The most profound lesson I learnt from a SANCS26 lecture by Thomas Attema, Senior Scientist at TNO and CWI, is that your data may already be in jeopardy. While many view the “quantum threat” as a future concern, cybercriminals and state actors are currently engaging in “harvest now, decrypt later” (HNDL) attacks.
The immediate risk to your organisation
If your business relies on the assumption that encrypted data remains private indefinitely, you are exposed to a severe strategic liability. Right now, adversaries are intercepting and archiving your company’s most sensitive long-term assets: intellectual property, financial records, and client secrets. They are not attempting to break your encryption today; they are waiting for the arrival of Q-Day. When quantum computers reach maturity, every secure file harvested today will be rendered transparent in seconds. If your data has a shelf life of more than five years, the theft is not a future possibility: the data has likely already been taken.
What is a “harvest now, decrypt later” attack?
A “harvest now, decrypt later” attack occurs when an adversary intercepts and stores encrypted data today with the intent to decrypt it once a cryptographically relevant quantum computer (CRQC) becomes available.
The encryption protecting your company’s most sensitive data is currently unbreakable by today’s fastest supercomputers, which often creates a false sense of security. However, the silent threat is that the data has already been “stolen” while encrypted, awaiting a future where current encryption becomes obsolete. Think of it like this: the lock hasn’t been picked yet, but the entire door has already been stolen and moved to a thief’s warehouse. The mistake is assuming that because they can’t read it now, it doesn’t matter that they have it.
Why standard encryption is vulnerable to quantum computing
Standard encryption methods like RSA and Elliptic Curve Cryptography (ECC) rely on mathematical foundations, such as factoring large prime numbers, that are “hard” for classical bits but “easy” for quantum qubits.
- Shor’s algorithm: Quantum computers use this specific set of instructions to solve the mathematical problems that form the foundation of RSA and ECC. It’s like the difference between trying every possible combination on a lock and having a key that reshapes itself to fit the lock perfectly.
- The Y2Q moment: Often called the “Y2K moment” of the 2030s, Y2Q represents the point where quantum mechanics renders current encryption standards ineffective.
The “shelf-life” risk: is your data a target?
The risk is most acute for data assets with a long “shelf life”. Public intelligence and historical breaches highlight how this “long game” puts organisations at risk:
- Intellectual property theft: Competitors target proprietary research and product designs. Even if it takes years to decrypt, that stolen IP can still be used to undercut your market position or leapfrog your R&D.
- Permanent personal data: Unlike a password or a credit card that can be changed, data like health history or fingerprints is permanent. If this data is harvested today, its exposure in the 2030s could lead to long-term blackmail or identity exploitation.
- Retrospective exposure: Any encrypted communication sent today, from VPNs to bank transfers, could be retrospectively opened and read once Q-Day arrives.
How to outrun the quantum threat: strategic solutions
Even though a CRQC does not yet exist, the risk to long-term data is active today. A “wait and see” approach is becoming a legal and commercial liability.
1. Adopt post-quantum cryptography (PQC)
Post-quantum cryptography consists of new mathematical puzzles that even quantum computers find impossible to solve.
- Compatibility: PQC does not require a quantum computer to run; it can be deployed on your existing laptops and servers today.
- Standards: NIST has recently finalized its first set of PQC standards, providing a roadmap for secure implementation.
2. Build “crypto-agility”
Crypto-agility is the ability of a system to swap out old encryption algorithms for new ones without rebuilding the entire infrastructure. Encryption is often hard-coded deep into software, like plumbing inside the walls of a skyscraper. Crypto-agility means redesigning your systems so the encryption is more like a modular power outlet that you can easily unplug and replace.
- Mapping: Organisations must map where encryption is used in their tech stack.
- Flexibility: A crypto-agile framework allows for the seamless replacement of algorithms as new quantum-resistant standards emerge.
How ITLawCo assists with quantum readiness
Navigating the transition to a quantum-safe environment requires a blend of technical insight and legal expertise. ITLawCo provides specialised support to ensure your business remains resilient:
- Quantum risk audits: We help you identify data with a long “shelf life” that is currently at risk of HNDL attacks.
- Compliance mapping: We ensure your security posture meets “state-of-the-art” requirements under regulations like GDPR and POPIA.
- Crypto-agility strategy: We assist teams in building frameworks that allow for the seamless adoption of NIST-standard PQC.
- Executive briefings: We translate technical quantum threats into actionable business and legal strategies for boards and leadership teams.
FAQs about quantum threats
What is Q-Day?
Q-Day is the predicted point in time when quantum computers will be powerful enough to render current encryption standards like RSA and ECC obsolete.
Does my business need a quantum computer to be safe?
No. Quantum-safe security (PQC) consists of mathematical puzzles that run on your current hardware and servers.
Why is HNDL a legal risk?
Regulations such as GDPR and POPIA demand “state-of-the-art” security. Failing to prepare for known quantum vulnerabilities can be viewed as a failure to protect data, leading to legal and commercial liability.
Is your encryption future-proof?
The window to protect your long-term data assets is closing. Ensure your business has the momentum to outlast the quantum threat.
Book a clarity session with an ITLawCo advisor today.
This article is intended for general information purposes and does not constitute legal advice. For advice specific to your business circumstances, please consult with an ITLawCo advisor.



