Back to research

S&P Global Ratings — RatingsDirect

April 1, 2026

The Frontier Of Cyber Risk: Crypto, Quantum, And AI

Three converging technology frontiers — decentralized finance, quantum computing, and AI — are individually and jointly reshaping cyber risk for credit markets and the issuers S&P Global Ratings covers.

Contributing author:Cristina Polizu, Benjamin Heinrich, Raam Ratnam, Alexander J. Gombach, Sudeep K. Kesh, Xu Han
Artificial IntelligenceQuantum ComputingCrypto Assets

Key Takeaways

  • As the frontiers of technology advance, new and escalating cyber threats could undermine the security of critical data and challenge existing safeguards, resulting in heightened operational and reputational risks that ultimately affect issuers' creditworthiness.
  • Cyberattacks on the crypto-asset ecosystem will increase as it grows and becomes more central to financial systems, raising the risk of an event with credit implications for both digital assets and issuers across asset classes and sectors.
  • Quantum computing could break the cryptography that underpins much of today's data security, exposing digital assets and organizations that rely on digital authentication and encrypted communications to significant new cyberthreats.
  • AI will continue to facilitate mass production of cyberattacks and create new attack vectors that bypass traditional safeguards, exploit cross-modal trust, and manipulate agent reasoning and decision-making.

Cyber risk is never static. Changes in technology and tactics ensure that threats, defenses, and the cyber battlefield itself are in a constant state of flux. These changes can be incremental, driven by existing factors, but technological innovation — and the innovative use of existing technologies — at the frontiers of cyber risk can give rise to sudden, fundamental shifts with ramifications for the entire cyber landscape.

S&P Global Ratings considers quantum computing, AI, and the growing role of decentralized finance and cryptocurrencies to be catalysts for this sort of radical change. Individually and in combination, they threaten new cyber vulnerabilities that could compromise the security and stability of credit instruments, markets, and the creditworthiness of issuers.

Crypto, Quantum, And AI Are The Key Frontiers Of New Cyber Risk

Risks emerging at the frontiers of cyber often involve new technologies and are thus potentially overlooked or misunderstood. Established cybersecurity measures may be ill-equipped to mitigate these threats. Effective response requires understanding the risks well enough to underpin proactive cybersecurity that prepares organizations for known threats, anticipates new threats, and can react rapidly to unforeseen ones. Against this backdrop, this overview accompanies a series of companion reports examining three key cyber risk frontiers.

Crypto assets

As the crypto-asset ecosystem expands and integrates further into mainstream finance, the potential for a crypto-centric cyber event to have significant or widespread ramifications is growing. We expect the frequency of cyberattacks on crypto assets and platforms to increase. A significant event could damage the ecosystem's reputation, affect market confidence, reduce user activity, and potentially trigger a massive liquidation of crypto assets, as has occurred previously.

Quantum computing

The development and widespread adoption of quantum computing threatens the viability of existing public-key cryptography, which underpins digital security. This threat affects every industry that relies on digital authentication and encrypted communications. Consideration of associated risks will have to begin ahead of quantum computing's deployment to be ready for the necessary cryptography transition.

AI

The emergence of AI has increased the risk of cyberattacks by enabling the mass production of traditional attacks and introducing new attack vectors. Retrieval-augmented generation (RAG), which allows large language models to retrieve data beyond their original training set, appears particularly susceptible: direct injection bypasses safety guardrails, indirect injection hides malicious instructions in processed data, and RAG poisoning compromises data to propagate incorrect or harmful responses. These attacks can bypass security measures, manipulate agent reasoning and decision-making, and lead to unauthorized data exfiltration and goal hijacking.

Cyber Risk Is Credit Quality Risk

Cyberattacks have generally had limited effects on credit quality where proactive and robust risk management, sufficient insurance, or adequate liquidity are in place. Negative rating actions linked to cybersecurity incidents occur where core business processes undergo significant disruption, recovery proves slow due to weak risk management, or financial damage is significant. Examples include Change Healthcare, whose outage disrupted payments across the healthcare services sector and contributed to two downgrades; Jaguar Land Rover Automotive, where a cyber incident materially affected production and sales; and the City of Hamilton, a Canadian municipality that experienced delays reconciling audited financial statements following a 2024 cyberattack.

New technologies, emerging in a period of heightened global geopolitical tension, could also amplify the already-increased volume of state-sponsored cyberattacks — including by proxies — targeting critical infrastructure. Indicators of inadequate cyber preparedness often include insufficient investment in emerging technologies and defenses, the absence of a formal cyber risk framework, unclear assignment of management responsibility, or a lack of a comprehensive incident response plan.

The Time To Prepare Is Now; The Time To Assess Is Always

Crypto assets' increasing adoption will continue to press the need for users and platforms to strengthen security practices. Quantum computing will require assessment of cryptography use across systems, identifying and protecting data with confidentiality requirements, and tracking dependencies on vulnerable public-key algorithms — a transition to post-quantum cryptography we expect to be investment-intensive and multiyear, involving vendors, standards bodies, and regulators. AI risks will continue to evolve rapidly; resilience to emerging and possibly unforeseen issues will require robust governance frameworks, self-healing architecture, and machine learning cybersecurity applications. Prioritizing resilience across all three frontiers will be key to addressing their potential credit implications.

The views expressed are those of the authors and do not necessarily reflect the opinions of S&P Global.