up:: The Human & Organizational Side MOC
The Three Numbers
The three numbers are exposure, the real deadline, and the ask, the only three figures a board acts on when it decides a quantum-risk program, and everything else in the memo is the evidence standing behind them. Number 1, exposure, is how much long-lived sensitive data is already at risk under harvest-now-decrypt-later, stated as the years it has to stay secret against the runway you have left. Number 2, the real deadline, is the threat date minus how long your migration takes, which is the day you actually had to have started. Number 3, the ask, is what closing the gap costs against what it protects, as a single investment figure. Compressing a multi-year technical program down to those three, with the analysis carried behind them instead of in front of them, is what turns understanding the problem into the authority to act on it.
The short version:
- The three numbers a board acts on are exposure, the real deadline, and the ask. Everything else in the memo is the evidence behind them.
- Each number is the compressed output of an upstream framework, so the three are summaries of real analysis rather than headline stats chosen to look sharp.
- Exposure composes the shelf-life question with the receipt method; the deadline is Mosca’s theorem restated as the threat date minus migration time; the ask is the inventory-first cost build’s output.
- The compression rule is the actual tool here: do the whole analysis, then lead with its three outputs, because a board buys a decision and volume reads as the absence of one.
- A finished memo passes the forward-upward test, which is that it is clear, honest, and short enough that a director carries it up the chain, to the full board or a regulator, with their own name on it.
Think of a coastal town the day a hurricane enters the forecast. The meteorologists have gigabytes of models, pressure readings, and satellite loops, but the mayor’s decision to order boarding-up and evacuation comes down to three numbers: how much damage is coming, when landfall hits minus how long the town needs to prepare, and what the protection costs against the value of what it saves. Every spaghetti-model plot and barometric chart still exists, and it all matters, but it lives behind those three as the reason to trust them. Hand the mayor the full model output and you have handed the decision back to someone who was counting on you to have made it. The three numbers are how a professional carries a mountain of analysis into a room that acts on a page.
What are the three numbers?
The three numbers are the three figures a board can actually act on, and the whole memo exists to produce them and defend them. Each one converts a different property of the quantum problem into something a decision-maker already knows how to weigh.
- Exposure. How much long-lived, sensitive data is already at risk under harvest-now-decrypt-later, stated as the years the data has to stay secret against the runway you have left. This is the number that turns an abstract future threat into a present liability, because harvesting is collecting today and the clock on those records is already running.
- The deadline, the real one. Not the date a quantum computer arrives, but that date minus how long your migration takes, which is the day you actually had to have started. For a board, “we are already behind by this much” is a far sharper input than “sometime in the 2030s.”
- The ask. What closing the gap costs against what it protects, as a single investment figure the board can weigh against every other use of that money. Almost nothing gets funded without this number, and burying it is how good plans die unfunded.
The frame applies whenever a technical program has to survive contact with a non-technical decision-making body: a board, an investment committee, a regulator, an executive sponsor holding the budget. It applies less, and needs adapting, when the audience is your own engineers, who need the reasoning laid out in full rather than compressed, which is a different document for a different reader.
The three are not a checklist you bolt onto a report. They are the report’s conclusion, promoted to the front, with the rest demoted to support. That inversion is the entire move, and the section on the compression rule is where it gets its teeth.
Where does each number come from?
Each number is the board-facing output of an upstream framework, which is what keeps the three honest. A number nobody can trace back to a method is a number a board learns to distrust, so the power of the three is that each one has a defensible pedigree.
| Number | What it states | Which upstream framework produces it |
|---|---|---|
| 1. Exposure | How much long-lived data is already at risk under HNDL, as years-it-must-stay-secret against the runway left | The shelf-life question (the secrecy years) composed with the receipt method (the migration reality that shortens the runway) |
| 2. The deadline | The threat date minus your migration time, the day you had to have started | Mosca’s theorem, restated as the last-safe-start date |
| 3. The ask | What closing the gap costs against what it protects, one investment figure | The inventory-first cost build’s output |
Exposure composes two measurements. The shelf-life question measures how long each data class has to stay secret, by asking its business owner on what date a full publication would stop hurting the company. That produces the years-must-stay-secret side. The receipt method measures how long your organization actually takes to retire an algorithm, pulled from the record of a migration you already finished, which sets how much of your runway is already spent. Put together, they answer the exposure question a board feels: we hold data that must stay secret for this long, it is being harvested now, and our own history says we cannot re-protect it fast enough. Exposure is the demand side of the problem, sized in years rather than in a fabricated breach-loss dollar.
