Digital security is about to undergo an unprecedented revolution as quantum computing threatens the encryption algorithms we use to protect sensitive data.
Breakthroughs in quantum technologies are accelerating and the timelines shrinking before the protocols we rely on for data security are broken.
Google Cloud is targeting full quantum readiness by 2029, in a roadmap that includes ‘Store Now Decrypt Later’ mitigation by the end of 2027. Microsoft’s Quantum Safe Program is working toward similar deadlines.
NIST has warned that the transition to post-quantum cryptography (PQC) will take several years, because companies will have to update the algorithms across the products and services they use, and ensure they integrate with upstream and downstream technologies.
While quantum risk feels like a problem for tomorrow, the ‘Harvest Now Decrypt Later’ threat (HNDL) is one businesses face today as cybercriminals stockpile data ready to decrypt once quantum technologies are available.
In this article, we’ll expose the data most at risk and the steps businesses can take now to protect it using data intelligence as the foundation for their quantum resilience strategy.
The data question you need to know today
Most quantum readiness plans start with identifying the vulnerable algorithms being used. But this doesn’t answer the question at the heart of effective resilience strategies to defend against HNDL attacks.
Cybersecurity agencies including NIST, CISA and NSA in the US, the NCSC in the UK and others are specifically warning about long-lived sensitive data and confidential information. They recommend that businesses first focus on identifying long-lived data and securing it against current cyberthreats before building a migration roadmap to transition to PQC.
Prioritizing data security is a balancing act, as businesses work with limited resources and rapidly expanding data environments. HNDL adds further complexity, since businesses need to prioritize both:
-
Unprotected sensitive data; and
-
Long-lived sensitive data, even where it’s already be protected with encryption
What makes sensitive data long-lived?
When considering HNDL threat, retention requirements are a misguided indicator of the risk. Some types of data need to be kept for a long time, but lose their value quickly. Other types of data may only be required for a short time, but are of high value for extended periods.
For example, a payment card number is valid for a fixed amount of time and if the card is lost or stolen, it can be replaced with a new number to reduce fraud risk. Bank statements displaying that card information may be retained for several years even after the card has been replaced.
Meanwhile, health information and biometric information can’t be replaced if it's exposed. That information remains valid and useful throughout the lifetime of the individual.
It can help to consider data longevity in terms of its retention timeline, confidentiality timeline and its exposure timeline.
| Timeline | What it tells you |
| Retention timeline | How long information is required or needs to be kept |
| Confidentiality timeline | How long disclosure of the information could still cause harm |
| Exposure timeline | How long copies of the information continue to exist |
There are four primary patterns that contribute to making some data types more long-lived than others:
-
Information that can’t be reissued. This includes biometric information, genetic information and identity attributes. It can also include identifiers such as National Insurance Numbers which are issued for life.
-
Information that follows and develops with an individual throughout their life. This includes information such as health history, financial history, legal information and government records that are built over time and retain relevance and significance to the individual over many years.
-
Information with long-term strategic value. This includes intellectual property, research, patents and trade secrets that are valuable because of the advantages they offer while they are secret.
-
Legacy information that becomes more valuable when combined with other data. Different aspects of our personal information are available in different places. While an old address in isolation may seem to be of limited use, when it's combined with other information about us, it’s relatively straightforward to develop a comprehensive identity profile.
Identifying long-lived sensitive data with data intelligence
Sensitive data does not remain inside the application where it was first collected. It moves through normal business processes in reporting, analytics, email, file sharing, migrations, backups, cloud adoption, collaboration tools and downstream processing.
Over time, a single record can become many records governed by very different controls.
When it comes to identifying long-lived sensitive data, it’s important to consider the question:
Which information has a long confidentiality lifetime, and where is that information within our organization?
Organizations process millions of records every year, so it’s important to prioritize the areas that matter most for any given objective. In the case of HNDL and quantum readiness, this means focusing on identifying data with a long confidentiality timeline, is irreplaceable and widely distributed.
This increases the likelihood that the information is exposed or vulnerable to exposure, and will retain its usefulness beyond the quantum timeline.
NIST's Migration to Post-Quantum Cryptography project places cryptographic visibility and risk management at the foundation of migration, with the aim of building a comprehensive cryptographic inventory that can guide prioritization.
Adding data intelligence allows that prioritization to become more specific.
|
Cryptographic intelligence establishes where quantum-vulnerable algorithms, certificates, protocols and dependencies are used. Data intelligence establishes what sensitive information exists within those environments, where additional copies have propagated and which datasets carry the longest confidentiality requirements. |
Ground Labs' solutions identify sensitive information across structured and unstructured data stores spanning on-premises, cloud and hybrid environments in a reliable, accurate and repeatable manner.
For quantum-readiness purposes, that can help organizations identify:
-
biometric, health and identity information with long confidentiality requirements
-
financial and regulated data held under extended retention requirements
-
sensitive information in legacy systems and archives
-
unexpected duplicates and exported copies
-
concentrations of high-value information
-
proprietary or business-specific data identified through custom patterns
-
sensitive information appearing outside its expected control environment
Quantum readiness starts with data intelligence
NIST has standardized the first PQC algorithms and says migration should begin now. Google and Microsoft have moved their major transition targets to 2029. The NCSC expects the highest-priority migration activity to be completed by 2031 and wider migration by 2035. However, these timelines don’t prioritize what needs to be addressed first.
Some sensitive data loses value quickly. Some can be replaced after compromise. Other information remains part of a person, organization or government for decades. Legacy copies can extend that exposure further still, particularly when data has spread across environments that are no longer visible to security, risk, governance and control teams.
Identifying that information gives quantum-readiness programs a more useful basis for prioritization.
Enterprise Recon provides the data intelligence needed to locate long-lived sensitive data across distributed environments, identify unexpected copies and understand where the greatest concentrations of enduring information reside. Ground Labs Professional Services can extend that capability through data intelligence, analysis and quantum resilience advisory engagements.
PQC migration will ultimately address at-risk cryptography, but data intelligence establishes where that protection should begin and which information needs the strongest protection now.
Frequently asked questions
What is long-lived sensitive data?
Long-lived sensitive data is information that remains confidential, valuable or potentially harmful if exposed for many years.
How do you determine the confidentiality lifetime of data?
Consider how long disclosure could cause harm, whether the information can be replaced, its retention requirements and whether its value persists when combined with other information.
Is data retention the same as data confidentiality lifetime?
No. Retention defines how long information must or should be kept. Confidentiality lifetime describes how long the information needs to remain protected from disclosure.
Which types of personal data are long-lived?
Examples include biometric and genetic information, health histories, identity attributes and other sensitive information that remains relevant for many years.
Why does legacy data matter for quantum risk?
Historical information can remain sensitive and may become more valuable when combined with newer identity, financial or personal records.
How should organizations prioritize data for PQC migration?
Prioritization should consider confidentiality lifetime, sensitivity, replaceability, current exposure and the cryptography protecting the data.
How does data intelligence identify long-lived sensitive data?
Data intelligence locates sensitive information across distributed environments and provides evidence about where copies exist, how widely information has spread and which locations require further assessment.
How does Enterprise Recon support long-lived data analysis?
Enterprise Recon identifies sensitive information across structured and unstructured environments, helping organizations find unexpected and legacy data that can inform quantum-risk and PQC priorities.