{"id":"c834d6be-2a43-48c4-a553-7272db5fcbb1","arxiv_id":"2506.12096","paper_version":2,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":2.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A systematic literature review concludes that quantum-resistant cryptography and quantum key distribution are necessary to secure accounting and finance systems against future quantum attacks.","lead":"This paper reviews how quantum computers could break today's encryption used in accounting and finance, and argues that quantum-resistant algorithms and quantum key distribution are needed to secure future financial systems. It matters because organizations are urged to plan post-quantum security transitions, and this review offers a conceptual framework for that planning.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The central claim overreaches: QKD is presented as necessary even though the paper's own PQC discussion and NIST-standardized post-quantum algorithms provide quantum-resistant key establishment without QKD, making the conclusion internally inconsistent and unsupported.","rationale":"The reader's weakest-assumption analysis focused on the unreliable article selection counts in Section 4.2.1. That is a legitimate methodological concern, but it is not the most load-bearing problem for the central claim. Even a perfectly executed systematic review would not justify the conclusion that QKD is necessary, because the paper's own analysis relies on PQC as sufficient protection against quantum attacks, and NIST-standardized PQC provides quantum-resistant key establishment without QKD. The stronger and more central concern is the internal inconsistency between the sufficiency of PQC in the propositions and the necessity of QKD in the abstract and conclusion. The paper also contains technical inaccuracies, such as describing Shor's algorithm as running on a 100-bit quantum computer and claiming Grover's algorithm makes encryption 'more secure', that further undermine confidence in the technical framing. However, the core recommendation that accounting and finance organizations should move to quantum-resistant cryptography is mainstream and correct, and the QKD overclaim is correctable in revision. Therefore the reader's conditional verdict remains appropriate; I do not propose moving to accept or reject, but the revision should explicitly remove or hedge the claim that QKD is necessary.","tokens_in":31626,"tokens_out":4118,"duration_ms":49038,"concrete_test":"Extract from the final 54 selected articles (Flow Diagram 1) every explicit statement that QKD is 'necessary', 'required', or 'essential'; then independently verify whether any selected source demonstrates that NIST-standardized PQC (e.g., FIPS 203 ML-KEM, FIPS 204 ML-DSA) is insufficient for accounting/finance confidentiality or integrity. If no source establishes PQC insufficiency, revise the abstract and Section 8.0 to say PQC is necessary and QKD is one possible enhancement. As a second check, re-run the literature synthesis with 'QKD' removed from the search string; if the same quantum-resistant conclusion survives, QKD is demonstrably not necessary.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The abstract and Section 8.0 conclude that quantum-resistant algorithms and QKD are 'necessary' for securing accounting and finance systems. The paper never supplies an argument that PQC alone is insufficient. In fact, Section 3.4.1 and Section 5.1.1 treat lattice-based PQC (Kyber, Dilithium) as sufficient to resist Shor's and Grover's attacks, which undercuts the claim that QKD is also necessary. QKD is a key-establishment mechanism with known limitations (distance, trusted relays, implementation attacks), and NIST-standardized PQC (FIPS 203/204/205) already provides quantum-resistant key establishment and digital signatures without QKD. The paper also conflates QKD with encryption in Section 5.2, calling it 'unbreakable encryption', which is technically inaccurate. The necessity claim is therefore both internally inconsistent and outside the current consensus. The literature-selection problems identified by the reader are real, but they are not the most load-bearing issue: even if the 54-article corpus were perfectly representative, the conclusion that QKD is necessary would still be unsupported by the paper's own evidence. The broad recommendation to adopt PQC is sound, but the specific addition of QKD as a requirement should be weakened to 'one optional enhancement' unless direct evidence of PQC insufficiency is provided.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper presents a systematic literature review (PSALSAR) of quantum computing and cybersecurity in accounting and finance. It develops an integrated conceptual framework that adapts Thompson et al.'s personal computing utilization model and adds two quantum-specific constructs (quantum resistance of accounting algorithms and QKD integration), then uses the framework to evaluate four propositions. The article concludes that quantum-resistant algorithms and quantum key distribution (QKD) are necessary for securing future accounting and finance systems, recommending that organizations transition encryption infrastructure to post-quantum primitives and consider QKD.","tokens_in":31909,"tokens_out":3755,"duration_ms":42473,"significance":"If the underlying corpus were reliable, the paper would provide a useful interdisciplinary synthesis and a structured framework for studying quantum security adoption in accounting and finance. Its mapping of research gaps to propositions, explicit use of a systematic review protocol, and attention to organizational and human factors are genuine strengths. However, the