Post-Quantum Migration and the Rupiah: Cybersecurity as a Financial-Stability Channel

Rupiah Stability Watch · 2026-08-15

The premise

Post-quantum cryptography is not a rupiah forecast. It is a slow maintenance problem for the trust machinery that lets a modern currency move without visible friction.

That distinction matters. The rupiah is usually discussed through rates, reserves, oil, bond flows, inflation, and Bank Indonesia credibility. Rupiah Stability Watch has treated those channels directly in pieces such as “Bank Indonesia’s Defensive Stance,” “Indonesia’s Balance-of-Payments Adjustment,” “Who Is Buying the Rupiah?,” “Indonesia’s Triple Classification Risk,” “S&P Family Divergence,” and “Pacific Security Realignment and the Rupiah.” This analysis adds one quieter channel: the cryptographic infrastructure beneath payments, securities settlement, foreign-exchange trading, tax and customs collection, bank connectivity, and corporate treasury systems.

The immediate signal is not panic. MIT Technology Review’s August 13, 2026 piece on building a practical path to post-quantum cryptography describes the transition as “a manageable evolution, not a crisis,” while still noting expert survey estimates that a quantum computer able to break a 2048-bit RSA key within 24 hours could plausibly be a 2040 problem, not a science-fiction problem. The same article highlights the nearer “harvest now, decrypt later” risk for data that must remain confidential for more than ten years.

For Indonesia, the financial-stability question is therefore not whether quantum risk is moving USD/IDR today. I see no evidence for that. The question is whether a credible, visible, and well-tested migration plan can reduce a future tail risk before markets have a reason to price it.

The transmission chain

The chain is simple enough to name, even if it is hard to measure:

cryptographic confidence → payment and settlement continuity → bank and market trust → sovereign and corporate risk premium → capital-flow composition → rupiah pressure → household and business costs.

A delayed or disorderly migration would not have to “break the rupiah” to matter. It could matter through smaller mechanisms:

Those are second-order channels. They would be hard to see in ordinary USD/IDR moves because they would be mixed with the usual emerging-market variables: Federal Reserve expectations, commodity prices, current-account data, fiscal signals, and domestic politics. But hidden does not mean irrelevant. Operational resilience is one of the ways confidence compounds quietly.

What the evidence supports

The global post-quantum transition is real. NIST approved three post-quantum cryptography Federal Information Processing Standards in August 2024: FIPS 203 for key encapsulation, FIPS 204 for digital signatures, and FIPS 205 for stateless hash-based digital signatures. NIST says these standards are designed to resist future attacks by quantum computers that threaten current standards.

The migration is also organizational, not only mathematical. CISA, NSA, and NIST’s quantum-readiness material urges organizations, especially critical-infrastructure operators, to establish a quantum-readiness roadmap, prepare a cryptographic inventory, assess supply-chain exposure, engage vendors, and clarify vendor responsibilities. That language matters for financial stability because banks and payment systems do not run on one cryptographic library. They run on layered internal systems, vendors, certificates, hardware modules, network links, customer-facing applications, backup systems, and cross-border dependencies.

Financial authorities already treat cyber and operational disruption as a systemic issue. The Financial Stability Board warns that a cyber incident at one financial institution, or at one of its third-party providers, can spill over across borders and sectors. It also emphasizes that timely and accurate information is crucial for incident response, recovery, and financial stability.

The Bank of England frames operational resilience as a macroprudential issue: operational disruptions can create financial-stability impacts because of the structure of the financial system and the behaviour of participants. Its 2024 paper names recent incidents involving CrowdStrike, Swift, ICBC Financial Services, and ION as examples of how digital and third-party dependencies have become part of the stability perimeter.

For financial market infrastructures, the standard is even more direct. CPMI-IOSCO guidance says the safe and efficient operation of FMIs is essential to maintaining and promoting financial stability, and that FMIs can become sources of shocks or channels through which shocks are transmitted across markets. The same guidance says critical operations should be designed and tested for safe resumption within two hours after disruption and completion of settlement by the end of the value date.

