Cost of Delay for Post-Quantum Migration: Putting Classical and Harvest-Now-Decrypt-Later Risk on One Ordered List
This paper proposes a unified framework that converts both classical security risks and Post-Quantum "Harvest-Now-Decrypt-Later" threats into a single currency-based "cost of delay" metric, enabling organizations to optimally prioritize and sequence cryptographic migration tasks against existing security backlogs.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a vault where the most valuable secrets of our digital world are kept. For decades, the locks on these vaults have relied on mathematical puzzles that are easy to create but nearly impossible to solve without the right key. However, a new kind of machine is on the horizon—a quantum computer so powerful it could crack these puzzles in moments, rendering the current locks useless. The danger is not just that these machines will arrive in the future; it is that enemies can be recording encrypted data today, storing it in vast digital warehouses, and waiting to unlock it once the quantum machines arrive. This is known as "harvest now, decrypt later." Organizations face a difficult choice: they have a backlog of ordinary security problems to fix, like broken doors or weak windows, and they must also prepare for this future quantum threat. But they have no common way to measure which problem is more urgent. Is it more important to fix a leaky roof today or to reinforce the vault against a future storm?
An independent researcher named Animesh Shaw has developed a new method to answer this question by translating both threats into a single, familiar language: the cost of delay. Instead of using abstract scores or separate lists, the method calculates exactly how much money an organization loses for every year it waits to fix a specific piece of data. For ordinary security risks, this is a standard calculation based on how likely a breach is and how much damage it would cause. For the quantum threat, the calculation is more subtle. It measures the rate at which waiting allows an enemy to record more data that will eventually be decrypted. The key innovation is that these two calculations are not simply added together. The model recognizes that if a classical hacker steals the data first, the quantum enemy has nothing left to steal. By accounting for this competition, the method produces a single, precise annual cost for delaying action on any specific asset.
To test this approach, the researcher applied it to four different types of public systems: a national identity platform, a core banking system, a medical record system, and a demonstration online store. The study did not use real, private data from these organizations but rather built models based on public documentation and reasonable assumptions about how these systems work. The results revealed a clear pattern. For data that is short-lived or changes frequently, the ordinary security risks usually dominate the list of priorities. However, for data that must remain secret for decades and is transmitted over networks where it can be easily recorded, the quantum threat becomes the primary driver of urgency. In one specific case involving a national identity system, the new method moved a type of registration packet from sixth place on the priority list to the very top, a shift that would not have happened if only traditional security risks were considered.
The study also explored how much the final ranking depends on uncertain guesses, such as exactly when the powerful quantum computer will arrive. The analysis showed that for most systems, the order of priorities is surprisingly stable. The biggest factors driving the cost of delay are not the arrival date of the quantum machine, but rather the value of the data and how much of it is generated and transmitted each year. While the quantum threat is real and serious, it does not completely overturn the standard way organizations prioritize their security work, except for a specific class of long-lived, quiet, and recordable data. For these specific assets, the cost of waiting is so high that they must be addressed immediately, regardless of other pressing issues.
The researcher verified the method through rigorous mathematical proofs and computer simulations, ensuring the logic holds up under different scenarios. The findings suggest that while organizations should not panic and abandon their current security plans, they must identify and protect their long-term secrets with a new sense of urgency. The method provides a clear, quantitative way to decide which data needs the strongest protection right now, ensuring that limited resources are spent where they will prevent the most irreversible loss. It turns a complex, futuristic dilemma into a practical financial decision, allowing leaders to see clearly which digital assets are most at risk of being stolen today and decrypted tomorrow.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.