2026-06-24OPINION · CYBERSECURITY · POSTQUANTUMCRYPTOGRAPHY · INFORMATIONSECURITY · CYBERRISK · BOARDGOVERNANCE5 MIN READ READ
FILED UNDER

Harvest Now, Decrypt Later: The Attack Has Already Begun

If you can't answer three questions about your cryptographic inventory, the risk is real and unmanaged

The Attack Is Already Underway

The White House has accelerated its deadline for federal agencies to migrate off quantum-vulnerable cryptography. The Ars Technica report frames it as a race against an emerging threat, which undersells the situation. The urgency in that order exists because adversaries, principally state actors, have been collecting encrypted data for years and holding it until quantum capability matures enough to read it retroactively. The attack is in progress. Only the decryption is pending.

That is the “harvest now, decrypt later” strategy, and it needs no quantum computer today. It needs storage, patience, and a reasonable belief that the capability arrives within the decade — which is exactly the timeframe nation-state programs are built around. If your organisation handles data that stays sensitive for ten years or more, whether that is health records, legal advice, financial instruments, defence contracts or intellectual property, the collection phase against it has in all likelihood already happened.

What the Policy Response Is Telling You

Governments do not compress national security deadlines for no reason. A shortened timeline in an executive order is an implicit statement that the intelligence community thinks the window is narrower than what has been said publicly. It is worth reading it that way.

Australia is not an observer to this problem. Australian government agencies, financial institutions, and critical infrastructure operators sit within the same threat environment. AUKUS alignment, Five Eyes intelligence sharing, and Australia’s role in regional security make Australian data — government, defence-adjacent, and commercial — a legitimate collection target. The fact that Australia lacks an equivalent executive order with hard deadlines doesn’t mean the threat is more distant here. It means the governance response is less mature.

APRA’s CPS 234 requires regulated entities to maintain information security capability commensurate with the size and nature of threats to their information assets. Post-quantum cryptographic risk is not a hypothetical future threat for institutions managing data with long-term sensitivity. It is a present-tense material risk that belongs in risk registers now, not after a domestic regulatory mandate arrives.

The Inventory Problem

Most organisations have no clear picture of where cryptography is actually deployed across their environment. Not at the asset level, not at the data classification level, and not in terms of which data sets have long-term sensitivity that makes them attractive for harvest-now-decrypt-later collection.

This matters because the migration to post-quantum cryptography isn’t a single switch. It requires knowing what algorithms are in use, where, protecting what data, in what systems, with what dependencies. Cryptographic libraries are embedded in applications, infrastructure, third-party software, cloud services, and vendor products — much of it not visible without deliberate inventory work. Some of it will require vendor action, not internal remediation. Some of it will be in systems with long replacement cycles. None of it can be addressed without first understanding the landscape.

Every remediation plan depends on that inventory existing. It also takes the longest, shows the least to a board, and is therefore the first thing to slip. An organisation that has not started one is not preparing for a future threat; it is running behind a current one.

What Audit and Risk Committees Should Ask

Whether post-quantum migration appears on the IT roadmap is not especially informative. What matters is whether anyone has assessed which data assets are already exposed to retroactive decryption, and what the consequence would be.

Three questions to the CISO or CTO get you most of the way. Do we hold a cryptographic inventory — an actual record of which algorithms protect which data in which systems, rather than a plan to build one? Have we identified the data whose sensitivity persists for a decade or more, and formed a view on whether a capable adversary has already collected it? And are we tracking NIST’s post-quantum standards and ASD’s migration guidance against a board-level timeline that reflects how long our systems really take to replace?

Vague answers to those are themselves the answer.

The Vendor and Consultant Problem

The migration market will get loud over the next two or three years. Existing products will acquire “quantum-ready” labelling with no change to the underlying engineering, and readiness assessments will be sold that produce a report and no remediation. Both deserve scepticism.

The real work is dull and long: inventory, classification, prioritisation, vendor chasing, staged migration over multiple years. It does not package neatly into a product sale or a six-week engagement, which is why so much of what will be offered instead is a procurement decision dressed as a programme.

The Honest Position

Treat the accelerated US deadline as a signal rather than an isolated policy event, because it reflects assessments that are not fully public. Australian organisations in financial services, critical infrastructure and anything government-adjacent sit in the same collection environment.

What has already been taken cannot be un-taken. The only variable left is whether that data is still protected when the capability to read it arrives, and that depends on whether cryptographic migration gets funded and governed as a material risk response or deferred as an IT project. Starting the inventory is the part nobody can do for you, and for some categories of data the window has already shut.

Next dossier
The Essential Eight Is Retiring. Your Governance Model Should Too. →
Engage the author
Adam van Vliet is currently taking on briefs.
Brief Adam
Share