
Elevator Ventures Podcast · 2025-04-30 · 24 min
Post-quantum cryptography has moved from a fringe concern to a critical regulatory imperative for financial institutions. Gartner named it a top-10 strategic technology trend, and NIST has set a 2030 deadline for migration - a timeline now adopted by national security agencies across Europe. The episode opens with a technical webinar between Petr Dvorak (Wultra CEO) and Yeri Pavlo (mathematical security expert at Raiffeisen Bank), who explain the existential threat quantum computers pose to current encryption standards like RSA and elliptic curve cryptography. Their discussion reveals the scope of the challenge: banks cannot simply swap algorithms - they must overhaul virtually every piece of software. The conversation touches on 'harvest now, decrypt later' attacks, where adversaries collect encrypted data today for future decryption when quantum capabilities arrive. Pavlo emphasizes that SHA-1, known to be broken for nearly 30 years, only recently fell out of use - illustrating how slow legacy technology transitions actually are. Wultra positions itself as the first fully packaged post-quantum authentication solution ready for immediate deployment. Dvorak, whose background includes a mobile banking development studio sold to Avast, founded Wultra to address the authentication gap he observed in the industry. He highlights Raiffeisen Bank as their first major customer, a critical reference point for competing against entrenched legacy vendors. The transition to post-quantum authentication isn't a background technical upgrade but requires re-enrolling all users - making it organizationally complex beyond its technical demands.
NIST set a 2030 deadline for post-quantum cryptography migration, adopted by national security agencies across Europe including Czech, French, and German agencies. Quantum computers will render current RSA and elliptic curve cryptography unsafe, and the regulatory pressure is rising across agencies and analyst firms like Gartner.
Attackers can collect encrypted data today that remains secure under current cryptography, but will become decryptable once quantum computers arrive. Organizations must consider the future value of information they protect today and ensure cryptographic protection outlasts the threat horizon.
No - it requires re-enrolling all users to new authentication methods and affects every encrypted system at a bank, not just customer-facing authentication. Banks cannot automatically convert legacy PIN codes or credentials; it requires planning and organizational change beyond technical implementation.
Wultra provides the first fully packaged post-quantum authentication solution ready for immediate deployment, plus migration blueprints to help institutions transition from legacy cryptography. The company was recognized as a rising star by Kuppinger Cole for this offering.
Banks should start immediately in 2025 with market research and vendor assessment. Waiting until 2029 forces 100% resource allocation just to meet the 2030 deadline, and every year of delay increases pressure on resources and vendor capacity.
Computed from the transcript - who did the talking, and the words that came up most.
Join Petr Dvořák, CEO and Founder of Wultra, as he explores the Post-Quantum Authentication and the future of banking. Hear highlights from his webinar with Jiri Pavlu, Mathematical Security Expert at Raiffeisenbank Czech Republic, as they discuss how banks can prepare for the post-quantum era. After that, our Senior Associate, Noémi Szabó, joins Petr to talk about Wultra's vision, its future, and why we’re excited to back this company. Watch the entire Webinar here ! Learn more about Wultra: Subscribe now for insights on the venture capital world, tech trends and market intelligence! Visit our Website: Reach out to us to send interesting startups, share your feedback, or just say hi at: office@elevator-ventures.com
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to a new episode of the Elevator Ventures podcast. I'm Mara Ene, the PRN Marketing Manager at EV and I'm excited to be your host in our journey through venture capital and innovation. From Vienna, right in the heart of Europe, we elevate your growth. Today's spotlight is on Vultra, one of our portfolio companies and a market leader in the cybersecurity space. Firstly, you'll hear the highlights of an insightful discussion between Petr Dvorak, CEO and founder of Vultra, and Egypt Pavlou, security expert at Trifeze and Bank Czech Republic. They explore the post quantum authentication in banking as part of an in depth webinar that is linked in the episode description. Make sure to check it out after listening to this podcast. Afterwards, our senior associate Noemi Sabo will join Petter for a conversation about Vultra's inception story, vision and future goals. Let's dive in. Hello everyone, once again, welcome.
