Most security risks become real when an attack happens. The quantum threat is different: an attacker can copy your encrypted data today, store it cheaply, and wait for a quantum computer powerful enough to decrypt it. This strategy is known as “harvest now, decrypt later” — and it means some of your data may already be exposed.
How the attack works
- An adversary records encrypted traffic or steals encrypted files and backups.
- The data is stored — storage is cheap and adversaries can be patient.
- When a sufficiently powerful quantum computer exists, it breaks the public-key algorithms (such as RSA or elliptic-curve Diffie–Hellman) that protected the session keys.
- With the keys recovered, the recorded data can be decrypted.
Which data is at risk?
The question isn’t whether data is encrypted, but how long it must stay secret. A useful rule of thumb, often called Mosca’s inequality, compares three numbers:
- x — how many years the data must remain confidential;
- y — how many years it will take you to migrate to quantum-safe cryptography;
- z — how many years until a cryptographically relevant quantum computer exists.
If x + y > z, you have a problem. Because nobody knows z with certainty, organisations holding long-lived secrets — health records, financial and legal data, trade secrets, government and defence information — should assume they are exposed.
What is not at risk in the same way
- Short-lived data, such as one-time codes or transient session information, has little value years later.
- Symmetric encryption like AES with long keys is far more resistant; the main weakness is the public-key exchange used to agree those keys.
- Digital signatures are a related but different issue: they need upgrading so forgeries aren’t possible in the future, but recorded traffic doesn’t make past signatures less valid.
What to do about it
- Classify data by confidentiality lifetime and identify where long-lived data travels over networks.
- Prioritise data in transit across public networks, which is easiest to harvest.
- Deploy hybrid post-quantum key exchange (classical + ML-KEM, standardised by NIST in FIPS 203) on the most sensitive connections.
- Re-encrypt long-term archives where feasible, and protect backups.
- Build crypto-agility so future changes are configuration, not re-engineering.
Our Quantum Computing team helps organisations identify long-lived data, prioritise systems and pilot hybrid post-quantum protection.
Frequently asked questions
What does “harvest now, decrypt later” mean?
It describes attackers collecting encrypted data today and storing it until a future quantum computer can break the public-key cryptography that protected it.
Is my encrypted data at risk today?
Data that must stay confidential for many years may be. If the time the data must stay secret plus the time you need to migrate exceeds the time until quantum computers can break current encryption, the data is exposed.
How do I protect against harvest-now-decrypt-later attacks?
Prioritise long-lived sensitive data in transit, deploy hybrid post-quantum key exchange based on NIST standards, protect archives and backups, and build crypto-agility.