central conclusion about QKD necessity is not supported by the paper's own evidence, and the reported literature-selection counts do not reconcile. The study should therefore be treated as a promising framework paper whose empirical grounding and concluding claims need substantial revision. There are no machine-checked proofs or reproducible code in the manuscript; its value rests on the systematic-review synthesis, which currently has arithmetic and documentation problems.","major_comments":[{"comment":"The article screening counts are arithmetically inconsistent and do not reproduce the final corpus of 54 papers. Starting from 3,006 retrieved records, the manuscript removes 57 duplicates, 12 non-English documents, and 353 exclusions, leaving 2,584 records, but the next sentence reports 212 records after a time filter. Subsequently it states that 1,024 publications were eliminated and then that 894 more articles were dropped, yielding 454 articles, which is impossible from the preceding counts. Because the 54-article corpus is the evidence base for the propositions and framework in Sections 3 and 5, this must be corrected and the flow diagram reconciled with the narrative.","section":"Section 4.2.1, Flow Diagram No.1"},{"comment":"The complexity of Shor's algorithm is misstated as O(log N), and the claim that a functional 100-bit quantum computer could break RSA in hours or days is technically inaccurate. Shor's factoring algorithm has polynomial complexity in the number of bits, not O(log N), and the resource estimates for breaking realistic RSA key sizes require thousands of logical qubits. These inaccuracies matter because the paper's urgency and its 'necessary' security recommendation are based on the expected impact of Shor's algorithm; the threat assessment should be corrected to reflect the actual complexity and resource requirements.","section":"Section 2.6.2, Peter Shor's concept"},{"comment":"The conclusion that QKD is necessary for securing accounting and finance systems is unsupported by, and inconsistent with, the paper's own discussion. Section 5.1.1 and Section 5.2 state that lattice-based post-quantum cryptography (Kyber, Dilithium) resists Shor's and Grover's algorithms and provides quantum-resistant key establishment, yet no argument is given that PQC alone is insufficient. The paper also describes QKD as 'unbreakable encryption' and treats it as performing encryption, whereas QKD is a key-establishment mechanism with known limitations (distance, trusted relays, implementation attacks) and is not equivalent to encryption. The recommendation should be weakened to: post-quantum algorithms are necessary, and QKD is an optional enhancement, unless direct evidence of PQC insufficiency is provided.","section":"Abstract and Section 8.0"},{"comment":"The claimed 'testing' of the four propositions is not an independent test. The propositions are formulated in Section 3.4 from the same systematic literature synthesis that is then cited in Section 5.1 as evidence for each proposition. This creates a circular structure in which the literature both generates and confirms the propositions. The manuscript should acknowledge this explicitly and reframe Section 5.1 as a thematic synthesis or illustrative mapping rather than an empirical test of the propositions.","section":"Section 5.1, Testing of Propositions"}],"minor_comments":[{"comment":"The table cites 'Booth et al. [12]' for the PICOC definition, but reference [12] in the reference list is Sandhu (2021), not Booth et al.; the citation should be corrected or the reference added.","section":"Table 3"},{"comment":"The Thompson et al. (1991) model is inconsistently cited as [6], [46], and [47] in different places; the reference numbering should be reconciled throughout.","section":"Sections 3.1, 3.2, 5.0"},{"comment":"The text refers to 'the researcher [309]', but the reference list contains only 118 entries; this and other orphan citations should be fixed.","section":"Section 2.2.1"},{"comment":"There is a typo in the inclusion criteria: 'Papars' should be 'Papers'.","section":"Table 4"},{"comment":"The notation '0((N)^1/2)' should be 'O(\\sqrt{N})' for the number of Grover iterations; the current notation is nonstandard and confusing.","section":"Section 2.6.2"},{"comment":"The description of a qubit as a 'microorganism' appears to be a typo for 'microscopic object' or 'physical system'.","section":"Section 2.2.2"}],"recommendation":"major_revision","confidential_remarks":"The manuscript's central PQC recommendation is broadly sound and the framework has potential value, but the unsupported necessity claim about QKD and the unreconcilable screening counts are load-bearing issues. Both are fixable within the manuscript's scope: the conclusion can be weakened to match the evidence, and the systematic review numbers can be corrected or transparently reported. I would not recommend rejection, but the current version should not be published without addressing these points."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear colleague,\n\nThe punchline: this is a systematic literature review applying the PSALSAR method to quantum computing and cybersecurity in accounting and finance. The broad recommendation—that the sector should plan for post-quantum cryptography—is sensible and consistent with the wider consensus. But the paper oversells QKD as necessary, and its methodology section has reconciliation problems that would need fixing before I'd trust the corpus.