Welcome to the third installment in “A Walk in the Park,” a new short video series that explores the forces reshaping the future of digital trust. Over the next five weeks, we’ll take conversations out of the conference room and into the open air as our experts unpack some of the biggest challenges facing security leaders today. Watch the first, second, third and fourth episodes here.
One of the largest data heists in history is happening right now. The only catch is, the thieves can’t read what they’re stealing yet. They’re grabbing encrypted data anyway, parking it, and waiting for the technology to catch up.
That’s harvest now, decrypt later. And if you’re filing it under “2035 problem,” I’d like to change your mind.
▶️ Watch the episode: Ryan Sanders and I get into this topic in the final episode of A Walk in the Park. Here’s the short version. Below, I go deeper into the threat, and its quieter cousin, Trust Now, Forge Later.
Harvest now, decrypt later, in plain terms
Let’s start with the risk.
We know that inevitably, a quantum computer will be capable of breaking RSA and ECC. Those are the algorithms protecting pretty much everything moving across the internet right now. When that capability arrives, whoever has it can read data encrypted with those algorithms.
Adversaries understand this, and they aren’t waiting. They’re pulling encrypted data off the internet and out of your networks today, storing it, and banking on the moment when they can open all of it.
This isn’t a scare tactic. NIST and government bodies around the world have formally flagged it as a serious threat. It’s a big reason the U.S. just signed an executive order in June 2026 to push federal agencies onto post-quantum cryptography faster.
The logic is blunt. If your data still has value in five or ten years, it’s at risk today. The moment it leaves your network encrypted with cryptography that we know quantum will break, it’s exposed. Health records, financial records, intellectual property. Anything with a long shelf life.
It’s quieter cousin: Trust Now, Forge Later
There’s a second threat getting attention, and it’s worth understanding, because it’s a different animal altogether. Trust now, forge later.
Harvest now, decrypt later is about revealing data. Exposing things that were supposed to stay secret.
Trust now, forge later is about impersonation.
It’s an attack that would let someone recreate a cryptographically derived identity. Think of the certificate on a web server. Or a root of trust. With that, an attacker could impersonate a trusted part of your environment and take action on your network.
Now, trust now, forge later is the less urgent of the two right this minute. It needs a cryptographically relevant quantum computer to actually exist. Harvest now, decrypt later doesn’t. The harvesting is happening today. Only the decryption waits.
So neither should be discounted. But the immediate priority is clear. Protect against the harvesting that’s already underway.
“But the quantum computer doesn’t exist yet”
This is the objection I hear most. And it’s fair. A quantum computer that can break today’s encryption doesn’t fully exist yet. Not that we know of.
So let me make the case for why this is a problem today. It rests on two facts, and neither one relies on hope.
First, we don’t know the timeline. The experts give ranges, and those ranges keep getting shorter, not longer. Google recently pulled its own post-quantum deadline into 2029, citing faster-than-expected progress. When the people building these machines move their date up, you can assume the threat is arriving sooner.
Second, and this is the one that should actually drive your planning. The time it takes to migrate all of your relevant data and systems to quantum-safe cryptography is measured in years, not weeks or months. So even if the quantum computer were a decade out, a migration that eats most of a decade means you’re already behind.
The math doesn’t leave room to wait for certainty.
Where to start
For the CISO hearing “post-quantum” and feeling buried, the first move isn’t ripping out algorithms.
It’s knowing what you have and what it protects. You can’t prioritize a migration without understanding where your most sensitive, longest-lived data lives. Because that’s what an adversary is likely harvesting first.
The heist is already underway. The data leaving your network today is the data getting decrypted later. So start preparing now. The one thing you can’t do is go back and re-protect what’s already been taken.
That’s a wrap on this series. Four forces, one shift, and a lot of work ahead. It all ladders up to the same place: your Trust Infrastructure, and how you choose to manage it from here. Thanks for walking with us.