Speaker B: Our webinar's topic today is post Quantum why banks should start the Transition today.
Speaker A: And the webinar will be led by two panelists today, our special guest, Yeri Pavlo, um, mathematical security expert at Raiffeisen bank and Petr Dvorak, Vultra's CEO and founder. So let me give the floor now
Speaker B: to Jiji and Petr.
Speaker C: Excellent. Thank you Magra for the introduction. Uh, quantum computers indeed pose quite a threat. I think that if you look at banks now and what they do, they mostly focus on artificial intelligence on the innovation side and topics like uh, compliance with PSD3, EUID wallet and other regulatory requirements. And what we are aiming today is to basically bring forward this uh, topic of post quantum cryptography which might be slightly unexpected because couple years ago it was not on the radar of anyone. Now the radar is uh, moving towards it quite dynamically. Let me just mention that if we look into what is post quantum cryptography, uh, it is uh, on the radar of Gartner who actually named it one uh, of top 10 strategic technology trends for 2022. Uh, it is not some selective category. These are overall strategic trends in technology and uh, they claim that quantum computing will render traditional cryptography unsafe by 2029. Uh, they uh, continue its work starting the post quantum cryptography transition now. Uh, they not only post uh, uh, quantum cryptography as a, like a general broad trend, but they actually also posted it in a hype cycle for digital banking transformation, uh, where it is uh, currently at the peak of inflated expectations with expected time to plateau in two to five years. But what is the impact on the bank, Hiriko? I mean I know that you cannot really talk about specifics of um, uh, how Raiffeisend bank is moving forward, but the impact in general is quite vast, isn't it?
Speaker D: Yeah, I mean if you consider everything uh, where you used secure connection and uh, you are not relying on some pre shared passwords and even then, sometimes then uh, you are relying on two, uh, or three algorithms. Uh, globally everyone is relying on the same algorithms. Three algorithms. And uh, those are exactly those algorithms which are vulnerable to quantum computers. It could be said that the quantum computers uh, cannot do that much. But uh, unfortunately the things that they can do really well are exactly those things that uh, we need to be hard for our, for our connections, for our networks to be secure. So in this sense it's a very unfortunate coincidence. Uh, but uh, it's the world we live in. So everywhere you encrypt something, everywhere you need uh, to certify something with electronic signatures. Everything that you can think of, uh, is uh, going to be broken basically.
Speaker C: That's extremely interesting because I think that people are underestimating the impact. But it seems that in the next couple of years banks will essentially have to operate every single piece of software in the organization to be ready for pqc.
Speaker D: Um, uh, basically yes. And uh, if someone thinks that uh, this is not so big deal, that well, here we have a box with one algorithm, here we have a box with another algorithm, we can just swap those boxes or just take one box out and plug another box in and that this is something that can be done in um, two, four, five years, then it's. Then that person is probably very mistaken. Um, an example from history, um, just one algorithm not as widely used as RSA. Uh, SHA1 function, hashing function. Uh, it was known currently it was, it's known for 20, 25, almost 30 years now that it's not secure and that it shouldn't be used like every. It shouldn't be used anywhere where you rely on its security properties. Uh, I think that the last time I've seen it used somewhere was two years ago. And currently you can break it on your regular computer. Like I have my laptop here and uh, I could just break it online with encryption.
Speaker C: Specifically, uh, I would say that we already have a problem in a sense. There is a bit of a discussion about the subject of harvest, uh, now decrypt later, which uh, is actually being used as the main business case motivator for switching from classical cryptography to post quantum cryptography. And essentially the idea is that if you have this timeline of uh, your decryption capabilities, you start with fully encrypted uh, data content which eventually will become weakly encrypted and eventually it can be fully decrypted. And uh, it means that uh, actually if you have some information worth protecting, um, you should probably think about when it's worth to start protecting it better. And what is the durability? Uh, are there any general guidelines on how to think about, let's say value of information we protect or how do you think about this, uh, in a bit more structured terms?
Speaker D: Well, you need to try to model your attacker that you are actually protecting yourself from. Um, again, useful mental. Why or why this is a useful mental model? Um, well, you need to know who is actually will actually be trying to get your data. I mean you cannot protect yourself from God, you cannot protect yourself from omniscient, omnipotent being. But uh, fortunately hackers are not gods. Not yet actually. So that's good news. And um, if you are trying just um, I mean if I were to just uh, encrypt my poetry, for example, if I were to write poetry and I would like not, I wouldn't like anyone to read it, I could protect it, I could encrypt it and then I would need to start thinking about who would actually like to read my poetry. If my poetry is so bad that no one would like to read it, probably no one will even try to break the encryption. So maybe I don't need to worry about migrating to post quantum cipher seeds. However, if my data has some value then um, uh, it will also have the same value or lesser value in uh, some defined time horizon, then I need to think about the time horizon. So if I suspect that um, an attacker would obtain $20,000 in 10 years if he has access to his data, then I should probably make sure that uh, it will cost the attacker more than $20,000 to break the data in 10 years.
Speaker C: Currently, uh, quite a lot of uh, drive uh, of post quantum cryptograph, uh uh, originated uh by basically standardization uh institutes and uh, national security agencies. NIST actually uh, set timeline to migrate to post quantum cryptography by 2030. And most uh, of the European nation actually signed uh an additional statement like common statement that they will follow this timeline including uh, ANSI from French or German National Security Agency or Czech national National Security Agency in our case. And this practically means that we have some five years or so to do the transition taking into account all the bubbles that we had in the beginning. This is actually quite a lot of work. It is still mostly um, driven by regulatory, not so much by actual threat of quantum computers. But if we want to meet the timeline, that's actually not easy for a bank to do because in 2025 which is now you probably haven't even budgeted for this, uh and so you cannot do any activities in next year. You should be conducting uh, basically market research, understanding uh, how your vendors are getting ready for post quantum cryptography if they can uh, fulfill the requirement or if you have to replace them, then there is a replacement year uh that uh, you will be conducting RFPs and uh, doing vendor selection. Then uh, there is next year projects and migration which will take more time than you probably allocate because as I said I mentioned you have to replace uh almost everything. And uh, then you will have to deprecate legacy solutions and basically put them out of business. And uh, this means that if you want to make it by 20302026 is probably the latest, you can start with some activities uh, in your organization. Because we are slowly running out of time. Let me just uh, quickly wrap it up and IRCOY will be happy for your closing remarks. So the way we currently see it at Vultra is that the QD is approaching right, and uh, regulatory uh push is essentially towards the year 2030. Even though we might not be having this uh, practically usable quantum computer by that time. The regulatory pressure overall is rising. Not um, only by regulatory uh agencies, but you are also pushed by commercial agencies like Gartner and other consultants. And what you should take uh into account is that transition takes time. What would you uh, like suggest your colleagues from banks and people uh to think about as the next step of this discussion that we had?
Speaker D: Well you really need start preparing now and uh, everything points to the year 2030 as being the latest where you need to migrate. And it really for banks it really doesn't matter whether they need to migrate because of regulatory requirements or practical quantum computers. You don't really care. You just need to migrate. So whatever the reason, you have to migrate. And uh, if you want uh, some help maybe uh, I can only recommend uh the PQC Migration Handbook from tno. It's European Organization from Netherlands I believe and they've prepared rather, rather thick book on uh, how to best plan and prepare for quantum my post quantum migration. It's. I can recommend this if you need something which you could do now. You should probably read this.
Speaker C: Thank you. That's a really helpful uh, Suggestion and good reading recommendation. Definitely. We can put it in later, follow up as a link uh, to uh, to our audience. Thank you so much Erko for the discussion. Uh, thank you very much. It was super interesting.
