On September 11, 2026, the Reserve Bank of India (RBI) gave a clear order to the financial sector. At the Global Fintech Fest (GFF) 2026 in Mumbai, RBI Deputy Governor Shirish Chandra Murmu issued a warning. He stated that banks, payment providers, and fintechs must start building quantum-resistant security systems right away. The message was simple. The tech that runs India’s digital economy faces a major new risk. Quantum computers cannot break bank security today. But fixing old security systems takes years. Banks cannot afford to wait.
For over ten years, digital payments and cloud tech have driven India’s financial growth. Now, the central bank says this same tech must prepare for a massive threat. Murmu noted that no single bank can fix this alone. Modern payments rely on a complex web of banks, tech vendors, and payment networks. Securing this infrastructure requires a massive team effort across the entire sector.
The Macro Stakes: UPI Scale and Systemic Risk
Look at the size of India's digital payments to understand the RBI's worry. Cybersecurity is no longer just an IT problem. It is vital to keeping the entire economy stable. This is just as critical as when RBI forex interventions protect market liquidity. According to Murmu, the Unified Payments Interface (UPI) handles so much money that it is now critical national infrastructure.
| Indicator | FY2025-26 Data |
|---|---|
| UPI Transactions (Volume) | 24,162 crore (~241.62 billion) |
| Transaction Value | ~₹314 lakh crore |
| Share of Digital Payment Volume | ~85% |
UPI handles about 85% of India's digital payment volume. A major hack here would be a total disaster. It would stop consumer spending in its tracks. It would freeze merchant cash flows and hurt the broader economy. The Bank for International Settlements (BIS) strongly agrees. It calls payment systems essential for modern economies. Today, keeping payment systems safe from hackers is the backbone of financial stability.
The "Harvest Now, Decrypt Later" Threat
The RBI wants to act before a real attack happens. A big worry is the "harvest now, decrypt later" (HNDL) threat. Hackers do not need the power to read stolen data right now. Instead, they steal and save scrambled data today. They then wait until quantum computers are strong enough to unlock it.
This poses a huge risk for banks. Bank data must stay secret for a very long time. Stolen files might hold corporate secrets, bank chat logs, and identity records. Even years from now, hackers could use this old data to steal identities or money. The BIS says banks must act now to stop this long-term risk. Old data must not become a future weapon.

Inside the RBI's Q-SAFE Committee
The RBI did not just start talking about this issue. On May 25, 2026, the RBI created a special team. This group is the Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) committee. This panel is actively building India’s future financial security plan.
Dr. Anil Prabhakar from IIT Madras leads the group. It includes top experts from the State Bank of India (SBI), NPCI, MeitY, and the Data Security Council of India. The committee must write a full report within six months of its very first meeting. They are working on a strict deadline.
The Q-SAFE team is checking the tech that Indian banks currently use. They are looking at global rules and creating a roadmap to secure the banking system. Most importantly, they are studying a Cryptography Bill of Materials (CBOM). A CBOM forces a bank to list every single security code hidden in its software.
NIST Standards and the Upgrade Path
What does quantum-proofing actually mean? It means updating systems to block advanced quantum attacks. Today, banks use public-key math to verify users, protect data, and secure apps. A strong quantum computer could easily break this math. As IT teams manage complex security migrations daily, this new shift will be their biggest test yet.
Luckily, new global rules are ready to use. In August 2024, the National Institute of Standards and Technology (NIST) released three standards: FIPS 203, FIPS 204, and FIPS 205. These rules protect digital signatures and data sharing. Indian banks can use these tools to start upgrading their tech today.
But updating bank security is very hard. Large banks use decades-old tech. Changing the security layer affects core databases, vendor software, and daily operations. Upgrading everything at once takes years. This is exactly why Murmu said the hard work must start today.
Action Steps: CBOM and Cryptographic Agility
Banks and fintechs face a massive, costly task. First, they must build a full list of their security tools. They must find all current codes, keys, and software hiding in their systems. This is why the RBI wants to force CBOM audits.
Next, banks must find their most important systems. Tools that handle core banking, big money transfers, and digital signatures need updates first. Tech teams must then test the new quantum codes. The BIS Project Leap Phase 2 showed that these new codes work in real payments. However, the new math needs more computer memory. The new digital signatures are much larger. This means moving data takes slightly longer.
The biggest goal here is "cryptographic agility." This means building systems where security codes can be swapped out easily in the future. Banks cannot hardcode a single security rule ever again. If they do, future updates will be too hard and cost too much money.
AI Accountability in Banking
At the fintech event, Murmu also warned about Artificial Intelligence (AI). Banks are starting to use agentic AI. These are systems that make big financial choices on their own. This shift creates a major new problem for regulators.
Murmu made one rule very clear. If an AI makes a bad choice, the bank is still at fault. Banks absolutely cannot blame the machine. Bank leaders must fully understand the AI tools they deploy. Whether facing AI risks or quantum hacks, the RBI demands that banks build safe systems from the ground up.
The News4Bharat POV
The RBI’s warning kicks off a massive spending cycle for banking tech. Big banks will spend heavily on new servers, cloud tools, and security tests over the next five years. Just as the RBI manages massive liquidity auctions to keep markets safe, it is now forcing heavy tech spending to keep data safe. But smaller fintech firms will face the hardest road.
Small payment apps do not own their core tech. They rely heavily on big cloud providers and API vendors. If a small firm tries to use the new NIST standards, but its vendor is slow, the upgrade stops completely. We expect the RBI’s new roadmap to push big banks and networks like NPCI to upgrade first. The smaller players will then be forced to follow.
We must also closely watch system speed. For a system like UPI, which processes thousands of taps a second, even a tiny delay matters. Indian banks must test these new codes hard. The fast UPI speeds that users expect must not slow down just to meet security goals.
Editorial Closing: Defending the Digital Scale
The RBI just made quantum tech a top priority. Everyday users do not need to worry about their bank accounts today. However, the banks holding that money must move fast. Elite cybersecurity is now the basic backbone of a stable economy.
Everyone is watching the Q-SAFE committee. By late 2026, the group should share a clear, strict plan. Banks and tech vendors should expect new rules focused on agile architecture very soon. India has successfully built a massive digital economy. The true test now is how well the nation can defend it.

