The Human Cost of Quantum Risk: Why Cryptographic Failure Becomes a Societal Event
- Brian Couzens
- Jun 25
- 6 min read

We built a digital society on a promise we never had the means to keep.
Quantum computing is not the threat. The breach of that promise is.
---
For two decades, boards have governed cryptographic risk as though it were an accounting category. If the balance sheet survives, the regulator is satisfied, and the insurance renewal clears, the assumption is that the risk has been managed. Quantum computing destroys that assumption. Not because it introduces a new cost line, but because it exposes who actually bears the cost when cryptography fails.
The answer is not the organisation. It is the people whose data the organisation holds.
A hospital that defers its post-quantum migration does not bear the primary cost of a patient's genomic record being decrypted two decades after exfiltration. The patient bears it. And so do the patient's children. A bank that delays archive re-encryption does not bear the primary cost of a customer's lifetime transaction history becoming readable. The customer bears it. A government that postpones digital identity migration does not bear the cost of a citizen's biometric enrolment becoming forgeable. The citizen bears it, and has nowhere else to take their citizenship.
This is the asymmetry that makes quantum risk unlike any threat governance has previously managed. The organisations that hold the data hold the capacity to act. The individuals whose lives are encoded in that data hold neither knowledge of the exposure, nor consent over the decision, nor any means of mitigation.
**Governing accounting is not governing risk.**
---
## Harvest Now, Decrypt Later: The Long Game
The mechanism at work is called Harvest Now, Decrypt Later. Adversaries do not need to decrypt today. They need only to acquire encrypted archives today and wait for the cryptanalytically relevant quantum computer to mature. The strategy is not new. It is among the oldest in signals intelligence.
The Allied VENONA programme began intercepting encrypted Soviet diplomatic communications in 1943. Analysts continued to decrypt and read those messages into the 1980s, four decades after interception. Peer-reviewed research published in the journal *Telecom* in late 2025 formalised HNDL as a distinct temporal cybersecurity risk, demonstrating that sectors with long retention obligations, healthcare, financial services, national identity, face exposure windows extending across generations under delayed post-quantum adoption.
Quantum computing does not invent the strategy of deferred decryption. It industrialises it.
The individuals affected live unknowing inside exposure windows that were opened on their behalf by institutions they trusted. They received no breach notification that conveyed the true severity, because at the time of exfiltration the data was encrypted. They cannot take protective action, because no protective action exists for data already taken. Their exposure window is set not by the organisation's retention schedule, but by the sensitivity lifespan of the data itself.
A medical record remains sensitive for a patient's lifetime. Genomic data extends that exposure to parents, siblings, and children who never interacted with the organisation that held it. A childhood school record, a safeguarding file, a paediatric health assessment: each of these created today under current protection will outlive its own encryption while the subject is still in their twenties. NIST plans the deprecation of classical asymmetric cryptography by 2030. No other institutional decision so cleanly commits a named future adult to a risk they had no part in accepting.
---
## A Behavioural Biography, Not a Database Record
Quantum decryption does not expose isolated records. It exposes human lives.
A decade of transaction history is a behavioural biography. It reveals where a person lived, who they paid, which medical providers they visited, which organisations they donated to, when their patterns changed. In criminal hands, that reconstruction enables hyper-targeted fraud calibrated to the victim's actual behaviour. In state hands, it enables economic surveillance with the granularity of an auditor and the permanence of an archive.
What makes financial exposure distinctive is the weakest steward rule. An individual's financial life is distributed across banks, payment processors, credit bureaus, merchants, and insurers, each holding fragments under separate encryption decisions. The institution that migrates early protects its fragment. The individual's true exposure is defined by the slowest institution in the chain, the one they never chose, never audited, and cannot leave.
Identity data is more fundamental still. A compromised password is changed in a minute. A compromised date of birth, biometric template, national identity number, or maiden name is compromised permanently. Retroactive decryption of an identity archive converts a historical breach into a permanent, lifelong fraud capability against every individual in it. The consequence, from the individual's side, is the loss of the ability to prove reliably and exclusively that they are themselves.
The harm does not distribute evenly. It concentrates on those with the least capacity to anticipate or absorb it. Children carry the longest exposure window and zero agency. Refugees face biometric enrolments and movement records held by humanitarian agencies, targeted by the very states they fled. Patients with psychiatric histories, genomic conditions, or reproductive health records cannot move their data out of a slow-migrating institution without declining care. These populations are not edge cases in the exposure model. They are its most acute expression.
---
## Trust Debt: The Liability That Cannot Be Written Down
There is a concept that governance urgently needs to name: trust debt.
Technical debt describes the accumulated cost of deferred remediation in code and infrastructure. Trust debt is its governance equivalent: the obligation created when an institution continues to collect, retain, and exploit personal data under assurances of confidentiality without maintaining the cryptographic infrastructure required to guarantee that privacy across the sensitivity lifespan of the data.
Like technical debt, trust debt compounds. Each year of deferred migration enlarges the corpus of harvestable ciphertext while the trust drawn against it continues to operate at face value. Unlike technical debt, it cannot be restructured or written down, because the creditors are the data subjects, and the currency is the irreversible exposure of their lives.
An organisation may still, after honest analysis, sequence its migration over years. What it may not honestly do is describe that sequencing as risk deferred rather than trust debt accumulated. The harvesting is current. The archives are growing. Each year of deferral enlarges the corpus that no future budget can recall.
To make that obligation operational, boards need an instrument that measures human exposure alongside commercial asset value. The Human Harm Score does this across four dimensions: Exposure Population, how many identifiable individuals each data category implicates; Sensitivity Lifespan, how long that exposure remains harmful; Reversibility, whether the harm can be mitigated once it materialises, with genomic and biometric data anchoring the irreversible end; and Vulnerability Weighting, whether the category disproportionately exposes the populations least able to survive it. The composite score sits alongside commercial and regulatory scores in migration triage. It forces the board to answer a qualitative question about each archive it holds rather than hiding behind a numerical compliance average. The score surfaces the questions. The board answers them.

