Stablecoins and tokenised real-world assets are pulling banks, neobanks and other regulated institutions deeper and more willingly into digital markets.

According to Blair Canavan, Director of Alliances for the Post Quantum Cryptography (PQC) Portfolio at Thales, digital assets are moving out of niche pilots and into supported financial infrastructure.

As he explains, stablecoins are being tested for various things from payments to treasury operations, while tokenisation is opening new ways to issue, manage and transfer traditional instruments.

Blair attributes the shift to evolving business demand rather than novelty.

Institutions are looking to improve settlement efficiency and build new value-based services for customers.

Regulatory frameworks are also becoming clearer in many markets, while the underlying technology has matured significantly.

Growing adoption, he argues, pushes the conversation beyond blockchain technology itself.

Blair Canavan
Blair Canavan

“The real question is how institutions build the trust, governance and

resilience needed to operate digital financial services securely and at scale,” Blair says.

Security Has Outgrown the Wallet

As digital assets become increasingly leveraged within regulated financial services, institutions must demonstrate not only that all assets are protected but also that every transaction is governed, accountable, and auditable.

Private key protection remains foundational, Blair points out, but the scope of responsibility for institutions has expanded well beyond it as digital assets move into mainstream financial operations.

Institutions are now managing risk across the entire transaction lifecycle, covering both operational risk and insider risk.

Policy controls and governance checks keep any individual from holding unchecked authority.

Compliance adds a third layer, maintained through the auditability and transparency regulators increasingly expect.

Business continuity is a serious consideration too, with institutions needing infrastructure resilient enough to support secure operations and recovery without putting sensitive cryptographic assets at risk.

The focus, as adoption matures, shifts from safeguarding keys to building operational environments that support governance, accountability and resilience at scale, he adds.

“The key question is no longer just whether a private key is protected, but whether the entire ecosystem around it can be trusted to operate securely, consistently and transparently,” he explains.

What a Complete Trust Framework Looks Like

A complete trust framework, in Blair’s view, combines several complementary capabilities.

Security protects cryptographic keys and other sensitive assets throughout their lifecycle.

Governance defines who can approve transactions, how authority is delegated, and how policies are enforced consistently across an organisation.

Compliance provides evidence, through audit records and reporting, that those controls are actually working.

Interoperability also matters because institutions rarely run on a single blockchain or technology environment.

Trust cannot stop at organisational boundaries; it must extend consistently across industry partners, platforms and networks.

They need consistent security, governance and operational controls across multiple networks and existing banking infrastructure.

Resilience ensures services stay available and recover securely from failures or cyber incidents.

Blair also flags crypto agility as a strategic capability in its own right, alongside the other five.

Institutions, he argues, are designing systems that can adopt new standards, including NIST-approved post-quantum algorithms, with minimal disruption, rather than assuming today’s cryptography will remain sufficient indefinitely.

Trust Requires Distributed Authority

“Good governance is about ensuring that trust is adequately distributed rather than concentrated,” Blair says.

Of the six pillars, governance is often considered the hardest to put into practice, and Blair reasons this is because it requires separating responsibilities, so no individual, application or administrator holds end-to-end control over critical operations.

In practice, one team might initiate a transaction, another might review it, and further approvals kick in depending on the transaction’s value, destination or risk profile.

Policy engines can automate much of this, applying approvals consistently rather than relying on manual processes.

Technology supports governance, Blair maintains, but governance itself remains an organisational discipline that creates accountability throughout the transaction lifecycle.

Designing Auditability In From Day One

Auditability should be designed into an institution’s architecture from day one, according to Blair. It must not be retroactively added once regulators start asking questions.

Meeting that standard means capturing reliable evidence of every critical operation, including who approved it and how it was protected.

Those records need to feed into operational monitoring, governance and compliance systems, he stresses, to support forensic investigations and regulatory reporting without manual reconstruction after the fact.

“Organisations that operate most successfully are those that treat auditability as part of the operational design rather than as a reporting exercise,” Blair notes.

Where Banks Hit Friction Connecting Old and New

One of the biggest challenges institutions face is consistency, Blair observes.

Banks are integrating new digital asset platforms into existing and evolving infrastructure rather than replacing it overnight.

Different blockchain networks bring different operational models, governance requirements and cryptographic implementations.

Maintaining consistent security policies and access controls across those environments is significantly harder than securing any single platform.

“Success depends on building common trust services that span traditional and digital infrastructure rather than treating each blockchain as a separate technology island,” Blair contends.

Resilience Beyond Disaster Recovery on Paper

Operational resilience, Blair says, is about maintaining trusted services through both expected and unexpected events.

It requires staying available and recovering without compromising cryptographic integrity or governance controls.

Equally important is exercising those capabilities regularly.

Recovery plans that exist only on paper offer limited assurance, he notes. Institutions need confidence that systems, teams and processes will actually work together under real conditions.

“Resilience is ultimately measured by how effectively an organisation continues operating when something goes wrong,” he adds.

Crypto Agility Without the Quantum Panic

In January 2026, the G7 Cyber Expert Group, co-chaired by the US Treasury and the Bank of England, published a roadmap urging financial institutions to migrate critical systems to post-quantum cryptography between 2030 and 2032, with a wider transition target of 2035.

Deadlines like that can cause alarm, but Blair’s advice is not to overreact.

“The important message isn’t to panic about the imminent emergence of quantum computing platforms,” Blair insists. “It’s to recognise that cryptography has always evolved, and it will continue to evolve as needed.”

Crypto agility means designing infrastructure so algorithms, keys and certificates can be updated as standards change, without requiring a full architectural rebuild each time.

The principle, he points out, applies well beyond post-quantum cryptography, supporting regulatory change and evolving industry standards more broadly.

G7 isn’t the only deadline drawing attention. Google has set a public target for its own migration, committing in March 2026 to complete its transition to post-quantum cryptography by 2029.

For banks and fintechs still watching from the sidelines, Blair’s advice is not to rip and replace existing infrastructure.

The first step is understanding where and how cryptography is used across the organisation, and whether current systems can evolve over time.

Those existing investments, he adds, will continue to provide value, much of it for years to come.

From there, the priority is to assess whether those platforms already support crypto agility, then to build a phased migration strategy aligned with emerging standards and business priorities.

Post-quantum migration, he continues, will be a journey rather than a single project, and organisations that start assessing and planning early can spread the effort out rather than facing urgent pressure later.

“Better a month early, rather than a day late,” Blair says.

The HSM as the Infrastructure Underneath It All

Rather than a standalone security product, Blair positions the hardware security module, or HSM, as one of the foundational trust anchors within this wider framework.

It establishes a certified, hardware-rooted environment for generating and protecting cryptographic keys, though its value extends beyond key protection alone.

When integrated with governance policies, identity systems, transaction workflows and compliance processes, the HSM helps ensure that cryptographic authority is exercised in a controlled, auditable, and policy-driven way.

As institutions adopt new cryptographic standards, including post-quantum algorithms, the HSM underpins the entire infrastructure supporting long-term cryptographic evolution.

“Rather than being viewed as an isolated security device, it becomes an enabling component of resilient, trusted digital financial infrastructure,” Blair says.

What Separates the Institutions That Get This Right

Asked what will separate the institutions that get this right from those that do not, Blair contends success will not necessarily go to whoever adopted digital assets first.

“They’ll be the ones that built trust into their platforms from the beginning, and not as an afterthought,” he maintains.

Those institutions will treat the six pillars as strategic capabilities, not standalone projects.

Their architecture can evolve as standards, regulations and cryptographic requirements change, without requiring a fundamental redesign each time.

Blair expects institutions that optimise purely for speed of deployment, without building the operational foundations to scale, to struggle.

“In the long run, digital finance won’t be defined by who implemented blockchain the fastest. It will be defined by those who designed and built infrastructure that their customers, regulators and business partners can continue to trust as the ecosystem evolves,” Blair says.

Featured image: Edited by Fintech News Singapore based on an image by Frolopiaton Palm via Magnific.