Harvest now, decrypt later:
What's captured today will be decrypted later

Why Long-Term Assets Are Already at Risk Today

The debate over post-quantum cryptography all too often narrows down to the question of choosing the right algorithm. ML-KEM or a hybrid scheme? The reality, however, is that the vast majority of organizations cannot answer the simpler question of where cryptography is actually used. It’s only seemingly simpler. Without knowing where the algorithms are used, the discussion about their selection is merely a technical exercise and a dead end with no follow-up steps.

The attack may already be underway

"Harvest now, decrypt later" describes a simple method of attack: an attacker intercepts and stores encrypted communications today without being able to read them. They wait for the moment when a cryptographically relevant quantum computer becomes available—one capable of breaking today’s asymmetric cryptography, such as RSA, Diffie-Hellman, and elliptic curves (ECDH and ECDSA)—to decrypt the data retroactively. NÚKIB explicitly cites this scenario as the main reason why the transition to quantum-resistant encryption must occur more quickly in the area of data confidentiality than in other areas of cryptography.

A key feature of the attack is that, from the defender’s perspective, nothing is happening right now, but the damage will not become apparent for years. This changes the way we should think about the risk: the question is not “when will a sufficiently powerful quantum computer—or a cryptographically relevant quantum computer—be developed,” but “how long must the confidential data we send today remain confidential.” If the answer is longer than the time horizon for the emergence of decryption capabilities, the risk is real regardless of whether a quantum computer already exists. Moreover, we probably won’t learn of its existence immediately from newspaper articles, but only after a significant delay.

It is clear that this type of attack—or, rather, defense against it—makes sense only for long-term assets such as health information, know-how, strategic plans, and the like. Devoting resources to protecting receipts from point-of-sale systems is certainly not a priority.

Estimates of when a quantum computer will become available vary and change rapidly over time. Unfortunately, the time available for preparation is steadily shrinking. Both Germany’s BSI and NÚKIB agree that the early 2030s is the target date for preparing the protection of sensitive information with a critical level of confidentiality. Therefore, in an appendix to the Minimum Requirements for Cryptographic Algorithms, NÚKIB classifies algorithms for key establishment that protect the confidentiality of this data as a high-priority area, with a recommended deadline for completing the transition by the end of 2030. This may seem like plenty of time, but the transition to PQC algorithms will be a process spanning many years with an impact on the entire organization.

What the Data Says

The debate over post-quantum cryptography often takes place at the level of principles. However, there is also hard data on the subject that shows there is a significant gap between what companies know about the risk and what they do about it, and that the cost of inaction in cybersecurity is generally on the rise.

Readiness for PQC remains low, even among otherwise advanced security teams. According to a 2025 DigiCert study (1,042 security managers and C-level executives across various industries), 69% of respondents believe that quantum computers will break today’s encryption by 2030, but only 5% of companies have quantum-resistant encryption actually deployed. 46.4% of organizations admit that a significant portion of their encrypted data could be compromised. An ISACA survey of more than 2,600 professionals conducted in 2025 yields similar results: only 5% of organizations have a defined strategy for preparing for the quantum threat, even though two-thirds of respondents express concern about the future ability of quantum computers to break encryption. The independent Qtonic Quantum benchmark for Fortune 1000 companies yielded an average readiness score of 18 out of 100—this figure should be taken with a grain of salt (as it is based on a single company’s methodology), but other sources also confirm this trend.

Investment in security is on the rise, but so far it’s going elsewhere. According to Gartner, global spending on information security rose to $213 billion in 2025 (up from $193 billion in 2024), and is expected to exceed $240 billion in 2026. However, only a fraction of this growing amount is currently being allocated to preparing for a post-quantum future.

On the other hand, investment in quantum technologies is growing, which serves as a useful reminder that PQC is not a purely hypothetical threat. Private investment in quantum computing reached $3.77 billion in the first three quarters of 2025, while government investment exceeded $10 billion as of April 2025 (Japan alone announced $7.4 billion). In addition, the U.S. Department of Commerce announced a $2 billion grant for nine quantum companies in exchange for a minority stake. Whether a quantum computer is developed in 2030 or later, the pace of funding suggests that academic research alone will not determine the outcome.

