TL;DR: Encrypted data theft is already a live threat because attackers can store it now and decrypt it later, while EY says 87% of UK business leaders expect quantum disruption by 2030 and ISACA found 56% of security and trust professionals are concerned, according to Ground Labs. The practical issue is not distant quantum capability but how long sensitive data, digital identities and certificates remain valuable and exposed.
NHIMG editorial — based on content published by Ground Labs: Harvest now, decrypt later: Why quantum risk cannot wait
By the numbers:
- EY’s 2026 Quantum Business Readiness Report found that 87% of UK business leaders expect disruption from quantum computing by 2030.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: How should organisations reduce harvest now, decrypt later risk?
A: Start by identifying encrypted data that must remain confidential for years, not months.
Q: Why does quantum risk matter for non-human identities now?
A: Quantum risk matters now because organisations can already lose confidentiality through harvest-now, decrypt-later collection.
Q: What usually breaks when cryptographic inventory is incomplete?
A: Incomplete inventory breaks prioritisation.
Practitioner guidance
- Map long-lived data first Identify the records, identities and communications that must remain confidential beyond 2030, then rank them by exposure and business value.
- Build a cryptographic inventory tied to identity systems Create an inventory of algorithms, keys, certificates, libraries and protocols, then link each item to the identity, signing or transport service it protects.
- Reduce duplicate exposure before migration Delete redundant copies, enforce retention policies and remove unnecessary access to sensitive archives across cloud, SaaS, backups and analytics environments.
What's in the full article
Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:
- NIST post-quantum standards and the migration timeline details behind FIPS 203, 204 and 205
- Stepwise guidance for building a cryptographic inventory across applications, keys, certificates and libraries
- Practical methods for prioritising long-lived data by exposure, sensitivity and confidentiality lifespan
- Vendor and supply-chain considerations for crypto-agility planning across dependent systems
👉 Read Ground Labs' analysis of harvest now, decrypt later risk and PQC migration →
Harvest now, decrypt later: what identity teams need to act on?
Explore further
Harvest now, decrypt later creates a confidentiality-lifespan problem, not a crypto problem alone. The article is right to frame quantum risk as current because the adversary objective is time-shifted theft. Data that stays sensitive for years is the real target, which means the governance question is how long information must remain confidential and where it exists. Identity, certificate and signing data matter here because they anchor trust over long periods. Practitioners should manage exposure by confidentiality horizon, not by cryptography in isolation.
A question worth separating out:
Q: Who is accountable for post-quantum migration across partners and contractors?
A: Accountability sits with the organisation that owns the trust boundary, but the work spans vendors, contractors, and federated partners. Identity teams should define who approves changes, who validates compatibility, and who owns rollback if a cryptographic transition disrupts access. Cross-organisation trust is a governance issue, not just a technical one.
👉 Read our full editorial: Harvest now, decrypt later exposes long-term identity data risk