Quantum Computing Threatens Current Encryption Standards, Posing Retroactive Risk for Cyber Insurance
The cybersecurity landscape is facing a significant, long-term challenge with the accelerating development of quantum computing. A recent warning from a global cybersecurity firm, Fortinet, highlights that data encrypted with current standards and stolen today could be decrypted by quantum computers as early as 2030. This phenomenon, dubbed 'Harvest Now, Decrypt Later' (HNDL), implies that malicious actors are already collecting vast amounts of encrypted data, patiently awaiting the advent of sufficiently powerful quantum machines to render it readable.
This development is particularly critical for organizations and cybersecurity practitioners because it introduces a retroactive risk that current security measures and even cyber insurance policies may not adequately address. The timeline for viable quantum computers capable of breaking existing algorithms has been shortened due to significant investment in the field. This means that a breach discovered in 2030, but stemming from data exfiltrated in 2026, could fall outside the coverage of many claims-made cyber insurance policies, which typically respond to incidents discovered during the policy period.
The broader trend here is the continuous evolution of cyber threats, driven by advancements in technology. Just as AI is accelerating the speed and sophistication of attacks, quantum computing represents a paradigm shift in decryption capabilities. This isn't merely a theoretical concern; the U.S. Government Accountability Office (GAO) has also warned about the potentially catastrophic economic and security implications if the nation fails to prepare for cryptographically relevant quantum computers. The challenge is that while the probability of a CRQC being built in the next 10 years is considered low, the risk of data harvesting today for future decryption is very real.
In practice, organizations must prioritize cryptographic agility and begin exploring post-quantum cryptography (PQC) solutions. This involves assessing current encryption usage, identifying critical data that would be vulnerable to quantum attacks, and developing a roadmap for migrating to quantum-resistant algorithms. Practitioners should also engage with their cyber insurance providers to understand how HNDL scenarios are addressed in their policies, particularly regarding retroactive dates and continuity of coverage. The shift towards quantum-safe encryption will require significant investment and planning, but proactive measures taken today will be crucial in safeguarding sensitive data against future quantum threats.
Read original source