Why HNDL is a today problem, not a 2030 problem
Storage is cheap, bandwidth taps are abundant, and most enterprise TLS still depends on RSA or elliptic curve key exchange. An attacker who records a TLS 1.2 or TLS 1.3 handshake using classical Diffie Hellman can later recover the shared secret once Shor's algorithm runs on a fault tolerant quantum computer.
The UK National Cyber Security Centre, NIST and the EU all now expect organisations to be planning their migration to post quantum cryptography. Waiting for a public demonstration of a cryptographically relevant quantum computer (CRQC) means that ten or more years of your most sensitive traffic is already in someone else's archive.
Which UK data is most at risk
Not every byte needs to move first. Prioritise data whose value extends beyond the expected CRQC arrival window.
- NHS patient records and genomic data, which remain sensitive for a lifetime.
- Financial services trade secrets, M&A communications and long dated contracts.
- Government and defence communications under the Official Secrets Act.
- Intellectual property in pharma, aerospace, energy and advanced manufacturing.
- Long lived code signing roots, firmware update keys and certificate authorities.
A 12 month CISO plan
You do not need to migrate everything in a year. You need to know what you have, what is exposed, and have a defensible plan your board and regulator can review.
- Months 1 to 3: build a cryptographic asset inventory across TLS endpoints, VPNs, HSMs, code signing chains, document signing and archive storage.
- Months 4 to 6: tag each asset by data lifetime and exposure. Rank by HNDL risk.
- Months 7 to 9: pilot a hybrid handshake (for example X25519 with ML-KEM-768) on a non critical workload and measure latency and payload size.
- Months 10 to 12: define crypto agility requirements for vendors, update procurement standards and brief the board with a regulator ready evidence pack.
What the regulator will ask
PRA, FCA and NCSC supervisors are starting to probe operational resilience plans for quantum readiness. The minimum bar is a documented inventory, a risk ranked migration roadmap, and evidence that crypto agility is being built into new systems. By 2027, expect formal expectations for financial services and critical national infrastructure.
Frequently asked questions
Is harvest now, decrypt later already happening?
Yes. Western intelligence agencies and multiple security vendors have observed bulk collection of encrypted traffic by state actors that has no plausible classical decryption use. The cost of storage makes speculative capture economic even with a ten year payoff.
When will quantum computers break RSA 2048?
Consensus estimates place a cryptographically relevant quantum computer between 2030 and 2035, with significant uncertainty. The relevant question is not the exact date but whether your data still needs to be secret then.
Does TLS 1.3 protect against HNDL?
No. TLS 1.3 still relies on classical key exchange by default. Hybrid post quantum key exchange in TLS 1.3 is now being standardised and rolled out by major browsers and CDNs, but enterprise endpoints lag.
Want a tailored view for your organisation?
Get in touch and qubion will match you with marketplace vendors who can map your quantum exposure, opportunities and a 12 to 36 month plan.
Find a vendor