\n\nWhat's actually here: a structured search of Scopus and WoS, a conceptual framework layering Thompson's adoption model with quantum-specific constructs, and four propositions tested against the literature. The literature synthesis is reasonably broad, and the mapping to accounting workflows (audit trails, cloud bookkeeping, interbank communication) is useful for practitioners who need a starting point. The paper correctly identifies Shor's and Grover's threats to RSA/ECC and points to NIST's PQC candidates (Kyber, Dilithium) as replacements. That is accurate and timely.\n\nThe soft spots: First, the selection arithmetic doesn't add up. The paper reports 3,006 retrieved, then 57 duplicates, 12 non-English, 353 excluded, a time filter, then \"212 articles,\" then \"454\" after exclusions that should have reduced the count. The numbers are never reconciled, and the final drop to 54 is not explained from 454. That undermines the claim of systematic rigor. Second, there are technical inaccuracies: Shor's algorithm is stated as O(log N) time, which is wrong (it's polynomial in the number of bits, and even the paper elsewhere says polynomial); a \"functional 100-bit quantum computer\" would not break RSA in hours or days—that's off by many orders of magnitude. Third, and most load-bearing, the conclusion that QKD is \"necessary\" is not supported by the paper's own evidence. The authors themselves treat lattice-based PQC as sufficient to resist quantum attacks, and NIST-standardized algorithms already provide quantum-resistant key establishment. QKD is a legitimate option, but calling it necessary is an overreach that the paper does not justify. The correct fix is to weaken that claim to \"optional enhancement\" unless the authors can show PQC insufficiency.\n\nWho should read it: accounting and finance professionals wanting a survey of the threat landscape and a framework for thinking about adoption. Not a technical audience.\n\nRecommendation: if the authors correct the count reconciliation, fix the technical errors, and soften the QKD necessity claim, the paper could pass as a serviceable review. As it stands, I'd send it back for major revision rather than desk reject, because the core direction is right and the flaws are fixable. It deserves a serious referee if the editors are willing to require those revisions.","headline":"A serviceable but flawed systematic review: the PQC recommendation is sound, the QKD necessity claim is overreach, and the selection counts don't reconcile.","tokens_in":32394,"tokens_out":1928,"would_cite":false,"duration_ms":21535,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Quantum-safe crypto and QKD are finance's future, review finds","keywords":["Quantum Computing","Cybersecurity","Accounting","Finance","Quantum Key Distribution","Post-Quantum Cryptography","Systematic Literature Review","PSALSAR"],"falsifier":"Run Shor's algorithm on a fault-tolerant quantum computer against the RSA key sizes used in financial reporting; the paper cites an estimate that 2048-bit RSA could be factored in about 8 hours with 20 million noisy qubits. Success would confirm the threat, while a failure of that scale, or a demonstration that financial systems remain secure through classical encryption alone, would contradict the paper's claim that post-quantum algorithms and QKD are necessary.","tokens_in":31432,"feed_emoji":"🔐","tokens_out":7438,"duration_ms":83448,"temperature":0.7,"pith_summary":"This paper is a systematic literature review of how quantum computing will change cybersecurity in accounting and finance. Its central conclusion is that the public-key encryption now protecting financial records (RSA, ECC, and related schemes) will become breakable as quantum computers mature, so organizations must move to quantum-resistant algorithms and quantum key distribution (QKD). The authors construct a sixteen-dimension conceptual framework that combines an established technology-adoption model with quantum-specific security constructs, and they use it to test four propositions about encryption strength, unauthorized access, organizational disruption, and adoption costs. The contribution is a structured warning and roadmap rather than an empirical demonstration: if the review's reading of the literature is right, finance and accounting systems should begin their post-quantum transition now.","feed_headline":"Quantum-safe crypto and QKD are finance's future, review finds","feed_subtitle":"A systematic review warns Shor's algorithm will break RSA and ECC, making quantum-resistant algorithms and QKD essential.","key_machinery":"The load-bearing mechanism is a three-layer conceptual framework that adapts a 1991 personal-computing utilisation model and contingency theory to quantum security. It adds four quantum-specific constructs (quantum resistance of accounting algorithms, QKD integration, organizational quantum readiness, and stakeholder interdependence), yielding sixteen dimensions used to evaluate each of the four propositions. The framework performs the translation from the abstract threat of Shor's algorithm into audit-ready variables that an accounting organization can assess, such as job fit, complexity, structure, goals, and perceived consequences.","core_discovery":"The paper's central claim is that securing accounting and finance systems in the post-quantum world requires quantum-resistant cryptographic algorithms and quantum key distribution, because Shor's algorithm can solve the integer-factorization and discrete-logarithm problems behind RSA and ECC in polynomial time, while Grover's algorithm speeds up brute-force search against symmetric encryption. Based on a synthesis of 54 selected studies, the authors conclude that current financial encryption is vulnerable to quantum attacks and that lattice-based and hash-based post-quantum cryptography, together with QKD for key exchange, are the necessary remedies. They further argue that the transition is organizational, not purely technical: adoption depends on cost, complexity, skills, regulatory pressure, and cultural readiness, which the paper's four propositions map onto specific challenges and benefits.","pith_inferences":["An implication the paper leaves implicit is the 'harvest now, decrypt later' risk: encrypted financial records captured today can be stored and decrypted once a quantum computer exists, so long-lived records such as audits may need quantum-safe protection before the attack is practical.","A concrete next step the paper calls for but does not design is a pilot QKD deployment for a specific accounting function, such as interbank reconciliation, where eavesdropping detection and operational latency could be measured directly.","The framework could be operationalized as a readiness index that scores organizations on infrastructure, skills, and regulatory exposure; the paper mentions the idea of a quantum security index but leaves its construction to future work."],"forward_implications":["Financial institutions should begin migrating encryption of audit trails, ledgers, and interbank communications to standardized post-quantum algorithms, since current RSA/ECC protection has a finite lifespan.","QKD should be considered for key exchange wherever the physical infrastructure supports it, because it detects eavesdropping rather than merely making decryption hard.","The transition will require revising cybersecurity governance, retraining accounting and IT staff, and reworking workflows with quantum key management and post-quantum signature verification.","Regulatory and standards bodies will need to embed quantum-safe requirements into financial reporting and audit frameworks.","High initial cost and complexity will slow adoption, but the paper's Proposition 4 holds that security and compliance benefits eventually outweigh these barriers."],"supporting_citations":[{"why":"Supplies the polynomial-time factoring and discrete-log algorithms that threaten RSA and ECC.","marker":"[3]"},{"why":"Provides the industry-survey evidence that most large firms expect quantum computers to break current encryption by 2030.","marker":"[6]"},{"why":"Establishes the accounting-specific cybersecurity context the review builds on.","marker":"[2]"},{"why":"Grounds the survey of quantum computing applications in finance, including optimization and risk analysis.","marker":"[4]"},{"why":"Sets out the quantum-era cybersecurity threats that motivate the paper's research questions.","marker":"[5]"},{"why":"Contributes the technology-adoption model that the paper adapts into its user-level constructs.","marker":"[47]"},{"why":"Defines quantum key distribution and its eavesdropping-detection property, which the paper's security claims rely on.","marker":"[58]"},{"why":"Supplies the systematic-review protocol used to select and synthesize the 54 studies.","marker":"[81]"}],"fun_headline_variants":["Shor's algorithm threatens finance; QKD and post-quantum crypto are the fix","Post-quantum cryptography and QKD are vital for finance systems","Quantum attacks break RSA and ECC; adopt QKD and post-quantum crypto","Finance cybersecurity needs quantum-resistant crypto and QKD","Post-quantum finance: Shor's algorithm makes current crypto obsolete"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The central argument assumes the 54 selected studies are a fair and representative sample of the literature, so the conclusions about quantum threats and remedies reflect the field rather than a skewed subset.","fun_headline_variants_meta":{"raw":{"variants":["Shor's algorithm threatens finance; QKD and post-quantum crypto are the fix","Post-quantum cryptography and QKD are vital for finance systems","Quantum attacks break RSA and ECC; adopt QKD and post-quantum crypto","Finance cybersecurity needs quantum-resistant crypto and QKD","Post-quantum finance: Shor's algorithm makes current crypto obsolete"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001359,"raw_usage":{"total_tokens":5511,"prompt_tokens":939,"completion_tokens":4572,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":555,"completion_tokens_details":{"reasoning_tokens":4475}},"tokens_in":555,"tokens_out":4572,"duration_ms":33515,"temperature":1.0,"reasoning_tokens":4475,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T04:17:40.497370+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run Shor's algorithm on a fault-tolerant quantum computer against the RSA key sizes used in financial reporting; the paper cites an estimate that 2048-bit RSA could be factored in about 8 hours with 20 million noisy qubits. Success would confirm the threat, while a failure of that scale, or a demonstration that financial systems remain secure through classical encryption alone, would contradict the paper's claim that post-quantum algorithms and QKD are necessary.","supporting_citations":[{"cited_title":"Personal computing: toward a conceptual model of utilization,","cited_arxiv_id":null,"evidence_quote":"Contributes the technology-adoption model that the paper adapts into its user-level constructs."},{"cited_title":"Quantum Key Distribution (QKD) for Symmetric Key Transfer,","cited_arxiv_id":null,"evidence_quote":"Defines quantum key distribution and its eavesdropping-detection property, which the paper's security claims rely on."},{"cited_title":"Ecosystem services research in mountainous regions: A systematic literature review on current knowledge and research gaps,","cited_arxiv_id":null,"evidence_quote":"Supplies the systematic-review protocol used to select and synthesize the 54 studies."}],"review_version":1}