UPSC Darpan

Science & TechnologyGS38 October 2026

Banks Told to Build Quantum-Safe Encryption Plan After Financial Sector Declared Critical Infrastructure

Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें

The news

New Delhi, October 7. The government has directed banks to develop a sector-wide quantum transition and adoption strategy, with an artificial intelligence resilience framework, after the banking, financial services and insurance sector was identified as critical information infrastructure, The Economic Times reports, citing people familiar with the matter. A working group under the State Bank of India chairman is examining it, and the finance ministry has asked banks to assess post-quantum vulnerabilities. The main fear is “harvest now, decrypt later”: attackers copy encrypted banking data today and wait for quantum computers able to read it. A Department of Science and Technology report in May, “Quantum-Safe Ecosystem in India”, said ministries and regulators should set up cryptographic asset repositories for critical information infrastructure by 2027. In September, PwC said banks should begin migrating to post-quantum cryptography immediately.

The chain in one line: Banking runs on public-key encryption → quantum algorithms could break it in future → adversaries harvest encrypted data now → BFSI identified as critical information infrastructure → banks told to inventory cryptography and plan migration

Static syllabus linkage

  1. The IT Act, 2000 gives critical systems a special legal shield. Section 70 lets the government declare a computer resource that affects critical information infrastructure a protected system, with unauthorised access punishable by up to ten years. Section 70A makes the National Critical Information Infrastructure Protection Centre the nodal agency, and Section 70B makes CERT-In the national agency for cyber incident response.
  2. The National Quantum Mission builds the capability that creates the risk. Approved by the Union Cabinet in April 2023 with ₹6,003.65 crore for 2023-24 to 2030-31, the Mission under the Department of Science and Technology funds quantum computing, communication, sensing and materials. Quantum-safe migration is its defensive twin.

Why UPSC loves this

  1. Cyber security of the financial system is a GS3 favourite. The syllabus asks about “Basics of cyber security”. Quantum risk adds a time dimension: data must stay safe for years.

Prelims nuggets

  • Under Section 70A of the IT Act, 2000, the National Critical Information Infrastructure Protection Centre is the nodal agency for protecting critical information infrastructure.
  • In August 2024 the U.S. National Institute of Standards and Technology published its first post-quantum cryptography standards.
  • Shor’s algorithm, run on a large quantum computer, could factor the large numbers on which RSA encryption relies.
  • CERT-In functions as the national agency for incident response under Section 70B of the IT Act, 2000.

Analysis

  1. The deadline is set by data lifetime, not by when quantum computers arrive. Loan records and identity data stay sensitive for decades, so data stolen now is exposed whenever decryption becomes possible. If migration takes years and data must stay secret for years, the clock has already started. That is why an inventory of where cryptography is used comes first.
  2. Lens — Innovation and safeguards: one sector cannot migrate alone. Banks connect to payment networks, insurers and government systems, so a weak link anywhere exposes all, as ET’s summary of the concerns notes. A common standard set by regulators avoids incompatible choices. The counter-risk is a rushed switch to immature algorithms; a sound officer phases migration, beginning with the longest-lived data.
  3. Directing banks informally weakens accountability. The direction is reported through anonymous officials, not a published notification. Regulated entities answer to RBI rules; clear, public timelines would let boards budget and auditors check progress.

Possible Mains question

What is the “harvest now, decrypt later” threat? Examine why India’s banking sector must begin migrating to post-quantum cryptography now. (10 marks, 150 words)

Model approach

  1. Directive — Examine. Explain the threat, then test the case for acting now.
  2. Introduction — today’s theft, tomorrow’s decryption. Define HNDL in one line.
  3. Body — long-lived data makes the risk current. Migration time plus secrecy time exceeds the quantum horizon. Value addition: DST’s 2027 repository target. Draw a timeline.
  4. Body — interlinked systems need a common standard. CII status under Section 70; NIST’s 2024 standards.
  5. Conclusion — inventory first, phased migration. RBI-led roadmap with public timelines.

Administrator's brainstorm

As Chief Information Security Officer of a public sector bank, where do you start?

I would build an inventory of every system using public-key cryptography, ranked by how long its data must stay secret. Long-lived records would move first to standardised post-quantum algorithms, tested alongside existing ones. I would report progress to the board as a risk metric.