In the European context, the picture is rounded out by the ENISA Threat Landscape 2025: during the period under review (July 2024–June 2025), it recorded 4,875 incidents; phishing was the entry point for 60% of attacks; and attacks on operational technology (OT) now account for 18.2% of all identified threat categories. In the Czech Republic, NÚKIB recorded a total of 203 cybersecurity incidents in 2025. None of these directly concern quantum risk, but they illustrate the environment in which companies are addressing post-quantum preparedness: a growing number of attacks, increasing budgets, and mounting regulatory pressure—amidst which cryptographic agility remains on the periphery of attention for now.

Why Taking Inventory Is Harder Than It Looks

Figuring out what to encrypt sounds like an administrative task that would take a few weeks. In reality, however, it is one of the most difficult steps in the entire preparation process, for three reasons.

First, cryptography is scattered across layers that no one normally monitors comprehensively: source code and libraries, TLS configurations on dozens of servers, certificates, HSMs, VPN concentrators, IoT and OT devices, as well as CI/CD pipelines and code repositories, where hard-coded algorithms often end up. Security teams typically have tools that cover fragments of this landscape—certificate management, vulnerability scanning, and network monitoring—but none of them provides a comprehensive overview on its own.

Second, some of the cryptography comes from outside sources. It is estimated that 70–90% of today’s software is composed of third-party code in the form of open-source libraries, vendor SDKs, and third-party APIs, and this code has its own cryptographic dependencies that the internal team is unaware of. Without an inventory, a problem in such a library is only discovered when it needs to be resolved urgently—not before.

Third, an inventory is not a one-time project, but a dynamic process in an environment that changes faster than it can be documented. Regulatory pressures such as NIS2, DORA, and PCI DSS 4.0 are increasingly explicitly requiring the ability to demonstrate what cryptography an organization uses and where. This pressure will intensify and be ongoing. The reality is that the question, “If we had an audit tomorrow, would we be able to present a complete cryptographic inventory?” is, frankly, unanswerable in many organizations today.

Steps That Make Sense

It is clear from the above that PQC cannot be avoided in the long term, and the larger the organization, the more urgent it is to begin preparations. It is equally clear that adapting to the post-quantum era will require considerable effort and financial resources. Therefore, before an organization delves into the technical details, it makes sense to first answer three questions:

  1. where asymmetric cryptography is used throughout the organization to protect data confidentiality (communications, storage, backups, etc.),
  2. how long this data must remain confidential, and
  3. who owns the system in question, so that the change has a designated person responsible for it.

 

These steps are part of general security and risk management and make sense regardless of PQC. No matter how you approach PQC, these steps will certainly not be wasted. SEFIRA guides customers through the transition to post-quantum cryptography, from consulting to the implementation of specific solutions.

Sources Used

  • DigiCert, Quantum Readiness Gap Study (2025): www.digicert.com/news/quantum-readiness-gap-a-digicert-study-on-quantum-safe-encryption

  • ISACA, survey of 2,600+ professionals (2025): cited from Security Boulevard, www.securityboulevard.com/2025/05/survey-surfaces-limited-amount-of-post-quantum-cryptography-progress

  • Qtonic Quantum Benchmark, Fortune 1000 (2025): www.pr.com/press-release/968091

  • Gartner, Forecast: Information Security, Worldwide (2025–2026): www.gartner.com/en/newsroom/press-releases/2025-07-29-gartner-forecasts-worldwide-end-user-spending-on-information-security-to-total-213-billion-us-dollars-in-2025

  • IBM, Cost of a Data Breach Report 2025: www.ibm.com/reports/data-breach

  • Ransomware Statistics 2025: Summary Based on Data from www.industrialcyber.co and Emsisoft/GuidePoint

  • Cybersecurity Ventures, Estimate of the Cost of Cybercrime (2025): www.cybersecurityventures.com/official-cybercrime-report-2025

  • Quantum Investments 2025: www.souhrn according to McKinsey (Quantum technology investment hits a “magic moment”) and SpinQuanta

  • ENISA, Threat Landscape 2025: www.enisa.europa.eu/publications/enisa-threat-landscape-2025

  • NÚKIB, Monthly Reports on Cyber Incidents 2025: www.nukib.gov.cz