Interview: “Quantum-safe begins not with technology, but with people”

At the 4th General Assembly of the Swiss FS-CSC, Prof. Verena Zimmermann, Assistant Professor in the Department of Humanities, Social and Political Sciences at ETH Zurich, spoke about the challenges and opportunities of quantum technologies for cyber security. Her main message was that making the future quantum-safe is not just a matter of technology but, above all, of organisations and people.

Verena Zimmermann, why should financial institutions act now on quantum technologies?
Quantum technologies offer enormous potential – for everything from simulations and data analyses to new forms of encryption. At the same time, though, they pose a threat to existing cryptographic processes. Powerful quantum computers may eventually be able to break some of the encryption used today. That’s why organisations need to start preparing their systems now for a quantum-safe future.

Quantum is often talked about mainly as a technological issue. You take a broader view. Why is that?
Because the real challenges are often not technological in nature. Our research shows that issues such as governance, training, collaboration and communication are key. Quantum technologies don’t just affect IT departments. They demand new skills and informed decisions at the management and regulatory levels.

What are the main areas where action is needed?
In an interview study with quantum experts and an analysis of national quantum strategies, four main action areas emerged: 1. innovation, research and development, 2. infrastructure and staff development, 3. security and safety, and 4. collaboration, inclusion and diversity. Sustainable quantum strategies need to cover all of them.

Where do you see the biggest challenges for the financial sector?
One central challenge is migration to quantum-safe systems. Many organisations have no overview of the cryptographic protocols that are used in their applications. At the same time, there is a risk of what are known as “store now, decrypt later” attacks, where data are stolen with a view to decrypting them at a later date. That’s why crypto-agility and early planning are so important when it comes to migration.

You also talked about knowledge gaps among decision-makers. Why is that problematic?
Because technological transformations are not driven by specialists alone. Managers, directors and regulators take strategic decisions on investments, priorities and risks. If they lack the necessary understanding, important developments can be underestimated or addressed too late. So training and professional development are a central part of quantum-readiness.

You devoted an important part of your lecture to the “human factor”. Why does that play such a big role?
For a long time, human beings have been seen as the weakest link in cyber security. That view is too narrow. Human beings don’t just cause risks: they can also actively strengthen security and resilience. It’s vital that organisations create the framework within which they can do that: processes that are easy to understand, technologies that are fit for purpose, clear communication and a culture that supports safe behaviour.

What specifically does that mean for companies?
Rather than focusing purely on error prevention, organisations should empower, motivate and support their staff. Safety-conscious behaviour doesn’t happen in a vacuum. It is influenced by knowledge, skills, available resources, leadership, feedback and organisational values. For that reason, cyber resilience is always a question of management too.

What is your most important message to members of the Swiss FS-CSC?
Quantum safety isn’t just about technology. It comes about through the interplay of people, organisations and technologies. Seeing quantum as purely an IT issue is too restrictive. The organisations that will be successful are the ones that view technological innovation holistically and in a socio-technological context – in other words, taking account of the organisational culture, processes and the human factor. The human factor doesn’t just mean end users: it covers everyone involved, from regulators and managers to employees.

One final question: what mindset should financial institutions adopt?
They need to shift away from a pure risk perspective in favour of a resilience perspective. Rather than thinking of people primarily as a source of errors, organisations should ask how they can enable, empower and motivate towards safe behaviour. In my view, that is where the key to a quantum-safe and cyber-resilient future lies.

About Verena Zimmermann
Prof. Verena Zimmermann is Assistant Professor at the Department of Humanities, Social and Political Sciences at ETH Zurich, and researches at the intersection of people and technology, particularly in the field of cyber security.

Prof. Dr. Verena Zimmermann

Quantum-safe at the Swiss FS-CSC
The Swiss FS-CSC is also tackling the issue of quantum-safe. It has set up a quantum-safe working group within the Technology, Innovation and Supply Chain chapter, which brings together cyber security experts from member institutions and is supported by the federal government. The group monitors developments in quantum computing and their impact on the financial sector, and offers a platform for member institutions to share their experiences. It is also drawing up guidelines on quantum resilience for the Swiss financial centre.