The deadline is Mosca restated. Mosca’s theorem is the timing rule X + Y > Z, where X is secrecy lifetime, Y is migration time, and Z is the years until the cryptography can be broken. Rearranged, the same arithmetic gives a date: the threat horizon Z minus your migration time Y is the last day you could have safely started. If that day is behind you, you are already late for the data whose X runs past it. The borrowed name stays, because renaming established work is a credibility own-goal, and Mosca’s own paper is the source. The migration time Y appears in both exposure and the deadline, which is not a duplication; it is the point. How long you take to move both spends your runway and sets your deadline, so a slow migration hurts you twice.
Source: Michele Mosca, “Cybersecurity in an era with quantum computers, will we be ready?”, IACR ePrint 2015/1075, eprint.iacr.org.
The ask is a costed number, built count-then-price. The inventory-first cost build produces the ask by running discovery first and pricing each driver against what the inventory finds, because the new algorithms are free and the cost is the labor of finding and replacing cryptography across the estate. The single large primary-source anchor for scale is the U.S. government’s projection that migrating priority federal civilian systems between 2025 and 2035 will cost about $7.1 billion in 2024 dollars, a figure produced by exactly this inventory-then-cost loop and not divisible down to a per-organization number, which is this Guide’s reading rather than an OMB statement. Your ask is your own inventory’s output, and until discovery has run, the ask is the scoped inventory itself, per the business case.
Source: Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, as required by Public Law 117-260, OMB PQC Report.
The three numbers are what these upstream tools are for. A reader who has worked through the shelf-life question, the receipt method, Mosca’s theorem, and the cost build has already produced all three; this frame is where they get assembled into the one page that moves money.
Why exactly three numbers, and why is everything else evidence?
Because a board acts on a decision, and three is the count that carries a decision without becoming a second problem to solve. The compression rule is the genuinely new tool in this frame, distinct from the upstream frameworks that feed it: do the whole analysis, then lead with its three outputs, and demote everything else to the evidence behind them. There are three reasons the count lands where it does.
- A board buys a decision, so it needs the conclusion, not the derivation. When you have done real work, the instinct is to show all of it, which hands the board every system, dependency, and phase. The board does nothing with that, because volume reads as an inability to say what matters most. You did the two hundred pages of thinking; the discipline is to compress it to the three numbers that carry the call, and compression is how you demonstrate command of the material rather than the opposite.
- Three is enough to be honest and few enough to be held. Exposure answers how bad, the deadline answers how urgent, and the ask answers what it takes. Those are the three questions any capital decision turns on. Drop below three and you have hidden one of them; a memo with exposure and a deadline but no ask is a warning, and a memo with an ask but no deadline is a wish. Climb above three and you are back to handing over the derivation, because the fourth and fifth numbers are always inputs to the first three.
- Everything else is evidence, which means it travels behind the numbers rather than being cut. Compression is not deletion. The inventory, the vendor analysis, the blast-radius ranking, the shelf-life dates with their owners’ names, all of it still exists and still has to be defensible, because the first hard question about any of the three numbers is answered from that evidence. The move is one of order and prominence: the three numbers lead the page, and the analysis stands behind them so a challenge on any single figure resolves to a source rather than to an argument.
The failure the rule prevents is the one most technical leaders walk into: leading with the journey instead of the destination and calling the length rigor. A 200-page roadmap works against its author, because it reads as an admission that they could not prioritize and so made the prioritization the board’s problem. The three numbers are the antidote, and they are only credible because the two hundred pages of evidence sit behind them, ready when asked.
What is the forward-upward test?
The forward-upward test is the finished-memo gate that rides inside this frame, and it is a single question: is the memo clear, honest, and short enough that a director hands it up the chain, to the full board or a regulator, with their own name on it, without translation or embarrassment? That property is what makes a great memo worth many times a great roadmap, because a document your board can forward untouched is the difference between being the person who understands the risk and being the person the institution trusts to manage it.
The test has three conditions, and a memo passes only when all three hold:
- Clear enough to restate. A non-technical director should be able to repeat the three numbers to someone above them without you in the room. If restating the memo requires you to translate it, it has not left your desk yet.
- Honest enough to forward without exposure. Nothing rounded down to keep the room comfortable, because a director who forwards a memo is putting their name on every figure in it. A board that later catches a softened risk stops trusting all of it, and the person who forwarded it wears that. The honest, uncomfortable version is the one that earns the mandate.
- Short enough to be read rather than skimmed. A director reads a page and skims a deck. The forward-upward property lives on a page a busy person above them will actually finish, which is why the three numbers lead and the evidence follows.
A memo that passes converts a sprawling technical problem into a decision the institution can carry upward, which is the whole reason to compress in the first place. This is the same upward-communication craft that the board briefing delivers as a spoken arc; the three numbers are the artifact that survives after you leave the room.
What does the memo look like when it’s compressed to the three numbers?
