Harvest Now, Decrypt Later: Why the Quantum Cybersecurity Threat Has Already Begun
Quantum cybersecurity is no longer only a future hardware concern. Information stolen today may remain valuable when quantum decryption becomes possible. Because replacing encryption across complex organisations can take years, governments and enterprises must identify vulnerable systems and begin post-quantum migration before cryptographically relevant quantum computers arrive.

Understand this faster with AI
Quantum computers capable of breaking widely used encryption systems have not yet been built. That does not mean organisations can afford to wait.
The emerging cybersecurity threat known as “harvest now, decrypt later” changes how governments and businesses must assess quantum risk. Under this model, an adversary intercepts and stores encrypted information today, even without the ability to read it. The attacker then waits for sufficiently powerful quantum computers or other cryptanalytic advances to make decryption possible.
Information protected today could therefore become exposed years later.
This means the quantum cybersecurity threat does not begin on the day a quantum computer breaks RSA or elliptic-curve cryptography. For information that must remain confidential for many years, the risk may have already started.
Why today’s encryption may not be enough
Public-key cryptography is a critical part of the modern digital economy. It protects internet connections, financial transactions, digital identities, software updates, cloud services, confidential communications and access to government systems.
Two of the most widely used families of public-key cryptography are RSA and elliptic-curve cryptography, commonly known as ECC. Their security depends on mathematical problems that are extremely difficult for conventional computers to solve at a useful scale.
A sufficiently capable quantum computer could change that assumption.
Using Shor’s algorithm, a fault-tolerant quantum computer could theoretically solve the mathematical problems underlying RSA and ECC far more efficiently than classical machines. Such a system would threaten both encrypted communications and the digital signatures used to authenticate software, documents, devices and users.
No cryptographically relevant quantum computer, or CRQC, is currently available. However, the uncertainty surrounding its arrival is precisely why the problem demands early action.
QuantumNews.in’s review of the quantum-safe security landscape noted that the Global Risk Institute’s 2026 Quantum Threat Timeline estimated that a cryptographically relevant quantum computer was “quite possible” within 10 years and “likely” within 15 years. These are projections rather than fixed deadlines, but they illustrate the planning window confronting governments and enterprises.
Security migration cannot begin only after the threat has been demonstrated. By then, information collected years earlier may already be waiting to be decrypted.
How harvest now, decrypt later works
An HNDL attack takes advantage of the difference between the useful lifetime of information and the time required to build quantum decryption capabilities.
An attacker first obtains encrypted data. This could happen through network interception, compromised infrastructure, stolen backups, cloud breaches, malicious insiders or surveillance operations. The attacker may not be able to understand the information at the time it is collected.
Instead of discarding it, the attacker stores it.
The data is then preserved until a sufficiently powerful quantum computer, improved cryptanalytic method or compromised key becomes available. Information that was unreadable when captured could then become accessible.
The model is particularly dangerous because storing encrypted data is easier and cheaper than building a quantum computer. An adversary does not need to know exactly when quantum decryption will become practical. It only needs to believe that some of the information being collected will remain valuable when that capability arrives.
Not all data carries the same risk. A routine message may have little value after a few months. Defence information, trade secrets, diplomatic communications, genomic records, long-term financial documents and critical infrastructure designs may remain sensitive for decades.
The longer the required confidentiality period, the greater the exposure to HNDL.
The threat is about timing
The central issue can be understood through three timelines:
How long the information must remain confidential
How long the organisation will need to replace vulnerable cryptography
When a quantum computer capable of breaking existing encryption may arrive
Consider an organisation holding information that must remain secret for 15 years. If migrating its systems to quantum-resistant cryptography will take five years, waiting another decade to begin may expose the data before the migration is complete.
Large organisations cannot replace cryptography instantly. Encryption is embedded across applications, certificates, identity systems, hardware security modules, virtual private networks, APIs, cloud infrastructure, mobile devices and third-party products.
Some systems may be updated through software. Others may require new hardware, redesigned protocols or replacement of equipment intended to remain operational for decades.
The migration must therefore be completed before the cryptographic threat becomes practical—not started after it arrives.
Technology companies are already moving
The response from major technology companies shows that quantum cybersecurity has moved beyond theoretical discussion.
