Harvest-Now, Decrypt-Later.

Data captured today can be decrypted tomorrow. The risk doesn't wait for the quantum computer to exist.

The attack

The public-key algorithms in widespread use today, RSA and ECC (elliptic-curve cryptography), are vulnerable to Shor's algorithm, which runs on cryptographically relevant quantum computers. Those computers don't yet exist at operational scale. Even so, the risk is already immediate, because of the harvest-now, decrypt-later (HNDL) pattern: encrypted traffic captured today can be archived and decrypted in the future, once the computational capability exists.

An adversary doesn't need to wait for the quantum computer to be ready. Intercepting and storing the encrypted traffic now is enough. The relevant question isn't whether your cipher is breakable today. It's whether it will be broken before the data loses its value.

Why timing matters more than the cipher

Across a measurement of 39,903 organizations, observed cryptographic vulnerability is high and nearly uniform across sectors (68–71 out of 100). What distinguishes sectors is the urgency of migration, determined by the threat horizon, the data's lifetime, and regulatory criticality. Cryptographic weakness varies little between them.

Sectors that retain data for decades, such as health and government, accumulate greater HNDL exposure than sectors with short-lived data, even with the same level of observed technical fragility. A trade secret may be sensitive for decades; a stock price tip expires in days.

The exposure window by sector

Health and government (data lifetime ≈ 20 years) accumulate more than a decade of exposed window, that is, the period between the sector's estimated quantum-maturity year and the end of the useful lifetime of data captured today. Retail, SaaS, and e-commerce (data lifetime ≈ 5–6 years) tend to have data expiring before quantum maturity, which lowers their migration urgency even with equally fragile cryptography.

76.4% of the 39,903 organizations analyzed fall in the Critical or High exposure bands. The distribution isn't a smooth gradient: it organizes into three blocks. Tier 1 (act now): government, health, pharma, health insurance, materials & chemicals, agribusiness, industrial manufacturing, defense & aerospace; Tier 2 (plan): utilities, oil & gas, traditional finance, payment processing; Tier 3 (maintain and monitor): cloud, telecom, SaaS, retail, e-commerce.

Data lifetime

Health and government data stays exploitable for 20 years. Retail data, for 5

Data lifetime defines the window: whatever is intercepted today keeps its value for that entire term.

SectorData lifetime · 0 to 20 yearsYears
Government / Unclassified
20
Hospitals and healthcare
20
Pharmaceuticals and biotech
20
Supplementary healthcare
20
Materials and chemicals
15
Agroindustry
15
Industrial manufacturing
15
Defense and aerospace
15
Utilities (energy)
10
05101520
SectorData lifetime · 0 to 20 yearsYears
Oil, gas, and energy
10
Traditional finance
10
Payment processing
10
Cloud
7
Telecom
6
SaaS
6
Retail and brands
5
E-commerce and marketplace
5
05101520
ScaleCritical80–100High60–80Moderate40–60Low20–40Minimal0–20

4 of 17

sectors with a 20-year data lifetime

between the longest and the shortest horizon

2046

how long data captured today still counts

What to do with that window

For Tier 1, we recommend an immediate cryptographic inventory, prioritization of long-validity data capturable today, and a post-quantum cryptography (PQC) transition plan with semi-annual targets. For Tier 2, a PQC roadmap and crypto-agility (the ability to swap cryptographic algorithms without major system rework) before the next cycle. For Tier 3, consolidate crypto-agility and watch for regressions.