Speaker B: Hello Peter. That was a very insightful webinar you had with Yiji. And we encourage our audience to listen to the full recording linked in the description down below. Thank you for taking the time now to be part of our own podcast at Elevator Ventures. We believe in world transmission and want our audience to learn more about it as well.
Speaker C: Thank you so much Nami for the invitation.
Speaker B: So Peter, can uh, you share a bit more about your background and what motivated you to start Vultra? What was the original vision and how has that evolved over time as the company has grown?
Speaker C: Sure. So it actually all started when uh, my partners and I sold uh, our previous company to Avast. The previous company was basically a mobile development studio. Um, it was uh, uh, building banking applications in uh, mainly Czech Republic but also Cee. And so very quickly after I joined Avast, I actually realized that um, uh, this employee status is not for me and I uh, wanted uh, some uh, new challenge and I decided to build something new. And uh, what I noticed quickly is that uh, banks are struggling with some topics with authentication and cybersecurity in general. They do not build it in house. And this was the time when mobile banking and digital banking was uh, evolving quite dramatically. So I decided to basically take this uh, opportunity um, because it was something I perfectly understood. I knew how these things work. I had a strong foundation from, from uh, the Charles University in Prague in terms of uh, theoretical computer science. And so I went for it. I uh, decided to build uh, cybersecurity solutions for the banks. And uh, uh, later on we narrowed down the vision more clearly towards the authentication. So our vision over time hasn't really changed so much. But I think that we communicated it more clearly now as we are growing bigger. Um, actually I can see that the less we uh, communicate now the more successful we are because everyone is uh, more clear on what we actually do and uh, understands our topic. So over time we have the same vision with clearer uh, more narrow communication which uh, uh, I think is quite understandable because if you are early stage startup, we start by not really knowing what you do and uh, later on as it becomes more clear it's also easier to communicate it uh, from a
Speaker B: broader perspective whether it's regulatory, technological or market related. What major challenges have you faced and how did you overcome them?
Speaker C: So first of all as A CE company. Of course we are strong in technology. That's not uh, a big issue for us. On a technology part we are actually pretty fast and that's uh, one of our main advantages. This also helps us to keep up with all the regulation that is changing quite dramatically. Europe is notoriously regulated. So except for our uh, fast uh, pace of technology advancement, we also decided to invest in operations uh, quite uh, early on so that we can get all the certification, we can get all the pen testing. We are always compliant with what's coming. Uh, so this is also something we managed to um, somehow um, solve just by keeping up fast enough. I would say our biggest challenge currently is basically how do we market the company globally because our potential is to become a global company. That's what we would like to achieve. And it's not really easy to compete with our legacy, well established competition that um, is already recognized by our customers. So I think the first step for us to overcome this challenge was to get the first large customer. Uh, we are happy to say that this was Raiffeisen bank in the Czech Republic. We m managed to get our first big reference and uh, as a result we were much more trustworthy and we are still building the trust. Um, because I understand the customer perspective. It is always a bit challenging to bet on a new player on the market. It's always safer to go for somebody who is already recognized. But it comes with price, it comes with uh, slow innovation, it comes with slow deployments, uh, higher costs of total ownership of the software. And this is what we are communicating to our customers, that we can have actually better product that is uh, innovating faster, bringing new features faster. It can help all the financial institutions that we work with compete with uh, uh, other companies much better. And we uh, can be cost competitive so to speak. So I would say that our biggest challenge was basically marketing sales from the Central European context. That's what we are currently working on the most.
Speaker B: After mentioning this, um, how do you see the future of post quantum authentication shaping up, especially in the banking sector. So uh, what role is Vulture playing in this shift and what excites you the most about it?
