up:: Quantum Risk Models MOC

What Data Is Vulnerable to Harvest Now, Decrypt Later

The data vulnerable to harvest-now-decrypt-later is any data an adversary can capture in encrypted form today that will still matter on the day a quantum computer can decrypt it. Three things have to line up: the ciphertext is reachable (it crosses a network, sits in a stolen backup, or lives in a captured archive), the protection depends on quantum-vulnerable key establishment (RSA, DH, ECDH, X25519), and the content stays sensitive longer than the years remaining before a CRQC plausibly exists. This note is the exhaustive catalog of what actually clears that bar, split into business data and personal data, with the de-scope of what can be left off the worry list.

The short version:

  1. The filter is lifetime, reachability, and cryptography together. Data qualifies when it crosses a vulnerable key exchange somewhere an adversary can record it and stays sensitive past the plausible CRQC horizon.
  2. On the business side, the big five are regulated records (health, financial, legal), deal and strategy material, intellectual property and R&D, long-retention communications archives, and the infrastructure secrets that unlock everything else.
  3. On the personal side, the permanent categories dominate: genomic data identifies you and your relatives forever, biometrics can never be reissued, and a lifetime of messages, health records, and location history stays revealing for decades.
  4. Sensitivity lifetime is often set by law, and the legal retention floors (6 years for HIPAA documentation, 7 for audit workpapers, up to 75 for classified material) are a ready-made map of what must outlive the migration.
  5. A real fraction of data can be honestly deprioritized: short-lived operational chatter, rotated secrets, and anything already public. Triage is the point of the catalog, and Mosca’s theorem is the clock it runs on.

Think of the adversary’s archive as a storage unit full of locked safes they hauled away years ago. Opening them waits on a tool that arrives years from now, and the wait is fine with them, because they read the shipping labels when they took them. The safes labeled “expires next week” were left behind. Every safe in the unit is one somebody decided would still be worth opening in 10 years, and this note is the list of what those labels say.

What makes a dataset harvestable in the first place?

A dataset earns a place on this list by passing the three conditions from the HNDL model, and running each candidate through them keeps the catalog honest rather than alarmist.

  1. Reachable ciphertext. The data crosses a network under TLS or a VPN, sits in an encrypted backup a thief could steal, or lives in a message archive a provider could be compelled or compromised to yield. Data that never leaves an air-gapped enclave is off the list no matter how sensitive it is.
  2. Quantum-vulnerable protection. The session keys or wrapping keys were established with RSA, DH, ECDH, or X25519, all of which fall to Shor’s algorithm. Data protected end-to-end by AES-256 with quantum-safe key handling is the mitigation, and data moved under hybrid PQC key exchange is already off the harvest list.
  3. Sensitivity that outlives the migration. The content still causes harm when decrypted years from now. This is the axis the rest of this note is organized around, because it’s the one that differs most between datasets, and it’s the one Mosca’s theorem turns into a deadline.

The rest is a catalog of what passes all three, which is worth having in one place because the most common HNDL failure is a team protecting its crown-jewel database while backups, executive messaging, and service-to-service traffic stay on vulnerable key exchange.

What business data is vulnerable to HNDL?

The business-side catalog groups into 9 families. For each, the question a leader should ask is the same: if a competitor or a foreign intelligence service could read this 8 years from now, what would it cost us?

The law itself defines the lifetime here, which makes these the easiest category to defend a priority call on. Records you’re required to keep are records an adversary has time to wait for.

  1. Health information. Patient records, claims data, clinical trial results, and mental and behavioral health records. HIPAA’s Security Rule requires covered entities to retain their compliance documentation for 6 years (medical-record retention itself is set by state law and often runs longer), and the underlying medical facts about a person stay sensitive for their whole life.
  2. Financial and securities records. Broker-dealer records carry 3-to-6-year retention under SEC Rule 17a-4, with certain corporate records (articles of incorporation, minute books, stock certificate books) kept for the life of the enterprise, and audit workpapers carry a 7-year retention under the SEC rule implementing Sarbanes-Oxley.
  3. Legal records under privilege. Litigation strategy, internal investigations, settlement negotiations, and outside-counsel communications. Privilege makes these valuable precisely because they were never meant to be seen, and matters run for years.
  4. Government and defense material. Classified information runs on declassification horizons of up to 25 years, extendable to 50 or 75 years for the most sensitive categories (human-source identities and weapons-of-mass-destruction design) under Executive Order 13526, and controlled unclassified information (CUI) across the defense industrial base inherits long sensitivity from the programs it describes.

