Office Space

The Breach That Hasn’t Happened Yet

Imagine learning that a foreign intelligence service intercepted your company’s encrypted email traffic three years ago. Loan files, policy documents, wire instructions, personnel records — all of it captured in transit and quietly archived. Nothing was opened. Nothing was leaked. By every current legal and technical definition, no breach occurred.

Now imagine that the encryption protecting those files stops working.

That is the premise behind “Harvest Now, Decrypt Later” — and it is not a thought experiment. CISA, the NSA, and NIST have jointly warned that adversaries are actively collecting encrypted data today with the intent of decrypting it once a sufficiently powerful quantum computer exists. The attack is already underway. The payoff is simply scheduled for later.

For executives at banks, insurers, title companies, and healthcare organizations — businesses whose records must remain confidential for decades — this changes the risk calculation in a way that most cybersecurity planning has not yet caught up with.

Why Today’s Encryption Has an Expiration Date

Nearly all of the encryption protecting business communications today — the technology behind secure email, TLS connections, VPNs, and digital signatures — relies on mathematical problems that are extremely difficult for conventional computers to solve. RSA and elliptic-curve cryptography (ECC) have held up for decades because factoring enormous numbers or solving discrete logarithm problems would take a classical computer longer than the age of the universe.

Quantum computers work differently. A cryptographically relevant quantum computer (CRQC) — one powerful and stable enough to run Shor’s algorithm at scale — could solve those same problems in hours. Current industry and government projections place the arrival of such a machine somewhere in the 2030s, with some assessments treating it as plausible before the end of this decade.

Here is the part executives tend to miss: the deadline is not the day the quantum computer arrives. The deadline is set by how long your data must stay confidential.

Security researchers formalize this with a simple framework known as Mosca’s theorem. Compare three timelines:

  • X — how long it will take your organization to migrate to quantum-resistant encryption
  • Y — how long your data must remain confidential
  • Z — when a cryptographically relevant quantum computer arrives

If X + Y is greater than Z, data you are encrypting today will be exposed. A title company whose escrow and closing records carry a 20-year confidentiality obligation, facing a realistic multi-year migration, is already inside the danger window — even under conservative quantum timelines.

The Government Has Already Set the Clock

This is no longer a research topic. The regulatory and standards machinery has moved:

  • August 2024: NIST finalized the first three post-quantum cryptography (PQC) standards — FIPS 203 (ML-KEM) for key exchange, FIPS 204 (ML-DSA) for digital signatures, and FIPS 205 (SLH-DSA) as a hash-based backup. A fourth standard, FIPS 206, is expected in 2026.
  • NIST IR 8547 transition plan: RSA-2048 and ECC — the algorithms underpinning most business encryption today — are slated for deprecation by 2030 and full removal from federal standards by 2035.
  • NSA CNSA 2.0: New national security systems must use quantum-resistant algorithms, with mandates beginning in 2027.
  • National Security Memorandum 10: Federal agencies must complete their post-quantum migrations by 2035 — an implicit acknowledgment that a CRQC could plausibly exist before then.

If you operate in a regulated industry, you have seen this movie before. Federal standards become examiner expectations. Examiner expectations become audit findings. Audit findings become insurance questionnaire items — and as we covered in our brief on how cyber insurance policies are changing in 2026, carriers are already tightening underwriting around demonstrable security controls. Cryptographic readiness is a near-certain addition to that list.

Which Data Is Actually at Risk

Not everything in your organization needs a quantum-safe wrapper tomorrow. HNDL is a patient attack, which means it targets patient data — information whose value survives the years it takes for decryption to become possible. The highest-exposure categories for regulated businesses:

Long-retention communications and archives. Email is the connective tissue of regulated business, and compliance rules require much of it to be preserved for years or decades. An email archive built for compliance and e-discovery is precisely the kind of dense, long-lived data store that makes harvesting worthwhile. The same logic applies to intercepted transmissions: encrypted email captured in transit today, containing loan documents or medical records, will still be sensitive when the encryption around it fails.

