Preparing secure exchange

01 Anonymise02 Shard03 Restore

Initialising protected session

MX in the news: Security Week. The ‘harvest now, decrypt later problem’.

SecurityWeek drew attention to a threat with an unusually long fuse: "harvest now, decrypt later". An attacker does not need to read stolen information today. They can copy encrypted files, retain them quietly and wait for future quantum…

In this guide

SecurityWeek drew attention to a threat with an unusually long fuse: "harvest now, decrypt later". An attacker does not need to read stolen information today. They can copy encrypted files, retain them quietly and wait for future quantum computers or other cryptographic advances to make the contents accessible.

That changes the risk calculation for information with a long commercial or legal life. Product designs, research data, source code, legal archives and strategic plans may still be valuable many years after they were first exchanged. Protection therefore needs to consider the useful life of the data, not only the strength of today's encryption.

2022 SecurityWeek reported on the sharding approach added to the MX file-transfer platform.
2024 NIST published its first three final post-quantum cryptography standards.
2035 The NCSC target for completing migration to post-quantum cryptography across systems, services and products.

A file can be unreadable when it is stolen and still become a valuable target if its secrets remain useful for years.

Why long-life data needs attention now
The threatTime begins working for the attacker

Harvest now, decrypt later changes the breach timeline

Traditional incident response often concentrates on immediate access and immediate harm. This threat follows a quieter pattern. Encrypted traffic or stored archives are collected first. The attacker may never reveal that the theft occurred, because the objective is to preserve the material until decryption becomes practical.

Long valueThe information remains useful well beyond its original project.
Frequent movementThe file crosses customers, suppliers, advisers and cloud systems.
Complete copiesA captured archive can be retained intact for later analysis.
Limited visibilityQuiet collection may leave little immediate evidence of misuse.

NIST now describes harvest now, decrypt later as a reason to begin adopting post-quantum cryptography. The NCSC has set a staged UK migration timetable: discovery and planning by 2028, early priority migrations by 2031 and completion by 2035. This is a substantial technology programme, particularly for organisations with legacy systems and complex supply chains.

SecurityWeek and MXAn architectural response

ASR changes what is available to collect

SecurityWeek's 2022 report covered the Anonymise, Shard and Restore method added to the MX platform. My MX Data, referred to as MX from this point, uses ASR as an additional protection method for sensitive B2B file exchange.

The process transforms the data so that the original content is not recognisable, separates it into protected shards and restores the file for an authorised recipient. An isolated shard does not contain the complete readable document or enough business context to reconstruct it independently.

The visual below shows why capturing one fragment is different from capturing a complete encrypted file.

Diagram showing an original file separated into incomplete shards, with one exposed shard containing no complete document

An isolated shard has limited value

The full information is restored only through the authorised process. ASR therefore reduces reliance on keeping one complete readable file in a single location.

An important distinctionASR is not another name for post-quantum cryptography, and it should not replace an organisation's migration to approved post-quantum algorithms. It is an additional architectural layer that changes how a business file is retained and restored.

Layered controlProtection beyond the shards

Future resilience still depends on today's operating discipline

Quantum risk does not remove familiar security problems. Public links can be forwarded today. Weak account recovery can undermine authentication. Old permissions can leave sensitive data available long after a project ends.

Complete-file model

One object is captured

  • Strong encryption protects the complete file.
  • A stolen copy can be stored for later cryptanalysis.
  • Access and evidence depend on the surrounding sharing process.
MX exchange model

Protection is distributed

  • ASR anonymises and separates the information.
  • Named recipients and MFA govern restoration.
  • Expiry, revocation and audit records remain attached to the exchange.

MX combines ASR with AES-256 encryption, named-user access, configurable expiry, multi-factor authentication and end-to-end activity records. These controls help an organisation manage both horizons: exposure that exists now and decryption risk that may mature later.

Action planStart with the data that will matter longest

Five steps for a more defensible exchange programme

01

Identify long-life secrets

Record which files would still damage the organisation if disclosed in five, ten or twenty years.

02

Map the cryptography

Find where vulnerable public-key cryptography is used and include suppliers, applications and specialist systems.

03

Control external handoffs

Replace open links with named recipients, expiry and clear revocation for sensitive exchanges.

04

Reduce complete-copy exposure

Consider ASR for highly sensitive transfers where a captured complete file would retain long-term value.

05

Plan PQC migration

Follow current NIST standards and the NCSC timetable rather than treating quantum readiness as a future procurement issue.

What the SecurityWeek story still gets rightThe collection may already be happening. Organisations cannot control when useful quantum computing arrives, but they can control which information is exposed as a complete object, who receives it and what evidence remains after the transfer.

SourcesFurther reading

The original coverage and current guidance

Give long-life sensitive files a more defensible route

Test named-recipient access, ASR, expiry controls and a complete activity record with a real customer, supplier or project exchange.

Michael Byrne
Written by

Michael Byrne

I'm a dynamic professional with extensive experience in project and business management across automotive, construction, and aerospace sectors. Currently, as Head of Digital at Majenta, I lead transformative projects, focusing on maintaining and enhancing MX as a high-performance file sharing platform. My role involves strategic project delivery and aligning digital initiatives with core business values. I excel in stakeholder management, problem-solving, and fostering strategic partnerships. Passionate about continuous learning, I thrive in high-pressure environments and enjoy contributing to MX's market presence through innovative solutions and robust project execution.

Insights & Trends Market Trends
MYMXDATA

Give sensitive files a clearer, more defensible route.

Start a seven-day trial with named-user access, detailed audit trails, unlimited file sizes and the patented ASR methodology.