Abstract

This piece develops the anchor threat of a post-quantum migration — harvest-now-decrypt-later — and the concrete artifact for defending against it: a data-at-risk inventory. It explains why this passive, future-capable adversary is the threat that forces action today rather than at quantum arrival, because the confidentiality of long-lived data recorded now is irreversibly lost once the attacker can decrypt. It lays out the inventory process: enumerate the data flows and stores carrying confidential data, assign each a confidentiality shelf-life, estimate the migration time and the uncertain time to quantum capability, and flag as at-risk any data whose shelf-life plus migration time exceeds the time to quantum. It turns this into a prioritization by risk margin, surveys the three control levers — shorten retention, accelerate migration, migrate confidentiality — and frames the inventory as a living artifact. The theme: harvest-now-decrypt-later is the threat that makes the migration urgent now, and a shelf-life-ranked data inventory is the tool that turns that urgency into a prioritized plan.

Of all the quantum threats, one is already in progress: an adversary recording your encrypted traffic and exfiltrating your ciphertext archives today, storing them, and waiting to decrypt once a quantum computer exists. This harvest-now-decrypt-later threat is the anchor of a post-quantum threat model because it is the only one that demands action before quantum computers arrive — anything recorded now whose confidentiality must outlast the transition is already being lost. Defending against it is not abstract; it starts with a concrete artifact, an inventory of data ranked by how long its secrecy must hold against the quantum clock. This article develops the threat and the inventory that answers it.

Why it is the anchor threat

Harvest-now-decrypt-later is distinctive because it decouples the moment of attack from the moment of harm. The adversary acts now, passively, capturing data it cannot yet read; the harm arrives later, when quantum capability lets it decrypt. Every other quantum threat is realized only when the quantum computer exists, but this one accrues today, at the instant of recording, which is why it alone forces action ahead of the quantum timeline rather than at it. Waiting until quantum computers arrive to migrate is, for this threat, already too late for everything recorded in the meantime.

The threat is also irreversible in a way that sharpens its urgency. Data recorded today under classical encryption cannot be un-recorded; once the adversary holds the ciphertext, the only thing standing between it and the plaintext is the classical scheme's resistance, which the future quantum computer removes. There is no later remediation — no key rotation or re-encryption of the attacker's copy — so the only defense is to have protected the data with quantum-resistant cryptography before it was recorded. This one-way, deadline-driven character is what makes it the organizing threat of the migration.

This is why the migration methodology and the threat model both center on it. It converts the abstract question of when quantum computers will arrive into a concrete present obligation: for any data whose confidentiality must last long enough, the protection must be upgraded now. The inventory that identifies which data those are is therefore the first operational step, and the rest of this article builds it.

Building the data-at-risk inventory

The inventory is constructed in steps. First, enumerate the data flows and stores that carry confidential data: connections to long-lived services, virtual private network traffic that may be recorded, backups, archives, and any repository whose contents must stay secret. This is a discovery exercise across the estate, and it should be exhaustive, because any confidential flow omitted is a blind spot the passive collector may be exploiting.

Second, assign each item a confidentiality shelf-life — how many years its secrecy must hold. This is a data-classification judgment, and it varies enormously: session content may need seconds, transactional records years, and some regulated or strategic data decades. Third, estimate the two other quantities the risk test needs: the migration time, how long it will take to protect that item with quantum-resistant cryptography, and the time to quantum capability, expressed as an uncertainty band rather than a single date because it is genuinely unknown.

Fourth, apply the test: an item is at risk if its shelf-life plus its migration time exceeds the time to quantum capability, because it will still require protection at a moment when the migration is incomplete and the attacker has arrived. Because the time to quantum is a band, the prudent practice is to test against the earlier, more pessimistic end, so that the inventory errs toward flagging data as at-risk rather than missing it. The output is a list of data flagged at-risk, which the next section ranks.

Enumerate confidential data, assign each a shelf-life, estimate migration time and the time to quantum, and flag any item whose shelf-life plus migration time exceeds it. Building the inventory Enumerate dataflows and stores Assign shelf-lifeyears of secrecy Estimate clocktime to quantum Flag at-riskx + y > z
Enumerate confidential data, assign each a shelf-life, estimate migration time and the time to quantum, and flag any item whose shelf-life plus migration time exceeds it.
\[\text{at-risk} \iff x + y > z \quad (x = \text{shelf-life},\ y = \text{migration time},\ z = \text{time to quantum})\]
\[\text{test against the pessimistic (earliest) end of the } z \text{ band}\]

The at-risk test and prioritization

The flagged items are not equally urgent, and the ranking is by risk margin. Define the margin as the time to quantum minus the sum of shelf-life and migration time; a positive margin means there is slack before the data is exposed, while a negative margin means the data is already at risk, and the more negative the margin, the more overdue its protection. Sorting the at-risk items by their margin, most negative first, produces the priority order for the migration: the data that is furthest past the safe line is protected first.

