Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Harvest now, decrypt later: what identity teams need to act on


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Encrypted data theft is already a live threat because attackers can store it now and decrypt it later, while EY says 87% of UK business leaders expect quantum disruption by 2030 and ISACA found 56% of security and trust professionals are concerned, according to Ground Labs. The practical issue is not distant quantum capability but how long sensitive data, digital identities and certificates remain valuable and exposed.

NHIMG editorial — based on content published by Ground Labs: Harvest now, decrypt later: Why quantum risk cannot wait

By the numbers:

Questions worth separating out

Q: How should organisations reduce harvest now, decrypt later risk?

A: Start by identifying encrypted data that must remain confidential for years, not months.

Q: Why does quantum risk matter for non-human identities now?

A: Quantum risk matters now because organisations can already lose confidentiality through harvest-now, decrypt-later collection.

Q: What usually breaks when cryptographic inventory is incomplete?

A: Incomplete inventory breaks prioritisation.

Practitioner guidance

  • Map long-lived data first Identify the records, identities and communications that must remain confidential beyond 2030, then rank them by exposure and business value.
  • Build a cryptographic inventory tied to identity systems Create an inventory of algorithms, keys, certificates, libraries and protocols, then link each item to the identity, signing or transport service it protects.
  • Reduce duplicate exposure before migration Delete redundant copies, enforce retention policies and remove unnecessary access to sensitive archives across cloud, SaaS, backups and analytics environments.

What's in the full article

Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:

  • NIST post-quantum standards and the migration timeline details behind FIPS 203, 204 and 205
  • Stepwise guidance for building a cryptographic inventory across applications, keys, certificates and libraries
  • Practical methods for prioritising long-lived data by exposure, sensitivity and confidentiality lifespan
  • Vendor and supply-chain considerations for crypto-agility planning across dependent systems

👉 Read Ground Labs' analysis of harvest now, decrypt later risk and PQC migration →

Harvest now, decrypt later: what identity teams need to act on?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Harvest now, decrypt later creates a confidentiality-lifespan problem, not a crypto problem alone. The article is right to frame quantum risk as current because the adversary objective is time-shifted theft. Data that stays sensitive for years is the real target, which means the governance question is how long information must remain confidential and where it exists. Identity, certificate and signing data matter here because they anchor trust over long periods. Practitioners should manage exposure by confidentiality horizon, not by cryptography in isolation.

A question worth separating out:

Q: Who is accountable for post-quantum migration across partners and contractors?

A: Accountability sits with the organisation that owns the trust boundary, but the work spans vendors, contractors, and federated partners. Identity teams should define who approves changes, who validates compatibility, and who owns rollback if a cryptographic transition disrupts access. Cross-organisation trust is a governance issue, not just a technical one.

👉 Read our full editorial: Harvest now, decrypt later exposes long-term identity data risk



   
ReplyQuote
Share: