top of page

PQC without Data Lineage Creates Hidden Quantum Era Exposure

  • Writer: Brian Couzens
    Brian Couzens
  • 2 minutes ago
  • 3 min read


Post‑quantum cryptography is being sold as the next great migration. Replace RSA and ECC, update certificates, test applications, move on. That narrative is incomplete. It protects the lock, not the contents of the safe.

The real exposure begins when an organisation cannot prove where its most valuable data has been. The Crown Jewel is the data itself — the record, design, or transaction whose loss would cause material harm. If that data has travelled through environments you cannot account for, the risk already exists. Quantum simply removes the delay between exposure and consequence.

The Problem

Cryptography protects data, not the other way around. Yet PQC programmes often start by cataloguing algorithms instead of tracing the information those algorithms defend. That inversion matters. When the data moves, the protection may not follow.

Every copy is a separate risk surface. Each has its own protection state, retention policy, and decay timeline. A copy in a forgotten backup is not a duplicate; it is an independent exposure. And independent exposures are the ones that breach.

In 2024, a European defence contractor discovered that archived project files encrypted with RSA‑2048 had been replicated into a supplier’s backup system. The supplier had migrated to cloud storage without re‑encrypting legacy archives. The files were never compromised, but the audit revealed a lineage gap that no cryptographic scanner could detect. The algorithm was sound; the custody was broken.

The Mechanism

Harvest‑Now‑Decrypt‑Later changes the meaning of time. Attackers can capture encrypted data today and wait for the protection to fail. NIST estimates that practical quantum attacks on RSA‑2048 could arrive within the next decade. The average retention period for healthcare records in the UK is twenty years. The mismatch is arithmetic. If your data lives longer than your cryptography, and you cannot locate every copy when the cryptography retires, you have already accepted a loss. You simply do not know when the bill comes due.

Without quantification, you cannot prioritise remediation, allocate budget, or defend your decisions to the board. Quantification is not a luxury; it is the language of accountability.

The Counterpoint

Inventorying cryptographic assets is necessary. It is not sufficient. A scanner can find RSA. It cannot reconstruct the path of the Crown Jewel behind it. Lineage tells you where that boundary must actually be drawn.

Lineage cannot stop at the enterprise edge. Data crosses internal systems, cloud platforms, SaaS environments, supplier infrastructure, processors, backup services, and archival layers. If the lineage breaks at any of those points, the break itself becomes a risk. Partial visibility is not benign; it is a liability.

Absolute lineage does not require omniscience. It requires intellectual honesty — the refusal to treat partial knowledge as certainty. For a Crown Jewel, you must be able to prove the chain of custody at the points where a loss would cause harm. If that custody cannot be demonstrated with evidence rather than inference, the gap is not operational. It is structural. PQC does not close that gap. It exposes it.

The Implication

PQC readiness metrics can be precise and still meaningless. “92% of cryptographic assets discovered” does not tell you which Crown Jewels depend on those assets or where those Crown Jewels reside. The inventory can be right and the answer can still be wrong. That is false precision.

The quantum threat is not just about algorithms. It is about data that matters, cryptography that will fail, adversaries who can wait, long‑lived information that remains valuable, and lineage that reveals the real exposure.

The Decision

The decisive question is not whether the organisation has found its cryptography. It is whether it can follow its most valuable data through its entire life and prove that the protection still holds.

If it cannot, PQC readiness is a claim, not a fact. That is not a readiness gap. That is a governance failure waiting to be discovered.






 
 
 

Comments


bottom of page