Imagine being able to solve in hours what would take our most powerful classical computers decades — not because of a faster chip, but because the rules of computation have changed. That’s the promise of quantum computing. It’s why governments, universities, and the private sector are racing to be first in reaching the next set of breakthroughs toward achieving quantum supremacy. We don’t need to predict an exact “Q-Day” when quantum computers become powerful enough to break public key encryption that secures our global internet and financial systems to understand the massive implications. Advancements in quantum computing have been uneven but steady, and they bring to light problems that are critical to national – even global – competitiveness and security.
For security leaders, the uncomfortable reality is that quantum risk doesn’t begin the day quantum machines go live. Risk begins earlier — the day attackers decide it’s worth collecting encrypted data and storing it for later. That day is now.
The strategy already has a name: harvest now, decrypt later (HNDL).
The HNDL Threat in One Sentence
Attackers capture encrypted traffic or steal encrypted files today, hold onto them for years, and decrypt them in the future when quantum capabilities make it feasible.
As a Nixon Peabody Intellectual Property partner puts it:
“In many instances, malicious actors are already capturing data encrypted with conventional techniques and holding onto it in anticipation of quantum computing systems that can easily reverse those encryption methods, making confidential customer information available to them.”
— Jamie Cooke, Nixon Peabody
Palo Alto Networks summarizes the urgency even more bluntly:
“Once a quantum computer reaches the threshold to break RSA or elliptic-curve encryption, it will already be too late to protect the data that was stolen years earlier.”
This statement goes to the heart of why quantum computing is a “prepare now” topic: some data must remain confidential for decades. If an organization handles information with a 10–30 year secrecy requirement — customer identities, transaction histories, contracts, IP, healthcare records, sensitive government communications — the risk clock starts when that data can be captured, not when it can be decrypted.

The Quantum Concern: Who and What is Most Exposed?
Organizations with the highest quantum exposure tend to be those holding long-lived sensitive data at scale: financial institutions, government agencies, defense contractors, healthcare providers, and cloud providers — and their associated data sets (PII, transaction records, intellectual property, diplomatic/classified archives, R&D, medical/genetic data, large stores of encrypted files).
The quantum concern is most often tied to widely used public-key cryptography that underpins key exchange, certificates, and digital signatures — systems we trust and rely upon every day for secure communication and transactions. This is why post-quantum cryptography (PQC) standardization is underway, and why organizations are being urged to begin planning migrations to PQC.
Preparation is not as simple as swapping one algorithm for another. Cryptography lives everywhere: inside applications, devices, libraries, certificate infrastructure, VPNs, identity systems, and third-party services. Many organizations suffer from cryptographic sprawl and don’t know every instance of where cryptography resides. Quantum readiness is a long-term project of:
- Discovery (what cryptography exists in an organization and where)
- Prioritization (which systems and data matter most long-term)
- Hybrid deployments of classic cryptography plus PQC, as standards mature
- Phasing out of legacy cryptography and maintaining an updated inventory over time

Advances in Quantum Computing Make Endpoint and Session Security More Important Than Ever
Harvest now, decrypt later starts with data theft. Attackers can’t decrypt later what they never captured.
This means quantum readiness is not only about managing cryptography — it’s also a reason to harden the ways data is accessed and exfiltrated today, particularly through endpoints, identities, and user sessions.
“Attackers that get hold of the secure private session key in the future can decrypt conversations recorded in the past which increases the need to protect data today against future attack capabilities.”
— Volker Rath, Field CTO for Cloudflare
In other words, the quantum future makes present-day exfiltration and breaches more consequential. If encrypted sessions and files can be harvested today, then the defensive priority isn’t only how cryptography should be migrated to PQC. It also needs to be: How do we reduce harvesting opportunities right now?
This places today’s need for strong authentication and session protection directly into the quantum conversation that’s occurring now — not as the “cryptography migration” piece, but as practical risk reduction today via:
- phishing-resistant authentication to reduce credential theft
- protections around shared workstations and re-authentication
- controls that verify user presence and protect the session, not just the login
- limiting lateral movement and data exfiltration paths
The More Attackers Steal Today, the More Exploitation Opportunities They Gain Tomorrow
Organizations don’t need to wait for perfect clarity to make progress. A strong start today includes:
- Discovery of where cryptography lives (in apps, devices, certificates, libraries, vendors)
- Evaluating and prioritizing long-lived sensitive data
- Measuring PQC readiness in controlled pilots
- Preparing for hybrid approaches as standards and interoperability mature
And, importantly, in parallel, reducing data harvesting risk today through phishing-resistant access, and tighter endpoint and session protections
This two-track approach is how organizations can avoid the false choice of “do we focus on the future threats posed by quantum computing, or do we focus on more immediate threats?” Organizations must do both because quantum presents a long-horizon threat that amplifies the cost of today’s breaches.
Closing Thought
The prospect of quantum computing can be a planning catalyst. If your organization holds data that must remain confidential for years, “we’ll address it later” is not a strategy. Leaders who have a better chance of navigating the quantum age are starting the crypto transition deliberately — and at the same time strengthening the endpoint and access controls that prevent harvesting in the first place.
Because in the quantum era, the consequences of what gets stolen today can arrive years later.