top of page

Moodys aligns with SITG-Position on PQC Risk

  • Writer: Brian Couzens
    Brian Couzens
  • Jun 19
  • 2 min read

#Moody's may have delivered one of the most important post-quantum signals of 2026.


Not because of a breakthrough in quantum computing.


Not because of a new cryptographic standard.


Because a global credit rating agency has started discussing Post-Quantum Cryptography (PQC) as a budgetary, governance and enterprise risk issue.


For many years, this has been the position of SITG-Consulting.


Our Quantum Risk White Paper, first published in 2024, revised in December 2025 and again in May 2026, argued that quantum risk should not be viewed solely as a cybersecurity problem.


It is a fiduciary risk.


A governance risk.


A strategic risk.


A board accountability risk.


The challenge was never simply whether a cryptographically relevant quantum computer would emerge.


The challenge was understanding the organisational consequences of failing to prepare.


Cryptographic discovery.


Asset inventories.


Dependency mapping.


Crypto-agility.


Migration planning.


Third-party risk.


Regulatory exposure.


Long-term protection horizons.


These are not technical exercises performed in isolation by security teams. They are enterprise-wide risk management activities with financial, operational and governance implications.


That is why the Moody's analysis is significant.


When cryptographers discuss quantum risk, it remains a technology conversation.


When security vendors discuss quantum risk, it remains a cybersecurity conversation.


When a global credit rating agency begins discussing the financial implications of PQC migration and the competition for capital between AI transformation and cryptographic transformation, the discussion has moved into a different domain entirely.


The boardroom.


The question is no longer:


"When will quantum computers arrive?"


The question is:


"What is the cost of delayed action, and who carries accountability for that decision?"


That is the language of fiduciary duty.


That is the language of enterprise risk management.


And increasingly, that is the language regulators, investors and ratings agencies are beginning to adopt.


Moody's is not creating a new conversation.


It is validating one that has been building for years.


Reference:


TechRadar reporting on Moody's analysis of PQC investment pressures and technology budget competition:



 
 
 

Recent Posts

See All
An Analysis of ASD's PQC Vendor Approach.

One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migratio

 
 
 

Comments


bottom of page