This ranking is what turns the threat model into an actionable plan. Rather than migrating uniformly or by convenience, effort goes to the data where the harvest-now-decrypt-later math is most adverse — typically the longest-retention, most sensitive archives and the flows to services holding them. The margin makes the prioritization objective and defensible: it is derived from each item's own shelf-life and the shared quantum clock, not from intuition about which systems feel important.

The at-risk items with the largest negative margins are, almost by definition, the long-lived confidential archives, because their large shelf-life dominates the inequality. This is why long-retention data is the recurring headline asset of the harvest-now-decrypt-later threat, and why an inventory that surfaces and ranks it is the practical core of defending against a passive collector. The margin turns the abstract inequality into a queue.

Long-retention data whose shelf-life plus migration time exceeds the quantum clock is harvested now for later decryption; ephemeral data expires before it matters. At risk versus never at risk Long-retention dataharvested now x + y > zdecrypt later Ephemeral dataexpires first x + y < znever at risk
Long-retention data whose shelf-life plus migration time exceeds the quantum clock is harvested now for later decryption; ephemeral data expires before it matters.

Three levers to shrink the risk

The inequality that defines risk also reveals three levers to reduce it. The first is to shorten the shelf-life: data that does not need to be kept, or does not need to stay confidential as long, can have its retention reduced, lowering its shelf-life and possibly moving it out of the at-risk set entirely. Minimizing retention is a data-governance control that directly attacks the risk, and it is often the cheapest lever because it may eliminate the problem rather than mitigate it.

The second lever is to shorten the migration time: accelerating the protection of a given item — prioritizing it, streamlining its migration — reduces the migration-time term and can bring the sum back under the quantum clock. The third and primary lever is to migrate the confidentiality itself, replacing the classical protection with quantum-resistant, typically hybrid, cryptography so that data recorded from that point forward is safe against the future decryptor. This is the direct remedy: once an item is protected with post-quantum cryptography, newly recorded copies are no longer harvestable.

These levers combine. For a given at-risk item, one might shorten its retention where policy allows, accelerate its migration because its margin is negative, and migrate its confidentiality to a hybrid scheme — reducing all three terms of the inequality at once. The inventory, by exposing each item's shelf-life, migration time, and margin, is what makes it possible to choose the right lever for each item rather than applying one blunt response everywhere.

Shortening retention, accelerating migration, and migrating confidentiality each reduce a term of the shelf-life-versus-quantum inequality. Three levers on the risk inequality Shrinking the riskattack the inequality Shorten retentionreduce shelf-life x Speed migrationreduce time y Migrate confidentialityquantum-safe now
Shortening retention, accelerating migration, and migrating confidentiality each reduce a term of the shelf-life-versus-quantum inequality.

A living inventory, and the agent angle

The data-at-risk inventory is not a one-time document but a living artifact. The time to quantum is an estimate that shifts as the field advances, and each shift re-ranks the margins; retention policies and data flows change; new confidential stores appear. Keeping the inventory current — re-running the at-risk test as the quantum estimate moves and as the estate evolves — is what keeps the prioritization valid over the years the migration spans. A stale inventory silently mis-prioritizes as the ground shifts beneath it.

The inventory also connects the threat model to the migration program. Its ranked output is exactly the prioritized worklist the migration methodology consumes: the highest-negative-margin data flows to the front of the hybrid-key-exchange rollout, and the controls chosen per item — shorten, accelerate, migrate — feed the execution phase. The threat model identifies and ranks the risk; the migration program acts on it; and the inventory is the shared artifact between them.

