
Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning
I’ve sat in enough boardroom conversations about quantum computing to notice a pattern. Someone raises it, someone else says “that’s ten years out,” and the topic gets tabled until next year’s budget cycle. The clock that matters isn’t the one measuring when a quantum computer arrives. It started running the moment your organization first sent sensitive data over a channel an adversary could capture and store.
A nation-state or well-resourced criminal group doesn’t need a working quantum computer today to threaten you. It needs storage capacity and your ciphertext, both of which it likely already has. It can sit on that data for years and decrypt it retroactively the day a cryptographically ...