The quantum clock is ticking. PQStation is getting ready
An NTU spin-off is helping banks and government agencies find and fix the cryptographic blind spots that may be unearthed by quantum computers.
Adversaries are already collecting encrypted data they cannot yet read, betting that a powerful enough quantum computer will one day shatter the protection around it. Security researchers call this “harvest now, decrypt later,” and it is why the arrival of quantum computing has become a practical concern for any organisation holding data with a long shelf life.
PQStation, an NTU spin-off, points to the National Institute of Standards and Technology (NIST), a non-regulatory agency of the U.S. Department of Commerce, which estimates that cryptographically relevant quantum computers could arrive between 2030 and 2035, while migrating an enterprise to quantum-safe cryptography takes three to five years on average. For most organisations the challenge is that they do not know the location of their own cryptography.
The firm was founded in August 2024 to close that gap. Its co-founder and chief executive, Dr Prasanna Ravi, is a research scientist at NTU’s College of Computing and Data Science who has studied quantum security since 2017, when the United States began standardising post-quantum algorithms. His group kept spotting weaknesses in how those algorithms behaved on real devices, at a layer the broader standardisation effort had largely overlooked.
The research turned commercial as standardisation concluded and governments began pressing organisations to act. “What had felt theoretical started converting into regulatory language and procurement decisions,” Dr Ravi says. A S$250,000 proof-of-concept grant from NTUitive confirmed the instinct. “It’s very rare for research to translate into industry so fast,” he says, and the group set its papers aside to build a product.
What you cannot see
PQStation’s platform, QVision, begins with discovery. It runs a cryptographic inventory across an organisation, mapping where encryption is in browsers, mobile apps, servers and networks, then identifies which assets are exposed to quantum attack and sets out a migration roadmap.
The biggest surprise, Dr Ravi says, is how invisible the problem is. “Many organisations don’t know what cryptography is used, where it’s used, or how deeply embedded it is,” he says. “There’s very limited visibility, and almost no ownership or
governance.” The footprint is almost always larger than IT teams expect, from legacy libraries buried in vendor software, to hard-coded certificates in middleware, to deprecated algorithms left running in production for years.
The blind spot has consequences once migration starts. Working with Mastercard on a white paper, “Preparing for the Quantum-Safe Transition,” made the point concrete for Dr Ravi. Switching on a new algorithm is a production decision, he notes, not a configuration change, where performance must be tested, backward compatibility confirmed and both ends of every connection made to support it. Financial systems built on hardware security modules, inter-bank messaging and long-lived certificates have little tolerance for downtime. He describes a compounding problem he calls cryptographic debt, where firms bolt on proxies and gateways to cover vendors that are not yet quantum-safe, adding complexity that makes the eventual migration harder.
First mover advantage
Persuading senior leaders to spend on a threat that has not yet arrived is a separate task. To that end, Dr Ravi draws a parallel with insurance. Security is preparation for realistic scenarios, he notes, and a break in a widely used algorithm is realistic, as is the prospect of it happening more than once.
A recent episode drives the message home. A paper claimed to break the security guarantees behind ML-KEM, one of the NIST post-quantum standards; researchers later found a flaw in the proof. Dr Ravi calls it a close shave. “Cryptography you’ve never looked at is cryptography you don’t control,” he says. Firms that build an inventory and the means to swap algorithms while time allows can meet the next scare calmly. Those that wait will pay more to migrate under pressure.
A coherent ecosystem
For a startup selling security infrastructure, credibility counts as much as technology, and Dr Ravi credits Singapore’s policy environment for supplying it. He points to the Cyber Security Agency of Singapore (CSA)’s Quantum-Safe Migration Handbook, which PQStation contributed to, its companion Quantum Readiness Index, Infocomm Media Development Authority’s (IMDA)’s National Quantum-Safe Network and bank trials convened by the Monetary Authority of Singapore. The agencies consult vendors like PQStation as they draft these frameworks.
That support has been practical. The CSA’s Cyber Security R&D Programme at NTU awarded PQStation about S$750,000 and connected it with industry partners keen to pilot the early work. At CyberSG Innovation Day in November 2025, Senior Minister of State for Digital Development and Information Mr Tan Kiat How named the startup among the programme’s results, citing field trials with 10 partners across finance and homeland security.
Over the coming year, PQStation is extending QVision to on-premise and cloud environments and building a testbed of hardware security modules, key management and certificate systems, so regulators and enterprises can watch post-quantum cryptography run before committing to it. “They want to see it. Touch it. Feel it,” Dr Ravi says. He puts the post-quantum market at US$3–4 billion by 2030 and expects tighter regulation within the year to steepen adoption. For now the startup is validating with banks, government agencies and payment operators. “Security has always been about scenario preparation,” Dr Ravi says, “and this scenario of quantum attacks is very realistic.”
Read the full newsletter or subscribe to NTU I&E for the latest updates, events and programmes.