For autonomous AI systems the at-risk inventory is dominated by a few large assets. Long-retention training-data archives and conversation logs, whose confidentiality obligations stretch for years, are the quintessential harvest-now-decrypt-later targets and will top the ranking; model weights protected at rest and the traffic to the services that hold them follow. The guidance is to build and maintain a data-at-risk inventory specifically covering these AI assets, rank them by margin against a pessimistic quantum estimate, and apply the three levers — minimize retention where the data need not persist, accelerate migration of the longest-lived archives, and migrate their confidentiality to hybrid post-quantum protection now — because for an AI platform, the training data being recorded today is precisely the asset a patient adversary is most likely to want to read in a decade.

⚠️
Recorded today, decrypted later — irreversibly. Data harvested now under classical encryption cannot be un-recorded; the only defense is post-quantum protection before recording. Build a data-at-risk inventory, rank by margin against a pessimistic quantum estimate, and migrate the longest-lived confidential data first.

Key takeaways

  • Harvest-now-decrypt-later is the anchor threat because it accrues today — a passive collector records ciphertext now to decrypt once quantum capability arrives — so it demands action before quantum computers exist.
  • The threat is irreversible: data recorded under classical encryption cannot be un-recorded, so the only defense is post-quantum protection applied before the data is captured.
  • The defense begins with a data-at-risk inventory: enumerate confidential flows and stores, assign each a shelf-life, estimate migration time and the time to quantum (as a band), and flag any item where shelf-life plus migration time exceeds the clock.
  • Prioritize flagged items by risk margin (time to quantum minus shelf-life plus migration time), most negative first; long-retention archives dominate because their large shelf-life drives the inequality.
  • Three levers shrink the risk: shorten retention (reduce shelf-life), accelerate migration (reduce migration time), and migrate confidentiality to hybrid post-quantum cryptography — often combined per item.
  • Keep the inventory living, re-ranking as the quantum estimate and estate change; for AI systems, long-retention training-data archives and conversation logs top the ranking and should be protected first.

Practitioner Toolkit

Copy-paste, strictly defensive artifacts you can use today. Nothing here attacks a real system.

Building a data-at-risk inventorychecklist

Confirm the inventory surfaces the harvest-now-decrypt-later risk.

  • Are all confidential data flows and stores enumerated, including backups and archives?
  • Does each item have an assigned confidentiality shelf-life?
  • Are migration time and a pessimistic time-to-quantum band recorded?
  • Is each item flagged at-risk when shelf-life plus migration time exceeds the clock?
  • Are at-risk items ranked by risk margin, most negative first?
🚀Defend against the collectorquickstart

Turn the inventory into prioritized action.

  • Rank at-risk data by margin against a pessimistic quantum estimate.
  • Shorten retention where the data need not persist.
  • Accelerate migration of the longest-lived, most-negative-margin data.
  • Migrate confidentiality to hybrid post-quantum cryptography now.
🔒Data-at-risk inventory policypolicy

A stub encoding the inventory and its levers.

data_at_risk_inventory:
  enumerate: [flows, stores, backups, archives]
  per_item:
    shelf_life_years: recorded
    migration_time: recorded
  time_to_quantum: pessimistic_band
  at_risk_test: shelf_life_plus_migration_gt_ttq
  rank_by: risk_margin_most_negative_first
levers: [shorten_retention, speed_migration, migrate_confidentiality]
review: living_document_re_rank_on_change
Illustrative documentation template, not a product config.

Glossary

Harvest-now-decrypt-later
A passive attack recording encrypted data today to decrypt once a quantum computer exists; the threat accrues at recording time and is irreversible.
Data-at-risk inventory
A catalog of confidential data flows and stores, each tagged with shelf-life, migration time, and a risk margin against the quantum clock.
Confidentiality shelf-life
How many years a data item's secrecy must hold; the dominant term in the at-risk inequality for long-lived data.
Risk margin
Time to quantum minus the sum of shelf-life and migration time; negative means already at risk, and more negative means higher priority.
The three levers
Shortening retention, accelerating migration, and migrating confidentiality — each reducing a term of the at-risk inequality.
Living inventory
A continuously maintained data-at-risk catalog, re-ranked as the quantum estimate and the estate change over the migration's span.

References

  1. Mosca, Cybersecurity in an Era with Quantum Computers (IEEE Security & Privacy, 2018)
  2. NIST IR 8547, Transition to Post-Quantum Cryptography Standards (2024)
  3. NIST SP 1800-38, Migration to Post-Quantum Cryptography (practice guide)
  4. Shostack, Threat Modeling: Designing for Security (Wiley, 2014)
  5. IETF draft-ietf-tls-hybrid-design, Hybrid Key Exchange in TLS 1.3