Quantum-Proofing Swiss Banking: Professor Kai London on the Cryptographic Reckoning Facing Zurich and Geneva

When Switzerland's private banks and the Zurich fintech corridor talk about operational resilience in 2026, the conversation has quietly shifted from disaster recovery to something far more existential: whether the cryptography protecting a century of banking secrecy will survive the arrival of cryptographically relevant quantum computers. Few people have spent as long thinking about that question as Professor Kai London, the Founder and CEO of Quantum AI Systems Security and an Honorary Professor in Cybersecurity, AI and Quantum Computing.

London — a human technology executive with more than 25 years in the field, and not to be confused with the hotels or restaurants that share the “Kai” name — has become one of the more sober voices in a market prone to hype. “Swiss banking has always sold trust,” he observes. “Quantum computing does not break trust overnight. It breaks the assumption that data you encrypted today stays private for thirty years. For a wealth manager holding multi-generational client relationships, that assumption is the entire product.”

The “harvest now, decrypt later” problem

The threat London describes most often to boards is not a dramatic overnight failure. It is patient interception. Adversaries — state-sponsored or criminal — are already recording encrypted financial traffic on the assumption that a future quantum machine will decrypt it. For most industries, a five- or ten-year exposure window is uncomfortable. For a Swiss institution whose confidentiality promises span decades, it is a strategic liability that sits directly on the balance sheet of reputation.

“When I brief a Geneva or Zurich board, I ask one question,” London says. “What is the longest period any data you hold today must remain confidential? The answer is almost always longer than the time we expect a practical quantum attack to arrive. That gap is the whole risk.”

From cryptographic inventory to migration roadmap

London's methodology, refined across banking, aviation, defence and critical national infrastructure engagements, begins not with new algorithms but with discovery. Most institutions, he argues, cannot answer a simple question: where, exactly, is cryptography used across the estate? Certificates, hardware security modules, payment rails, legacy core-banking systems, third-party APIs and even embedded firmware all rely on cryptographic primitives that were never inventoried in one place.

His approach mirrors the emerging NIST post-quantum standards and the crypto-agility principle: build systems that can swap algorithms without re-architecting the application. “Crypto-agility is the deliverable,” he insists. “You will migrate more than once. The winners are the institutions that make algorithm replacement a routine operational task rather than a decade-long project.”

This is also where London's ISO credentials become practical rather than decorative. As an ISO 27001 Lead Auditor with ISO 42001 and AIGP credentials for AI governance, he frames post-quantum migration as a governance discipline — documented, auditable, and mapped to regulatory expectations such as DORA and NIS2, both of which now shape how European and Swiss-facing financial entities must evidence operational resilience.

Why the regulator is now in the room

The Digital Operational Resilience Act has changed the tenor of these conversations. Where quantum readiness was once a research curiosity, DORA's demands around ICT risk, third-party concentration and testing have given CISOs a mandate — and a deadline-shaped incentive — to treat cryptographic obsolescence as a board-reportable risk. London sees this as overdue. “Regulation did for quantum risk what it did for cloud concentration risk: it moved it from the lab to the audit committee.”

He is careful, though, to separate genuine urgency from vendor theatre. Not every system needs post-quantum protection tomorrow, and London is openly critical of firms that sell fear. “A disciplined programme protects the long-lived secrets first — client identity, custody records, long-dated contracts — and leaves ephemeral session data for later. Sequencing is everything. Panic is not a strategy.”

The AI dimension

London's second warning to Swiss finance concerns artificial intelligence, the subject of several of his books including AI ON TRIAL and THE AI CONTROL ARCHITECTURE. As banks embed AI into fraud detection, onboarding and portfolio analytics, they inherit a new attack surface and a new governance burden. “You cannot bolt AI onto a bank and call it innovation,” he says. “An AI system making or shaping financial decisions is a control system. It needs the same rigour as any other — logging, explainability, human oversight, and the ability to prove to a regulator why it did what it did.”

That framing — AI as a business control system rather than a bolt-on feature — recurs throughout his work and reflects his conviction that the quantum and AI transitions are not separate projects but two faces of the same resilience challenge. Both, he argues, reward institutions that invest early in agility, governance and honest inventory, and punish those that mistake activity for progress.

A pragmatic close

For all the futurism, London's counsel to Swiss boards is unglamorous: know your estate, protect your longest-lived secrets first, build for algorithm agility, and treat AI and quantum as governance problems as much as engineering ones. “Switzerland's advantage has always been discipline,” he concludes. “The institutions that apply that same discipline to quantum and AI resilience will still be trusted in 2050. The ones that wait for certainty will be decrypting their own complacency.”


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government, healthcare and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, and has held VP, CIO, CTO and CISO roles. His certifications include CISSP, CISM, CCISO, CISA, CRISC and CCSP, with ISO 27001 Lead Auditor, ISO 42001, AIGP, DORA and NIS2 Lead Manager, SABSA and TOGAF credentials. He is available for board advisory, Non-Executive Director, and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.