Here is the compression run end-to-end on a generic mid-market company, so the shape is concrete. The company has finished one real cryptographic migration before, holds a mix of short-lived and long-lived data, and sells into a regulated sector. Watch the analysis collapse into three numbers, with the evidence named behind each.
- Exposure. The shelf-life question, asked of the business owners, returns a customer-identity archive whose records have to stay secret for the lifetimes of the people in them, call it 40 years, and that archive is crossing the network today under quantum-vulnerable key establishment. The receipt method, pulled from the company’s last SHA-1 exit, says its slowest surface took roughly 4 to 5 years to fully retire an algorithm. The number a board hears: 40 years of required secrecy on data being harvested now, against a runway our own history says we cannot cover. The evidence behind it is the shelf-life table with owners’ names and the dated receipt.
- The deadline. Take the published planning horizon for a relevant break as Z, subtract the measured migration time Y of roughly 4 to 5 years, and the last-safe-start date for the 40-year archive lands in the past. The number a board hears: for our longest-lived data, the day we needed to start has already gone by. The evidence behind it is Mosca’s arithmetic, re-derivable in the room, with the receipt supplying Y and the published estimates supplying the Z band.
- The ask. Discovery has not run estate-wide yet, so the defensible ask is the scoped cryptographic inventory that produces the real program total, bounded by a not-to-exceed figure and framed against the value of the archive it protects. The number a board hears: a bounded amount to find out exactly what this costs, against a foreseeable, larger loss if we start late. The evidence behind it is the cost-driver breakdown and the $7.1 billion federal anchor as scale context.
Three numbers, on one page, in the order a decision-maker thinks: the recommendation and the ask first, then the numbers, then the risks, then the evidence. The two hundred pages of thinking are all still there, filed behind the page, which is what lets the memo answer the first hard question without reopening the whole document. The detailed internal structure that turns this into a repeatable engagement deliverable is the work itself; the compression rule and the forward-upward test are the parts that belong to everyone.
How do you use the three numbers in the boardroom?
One level up, the three numbers are both what you present and what you audit. Presenting, you put exposure, the deadline, and the ask on the slide, and you keep the evidence in the appendix where a challenge can reach it without cluttering the decision. The board weighs three inputs it already understands, and the reversible first ask, a funded inventory with an owner and a return date, is the yes it can give in the room, per the board briefing.
Auditing is the sharper use, and it is the one that makes the frame a tool rather than a template. When a plan lands on your desk, the three-numbers read is your diligence in 90 seconds:
- Can I find the exposure, stated as years against runway rather than as a vague “high risk”?
- Can I find the real deadline, and is it the threat date minus migration time rather than the machine’s arrival date?
- Can I find the ask, and does it trace to an inventory rather than to a benchmark someone shopped?
A plan that answers all three, each traced to its evidence, is fundable. A plan missing any one of them is not finished, whatever its page count, and the missing number tells you exactly what to send back. Deploying the read on someone else’s plan is how a director or a CISO turns this from a way to write a memo into a way to govern a program.
Pro tips
- When someone hands you a thick roadmap, ask them to state the three numbers. If they cannot give you exposure, the real deadline, and the ask in three sentences, the roadmap is raw material rather than a finished plan, and the polite move is to send it back for its own conclusion.
- Put each number’s provenance one click behind it. Exposure traces to the shelf-life owners and the receipt; the deadline traces to Mosca’s arithmetic; the ask traces to the inventory. A number a director can trace is a number a director will defend upstairs, which is the forward-upward property doing its job.
- Interrogate the deadline first, because it hides the most common error. The follow-up when a deadline looks comfortable: “is that the machine’s arrival date, or that date minus our migration time?” The second is the real one, and it is usually years earlier.
- Interrogate the ask for its pedigree. “Is that grounded in our own inventory, or in a per-organization figure someone quoted?” No defensible universal per-organization number exists, so an ask with no inventory behind it is an estimate to challenge.
- Lead the ask with the scoped inventory when the full total is not yet defensible. A bounded first number gets a yes in the room and produces the real total, which beats asking for an unscoped multi-year figure and getting a deferral.
- Never inflate exposure or the ask to look impressive. A board that catches one soft input discounts all three. Honest and small beats impressive and shaky, every time, because the whole value of the three numbers is that a director can forward them without flinching.
Where does the three-numbers frame break?
The frame has honest edges, and naming them is part of the tool.
- No long-lived data. If the shelf-life question returns short answers across the estate, number 1 is honestly small, and the memo should say so plainly. The frame still runs; it just reports low HNDL exposure with the reasoning attached, and the urgency shifts to the trust side, where code-signing and root keys carry long service lives even when data lives are short, or to pure mandate compliance if a dated obligation binds you. A three-number memo that honestly says “exposure is low, here is why” is a pass, not a failure.
