Urgency
Harvest now, decrypt later
Adversaries don't need to break your crypto today. They can store ciphertext now and decrypt it once quantum computers arrive.
The threat model
Nation-state and sophisticated actors harvest TLS sessions, backups, and archives knowing future quantum computers will read them. Storage is cheap; breaking RSA today is not required. NIST describes this as harvest now, decrypt later — one reason post-quantum encryption should deploy as soon as feasible.
How ciphertext gets copied today
Adversaries do not need to break encryption today. The most common paths are breach and ransomware exfiltration (database dumps, file shares, backup appliances), long-term backups and archives (tape, S3 snapshots, email archives), cloud misconfiguration (public snapshots, open prefixes), and bulk network collection at scale. Incident response data shows exfiltration timelines compressing — copying ciphertext is faster than breaking it.
What adversaries store vs ignore
Harvesting matters when public-key cryptography wraps the secret. Adversaries store TLS handshakes plus ciphertext (not application data alone), database and backup blobs encrypted with RSA or ECIES, email and file archives, and signing keys. Modern TLS 1.3 with forward secrecy still leaves the handshake vulnerable to future discrete-log attacks — passive wire capture of application data alone is not enough without the handshake record.
Who faces the highest exposure
Healthcare records, financial transaction archives, M&A diligence, and classified-adjacent research often carry 20–50 year confidentiality requirements. Regional banks, payers, and government contractors hold exactly this data profile. When migration takes five to ten years across a mid-market estate, Mosca inequality often holds today.
Common misconceptions
Quantum-vulnerable does not mean broken today — RSA and ECDSA still protect data in transit and at rest right now. AES-256 symmetric encryption is not the primary HNDL concern; public-key layers are. TLS 1.3 forward secrecy limits passive decryption but stored handshakes remain a quantum target. Waiting until 2035 to start inventory compresses your migration runway and does not un-copy ciphertext already exfiltrated.
Mosca inequality ties it together
If data shelf-life (X) plus migration time (Y) exceeds the time until quantum breaks crypto (Z), you have HNDL exposure today. Mosca turns abstract quantum risk into a planning inequality boards and regulators understand — especially when migration takes five to ten years across a mid-market estate.
What to do this quarter
Run a cryptographic inventory on external TLS, JWKS, SSH, and email STARTTLS — not a spreadsheet snapshot. Tag findings by data shelf-life tier. Quantify Mosca exposure for your longest-retained data classes. Pilot hybrid TLS on a non-production path and attach re-scan proof after remediation. Export a CycloneDX CBOM for your GRC toolchain.
How Qtangl quantifies it
Every Qtangl assessment includes Mosca HNDL scoring — mapping your data retention horizon against estimated quantum timeline and migration runway. Quantum-vulnerable does not mean broken today; it means you need inventory and a migration runway now. Inventory aid, not formal audit.
Loading Mosca calculator…
Choose your path
Speak your language
HNDL means different things to boards, CISOs, engineers, and compliance teams. Start with the guide that matches your role.
Video explainer
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- What Is Q-Day? Quantum Computing and Cyber RiskPalo Alto Networks · 2026CRQC definition, HNDL threat model, and migration guidance for enterprise security teams.
- Why Your Encrypted Data Is Already Being Stolen (Jeremy Allison, CIQ)YouTube · 2025Practitioner perspective on HNDL, PQC migration complexity, and FIPS certification for open source.
- Unit 42 Incident Response Report — exfiltration timelinesPalo Alto Networks Unit 42 · 2025Incident response data showing compressed exfiltration timelines — copying ciphertext is faster than breaking crypto today.
- Quantum Threat Timeline Report (Mosca inequality)Global Risk Institute · 2023Dr. Michele Mosca's X + Y > Z framework for harvest-now-decrypt-later exposure planning.
Deep dive
After Jeremy Allison on HNDL: what your security team should do now
Extended analysis with industry context, action checklists, and Qtangl product tie-ins.
Read blog post →
How encrypted data is harvested
Practitioner guide to collection vectors — breach, backups, cloud, and transit.
Read guide →
Related
What is Q-Day?
When cryptographically relevant quantum computers break today's public-key crypto.
Read guide →