Source: 45 CFR § 164.316(b)(2)(i) (6-year documentation retention), govinfo.gov; 17 CFR § 240.17a-4 (broker-dealer retention, including life-of-enterprise records), govinfo.gov; 17 CFR § 210.2-06 (7-year audit-record retention under Sarbanes-Oxley), govinfo.gov; Executive Order 13526 §§ 3.3(a), 3.3(h), 75 FR 707, govinfo.gov.

2. Deals, strategy, and negotiations

This family has a sharp expiry pattern: catastrophic sensitivity for a window of months to a few years, then sudden decay once the deal closes or the strategy ships. It stays on the list because the window regularly exceeds the time an already-harvesting adversary needs.

  1. Merger and acquisition pipelines, due-diligence rooms, and valuation models.
  2. Board packets, minutes, and executive-committee material.
  3. Bid and proposal pricing for competitive procurements, where a rival reading last cycle’s numbers reprices every future cycle.
  4. Negotiation positions with suppliers, unions, regulators, and joint-venture partners.
  5. Unannounced product, market-entry, and restructuring plans.

3. Intellectual property and R&D

The longest-lived commercial category, and the one with the clearest precedent for state-scale theft. Trade secrets have no expiration date at all: a chemical formula, a chip layout, or a manufacturing process stays valuable as long as it stays secret.

  1. Trade secrets and proprietary formulas, explicitly protected because they’re kept confidential rather than patented.
  2. Drug discovery pipelines and pre-patent research, where the filing itself is the race.
  3. Semiconductor designs, industrial process parameters, and materials science data.
  4. Source code for proprietary systems, including the security-relevant parts an attacker reads for exploitable flaws.
  5. Training data, model weights, and evaluation results for proprietary AI systems.

The scale precedent is documented: one campaign observed since 2006 exfiltrated intellectual property from at least 141 organizations across 20 major industries, and the then-director of the NSA called the resulting losses “the greatest transfer of wealth in U.S. history.” Those campaigns had to break in and take plaintext. A harvesting adversary only has to record traffic and wait, which is why the actor landscape treats IP-rich sectors as standing targets.

Source: Mandiant, “APT1: Exposing One of China’s Cyber Espionage Units,” February 19, 2013 (“Since 2006, Mandiant has observed APT1 compromise 141 companies spanning 20 major industries” and “hundreds of terabytes of data from at least 141 organizations”), mandiant-apt1-report.pdf; Gen. Keith Alexander, quoted in U.S. House Committee on Energy and Commerce, Subcommittee on Oversight and Investigations, “Cyber Espionage and the Theft of U.S. Intellectual Property and Technology,” July 9, 2013, Serial No. 113-67, govinfo.gov. The hearing records the remark without naming a venue or date for it, so it is cited here as the hearing recorded it.

4. Communications archives

Email and messaging archives are the single densest HNDL target in most estates, because they concentrate everything else on this list into one searchable corpus: deals, legal strategy, credentials pasted into threads, HR matters, and years of candid internal reasoning.

  1. Executive and board email archives, often retained for a decade or more under litigation-hold and records policies.
  2. Secure-messaging history for legal, security, and leadership teams.
  3. Journaled and compliance-archived communications in regulated firms, retained by mandate.
  4. Support tickets and CRM interaction logs holding customer confidences at scale.

Once decrypted, an archive like this is searchable and correlatable in bulk, so the harm compounds: a single message embarrasses someone, and a corpus profiles them.