Indonesia has a domestic foothold for this work. A 2024 legal summary of Bank Indonesia Regulation 2/2024 says the rule applies to payment-system operators, money-market and foreign-exchange market participants, and other BI-supervised parties. It describes requirements around cyber-resilience strategy, roadmaps, risk profiles, data protection, monitoring, response, recovery, simulation, annual maturity reporting, identification of vital information structures, and mandatory incident reporting.

That is important. Post-quantum migration should not be treated as a separate technology project sitting outside financial regulation. It belongs inside the same operational-resilience perimeter that already covers payment, money-market, and FX-market actors.

What the evidence does not support

The evidence does not support a claim that post-quantum risk is currently moving the rupiah.

It does not support a claim of imminent cryptographic breakage. The most useful posture is neither complacency nor alarm. It is planned migration.

It does not support vendor advocacy. The point is not that Indonesia needs one named product, one foreign provider, or one fashionable security architecture. The point is that the currency system depends on a large web of cryptographic dependencies, and that credible migration requires inventory, sequencing, testing, procurement discipline, vendor accountability, and incident transparency.

It also does not support treating cybersecurity as a purely technical concern. In financial markets, technical continuity becomes confidence. Confidence affects spreads, liquidity, collateral behavior, sovereign auctions, and ultimately the exchange-rate environment in which households and firms buy imported goods.

The Indonesia-specific channel

Indonesia’s exposure is not simply that it has banks and payment apps. The exposure is that the country has been deliberately deepening digital financial infrastructure while also trying to defend monetary and external stability.

That creates benefits. Digital payments can reduce frictions, broaden inclusion, improve tax visibility, and make commerce less cash-bound. Cross-border payment links can reduce transaction costs. Faster settlement can improve liquidity use. These are resilience gains when they work.

But they also increase the amount of stability that rests on shared rails. If a future post-quantum migration is late, opaque, or uneven, the first-order problem may be operational. The second-order problem may be confidence in the institutions that maintain rupiah-denominated settlement.

This is where the issue connects with Rupiah Stability Watch’s earlier work. “Bank Indonesia’s Defensive Stance” treated credibility as a reserve and rate channel. “Indonesia’s Balance-of-Payments Adjustment” treated external financing and reserve adequacy as one system. “Who Is Buying the Rupiah?” examined the composition of confidence-sensitive inflows. The same logic applies here: a payment-system or settlement-system risk premium would be unlikely to announce itself as a clean line item. It would appear through liquidity preference, shorter holding periods, wider hedging costs, higher operational-risk assumptions, and a lower tolerance for simultaneous shocks.

Recent August monitors have also emphasized simultaneous stress channels. Cyber-infrastructure risk fits that frame. It is most dangerous when it arrives beside another pressure: oil-import strain, fiscal concern, weather-linked food inflation, a ratings-classification question, or a global dollar shock. A well-managed post-quantum transition reduces the chance that an infrastructure issue becomes the amplifier at the wrong moment.

Practical signposts to monitor

Signpost Why it matters for rupiah stability What would be reassuring
BI and OJK post-quantum guidance Turns a hidden technical migration into a supervised stability process Public roadmap, phased expectations, and clarity on supervised entities
Cryptographic inventory requirements Migration cannot be sequenced if institutions do not know where vulnerable cryptography sits Inventory deadlines, board accountability, and vendor inclusion
Payment-system and FMI testing Payments, settlement, and market infrastructure are the confidence core Exercises covering BI-FAST, QRIS-related dependencies, money-market, FX, and securities-settlement links where relevant
Treasury and auction continuity planning Sovereign financing credibility depends on auction and settlement reliability Tested fallback arrangements and transparent operational-risk governance
Bank disclosures Investors and depositors need evidence of orderly preparation, not slogans Annual reports or pillar-style disclosures naming cyber-resilience maturity, migration progress, and third-party risk management
Vendor and cloud concentration mapping A common provider can become a common failure channel Sector-level mapping of critical third parties and substitution paths
Incident reporting and communication Silence can widen risk premium faster than a contained incident Timely, factual reporting aligned with FSB-style convergence principles
Cost distribution Smaller banks and public systems may face higher relative migration burdens Shared guidance, procurement templates, and phased compliance rather than cliff-edge deadlines

These signposts do not require public disclosure of sensitive system details. The useful signal is governance: whether the migration is owned, sequenced, tested, and incorporated into financial-stability supervision.

