Harvest-Now, Decrypt-Later.

Data captured today can be decrypted tomorrow. The risk doesn't wait for the quantum computer to exist.

The attack

The public-key algorithms in widespread use today — RSA and ECC (elliptic-curve cryptography) — are vulnerable to Shor's algorithm, which runs on cryptographically relevant quantum computers. Those computers don't yet exist at operational scale. Even so, the risk is already immediate, because of the harvest-now, decrypt-later (HNDL) pattern: encrypted traffic captured today can be archived and decrypted in the future, once the computational capability exists.

An adversary doesn't need to wait for the quantum computer to be ready to act — they only need to intercept and store the encrypted traffic now. The relevant question isn't whether your cipher is breakable today. It's whether it will be broken before the data loses its value.

Why timing matters more than the cipher

Across a measurement of 39,903 organizations, observed cryptographic vulnerability is high and nearly uniform across sectors (68–71 out of 100). What distinguishes sectors isn't how weak their cryptography is — it's the urgency of migration, determined by the threat horizon, the data's lifetime, and regulatory criticality.

Sectors that retain data for decades — health and government — accumulate greater HNDL exposure than sectors with short-lived data, even with the same level of observed technical fragility. A trade secret may be sensitive for decades; a stock price tip expires in days.

The exposure window by sector

Health and government (data lifetime ≈ 20 years) accumulate more than a decade of exposed window — the period between the sector's estimated quantum-maturity year and the end of the useful lifetime of data captured today. Retail, SaaS, and e-commerce (data lifetime ≈ 5–6 years) tend to have data expiring before quantum maturity, which lowers their migration urgency even with equally fragile cryptography.

76.4% of the 39,903 organizations analyzed fall in the Critical or High exposure bands. The distribution isn't a smooth gradient — it organizes into three blocks: Tier 1 (act now): government, health, pharma, health insurance, materials & chemicals, agribusiness, industrial manufacturing, defense & aerospace; Tier 2 (plan): utilities, oil & gas, traditional finance, payment processing; Tier 3 (maintain and monitor): cloud, telecom, SaaS, retail, e-commerce.

What to do with that window

For Tier 1, we recommend an immediate cryptographic inventory, prioritization of long-validity data capturable today, and a post-quantum cryptography (PQC) transition plan with semi-annual targets. For Tier 2, a PQC roadmap and crypto-agility — the ability to swap cryptographic algorithms without major system rework — before the next cycle. For Tier 3, consolidate crypto-agility and watch for regressions.