Singapore’s financial sector now has a clear destination: quantum resilience before the end of the decade. The Monetary Authority of Singapore (MAS) has said it will set progressive timelines for financial institutions to map their cryptographic assets, decide what needs to move first, and build the skills and governance needed for a quantum-safe transition.

Locking in the destination, however, is not the same as knowing how to get there. For instance, a financial institution cannot replace cryptography with a single software update. Encryption and digital signatures are embedded in servers, channels, systems, platforms, cloud services, hardware, backups and vendor products. Most are hidden in the background and invisible to end users.

Migration to post-quantum cryptography therefore cannot sit with a technology or cybersecurity team alone. I have worked with many organizations on digital projects and have found that real progress begins only when transformation and change management are cultural norms.

Today’s exposure becomes tomorrow’s threat

It helps to be precise about the risk. While there is no known quantum computer today that can break widely used public-key cryptography at scale, Q-Day may be closer than many financial institutions assume.

Some experts place the arrival of a cryptographically relevant quantum computer within the next five to 10 years, a short window when major technology migrations can take just as long. Once such a machine becomes available, widely used public-key algorithms such as RSA and elliptic-curve cryptography could be broken, putting key exchange, authentication and digital signatures at risk. The question then is whether anyone can complete the transition before the threat arrives.

Under a “harvest now, decrypt later” attack, an adversary steals encrypted information now and stores it until a sufficiently powerful quantum computer can decrypt it. The attacker does not need quantum capability today, only access to valuable data and the patience to wait.

Start with business-critical systems and be open to the solutions out there

The first output should be a clear view of what matters most. We start with the “crown jewels”: high-value data and information that matters, then trace the systems and data flows that support them.

For these, build a living cryptographic inventory, sometimes called a cryptographic bill of materials. You do not have to start from zero. Automated discovery tools can widen the search, but cryptography hidden in firmware or controlled by a vendor may still require deeper checks.

Most importantly, the inventory must connect technical findings to business impact, ultimately toward a solution. For every critical use of cryptography, teams should be able to answer five questions:

  • What service depends on it?
  • What data is exposed if it fails?
  • How long must that data remain protected?
  • Who is responsible for fixing it?
  • What are the solutions and alternatives?

Decide what moves first and which solution to use

A long inventory without priorities can quickly become another compliance document that nobody uses. Institutions need a migration plan. A practical model should weigh data sensitivity, how long confidentiality must last, external exposure, operational importance, migration difficulty and the system’s lifespan.

A retiring system may not justify an expensive upgrade, but it still needs safeguards and a firm replacement date. It is imperative to decide which solution can be implemented and when.

There are useful signals elsewhere in APAC to gauge where we stand, both institutionally and as a country.

Australia’s cyber authority recommends a refined transition plan by the end of 2026, migration of critical systems and data from 2028, and completion by the end of 2030. Hong Kong’s banking sector, meanwhile, scored 2.3 out of 10 on its first Quantum Preparedness Index in 2026, with around half of surveyed banks lacking a formal post-quantum plan.

The region is clearly paying attention. The next step is turning awareness into measurable work and practical solutions.

Your migration will move at the speed of your slowest vendor

Even a well-prepared institution can be held back by a vendor that is not ready. Contracts signed today can either preserve future flexibility or lock in years of technical debt.

Ask key vendors where cryptography resides, which standards they can support, when production-ready upgrades will arrive, whether hybrid options are available, and what performance or interoperability issues to expect.

Those answers should feed directly into contract renewals, hardware upgrades and application-modernization plans. If a system cannot migrate in time, the institution should implement controls to mitigate future risks.

Test real workflows and be prepared for changes

NIST finalized its first three main post-quantum standards in 2024: ML-KEM for establishing secure keys, and ML-DSA and SLH-DSA for digital signatures.

That was a major milestone, but a standard on paper is not the same as a safe deployment. The field continues to evolve. NIST selected HQC as a backup to ML-KEM, while HAWK, a candidate post-quantum signature scheme, was withdrawn after an AI-assisted cryptanalysis result exposed a mathematical vulnerability. NIST said the HAWK finding does not affect its finalized ML-KEM or ML-DSA standards.

One might say that we can always replace and enhance, but new algorithms can bring larger keys, certificates and signatures, as well as different demands on processing, latency and network traffic.

Pilots should follow real workflows instead of testing an algorithm alone. How can these PQC tools be plugged into a system and process? Can we protect our systems and front-end users, including information on mobile devices such as tablets and smartphones? Is encryption applied to data seamlessly?

However, a bigger goal is crypto-agility: changing cryptography without rebuilding the system around it. That means avoiding hard-coded algorithms, separating cryptographic choices from business logic, centralizing policy and key management, and making discovery part of normal development.

This is the principle we’ve built Aires Applied Quantum around, keeping it easy to plug in PQC and cryptography solutions as an additional layer where needed, across systems and tools where organizations can use PQC more easily.

Build the evidence before supervisors ask for it

Quantum readiness needs one accountable executive and clear roles across several departments. The board does not need to debate algorithms, but it does need to approve the institution’s risk appetite, funding, priorities and exceptions.

Build the evidence as the program moves, not at the last minute for a supervisor. Keep an approved strategy, a dated inventory with known gaps, a risk-ranked backlog, vendor roadmaps, pilot results, security criteria, approved exceptions, budgets, milestones and regular management reports.

This is the difference between saying “we are monitoring quantum” and showing what has actually been found, decided, tested and fixed.

Nobody can say with certainty when a powerful quantum computer will arrive. But the work institutions must complete before then is already clear. Q-Day should be treated as the deadline, not the starting gun.


Ken Lin is Co-Founder and CEO of Aires Applied Quantum Technologies (AAT), one of Southeast Asia’s pioneering independent quantum technology companies. Before stepping into deep tech, Ken spent nearly two decades in Singapore’s banking sector, where he held senior leadership roles overseeing wealth management strategy, regulatory governance, product innovation, digital transformation and advisory across major regional and global banks.

In 2022, Ken made a decisive shift to pursue his personal passion for innovation and technology. He partnered with his brother, mathematician Lim Meng Liang, whose research in Diophantine equations laid the foundation for AAT’s proprietary quantum-safe and quantum-intelligence technologies. Together, they built a company focused on independent R&D, technology algorithms and homegrown intellectual property, a model the company says is relatively uncommon in an industry typically dominated by government-linked research or large multinational labs.

At AAT, Ken leads commercial strategy, investment planning and the translation of complex R&D into practical applications for governments, businesses and consumers. The company says it has secured multiple international patents in cryptography, quantum-safe algorithms and next-generation communication protocols, while building a sustainable and profitable business model around real-world deployment.

Ken’s work centers on the belief that quantum technology should not be locked behind exclusive institutions, but developed in ways that are accessible, transparent and commercially viable for organizations in the region and beyond.

Editor’s note: This contributed article has been lightly edited for TNGlobal style and clarity. The views and arguments expressed remain those of the author.

Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archives.

Featured image: Compagnons on Unsplash

AI agents are moving into the workplace faster than companies know how to manage them