Harvest Now, Decrypt Later: Why Your Encrypted Data Is Already at Risk

Right now, a copy of your encrypted data may be stored elsewhere, outside your control.  While it can’t be read yet, that assurance is temporary.

The RSA and elliptic-curve algorithms that protect most internet traffic today will not withstand a capable quantum computer.  Once such a machine exists, anyone with a stored copy can decrypt your data at will.  Security professionals call this approach “harvest now, decrypt later.” Critically, it does not require a quantum computer today, only patience and inexpensive storage, both of which adversaries have.

This is the first post in a series on quantum readiness, and it begins here for a reason.  Before discussing deadlines, inventories, or migration plans, consider this: for some of your data, the countdown did not start on a future “Q-Day.”  It has already begun.

The Attack That Runs Backward

Most cyberattacks must succeed immediately.  A stolen credential is useful until it is changed, and ransomware must be executed before detection.  Harvest now, decrypt later reverses this logic.  Attackers collect encrypted data today and decrypt it whenever the capability becomes available, whether in five or fifteen years.  Time favors the collector, not the defender.

The economics favor attackers.  Encrypted traffic obtained from a fiber tap, compromised router, or misconfigured cloud storage is inexpensive to store for years.  RSA-2048 and elliptic-curve schemes that secure today’s key exchanges are currently unbreakable by brute force, but they become vulnerable as soon as Shor’s algorithm runs on practical hardware.  Peter Shor published this algorithm in 1994; it efficiently factors large numbers and solves the discrete-logarithm problem, which underpins RSA and elliptic-curve cryptography.  No quantum computer can run it at scale yet, but every major government program assumes one will eventually exist.

Some Secrets Have a Long Shelf Life

The core issue is simple: how long must your data remain confidential?  Cryptographer Michele Mosca frames this as an inequality.  Add the years your information must remain secret to the years required to migrate to quantum-safe cryptography.  If that total exceeds the time until a capable quantum computer arrives, your data is already at risk; you cannot see the breach yet.

Applying this to typical enterprise data quickly clarifies the risk:

  • Genomic and health records that stay sensitive for a lifetime and implicate your children after that.
  • Defense and intelligence data are routinely classified for 25 years or more.
  • Financial, legal, and tax records carrying retention obligations of seven years and often far longer.
  • Trade secrets, source code, and intellectual property that hold value for as long as the business does.
  • Biometrics, which are permanent by definition.  You cannot reissue a fingerprint or an iris the way you reset a password.

For these types of data, a 2035 deprecation deadline is not sufficient.  Records transmitted this year must remain secure well beyond that date.  If a secret must be protected for twenty years and a quantum computer arrives in ten, the critical deadline has already passed.

This Is Not a Hypothetical Claim

Harvest now, decrypt later is not theoretical.  Bulk interception and long-term storage of encrypted internet traffic are well documented, as confirmed by years of public disclosures about national intelligence operations.  These agencies collect data at scale and retain what they cannot yet decrypt.  The United States government acknowledges this in its own guidance.  A joint advisory committee on quantum readiness, composed of members from the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the National Institute of Standards and Technology (NIST), cites harvest now, decrypt later as the reason organizations must begin migrating before a quantum computer becomes relevant.  When national security agencies confirm ongoing collection, it is prudent to believe them and plan accordingly.

You Cannot Unsend Harvested Data

The difficult reality is that any data already captured is lost.  You cannot recall, re-encrypt, or recover it.  The only factor you control now is how quickly you secure future data, which depends on your migration speed.

The good news is that the risk is focused. Symmetric encryption, like AES, remains strong.  While quantum computers weaken it, increasing the key length restores security, so AES-256 remains effective.  The main vulnerability lies with public-key algorithms, RSA and elliptic curve cryptography, which handle key exchange and digital signatures.  These cannot be patched and must be replaced.  NIST finalized replacements in 2024: ML-KEM for key exchange and ML-DSA for signatures.  Both are published, tested, and ready for deployment.  The algorithms themselves are not the obstacle.

The First Problem Is Finding the Locks

Migration is not as simple as swapping one algorithm for another.  The challenge is visibility.  Cryptography is embedded throughout an enterprise – in applications, libraries, protocols, stored data, hardware, and system connections.  In modern, well-documented software, much of this is easy to find.  In older custom systems, it is often hidden in legacy code, copied rather than imported, and maintained by people who may no longer be available.  You cannot migrate what you cannot identify, nor can you protect data processed by cryptography you have not located.

Quantum readiness begins as a discovery problem, not a deployment task.  Integrate it with efforts to understand what your legacy systems contain, how they are structured, and where real risks exist.  Locating encryption and understanding legacy code are essential steps in any serious modernization effort.  The harvest has a head start, and no future upgrade can recover that data.  Your job is to ensure the information you send tomorrow remains unreadable when decryption finally arrives.  The posts that follow move from that reality toward a defensible answer: the compliance deadlines that are already fixed, what changed in 2026 to compress them, and why building a clear inventory of your own cryptography is the true starting line.  If you treat it as a standalone scramble, you pay for quantum readiness twice.  If you treat it as part of modernizing the foundation, you do it once.

Book a Call with Aspen

If your board, customers, or regulators are asking about your quantum readiness and you are unsure how to respond, let’s talk.  Aspen can help you assess your legacy systems, identify cryptographic risks, and strengthen your modernization roadmap.

Schedule a discovery chat: https://calendly.com/aspen-ess/aspen-ess-discovery-chat