up:: The Human & Organizational Side MOC

When Crypto Fails, Who Actually Pays?

When a company loses the personal data of 147 million people, the story usually ends with a number. Equifax exposed the Social Security numbers, birth dates, and home addresses of roughly half the adult population of the United States in 2017, and the resolution most people remember is a settlement of at least 700 million.1 Set beside a company that size, the figure reads less like a penalty and more like a line item, a cost absorbed and moved past. The share price dipped and recovered. Told that way, the story quietly answers the question of who paid, and it lands on the wrong answer.

The fine is paid to one ledger, and the loss is carried on an entirely different one. Equifax wrote a check measured against its annual revenue, while the 147 million people whose identities now circulate permanently received a few years of credit monitoring and an exposure that never expires. A Social Security number is far harder to rotate than a password. The people who absorbed the real cost were never in the room where the risk got priced, and the accounting that reached the headlines was the corporate one.

I spend my working life on the post-quantum transition because it is this exact pattern, waiting to run at a scale nothing has matched. The cryptography protecting the internet right now is scheduled to fail, on a timeline measured in years rather than centuries, and when it does it takes down the trust that everything above it depends on. The reporting will again be corporate: a breach, an estimate, a remediation budget. The cost will again land where it always lands, on a person who never got a vote in the decision that exposed them. So the question worth holding, long before the machine that breaks the cryptography exists, is a plain one about who actually pays when it fails.

The cost shows up on two different ledgers

Balance-sheet accounting is built to make cryptographic risk look survivable, because it records the part a company can survive. A breach becomes a fine, a legal reserve, and a quarter of bad press, and each of those recovers. The part it leaves out is the one carried by the individual, because the individual never appears on the company’s books.

That omission is why the deferral decision keeps going the same way. When a board weighs migrating its cryptography against the cost of waiting, the fine is a known, bounded, insurable number, while the exposure of a customer a decade from now stays invisible to the model. The math that says “wait” only looks rational because the person who pays for waiting was left out of it.

There’s a habit underneath this worth naming plainly. Organizations rarely defer security out of malice. They defer it out of cost, out of convenience, and out of the reasonable-sounding judgment that the threat is still distant, and every one of those is a call made by people who will not personally absorb the consequence.

The encrypted records an adversary is quietly archiving today are moving through a door that a budget meeting held open this quarter. The people whose records they are will learn about that meeting years later, if they ever learn about it at all.

The harvest is already running against a person

The quantum threat gets described as a future event, and correcting that framing is usually the first thing I do, because the harm is present-tense. An adversary needs no working quantum computer to begin. They need only to record encrypted data now and store it until the tool to open it exists, a pattern the field calls harvest now, decrypt later. It’s a robbery already in progress; only the payoff sits in the future. The data being copied off the wire today is real data belonging to real people.

Line that up against the kind of information that has to stay private for a lifetime. A person’s medical history, genetic data, financial record, immigration status, and private messages each carry a confidentiality horizon measured in decades, which is exactly what makes storing today’s ciphertext worthwhile against a key that arrives in 10 or 15 years. A hospital’s records have to remain confidential for a patient’s life and beyond. The pattern is documented: a 2026 analysis of Nginx TLS configurations published on GitHub found that 28.9% specified RSA key exchange with no forward secrecy, meaning any session recorded today can be reopened later once that server’s long-term key is recovered.2 The person exposed by that gap is a patient who assumed the danger had passed, and the loss surfaces long after they stopped thinking about it.

When trust breaks, a person gets impersonated

Harvesting attacks confidentiality. The other half of the quantum threat attacks trust, and its human cost arrives faster. Public key infrastructure is the machinery that lets your browser know a bank is really the bank, and a quantum computer running against a certificate authority’s signing key can forge that proof at will, a scenario I map in PKI Collapse. Why it matters sits in one idea, blast radius: a single broken key compromises every person and device that ever trusted it, which for a widely used authority runs to billions of relying parties.

This has already happened once, with no quantum computer at all, and the people it fell on were ordinary. In 2011 a Dutch certificate authority named DigiNotar was breached, and the attacker minted at least 531 fraudulent certificates, one of them for Google’s mail service, then used them to read the email of roughly 300,000 people in Iran.3 Each of those was a real person. They were dissidents, journalists, and ordinary citizens whose private correspondence was opened while their browsers showed them a padlock and told them they were safe. The certificate that betrayed them was mathematically valid, and the cost of the forgery was measured in their safety. A quantum version of that failure is the same shape at a scale that reaches everyone.