- Before discovery has run. You cannot produce a defensible ask before you know the estate, so the ask becomes “fund the scoped inventory,” and the memo says exactly that. The three numbers still lead; number 3 is simply the bounded diagnosis that produces the eventual program figure.
- No binding mandate and no long-lived data. Here the deadline number is genuinely soft, and honesty means framing the driver as future-proofing rather than a dated obligation. Presenting a manufactured deadline in this case fails the forward-upward test the moment a skeptic checks it.
- The three numbers are a summary, not a substitute for the reversible first move. A board still needs a small, approvable action to say yes to. The three numbers make the case; the scoped ask with an owner and a return date is what actually gets funded, which is why the ask is one of the three rather than an afterthought.
Common misconceptions
- “The deadline is the date a quantum computer arrives.” The deadline is that date minus how long your migration takes, which is the day you had to have started. Presenting the machine’s arrival year as the deadline quietly grants yourself the entire migration window as free time, and that error is what turns “we should start soon” into “we were already late.”
- “A longer memo shows more diligence.” Length reads as less confidence rather than more. The rigor goes into the thinking behind the three numbers, and the confidence shows in the compression. A board reads a page and skims a deck, so page count buys you skimming.
- “The three numbers replace the evidence.” They summarize it. The inventory, the vendor analysis, the shelf-life dates all still have to exist and be defensible, because the first hard question about any number is answered from that evidence. Shipping three numbers with nothing behind them is how a memo collapses on its first challenge.
- “Exposure is a dollar figure.” Exposure is a years-against-years statement: how long the data must stay secret against the runway you have left. The dollar figure is number 3, the ask. Fabricating a breach-loss dollar for exposure invites the one question that sinks a request, which is how you know.
- “Any three numbers will do.” The three are specific and each traces to a framework. Swapping in vanity metrics, systems scanned or percent patched, produces a memo that looks quantified and decides nothing, because those numbers answer activity rather than exposure, urgency, and cost.
- “Softening the risk keeps the board comfortable and gets the yes.” A board that catches you rounding the risk down stops trusting all of it. The honest, uncomfortable version is the one that earns the mandate, and it is the only version that survives being forwarded upward with someone else’s name on it.
Questions people ask
What are the three numbers a board needs for quantum risk? Exposure (how much long-lived data is already at risk under harvest-now-decrypt-later, as years against runway), the real deadline (the threat date minus your migration time), and the ask (what closing the gap costs against what it protects, as one investment figure). A board acts on those three, and everything else in the memo is the evidence behind them.
Why three and not five or ten? Because a capital decision turns on how bad, how urgent, and what it takes, which is exactly three questions. Fewer hides one of them, and more is just the derivation creeping back onto the page, since the fourth and fifth numbers are always inputs to the first three.
Is exposure a dollar figure? No. Exposure is stated in years, the secrecy lifetime of your longest-lived data against the runway your migration history leaves you. The dollar figure is the ask. A fabricated breach-loss number for exposure is more likely to sink the request than carry it.
What is the “real” deadline? The threat horizon minus how long your migration takes, which is the last day you could have safely started. It comes from Mosca’s theorem rearranged, and it is usually years earlier than the date people first reach for, which is the machine’s arrival.
Do I need the full cost before I can present the ask? No. When discovery has not run, the defensible ask is the scoped cryptographic inventory that produces the real total, bounded by a not-to-exceed figure. It is the smallest, least-risky request in the whole program and the one that unlocks every number after it.
What is the forward-upward test? The check that a finished memo is clear, honest, and short enough that a director forwards it up the chain, to the full board or a regulator, with their own name on it, without translation or embarrassment. A memo that passes has stopped needing you in the room to defend it.
What if we have no long-lived data? Then number 1 is honestly small, and the memo says so with the reasoning attached. The frame still runs, and the urgency shifts to long-lived signing and trust keys or to a dated mandate, whichever applies. An honest low-exposure memo is a pass.
How is this different from just writing a shorter report? A shorter report cuts content to save space. This inverts the document: the three conclusions lead, and the full analysis stands behind them as evidence, so nothing is lost and the decision is what the reader meets first. Compression is a discipline of order and prominence, not a word count.
Where do the three numbers actually come from? Exposure composes the shelf-life question and the receipt method; the deadline is Mosca’s theorem; the ask is the inventory-first cost build’s output. Working through those upstream tools is how you produce the three, and this frame is where they get assembled onto one page.
Everything here is the map, given freely. When your team needs its exposure sized in its own risk terms, its real deadline computed from its own migration history, and an ask a finance committee will actually approve, all three compressed into a memo your board can forward upward, that’s the work I do. Request the workshop.
Last verified 2026-07-26 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.