring/discrete logarithm problemsLattice-based, hash-based problems (ML-KEM, ML-DSA, SLH-DSA)
Quantum vulnerabilityBreakable via Shor’s algorithm once quantum computers matureDesigned to resist both classical and quantum attacks
Key/signature sizeSmallerGenerally larger, raising bandwidth/storage overhead
Deprecation timelineDeprecated by 2030, disallowed by 2035 (per 2024 NIST guidance)Becoming the mandated standard across the same window
Migration complexityN/A (legacy baseline)Multi-year program touching PKI, identity, network, application layers

Why It Matters: The “Harvest Now, Decrypt Later” Math

The investment case for treating PQC as urgent rather than deferrable rests on a simple risk-timing framework. Mosca’s theorem compares three time horizons: the time required to migrate systems to post-quantum cryptography (X), the time during which data must remain secure (Y), and the estimated arrival of cryptographically relevant quantum computers (Z). If X + Y > Z, the migration is urgent — and for many organisations, Y extends well into the 2030s and beyond, since financial data may need protection for decades.

For a bank, Y is not a hypothetical variable — mortgage records, long-dated financial contracts, and account-holder personal data routinely carry multi-decade sensitivity windows. That makes the migration timeline math for financial institutions among the least forgiving of any sector.

Practical Migration Challenges Banks Must Budget For

PQC migration brings real practical challenges: many candidate algorithms require larger key sizes, increasing the data that must be stored and transmitted, along with greater computational overhead that can slow processing speed — and these algorithms may not integrate cleanly into older, legacy-heavy systems, which describes much of core banking infrastructure. A system built today with hardcoded RSA-2048 will require a full code rewrite for migration, while a system built with algorithm-agile design — where algorithm and key configuration sit outside core business logic — can migrate by updating configuration alone. That architectural distinction is now a genuine due-diligence question for any bank’s technology stack.

What to Do Next

  • Complete a full cryptographic asset inventory now — banks cannot migrate what they haven’t mapped, and inventory work is consistently cited as the essential first step across every institutional PQC playbook.
  • Prioritise algorithm-agile architecture in new systems to avoid costly full rewrites during the next migration phase.
  • Track the three converging 2026-27 deadlines (NIST FIPS 140-2 transition, EU national strategy milestone, NSA CNSA 2.0 acquisition requirements) as hard planning anchors, not soft guidance.
  • Treat long-dated data — mortgages, trusts, multi-decade financial contracts — as the highest-priority migration category, given the “harvest now, decrypt later” exposure window.
  • Monitor vendor and cybersecurity-equity exposure to the PQC market as it scales toward its projected $15 billion 2030 valuation, including hardware security module (HSM) and cryptographic-inventory tooling providers.

FAQ

Is post-quantum cryptography migration actually urgent, or is this a future-proofing exercise banks can defer?

It is genuinely time-sensitive. The “harvest now, decrypt later” threat is active today — adversaries are already capturing encrypted data at scale, betting on future quantum decryption capability, meaning data encrypted with classical methods now is already at risk for future exposure regardless of when quantum computers actually arrive.

What are the key NIST post-quantum standards banks need to implement?

NIST expects that two digital signature standards (ML-DSA and SLH-DSA) and one key-encapsulation mechanism standard (ML-KEM) will provide the foundation for most post-quantum cryptography deployments, with a backup algorithm (HQC) and a bandwidth-optimised standard (FN-DSA) rounding out the framework.

What is the deadline for banks to complete post-quantum migration?

NIST’s 2024 guidance states that classical public-key cryptography (RSA and Elliptic Curve Cryptography) should be deprecated by 2030 and disallowed by 2035, though several institutions, including Cloudflare, have set earlier internal targets, and regulatory deadlines are converging specifically around late 2026 and early 2027.


Discover more from The Economy

Subscribe to get the latest posts sent to your email.

Continue Reading
Advertisement
Advertisement

Trending

Copyright © 2026 The Economy, Inc . All rights reserved .

Discover more from The Economy

Subscribe now to keep reading and get access to the full archive.

Continue reading