Speaker C: Yep. So I think we can spend uh, a minute uh, just defining what post quantum authentication is, because that's a new subject. So basically people know authentication and banking services as um, entering the PIN code to approve a payment or uh, confirming something via push notification or logging in with the QR code and uh, using touch ID or face ID for authentication in mobile apps. The problem is that all of this uh, uh, technology that we commonly know and commonly use is based on legacy cryptographic algorithms, typically RSA or elliptic curve cryptography. Sorry for being a bit technical now but uh, it's important to get the understanding. Um, the problem is that with quantum computers all this authentication will suddenly bring no trust to our transactions PAYMENTS LOG and so post quantum authentication is essentially authentication which is resistant to quantum threats in all uh, possible touchpoints and use cases. And it's a completely new topic. Actually it is a topic which is inevitable. Uh, that's something that everybody will have to somehow adopt uh, if they want to stay uh, in the business. There is currently deadline by 2030, uh essentially introduced by NIST, then adopted by any and local cybersecurity agencies or the migration. And uh, so there is actually something that has to be done by 2030 uh and we are happy to say, and this is the exciting part that we are leading in the topic of post quantum authentication. We are basically the first company that provides a fully packaged solution that can be deployed tomorrow. We were recently recognized as a rising star by Kupinger Coal, a leading analyst in the digital identity. And hopefully uh, hopefully uh, this will help us uh, gain market share and uh, more traction. Now from the banking perspective, um, banks will be among the first adopters of post quantum authentication because they actually have some valuable assets to protect. They need trust of their customers. But there is also the regulation that we mentioned earlier. Uh, for example DORA regulation specifically requires banks to have up to date cryptographic algorithms. So in this sense regulation is actually playing in our favor. It helps us to convince the customers about the need of uh, our solutions. And so we are hoping that with this uh, tidal change in the next five years we will um, be able to convince as many customers as possible to basically uh, switch to our solutions because we understand their challenge, we understand this will be difficult. Uh, for banks. It's quite hard to do it. Uh, they have to do it to remain in business.
Speaker B: Speaking of this, what should financial institutions know before integrating this kind of tech? How does Woodrow help simplify the transition and what are the steps to begin with when implementing the solution?
Speaker C: Yeah, so thing that they should know is that uh, that's not a simple drop in replacement, something that will happen automatically in the background. Uh essentially they need to start early if they want to uh, have everything ready by UH 2030 every year which they delay, uh this switch will put more pressure on their resources and on their vendors. Mainly because if they start in 2029 they will basically allocate 100% of their resources just to post quantum authentication and post quantum cryptography in general. Because post quantum cryptography doesn't only affect, um, authentication, it basically affects every piece of software in, at the bank. So in the next five years, banks essentially have to update everything and if they delay it, that's a big issue. And so specifically with authentication, the project actually has impact on end users. So um, they will have to re enroll all the users back to uh, a newer authentication. You cannot magically convert PIN code, uh, from legacy authentication to the new one. So that's a bit of a challenge. It requires planning, uh, it's not a simple drop in replacement. And the way we can help is that we uh, first of all have a technology which is ready today, so they can deploy it today, they can uh, have it a little bit less stressful. But at the same time we have a blueprint project, so to speak, how to migrate our customers or our prospects from legacy cryptography to, to the new one to new authentication technology. So this is something that we can also help them with.
Speaker B: That's great. I think it clearly gives, uh, the message. Thank you Peter. That was incredibly insightful. We truly appreciate you sharing your expertise with us today and we also encourage our listeners to check out Woodra's website. It's a great company driving innovation in the cyber security field. Thanks again for being part of the podcast.
Speaker C: Awesome. Thank you so much and have a great day.
Speaker B: Thank you.
Speaker A: That wraps up another episode of the Elevator Ventures podcast. If you like this episode, make sure to subscribe to our channel and leave us a review on your favorite podcast platforms. Also, if you'd like to be featured, know an interesting startup or just say hi, send us your thoughts, uh, @officelevator ventures.com until next time, keep elevating your growth.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.