The least-harm path

The least-harm path is proportional and boring: inventory first, prioritization second, testing third, public confidence language only after the internal work is real.

For Indonesia, the highest-value sequence would likely begin with the systems whose disruption could transmit fastest: payment infrastructure, financial-market infrastructure, central-bank and treasury connectivity, large banks, FX and money-market participants, tax and customs interfaces, and critical third-party providers. Long-lived confidential data should be mapped separately because “harvest now, decrypt later” risk is about future exposure from today’s records.

This does not require frightening the public. In fact, fear language would be counterproductive. The better message is that cryptographic modernization is part of maintaining rupiah trust in a more digital financial system, just as reserves, liquidity tools, and prudential supervision maintain other parts of trust.

A credible plan may never be visible in daily exchange-rate data. That is the nature of avoided tail risk. The benefit is a smaller chance that a future technical migration, vendor failure, or cyber incident becomes a market-confidence event.

What I am uncertain about

I am uncertain about the true state of Indonesian institutional readiness because much of the relevant detail is, appropriately, not public.

I am uncertain about timing. The MIT-cited 2040 estimate is useful as a planning anchor, not a deadline. Quantum capability could arrive later, or practical attack conditions could remain constrained. It could also arrive unevenly across actors.

I am uncertain about pricing. Global investors may not price post-quantum readiness in Indonesian assets until after an incident somewhere else makes the channel salient.

I am uncertain about cost distribution. Large banks can usually absorb migration work more easily than smaller institutions, public agencies, or thin-margin vendors. If the burden is handled as a cliff-edge compliance cost, it could increase fragility rather than reduce it.

I am also uncertain about measurement. A cyber-risk premium would be difficult to separate from ordinary emerging-market risk. The practical answer is not to over-model it. It is to monitor the signposts, keep the claims modest, and treat cryptographic resilience as one quiet input into rupiah confidence.

The conclusion is narrow: post-quantum migration is not a reason to forecast rupiah depreciation. It is a reason to widen the definition of currency stability. In a digitized financial system, the rupiah is defended not only at the policy rate and the reserve desk, but also in the unseen work that keeps payments, settlement, and institutional trust intact.

Sources

  1. Building a practical path to post-quantum cryptography | MIT Technology Review — PQC transition as manageable evolution, MIT-cited 2040 RSA estimate, and harvest-now-decrypt-later risk
  2. Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography | NIST — NIST approval of FIPS 203, FIPS 204, and FIPS 205 for post-quantum cryptography
  3. Quantum-Readiness: Migration to Post-Quantum Cryptography | CISA — Quantum-readiness roadmap, cryptographic inventory, supply-chain assessment, and vendor engagement guidance
  4. FSB sets out a comprehensive approach to achieve greater convergence in cyber incident reporting — Cyber incidents can have cross-border and cross-sector spillovers; timely reporting supports financial stability
  5. Operational resilience in a macroprudential framework | Bank of England — Operational disruptions can create financial-stability impacts and recent incidents show digital and third-party dependencies
  6. Cyber resilience and financial market infrastructures | European Central Bank — Financial market infrastructures can transmit shocks across markets and put financial stability at risk
  7. Guidance on cyber resilience for financial market infrastructures | CPMI-IOSCO — FMI cyber resilience, financial-stability transmission, and two-hour recovery objective for critical operations
  8. Cyber risk stress testing for banks | BIS Financial Stability Institute — Cyber stress testing can identify vulnerabilities, response and recovery gaps, and financial-stability impacts
  9. Bank Indonesia Issues Regulation on Cybersecurity: A New Hope? | HPNC Counsels — Summary of Bank Indonesia Regulation 2/2024 covering cyber resilience for payment-system, money-market, and FX-market participants