Skip to main content

IT security

What is harvest now, decrypt later?

Attackers intercept encrypted data today to decrypt it once quantum computers can break the encryption. See who is at risk, and what to do about it.

In short

Harvest now, decrypt later is an attack strategy in which attackers intercept and store encrypted data today with the aim of decrypting it in a few years, when quantum computers are expected to be able to break the asymmetric encryption that protects it.

The data is safe now, but the harvesting is already under way, which is why the threat is real today for all data with a long confidentiality lifetime: trade secrets, patent groundwork, health data, contracts and government data.

The answer is post-quantum cryptography: NIST published the first quantum-resistant standards in 2024, and the EU's joint roadmap requires critical infrastructure to have transitioned by 2030 at the latest and everything else by 2035, with national plans under way from 2026. For businesses, the work starts with a cryptographic inventory: where is vulnerable encryption used, and which data lives the longest.

MI Support IT helps Danish businesses map and plan the transition.

Back to the glossary

What is harvest now, decrypt later?

Harvest now, decrypt later is an attack strategy with a long time horizon: the attacker intercepts encrypted traffic or steals encrypted datasets today (knowing full well that the content cannot be read yet) and puts them in storage. The day a sufficiently powerful quantum computer can break today's asymmetric encryption, the archive is unlocked.

The point that makes the threat relevant now: the protection of data intercepted today depends on whether the encryption holds for the entire lifetime of the data, not just today.

Why does the attack work?

Today's secure connections (TLS, VPN) use asymmetric algorithms such as RSA and elliptic curves for key exchange. A quantum computer capable of running Shor's algorithm at scale would be able to break precisely those, and thereby work out the session keys and decrypt the stored traffic. Nobody knows exactly when that will happen; serious estimates say 10 to 20 years, but the uncertainty is the problem itself: migrating cryptography takes many years in its own right, and the harvesting is already under way. Note that symmetric encryption such as AES-256 is not affected in the same way: it is the key exchange that is the weak link.

Who should take the threat seriously?

The risk depends on one thing: how long your data must remain confidential. Rule of thumb: if the data still needs to be secret in 10 years, it is in the risk zone already today. That applies, for example, to research and product data, patent groundwork, trade secrets and recipes, health data, long-term contracts, and everything in the public and financial sectors. A webshop transaction that is irrelevant in three years, on the other hand, is not the problem.

What is the answer? Post-quantum cryptography and a plan

The solution is called post-quantum cryptography (PQC): new algorithms that also withstand quantum computers. NIST published the first standards in August 2024 (including ML-KEM for key exchange), and they are already being rolled out in browsers and cloud services. Read more under quantum cryptography. Meanwhile, the EU has set out a joint roadmap: member states must be under way by the end of 2026 at the latest, critical infrastructure must have transitioned by 2030 at the latest, and remaining systems by 2035.

For your business, the work starts not with technology but with an overview in the form of a cryptographic inventory: where do you use vulnerable encryption (certificates, VPN, system integrations)? Which data has the longest confidentiality lifetime? And which suppliers have a PQC plan? From there, the migration can be prioritised as the standards mature.

How MI Support IT can help

We help make the quantum threat concrete: mapping your cryptography via PKI management, prioritising by data lifetime and building a realistic migration plan as part of your IT security. Contact us if you want to know where your environment stands in relation to the 2030 deadline.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.