5. Customer and personal-data holdings

Anything you hold about other people converts an HNDL event from an internal loss into a regulated breach with notification duties, liability, and identity-theft harm downstream. Customer PII databases, KYC files, loyalty profiles, and usage histories all sit here, and their sensitivity lifetime belongs to the data subjects rather than to you: a customer’s date of birth and Social Security number are as stealable in 15 years as today. The personal-side catalog below details why these fields age so slowly.

6. Financial operations

Treasury flows, payment instructions, payroll, banking credentials, and interbank traffic. Individual transactions decay fast, while the patterns stay valuable: years of payment flows map your suppliers, margins, customers, and cash position, which is competitive intelligence with a long shelf life.

7. Infrastructure secrets and security operations

A mixed-lifetime family that punches above its retention period, because these secrets unlock other data rather than being the prize themselves.

  1. Credentials, API keys, and service-account secrets captured in transit. Well-run rotation shortens their life; the observed reality of stale, unrotated secrets lengthens it.
  2. Long-lived cryptographic key material itself, including wrapped data-encryption keys whose key-wrapping path rides on vulnerable public-key crypto.
  3. Network architecture, VPN configurations, firewall rules, and asset inventories, which age slowly because infrastructure changes slowly.
  4. Incident-response and vulnerability-management communications, a map of exactly where you’re weak and how you respond.

8. Sector-specific operational data

  1. Energy and industrial operators. SCADA and OT telemetry reveals grid topology, plant operations, and process detail; OT environments also run the longest-lived hardware in any estate.
  2. Telecommunications. Carrier interconnect and signaling traffic aggregates everyone else’s communications metadata, which is why carriers headline the documented targeting.
  3. Healthcare and pharma. Clinical systems combine the regulated-records and R&D categories in one estate, per the medical-device note.
  4. Automotive, aerospace, and space. Telemetry and command links with multi-decade platform lifespans, where the hardware outlives the cryptography by design.
  5. Financial infrastructure. Payment-system traffic and clearing flows, dense with both money movement and personal data.

9. The public-sector tier

Diplomatic cables, intelligence reporting, defense logistics, census microdata, and law-enforcement files. Governments run the longest confidentiality horizons of any data owner, which is why the nation-state actors harvesting today treat each other as the primary targets, and why national mandates like CNSA 2.0 moved first.

What personal data is vulnerable to HNDL?

The personal catalog is organized by how long the data stays revealing, and it leads with the categories that never stop.

1. The permanent tier

  1. Genomic data. A genome identifies its owner for life and partially identifies their children, parents, and relatives who never consented to anything. The NIH’s genome institute states plainly that a DNA sample can never be truly anonymized, and research in Science projects that roughly 60% of genealogy-database searches for a person of European descent in the U.S. already return a third-cousin-or-closer match, close enough to identify people who never took a test themselves. Direct-to-consumer DNA results, clinical genetic tests, and research biobank data all transit networks today.
  2. Biometric templates. Fingerprints, face geometry, iris scans, and voiceprints authenticate you precisely because they can’t change, so a template decrypted in 12 years is as usable as one stolen today. NIST’s digital-identity guidance states the core problem directly, that biometric characteristics are not secrets, and notes that revocation schemes comparable to resetting a password remain limited. A password gets reset, and a fingerprint stays yours forever.
  3. Core identity fields. Date of birth, place of birth, mother’s maiden name, national ID and Social Security numbers, and the scanned passports and licenses sitting in email attachments and cloud drives. Most of these fields are practically unchangeable, and together they’re the raw material of identity theft for the rest of a life. That last point is reasoning rather than a cited finding: the sources below cover the genomic and biometric items above it, and no primary is offered for the identity-field tier.

Source: NHGRI, “Privacy in Genomics” (“a DNA sample can never be truly anonymized”), genome.gov; Erlich, Shor, Pe’er, and Carmi, “Identity inference of genomic data using long-range familial searches,” Science 362(6415), November 2018, doi.org/10.1126/science.aau4832; NIST SP 800-63B § 5.2.3 (“Biometric characteristics do not constitute secrets”), pages.nist.gov.

