NETS, which stands for Network for Electronic Transfer in Singapore, is Singapore’s primary electronic payment service provider and national debit scheme. A key player in Singapore’s payment ecosystem, NETS handles millions of transactions every day, processes huge amounts of data, and has multiple stakeholders.
The company started its quantum-safe migration process a few years ago, after realising the risks posed by quantum computers and related threats such as Harvest Now, Decrypt Later (HNDL) and Trust Now, Forge Later (TNFL).
At the inaugural Post-Quantum Security Summit 2026 in Singapore, jointly organised by Quantum Spectator and Frontier Enterprise, Abhisarika Singh, Vice President of Cybersecurity at NETS, explained NETS’ journey towards quantum readiness and how its crypto agility framework focuses on a phase-wise, service-based migration approach.
Assessing the quantum risk
When NETS discovered the quantum threat a few years ago, the organisation realised it was imperative that they understand and mitigate the risk as quickly as possible. Singh said, “We came to know about this a few years back, and it’s not about the technology; it’s about data risk. We came to know that there would be a risk in our cyber environment, and that we have to be ready in a few years’ time.”
“We knew that there is a data risk, and that there are two kinds of risks: Harvest Now, Decrypt Later (HNDL) and Trust Now, Forget Later (TNFL). We tried to understand what these risks are about,” she continued.
NETS asked a fundamental question, “Which risk is more important for us?”, leading them to study the quantum risk more deeply.
Singh explained, “In our environment, we use various cryptographic algorithms. For example, AES, SHA2, RSA, digital signature algorithms, ECDHA. When we drilled down on the problem, we saw that everything is going to be vulnerable soon because quantum computers will be mainstream really soon.”
Following that, NETS decided to develop a future-proof quantum strategy, which led them to explore Quantum Random Number Generation (QRNG), Quantum Key Distribution (QKD) and Post Quantum Cryptography (PQC).
Singh said, “When we analysed all three methods, we realized QRNG is easy to scale because it requires hardware and we can do it. There are solutions available. Then, between QKD and PQC, we asked, what is the best method? QKD definitely needs an environment with hardware and dedicated links, and scalability is quite challenging.”
Explaining why the organisation chose PQC, Singh explained, “There are many post-quantum algorithms available which are either lattice based or hash based. For example, CRYSTALS-Kyber, CRYSTALS-Dilithium, FALCON, and SPHINCS+. They are quite helpful. Although the risk is, even though they are scalable, they may be obsolete or have some vulnerabilities in a few years’ time. So we have to keep updating it.”
NETS’ migration strategy
Soon after exploring the quantum risk, NETS discovered three major challenges that could pose a hurdle to implementing their migration strategy. Singh describes them as (1) a diversity of requirements, (2) maintaining performance and reliability, and (3) business continuity.
She said, “The first challenge is there are different and distinct security, operational, and customer requirements. Some are critical applications; some are not very critical. The second challenge is that performance and reliability are very important for us. We cannot keep our customers waiting while we change the security aspects of our applications. And the third and most important is business continuity and customer experience. We have to keep business continuity a top priority, and that’s why we have to mitigate these challenges using our detailed migration strategy.”
To do this, NETS deduced that a successful migration requires business-wide readiness, strong governance, and phased execution. Rather than a risky “Big Bang” approach, the transition must be managed phase-by-phase and service-by-service, built on a thorough internal assessment of dependencies and risks.
The customer comes first
Singh then explained that, keeping the customer in mind, NETS chose to take a hybrid approach that combines classical cryptography (RSA, ECDSA) with post-quantum algorithms like ML-KEM. She added that this “creates a win-win situation for both business and security”.
She also pointed out three areas that a migration plan must address: application, infrastructure, and certificates. By prioritising the customer, NETS chose to focus on applications, and selected an application-level Proof of Concept (POC) to demonstrate first.
“We worked with one of our partners, and did our POC that way. That helped us protect our sensitive data in an easy way, without the tedious installation and complex operational challenges. The good points were that we got a better user experience, and end-to-end encryption was quite easy. But we are still on our journey. We have to work in a continuous way; it cannot be stopped overnight and it cannot be done in one day.”
Interoperability: A major roadblock
In spite of internal readiness, however, one of NETS’ biggest challenges has been in coordinating migration with external partners and stakeholders.
Singh said, “When we come to the external environment — because NETS is not working alone, we are working with our stakeholder banks, partners, vendors — there is another challenge. We have to work with them. We have to see if they have solutions available. If they don’t have solutions, we have to check their roadmaps. We have to push them to work towards it. And that was quite challenging, to be frank, because we have to create a shared target profile which would be applicable to everyone. It cannot be such that we use ML-KEM, but our partner doesn’t know it, and then we cannot communicate.”
Therefore, Singh said, NETS takes into consideration the readiness of different banks and vendors, ensuring that each step aligns with stakeholder capabilities. Concluding her presentation, she emphasized the need for continuous collaboration and ongoing efforts among all parties to ensure a smooth, successful transition.