There is a second threat mechanism that boards have largely failed to register: Harvest Now, Forge Later. Quantum capability does not only read historical records. It falsifies active authority. Adversaries who break classically encrypted cryptographic signing keys can forge identities, certificates, and operational instructions that classical systems will accept as authentic. In clinical settings, a forged diagnostic certificate or altered prescription instruction bypasses human scrutiny. In emergency response, a spoofed dispatch instruction or falsified location grid is measured in minutes and lives, not months and budget lines. HNDL exposes the past. HNFL weaponises the future.
---
## Breach or Betrayal
A conventional cybersecurity breach is an event. Data is taken, the incident response plan triggers, affected individuals receive generic notifications, and the matter closes. The organisation returns to operations.
Quantum exposure of harvested data is not an event. It is a permanent condition.
The data was given in trust, often under legal compulsion, by people who had no alternative. A patient cannot decline to have medical records. A citizen cannot decline to have an identity file. A child cannot decline to have a school record. When those archives become readable years or decades later, the public will not process it as an unfortunate IT incident. They will experience it as a fundamental betrayal of the trust infrastructure they were required to rely upon.
The distinction is not semantic. Organisations respond to incidents with internal processes. Populations respond to trust infrastructure failure by withdrawing participation. They withhold symptoms from clinicians. They avoid stigmatised services. They stop disclosing to journalists. They stop organising. The trust half-life of an institution found to have known, been warned, and failed to act is shorter than that of an institution that was genuinely surprised.
Technical failure propagates at the speed of exploitation. Trust failure propagates at the speed of news.
Engineering can contain the first. Only preparation, demonstrated and disclosed in advance, can contain the second.
---
The question that must now reach boardrooms is not the familiar one.
It is no longer: *What will this cost the organisation?*
The question that fiduciary governance cannot defer is this: *What will this cost the people who trusted us?*
When cryptography fails, software systems can eventually recover.
Human lives do not.


Comments