QuantumNews.in reported that Google established 2029 as its target for completing its transition to post-quantum cryptography. The company’s strategy addresses both the future risk to digital signatures and the more immediate concern that encrypted information may be collected now for later decryption.
Google has already deployed post-quantum protections in parts of Chrome and its cloud services. It is also integrating ML-DSA, a post-quantum digital-signature algorithm standardised by the US National Institute of Standards and Technology, into Android 17.
The importance of Google’s timeline is not that 2029 represents a predicted “Q-Day.” It demonstrates how long a major technology ecosystem expects migration to require.
Browsers, operating systems, cloud platforms, certificates, authentication services and software-signing infrastructure all depend on cryptography. Changing those systems while maintaining compatibility and performance requires years of testing and deployment.
Messaging platforms face similar challenges.
QuantumNews.in reported that IBM researchers have been working with Signal and Threema to develop quantum-resistant security for messaging applications. The work addresses both message content and sensitive metadata, including information about group membership.
Signal had already introduced post-quantum protection into its core protocol, but extending that protection to group messaging created significant technical overhead. A direct substitution of classical cryptographic components with larger post-quantum mechanisms could reportedly increase bandwidth requirements by around 100 times.
IBM and Signal explored a decentralised gatekeeper model using a modified form of ML-DSA. Threema has also worked with IBM researchers to integrate ML-KEM, a post-quantum key-encapsulation mechanism, without making the service impractical for users.
These efforts show that selecting an algorithm is only the beginning. Real-world migration must account for performance, bandwidth, compatibility, privacy and implementation security.
The standards now exist
The transition gained a clearer technical foundation when NIST finalised its first three post-quantum cryptography standards in August 2024.
The standards include:
ML-KEM, published as FIPS 203, for establishing shared encryption keys.
ML-DSA, published as FIPS 204, for digital signatures.
SLH-DSA, published as FIPS 205, as a hash-based digital-signature alternative.
NIST later selected HQC as an additional key-encapsulation algorithm, providing diversity beyond the initial standard.
Post-quantum cryptography, or PQC, is designed to operate on conventional computing infrastructure. Organisations do not need quantum hardware to deploy it. This makes PQC the most practical migration route for most digital systems.
Quantum key distribution, or QKD, provides another approach by using quantum physics to detect interception during key exchange. However, QKD requires specialised optical equipment and is generally more suitable for selected high-security connections than for universal deployment.
QuantumNews.in’s review of the sector found that many security architects expect a layered model: broad adoption of PQC across existing infrastructure, with QKD considered for particularly sensitive government, defence, financial or data-centre links.
What organisations should do now
The first step is not necessarily replacing every cryptographic system. It is understanding where vulnerable cryptography is being used.
Organisations need a cryptographic inventory covering applications, networks, certificates, cloud services, databases, devices and external suppliers. They must also identify which information has a long confidentiality period and which systems would cause the greatest damage if their authentication mechanisms were compromised.
The highest-priority areas are likely to include long-lived sensitive data, critical infrastructure, identity systems, software-signing processes and communications that may already be attractive to sophisticated adversaries.
Crypto-agility will also become increasingly important. Systems should be designed so that cryptographic algorithms and keys can be replaced without rebuilding the entire application or infrastructure.
Government migration requirements are beginning to reinforce this direction. QuantumNews.in reported that Canada required federal departments to submit post-quantum migration plans by April 2026, prioritise critical systems by 2031 and work towards full migration by 2035.
Such timelines underline the scale of the transition. Quantum-safe migration is expected to take years, not weeks.
A present risk created by a future machine
The exact arrival date of a cryptographically relevant quantum computer remains unknown. Predictions may change as researchers improve hardware, error correction and quantum algorithms.
But waiting for certainty is not a sound cybersecurity strategy.
Harvest now, decrypt later turns a future computing capability into a present information-security problem. Attackers can collect encrypted data now, while defenders must modernise complex systems before that data becomes readable.
The objective is not to declare that current encryption will fail tomorrow. It is to ensure that information requiring long-term protection does not become vulnerable because migration began too late.
The quantum computer that could break today’s encryption may still be years away. The data it could eventually expose, however, is already being created, transmitted and stored.
That is why the quantum cybersecurity threat has already begun.
Tags
Source Information
Discussion
0 professional contributions
Sign in to join this professional discussion.
Be the first to add a constructive contribution.
