The lovely people at Currency Research invited me to host a roundtable at the Central Bank Payments Conference (CPBC) in Istanbul. The rountable was about quantum computing or, more precisely, about quantum readiness: that is, how does a financial institution go about preparing for “Y2Q”, which is the time at which a quantum computer becomes capable of breaking the asymmetric cryptogtaphy used by banks, governments and others to protect data around the world. A working quantum computer capable of making off with everyone’s money (and worse) may not be that far off. Banks and others are already planning for Y2Q and working out how and when to migrate to post-quantum cryptography (PQC).

Google think we are getting ever nearer to Y2Q. Given the progress they see in quantum computing hardware development, quantum error correction and quantum factoring resource estimates, they have adjusted their quantum era timeline to 2029 and are taking action. They are prioritising PQC migration for authentication services and recommend that others do the same. Android 17 is integrating PQC digital signature protection using ML-DSA in alignment with the National Institute of Standards and Technology (NIST), building on Google Chrome support for PQC.
Whether working quantum computers capable of breaking today’s security are a few years away or a few decade away, they will undoubtedly be here one day so prudcent organisations are building their defences. Bruce Schneier, a leading expert in computer security (and someone who I always listen to on such matters) says that now is probably the right time to worry about, and defend against, attackers who are storing encrypted messages in hopes of breaking them later on future quantum computers.
(Your enemy could harvest your data and then tuck it away safely until a quantum computer comes out a decade from now, when they can then get access to your data.)
Unlike Y2K, where we knew exactly when we might get into trouble and could take (as it turned out, very successful) action to mitigate any problems, we do not know when we will reach Y2Q. But that’s no excuse for lack of preparation, and at the roundtable we discussed the first step, the quantum audit needed to findout which systems needs updating and prioritising the roll-out of PQC.
Quantum audits to one side, I must say it was an enjoybable and informative event. I found the discussions around tokenisation and stablecoins particularly useful in the context of other work right now. It was also an opportunity to catch up with old friends, one of them being Kosta Peric from the Gates Foundation. Kota took part in a fireside on inclusion that I found especially interesting.

As the picture shows, when the audience were asked what might make the biggest difference to cross-border payments in Africa, the overwhelming sentiment was in favour of interconnecting instant payment systems rather than, for example, using stablecoins or central bank digital currencies. This caught my eye because my Fime colleague Arnaud Crouzet and I have just published a paper on “Cross-border payments as a key opportunity for dometic schemes” in the Journal of Payment Strategy and Systems (Vol. 20, No. 3, Fall 2026) in which we use Africa as one of the case studies to illustrate the benefits of precisely this approach. We looked at the issues around the interconnection of domestic schems and concluded that:
- Interconnecting domestic payment schemes is no longer a purely theoretical idea. In several regions, it is already taking shape.
- It offers a realistic and practical path toward cross-border payments that are cheaper, faster and more transparent by leveraging assets that already exist.
- For domestic schemes, the opportunity is to move beyond a purely national utility role and become a meaningful participant in regional cross-border networks.
For central banks, regulators and schemes who are looking to exploit the possibilites here, all I will say is that I am sure that Fime’s expertise and experience can support management decisiom-making very effectively!