SecurityWeek drew attention to a threat with an unusually long fuse: "harvest now, decrypt later". An attacker does not need to read stolen information today. They can copy encrypted files, retain them quietly and wait for future quantum computers or other cryptographic advances to make the contents accessible.
That changes the risk calculation for information with a long commercial or legal life. Product designs, research data, source code, legal archives and strategic plans may still be valuable many years after they were first exchanged. Protection therefore needs to consider the useful life of the data, not only the strength of today's encryption.
A file can be unreadable when it is stolen and still become a valuable target if its secrets remain useful for years.
Why long-life data needs attention nowHarvest now, decrypt later changes the breach timeline
Traditional incident response often concentrates on immediate access and immediate harm. This threat follows a quieter pattern. Encrypted traffic or stored archives are collected first. The attacker may never reveal that the theft occurred, because the objective is to preserve the material until decryption becomes practical.
NIST now describes harvest now, decrypt later as a reason to begin adopting post-quantum cryptography. The NCSC has set a staged UK migration timetable: discovery and planning by 2028, early priority migrations by 2031 and completion by 2035. This is a substantial technology programme, particularly for organisations with legacy systems and complex supply chains.
ASR changes what is available to collect
SecurityWeek's 2022 report covered the Anonymise, Shard and Restore method added to the MX platform. My MX Data, referred to as MX from this point, uses ASR as an additional protection method for sensitive B2B file exchange.
The process transforms the data so that the original content is not recognisable, separates it into protected shards and restores the file for an authorised recipient. An isolated shard does not contain the complete readable document or enough business context to reconstruct it independently.
The visual below shows why capturing one fragment is different from capturing a complete encrypted file.
An isolated shard has limited value
The full information is restored only through the authorised process. ASR therefore reduces reliance on keeping one complete readable file in a single location.
An important distinctionASR is not another name for post-quantum cryptography, and it should not replace an organisation's migration to approved post-quantum algorithms. It is an additional architectural layer that changes how a business file is retained and restored.
Future resilience still depends on today's operating discipline
Quantum risk does not remove familiar security problems. Public links can be forwarded today. Weak account recovery can undermine authentication. Old permissions can leave sensitive data available long after a project ends.
One object is captured
- Strong encryption protects the complete file.
- A stolen copy can be stored for later cryptanalysis.
- Access and evidence depend on the surrounding sharing process.
Protection is distributed
- ASR anonymises and separates the information.
- Named recipients and MFA govern restoration.
- Expiry, revocation and audit records remain attached to the exchange.
MX combines ASR with AES-256 encryption, named-user access, configurable expiry, multi-factor authentication and end-to-end activity records. These controls help an organisation manage both horizons: exposure that exists now and decryption risk that may mature later.
Five steps for a more defensible exchange programme
Identify long-life secrets
Record which files would still damage the organisation if disclosed in five, ten or twenty years.
Map the cryptography
Find where vulnerable public-key cryptography is used and include suppliers, applications and specialist systems.
Control external handoffs
Replace open links with named recipients, expiry and clear revocation for sensitive exchanges.
Reduce complete-copy exposure
Consider ASR for highly sensitive transfers where a captured complete file would retain long-term value.
Plan PQC migration
Follow current NIST standards and the NCSC timetable rather than treating quantum readiness as a future procurement issue.
What the SecurityWeek story still gets rightThe collection may already be happening. Organisations cannot control when useful quantum computing arrives, but they can control which information is exposed as a complete object, who receives it and what evidence remains after the transfer.
