Regulation

LGT Financial Services Tests Post-Quantum Cryptography in Live Banking System

The Swiss bank has launched a hybrid key exchange pilot in its online banking platform, demonstrating how financial institutions can migrate to quantum-safe cryptography without disrupting customer operations.

3 min read
LGT Financial Services grounds post-quantum migration in live banking pilot

Treating post-quantum migration as a single, monolithic replacement effort can quickly overwhelm an organization. When companies transition from theoretical quantum awareness to actual implementation, the work spans applications, infrastructure and third-party vendors—making project coordination just as critical as the choice of cryptographic algorithms themselves.

LGT Financial Services AG brought quantum safety into its formal risk management process in 2022, when the subject surfaced during the firm's annual risk and cyber risk management meeting. The organization subsequently established a dedicated competence center to align security operations, infrastructure architecture, public key infrastructure teams, application owners, external vendors and risk management stakeholders. Christian Pfister, team leader for IT security operations and head of LGT's Quantum Safe Competence Center, outlined the bank's approach at DigiCert's World Quantum Readiness Day event.

Quantum safety is a resilience and risk management issue. The key question for leadership was straightforward: Which information must remain confidential long enough that it may be exposed to a future cryptographic break? We then explained that waiting until there is a cryptographically relevant quantum computer would leave too little time to identify dependencies, upgrade product, coordinate suppliers and safely migrate.

Christian Pfister, LGT Financial Services AG

Migration unfolds in stages

Rather than attempting to catalog, update and validate all cryptographic implementations simultaneously, LGT's competence center provides strategic direction while letting individual teams and service owners drive their own migration timelines. This distributed approach enabled the bank to launch focused initiatives while still building out its complete cryptographic inventory.

If you try to inventory, replace and validate every cryptographic use case at once, it makes the program unmanageable, and you can't measure the outcome. The [post-quantum cryptography] migration is not one project and one algorithm change; it's a series of migration waves.

Christian Pfister

Engaging suppliers emerged as a separate but equally important workstream, encompassing vendor management and procurement activities. Starting in 2023 or 2024, LGT began systematically questioning vendors about their product development plans, which post-quantum algorithms they support, implementation timelines and any compatibility limitations.

That vendor management, it seems now a very important part. Therefore, we got connections — connections to DigiCert, to experts to talk with. That was also a very important part [that] we coordinated with the Quantum Safe Competence Center.

Christian Pfister

Live pilot combines classical and post-quantum methods

LGT initiated its technical work by upgrading its Transport Layer Security configuration and conducting hybrid key exchange tests in isolated settings. The bank paired X25519, a classical key exchange mechanism, with the NIST-standardized Module-Lattice-Based Key-Encapsulation Mechanism, creating a hybrid approach that combines established cryptography with post-quantum protection.

This pilot is now live, and our online banking system uses hybrid key exchange, and our customers don't have any disruption. This principle we are going to follow in all areas.

Christian Pfister

The pilot uncovered interoperability challenges spanning the entire connection infrastructure, including load balancers and content delivery networks. Some connections experienced failures or reverted to previous configurations, underscoring the necessity of comprehensive end-to-end testing rather than examining individual components in isolation.

Most issues look familiar to anyone who has delivered major security changes. We are all familiar with legacy hardware, unsupported firmware [and] unmanaged libraries. The [pilot] exposes technical debt that already exists, and that's not the reason to wait. It's precisely why starting early matters for us.

Christian Pfister

Source: SiliconANGLE · Reporting supplemented by The Silicon Ledger staff.