2. The lifetime tier

  1. Health history. Diagnoses, prescriptions, mental-health treatment, reproductive-health decisions, substance-use treatment, and disability records. The clinical facts stay true, and stay consequential for insurance, employment, custody, and stigma, for the rest of a life.
  2. Wearable and health-app telemetry. Heart rate, sleep, cycle tracking, and fitness location traces, synced continuously over quantum-vulnerable connections and quietly reconstructing the health record above.
  3. A lifetime of correspondence. Email and chat archives are the personal version of the corporate archive problem: one decrypted mailbox yields decades of relationships, opinions, finances, and secrets, searchable in bulk. The Signal protocol’s post-quantum upgrade and iMessage PQ3 exist precisely because messaging vendors concluded this harvest is plausible enough to engineer against now.
  4. Photo and file backups. Cloud photo libraries and device backups, including intimate content, that document a whole life in one archive.

3. The decades tier

  1. Financial life. Bank and brokerage records, tax filings, and retirement accounts. A 30-year fixed mortgage, which Freddie Mac describes as the product of choice for nearly 90% of homebuyers, is a single document set that stays live for three decades.

Source: Freddie Mac, “Finding the Right Loan,” myhome.freddiemac.com. 2. Location history. Years of movement data from phones and cars reveals home, work, worship, medical visits, and relationships, and the patterns stay identifying and exploitable long after any single trip stops mattering. 3. Legal and immigration records. Family-court files, immigration applications, asylum claims, and criminal-record expungements, where later exposure can undo the legal protection the process granted. 4. Credential and vault backups. Encrypted password-manager vaults and seed-phrase backups for cryptocurrency wallets. A vault captured today under a vulnerable wrapping path is every account you had at capture time, and a decrypted seed phrase is the coins, whenever the keys still control them.

4. The persecution tier

Some personal data has a sensitivity lifetime set by politics rather than by the data itself: political affiliation and donations, union organizing, religious practice, sexual orientation and gender identity, activism, and a journalist’s contacts and sources. For a person whose government, employer, or family turns hostile later, retroactive decryption of this category is the difference between privacy and persecution, and bulk decryption of harvested traffic would expose it retroactively and at population scale. This is the category where HNDL becomes a human-safety problem rather than a corporate risk metric, and it’s the reason the human side belongs in every serious treatment of the threat.

How long does each category stay sensitive?

The table is the catalog compressed to one screen, with the retention or sensitivity anchor that makes each lifetime defensible rather than guessed.

Data categoryStays sensitive forAnchor
Genomic dataBeyond a lifetime, and it reaches relativesNHGRI; Erlich et al., Science 2018
Biometric templatesA lifetime, and they can’t be reissuedNIST SP 800-63B § 5.2.3
Core identity fields (DOB, SSN)A lifetime, and they’re rarely changeableIdentity-theft mechanics
Health recordsA lifetime45 CFR § 164.316 documentation floor; lifelong clinical relevance
Classified and defense materialUp to 25, 50, or 75 yearsExecutive Order 13526 §§ 3.3(a), 3.3(h)
Trade secrets and IPAs long as they stay secret, with no expiryTrade-secret law’s confidentiality condition
Mortgages and long financial instrumentsUp to 30 yearsThe 30-year fixed mortgage (Freddie Mac)
Litigation and privileged materialMatter lifetime plus years17 CFR § 210.2-06 7-year audit-record floor
Securities and broker-dealer records3 to 6 years by mandate, life-of-enterprise for some17 CFR § 240.17a-4
M&A and strategy materialMonths to a few years, catastrophicallyDeal windows
Communications archivesAs long as the archive existsLitigation hold and compliance journaling
Credentials and session secretsDays to years, depending on rotationRotation policy, observed rotation reality

The anchors’ full citations appear in the sections above.

Reading the table against the threat timeline is the whole exercise: every row whose lifetime plausibly overlaps the CRQC horizon is a row where Mosca’s inequality says the protection has to change before the machine arrives, and the rows near the top failed that test years ago.

What data can you honestly leave off the list?

