The Files That Are Already Saved
The inaugural QRIA briefing. Written for boards, executives, and operations leaders — not just security teams. Most of the encrypted data your organisation creates today is being collected by state actors and stored against the future arrival of a Cryptographically Relevant Quantum Computer that can break today’s encryption. The threat is called Harvest Now Decrypt Later. The capability that defeats today’s encryption is on probability bands across the 2030–2040 window. The standards to defend against it — NIST’s ML-KEM, ML-DSA and SLH-DSA — were finalised in August 2024. The decision window for migration is now. The cost of doing nothing is not paid today; it is paid in the decade after decryption, when the files that were collected in 2024 become readable in 2034. This piece is the accessible explanation, the practical action sequence, and the regulatory context for the executive who reads it.
The inaugural piece in the QRIA series. Written for board members, executives, and operations leaders — not just security teams. The quantum threat to your business is not a 2030 problem. It is a 2022 problem you have not noticed.
A Scenario Every Executive Should Imagine
It is the year 2035. A general counsel at a mid-sized pharmaceutical company opens a routine alert from her external counsel. A foreign news organisation has just published the full email thread between her CEO and two members of the board of directors, dated August 2023. The thread discusses the early-stage acquisition negotiations for a competitor that the company eventually walked away from. The communications were encrypted at the time. They were sent over corporate email, copied to personal Gmail accounts for redundancy, and backed up to a cloud-storage service the company uses for litigation hold. None of those systems was breached. There is no record of unauthorised access. The encryption that protected those emails in 2023 was the industry standard at the time.
The leaked thread is genuine. The general counsel knows it is genuine because she was on it. What she does not know is when it was originally collected, or by whom, or how many other threads from 2023 and 2024 and 2025 are sitting in the same archive waiting to be published next.
This scenario is not science fiction. It is the operational expectation of every credible national intelligence service this decade, every state-aligned cyber programme with a budget allocation, and a growing number of well-funded private actors with the patience to play a long game. The category name for the threat is harvest now, decrypt later. The acronym is HNDL. The QRIA series begins here because HNDL is the threat that makes the quantum question urgent for businesses that would otherwise dismiss it as a 2030 problem.
What Harvest Now, Decrypt Later Actually Is
The plain-language description requires no cryptographic background. Most of the data that moves across the internet, and most of the data stored in cloud-backup systems, corporate email archives, encrypted databases, and routine business systems, is protected by a class of mathematics that today’s computers cannot defeat. The two mathematical foundations most commonly used are called RSA and elliptic-curve cryptography, often shortened to ECC. When you send an encrypted email, log into a banking website, sign a contract with a digital signature, or upload a backup to the cloud, RSA or ECC is doing the protective work in the background. You do not see it. It does not slow you down. It works.
The reason it works is that breaking RSA or ECC by guessing requires a number of attempts so large that even the fastest supercomputers in the world today would take far longer than the age of the universe to succeed. The mathematical problem is, in the language of the field, computationally infeasible.
A quantum computer is a different kind of machine. It does not run faster than a classical computer in the way a Ferrari runs faster than a Volkswagen. It runs on different physics, and that different physics happens to make a small number of specific mathematical problems much easier to solve. RSA and ECC are two of those problems. A sufficiently capable quantum computer — the technical term is a Cryptographically Relevant Quantum Computer, or CRQC — can in principle break RSA and ECC in hours or days rather than billions of years.
A CRQC does not yet exist. The largest quantum computers built today are not capable of breaking the encryption that protects real business systems. The mainstream technical consensus is that a CRQC capable of breaking commercial-grade RSA and ECC is somewhere between five and fifteen years away. Probability bands published by the Global Risk Institute, the European Quantum Communication Infrastructure programme, and the US National Academies all place a meaningful probability of CRQC capability arriving in the 2030–2035 window, with the probability rising to majority confidence by 2040.
The HNDL threat does not require waiting for the CRQC to arrive. It works as follows. A state actor today collects and stores enormous volumes of encrypted data — emails, file uploads, VPN traffic, backup snapshots, anything an intelligence service can route through its collection infrastructure. The data is collected today, while it is still encrypted and unreadable. It is stored at near-zero marginal cost, because storage is cheap. When the CRQC arrives in five or ten or fifteen years, the actor decrypts the stored archive in bulk. The communications and documents that were sent in 2024 become readable in 2034.
The Storage Side — Why It Works Economically
The storage economics of HNDL are not in dispute and are not difficult to grasp. The cost of one petabyte of cold storage — the slow, high-capacity, low-access tier used for long-term archival — has fallen to under a thousand dollars a year in commercial cloud pricing. State intelligence services operate at orders of magnitude greater scale and at substantially lower unit costs because they build their own storage infrastructure rather than renting it. The National Security Agency’s Utah Data Center, completed in 2014, was sized at the planning stage for capacity measured in exabytes — thousands of petabytes. Similar facilities operated by China’s Ministry of State Security, Russia’s Federal Security Service, and the intelligence services of every European NATO member operate at scales that are not publicly disclosed but are widely understood to be comparable.
The economic point is this. Storing a hundred petabytes of encrypted traffic for thirty years, in expectation that a fraction of it will eventually become readable, costs less than the annual salary of a single senior analyst. There is no opportunity cost in storing it. There is no risk in storing it. The data sits patiently. It does not have to be analysed today. It does not have to be indexed today. It only has to be retained against the future capability to read it. Every state intelligence service in the world is doing this today. Most have been doing it since at least 2020. Some have been doing it since the late 2010s, when the academic literature on post-quantum cryptography established that the timeline was finite.
The Decryption Side — What Has to Be True
The decryption side depends on the arrival of a CRQC. The timeline is uncertain but the trajectory is established. IBM’s roadmap published in 2024 targets a fault-tolerant quantum computer with thousands of logical qubits by 2033. Google, IonQ, Quantinuum, PsiQuantum, and a growing number of well-funded private programmes have published broadly similar timelines. The Chinese state quantum-computing programme has reported milestones at scale and frequency that the open-source community treats with caution but cannot dismiss. The European Union’s flagship quantum-computing initiative is on a parallel track.
The probability bands are the honest way to describe what is known. By 2030, the probability that a CRQC capable of breaking commercial-grade RSA-2048 exists somewhere in the world — not necessarily disclosed publicly — is in the range of fifteen to twenty-five percent. By 2035, the probability rises to fifty to seventy percent. By 2040, the probability exceeds eighty percent. These are not predictions in the sense of "this will happen on this date." They are calibrated estimates of when the capability becomes meaningful for adversary planning. For HNDL purposes, the relevant probability is not "is it certain by 2035" but "is it high enough by 2035 that the data I am encrypting today is at risk by then." For any data with a meaningful shelf life, the answer is yes.
Need intelligence like this on a decision you're facing?
DSI Advisory Services helps boards, business leaders, defence institutions, and security leaders understand threats before they reach the horizon — where cyber, geopolitics, and business risk converge.