Financial and escrow records. Mortgage files, trust documents, and closing packages carry confidentiality obligations measured in decades, not quarters.

Health information. A person’s medical history does not lose sensitivity in ten years. HIPAA-covered data harvested now is a liability with no statute of limitations that matters.

Intellectual property and deal information. M&A negotiations, trade secrets, and strategic plans have long shelf lives. Notably, cryptographic posture is becoming part of transaction risk itself — an acquirer inheriting a target’s aging encryption estate is inheriting its future exposure, a dimension worth adding to any cyber due diligence process during mergers and acquisitions.

What Migration Actually Involves

We have written before about why encryption alone is not a silver bullet — it protects data without stopping phishing, fraud, or account takeover. The quantum transition is a different kind of limit: the algorithms themselves aging out. And unlike a phishing campaign, you cannot train your way through it or patch it on a Tuesday.

Post-quantum migration is an infrastructure program. Cryptography is embedded everywhere — email systems, web servers, VPNs, certificates, applications, vendor products, archived data — and most organizations have never inventoried it. That is why the joint federal guidance is blunt about sequencing: you cannot protect what you cannot see.

The authoritative starting point is the Quantum-Readiness: Migration to Post-Quantum Cryptography factsheet published jointly by CISA, the NSA, and NIST. Its core prescription for leadership:

  1. Establish a quantum-readiness roadmap with executive ownership — this is a multi-year program, not an IT ticket.
  2. Build a cryptographic inventory. Identify every system, application, and vendor product using quantum-vulnerable algorithms, and map each to the sensitivity and lifespan of the data it protects.
  3. Engage your technology vendors. Ask every provider handling sensitive data — including your email encryption provider — for their PQC migration roadmap and CNSA 2.0 alignment. Crypto-agility, the ability to swap algorithms without rebuilding systems, should now be a standard vendor selection criterion.
  4. Prioritize by data lifetime, not system age. The first systems to migrate are the ones protecting the longest-lived, most sensitive data — regardless of how new the hardware is.

Organizations that begin the inventory this year face a demanding but orderly transition. Organizations that wait for a headline will attempt the same work under deadline pressure, at emergency pricing, with regulators and insurers asking why they started late.

Five Questions Executives Should Ask This Quarter

You do not need to understand lattice-based cryptography to govern this risk. You need answers to five questions:

  1. What is our data’s confidentiality lifetime? Which records must remain protected for 10, 20, or 30 years — and what encryption protects them today?
  2. Do we have a cryptographic inventory? If the answer is no, that is the first deliverable and the first budget line.
  3. What are our vendors’ PQC timelines? Every provider touching sensitive data should be able to answer in writing.
  4. Who owns this program? Quantum readiness that lives in the IT backlog will not survive contact with the 2030 deprecation timeline.
  5. How will we evidence readiness? Examiners, auditors, and cyber insurers will ask. A documented roadmap is the difference between a finding and a footnote.

The Bottom Line

Harvest Now, Decrypt Later inverts the usual logic of a data breach: the theft happens years before the damage, and by the time the damage is visible, the window to prevent it has been closed for a decade. The standards are final, the federal deadlines are public, and the collection phase is — by the government’s own assessment — already in progress.

For leaders in regulated industries, the strategic question is not whether quantum computing will break today’s encryption. It is whether your most sensitive data will still need protecting when it does. For most banks, insurers, title companies, and healthcare organizations, the honest answer is yes — which means the migration clock started without you.

The organizations that treat this as a governance priority in 2026 will absorb the transition as routine infrastructure work. The ones that don’t will meet it as a crisis. If your board hasn’t been briefed on quantum risk, a structured boardroom cybersecurity engagement is the fastest way to turn an unfamiliar threat into an owned, scheduled program.

Receive the latest news in your email
Table of content
Related articles