An exhaustive catalog earns trust by saying what’s excluded, and a real fraction of any estate can be deprioritized with a clear conscience.

  1. Short-lived operational data. Session tokens, ephemeral telemetry, cache traffic, and routine operational chatter whose sensitivity dies in days or weeks. It’ll be decrypted someday and won’t matter.
  2. Properly rotated secrets. A credential rotated monthly is stale long before any CRQC exists. The caveat is the word “properly,” because rotation policy and rotation reality diverge in most estates.
  3. Already-public data. Marketing content, published filings, and open datasets. Decrypting a copy of what’s public reveals at most that you transmitted it.
  4. Data under quantum-safe protection end to end. Anything moved under hybrid key exchange or wrapped under ML-KEM-based key establishment is exactly the mitigated state the whole migration is driving toward.
  5. Unreachable data. Air-gapped archives and data that never transits a collectible path. The honesty check is that “unreachable” is a claim about your network reality, and it deserves verification rather than assumption, which is what a CBOM exists to establish.

The de-scope list is also the triage engine in reverse: shortening data lifetimes (delete what you don’t need), rotating faster, and moving the long-lived categories to hybrid first are the three moves that shrink the catalog fastest, per the migration on-ramp.

Common misconceptions

  1. “HNDL targets everything, so prioritization is hopeless.” The three-condition filter cuts most of an estate immediately, and the lifetime table sorts what’s left. The catalog looks long because it’s exhaustive across sectors; any single organization’s real list is much shorter.
  2. “Our data is encrypted, so it’s already protected.” The exposure is in how the keys were established. Data under AES-256 whose session or wrapping keys traveled by RSA or ECDH inherits their quantum vulnerability, which is the key-wrapping problem.
  3. “Personal data is a consumer problem, and business data is the real target.” Businesses hold the personal data at scale, so the two lists converge on the same databases. A breached enterprise is the delivery mechanism for the personal-side harm.
  4. “By the time decryption is possible, this data will be worthless.” True only for the short-lived tier, which is why it’s honestly de-scoped. Genomes, biometrics, health histories, and identity fields are as valuable in 15 years as today, and some grow more valuable as correlation tools improve.
  5. “Deleting old data is a compliance chore with no security payoff.” Retention minimization is the single cheapest HNDL mitigation there is: data you’ve deleted is data nobody can harvest from you, and shortening lifetimes moves rows down the table.

Questions people ask

Is my company’s data actually being harvested right now? Attribution for specific datasets is unprovable from the outside, and the sober actor case is that U.S. government advisories treat harvesting as a present activity, collection is passive and cheap, and IP-rich and infrastructure sectors match the documented targeting pattern. The planning assumption that your long-lived traffic crosses collectible paths is the defensible one.

What single dataset should I protect first? For most organizations it’s the communications archive and the backups, because they concentrate every other category in one place, they’re retained for years, and their key paths are the least examined. The HNDL urgency scoring turns that instinct into a defensible ranking.

Does HNDL threaten my personal messages even though I use encrypted apps? It depends on the app’s key exchange. Signal and iMessage added post-quantum protection to key establishment specifically to close the harvest window, and messaging that still rides classical ECDH remains harvestable in transit.

Should individuals do anything, or is this an enterprise problem? The highest-leverage individual moves are small: prefer messengers with post-quantum key agreement, keep genomic and biometric enrollment to what you’d accept becoming public someday, and treat “delete old data” as real protection. The structural fixes belong to the platforms and enterprises holding the data.

Is government data the main target? Governments run the longest horizons, and the documented economic-espionage record (the Mandiant APT1 report’s 141 organizations, cited above) shows commercial IP was taken at industrial scale when it required active intrusion. Passive harvesting lowers the cost of the same appetite, so the answer is both.

Go deeper


Everything here is the map, given freely. When your team needs this catalog turned into a ranked inventory of your own data, with lifetimes measured, capture paths verified, and a migration order your regulator would accept, that’s the work I do. Request the workshop.

Last verified 2026-08-27 · Updated 2026-08-27 · Maintained by Addie LaMarr, LaMarr Labs.