Enterprises aren't moving fast enough on post-quantum cryptography preparations – ‘harvest now, decrypt later’ attacks mean it could cost them

Security leaders are concerned that encrypted data is already vulnerable to 'harvest now, decrypt later' attacks

Post-quantum cryptography concept image showing digitized data storage cubes with exposed numbers and binary code.
(Image credit: Getty Images)

Organizations could face a ticking quantum time-bomb, according to new research from DigiCert, with the vast majority aware that they aren’t properly prepared.

An overwhelming 85% of IT and security leaders believe that quantum computing advances will break existing security standards within a decade, yet only 7% have deployed quantum-safe certificates so far.

A key worry among survey respondents lies in the risk of ‘harvest now, decrypt later’ (HDNL) attacks. This refers to a method whereby threat actors steal and save encrypted data with the goal of cracking it later on using quantum computers.

More than eight-in-ten believe that at least some of their encrypted data is vulnerable to HDNL attacks right now, with around one-third reckoning that more than a quarter of it is vulnerable.

Latest Videos FromIT Pro

They expect financial transaction records and banking data to be targeted first, followed by cryptocurrency private keys and wallets.

Some respondents even pointed to politically sensitive disclosures and high-profile leaked documents, such as WikiLeaks-style disclosures and the Epstein files, as examples of information that could remain valuable to attackers for years.

"What's particularly concerning is that more than a third of UK organizations believe over a quarter of their encrypted data is already vulnerable to 'harvest now, decrypt later' attacks," said Simon Pamplin, CTO of Certes.

"For organizations handling financial data, customer records and personally identifiable information, this is no longer a future planning exercise. Data being stolen today will be exposed years from now if it isn't adequately protected."

A post-quantum cryptography roadmap

With the publication of the National Institute of Standards and Technology’s (NIST) post-quantum cryptography (PQC) standards in August 2024, organizations have been given a clearer path forward, and are at least starting to prepare.

Nearly nine-in-ten are planning, testing, or implementing PQC initiatives, while half have conducted quantum risk assessments, 45% have developed transition plans, and 44% have created cryptographic inventories.

Pamplin noted that the biggest obstacles to preparation aren’t awareness, however, it’s the "absolute complexity” of making cryptographic changes across an array of legacy applications, hybrid environments, and edge infrastructure.

These were “never designed with crypto agility in mind,” he said.

UK firms are acting fast

Preparedness appears to vary more by industry than geography. Retail was the only major industry where more respondents reported being unprepared than highly prepared, while manufacturing showed the greatest divide, with respondents split between feeling highly prepared and not prepared at all.

The UK reported the highest share of organizations identifying as leading edge, at 18%, closely followed by the US at 17% and Australia at 10%.

Cryptographic inventories, certificate visibility, migration planning, and crypto-agility are becoming foundational to quantum readiness, the researchers said.

Indeed, those that establish visibility early will be better positioned to prioritize migration, measure progress, and adapt as PQC becomes the new standard.

"Organizations need to stop thinking about post-quantum cryptography as simply replacing algorithms," said Pamplin.

"They should be focusing on protecting the data itself with a data-centric, crypto-agile approach that reduces risk today while creating a practical path to long-term quantum readiness."

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Emma Woollacott

Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.