Enterprises aren't moving fast enough on post-quantum cryptography preparations – ‘harvest now, decrypt later’ attacks mean it could cost them
Security leaders are concerned that encrypted data is already vulnerable to 'harvest now, decrypt later' attacks
Organizations could face a ticking quantum time-bomb, according to new research from DigiCert, with the vast majority aware that they aren’t properly prepared.
An overwhelming 85% of IT and security leaders believe that quantum computing advances will break existing security standards within a decade, yet only 7% have deployed quantum-safe certificates so far.
A key worry among survey respondents lies in the risk of ‘harvest now, decrypt later’ (HDNL) attacks. This refers to a method whereby threat actors steal and save encrypted data with the goal of cracking it later on using quantum computers.
More than eight-in-ten believe that at least some of their encrypted data is vulnerable to HDNL attacks right now, with around one-third reckoning that more than a quarter of it is vulnerable.
They expect financial transaction records and banking data to be targeted first, followed by cryptocurrency private keys and wallets.
Some respondents even pointed to politically sensitive disclosures and high-profile leaked documents, such as WikiLeaks-style disclosures and the Epstein files, as examples of information that could remain valuable to attackers for years.
"What's particularly concerning is that more than a third of UK organizations believe over a quarter of their encrypted data is already vulnerable to 'harvest now, decrypt later' attacks," said Simon Pamplin, CTO of Certes.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"For organizations handling financial data, customer records and personally identifiable information, this is no longer a future planning exercise. Data being stolen today will be exposed years from now if it isn't adequately protected."
A post-quantum cryptography roadmap
With the publication of the National Institute of Standards and Technology’s (NIST) post-quantum cryptography (PQC) standards in August 2024, organizations have been given a clearer path forward, and are at least starting to prepare.
Nearly nine-in-ten are planning, testing, or implementing PQC initiatives, while half have conducted quantum risk assessments, 45% have developed transition plans, and 44% have created cryptographic inventories.
Pamplin noted that the biggest obstacles to preparation aren’t awareness, however, it’s the "absolute complexity” of making cryptographic changes across an array of legacy applications, hybrid environments, and edge infrastructure.
These were “never designed with crypto agility in mind,” he said.
UK firms are acting fast
Preparedness appears to vary more by industry than geography. Retail was the only major industry where more respondents reported being unprepared than highly prepared, while manufacturing showed the greatest divide, with respondents split between feeling highly prepared and not prepared at all.
The UK reported the highest share of organizations identifying as leading edge, at 18%, closely followed by the US at 17% and Australia at 10%.
Cryptographic inventories, certificate visibility, migration planning, and crypto-agility are becoming foundational to quantum readiness, the researchers said.
Indeed, those that establish visibility early will be better positioned to prioritize migration, measure progress, and adapt as PQC becomes the new standard.
"Organizations need to stop thinking about post-quantum cryptography as simply replacing algorithms," said Pamplin.
"They should be focusing on protecting the data itself with a data-centric, crypto-agile approach that reduces risk today while creating a practical path to long-term quantum readiness."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Two-thirds of workers are so fed up with ‘AI slop’ that they ‘feel nostalgic for pre-AI work’News A survey has revealed that dealing with low-quality 'AI slop' is making jobs feel less meaningful and more repetitive
-
The AI vulnerability flood: 7 critical takeaways from the Sophos Mythos expert briefingNavigating the shift from conversational AI to automated, long-running exploitation pipelines
-
A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’News NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration
-
Enterprises are preparing for a post-quantum world – experts worry it could be too late for manyNews More than 100 million firms are expected to embrace post-quantum algorithms by 2035, but that's just a drop in the ocean
-
Google just revised its ‘Q-Day’ timeline: Quantum computers could break existing encryption techniques within three years – and enterprises are nowhere near readyNews Google has warned that “Q-Day”, the point where a quantum computer is powerful enough to crack current encryption techniques, could come as soon as 2029.
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
Nearly half of enterprises aren't prepared for quantum cybersecurity threatsNews Most businesses haven't even started transitioning to post-quantum cryptography, research shows
-
Get started on post-quantum encryption, organizations warnedNews The UK's national cybersecurity agency is urging companies to begin preparing themselves for quantum threats by 2035.
-
NIST aims to quantum-proof encryption with new algorithmsNews Three algorithms are now in draft and more are on the way to bolster enterprise defenses
-
C-suites consider quantum a serious threat and "amazing" deepfake attacks are just 'months away'News Deepfake technology has matured at a rapid rate, and video scams are likely to be a on par with the more convincing voice-only campaigns very soon, one expert says