Singapore’s Monetary Authority is gearing up banks for a major cybersecurity overhaul that won’t touch cryptocurrencies but instead targets the cryptographic tools underpinning bank operations. Starting in 2026, financial institutions must report where and how encryption protects customer data, payment processes, and interbank communications.

Clarifying What 'Cryptos' Means for Banks

The term "cryptos" in the Monetary Authority of Singapore’s directive has sparked confusion. It does not refer to Bitcoin, Ethereum, or any digital currency holdings. Rather, it points to cryptographic assets such as encryption keys, digital certificates, signatures, and algorithms. These elements form the backbone of data security in banking infrastructure, guarding sensitive information against breaches and unauthorized access.

Banks are required to compile a full inventory of these cryptographic tools across all operations, including mobile banking platforms, payment authorization systems, internal data repositories, and cloud services even those provided by third-party vendors. This effort acknowledges that vulnerabilities may exist not only in in-house systems but also in the external technology that banks rely on.

Preparing for the Quantum Computing Challenge

The MAS is pushing banks to identify cryptographic methods vulnerable to attacks from future quantum computers. Quantum machines could potentially break current encryption algorithms, compromising sensitive financial data. To mitigate this risk, the regulator will set phased deadlines for banks to assess their cryptography, prioritize vulnerable systems, and migrate to quantum-resistant solutions.

Critical systems, such as those authorizing payments or managing long-term customer records, will take precedence in this migration. Less sensitive data that quickly loses value may be updated later. This targeted approach allows banks to focus resources where the impact of quantum attacks would be most damaging.

The MAS’s move follows its earlier advisory on quantum-related cybersecurity risks, marking a shift from general guidance to a structured, enforceable framework. These developments echo global trends as financial institutions worldwide brace for the disruptive potential of quantum computers on existing encryption standards.

This material serves informational purposes and does not constitute financial advice.