The person who pays is never in the room

Notice who’s absent from every one of these decisions. The patient whose record has to stay private for 50 years sits nowhere near the risk committee, and the citizen whose identity can be forged has no say in a vendor’s migration timeline. The cost of failure is borne almost entirely by people with no vote in whether the work gets done, and that asymmetry is the quiet engine behind most deferral. When the security around a hospital fails, for any reason, the bill is concrete: in 2017 a single piece of malware forced English hospitals to cancel more than 19,000 appointments and divert emergency patients away from 5 accident-and-emergency departments in a matter of days.4 The organizations recovered. The person whose surgery was cancelled that week carried the whole cost of the failure and appeared in none of the accounting.

Why I say who pays out loud

At a quantum security summit in Washington this summer, I was the one panelist who spent her time on people, and afterward a line of engineers and executives formed to tell me it was the part they recognized from their own organizations and the part nobody else had named. The technical arm of this transition is well covered. The cryptographers are brilliant, the standards are published, and the timelines are argued in good faith. The arm almost no one treats as real work is the one that asks what a cryptographic failure does to a human being who will never read a word about lattices.

That’s the whole reason I frame the transition around the person rather than the balance sheet. When the accounting gets done in dollars a company can absorb, the migration looks optional, a schedule to slip whenever the budget is tight. Do the accounting instead in the patient whose records surface in a decade and the citizen whose identity is forged in an afternoon, and it looks like what it is, a duty owed to people trusting a system they’ll never see to protect what they can’t protect on their own. My North Star has stayed the same since I started: protect people’s data. The migration is for the person who never gets to vote on it, and someone in the room has to keep saying so.


The precedent

Apache published a patch for CVE-2017-5638 in Apache Struts on 6 March 2017 and disclosed the vulnerability on the 7th. On 10 March, attackers exploited it on Equifax’s online dispute portal, then moved laterally for two months. Between May and July they exfiltrated records on 147.9 million people. Equifax found the suspicious traffic on 29 July and disclosed publicly on 7 September. What made it unlike a normal breach is who was in the data: Equifax is a credit bureau, so the overwhelming majority of those people were not its customers, had never entered into any agreement with it, had not been asked, and had no mechanism available to opt out of being in the file. In 2019 the company settled with the FTC, the CFPB, and the states for at least $575 million. The disclosed information stayed disclosed.

Equifax breach, 2017; FTC settlement, 2019

The moral: the loss fell on 147 million people who had never chosen the relationship, and the settlement went to the party that had.

Cryptographic decisions allocate risk the same way and more durably, because a key length or a deprecation date chosen today determines whether records are readable decades from now, long after the deciding organization has restructured or been acquired. The people in those records are usually not parties to the decision and usually have no way to become parties to it. Equifax was not unusual in its security posture at the time, and the mechanism was not negligence beyond the ordinary. It was an ordinary judgment made by the only party at the table, about data belonging to people who were not there.


Everything here is the map, given freely. When your team is ready to plan the human and organizational side of this transition with the same care it gives the cryptography, so the people downstream are genuinely protected, that’s the work I do.

Last verified 2026-07-26 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.

Footnotes

  1. Federal Trade Commission, “Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach,” July 22, 2019. The breach affected approximately 147 million people. FTC press release

  2. Balaji et al., “Operationalising Post-Quantum TLS,” arXiv:2605.17955, 2026. An analysis of Nginx TLS configurations published to public GitHub repositories found 28.9% specifying RSA key exchange with no forward secrecy. The corpus is 8,443 configuration files rather than a scan of live servers, the denominator behind the 28.9% isn’t stated, and the authors include a commercial post-quantum vendor and the funding bank. arXiv:2605.17955

  3. Fox-IT, “Black Tulip, Report of the investigation into the DigiNotar Certificate Authority breach,” 2012. The report documents at least 531 fraudulent certificates and interception affecting roughly 300,000 unique Iranian Gmail users. Fox-IT Black Tulip report, hosted by ENISA

  4. UK National Audit Office, “Investigation, WannaCry cyber attack and the NHS,” April 2018. NHS England estimated over 19,000 appointments cancelled, at least 81 of 236 trusts affected, and 5 acute trusts diverting patients from their accident-and-emergency departments. NAO report