Quantum computing still sounds like a future problem. Something we'll deal with in 10 or 20 years.
That's the wrong way to look at it.
The real problem starts today, because attackers can collect encrypted information now and wait for quantum computers to become capable of breaking the cryptography that protects it.
Think of it like stealing a safe.
The attacker can't open it today. Fine. They don't need to. They steal the safe, store it somewhere, and wait until they get the technology—or the key—to open it years later.
For organizations protecting data with a long confidentiality lifetime, that changes the risk calculation completely.
This is where quantum threat modeling comes in.
The Core Threat: Harvest Now, Decrypt Later
The most important quantum-related threat to understand is Harvest Now, Decrypt Later (HNDL), also commonly called Store Now, Decrypt Later (SNDL).
The attack is surprisingly simple.
An attacker intercepts encrypted traffic or steals encrypted data today. They can't decrypt it with current technology, so they store it and wait for sufficiently capable quantum computers to become available.
Once quantum computing can efficiently attack the underlying public-key cryptography, that stored information may become readable.
Imagine an organization sending sensitive intellectual property over an encrypted connection.
An attacker captures the traffic.
Today, the ciphertext looks useless.
Ten or fifteen years from now, the cryptographic assumptions protecting that data may no longer hold.
The attacker hasn't broken the encryption today. They simply saved the problem for later.
That matters because not all data has the same lifetime.
A marketing campaign might become irrelevant within months. A medical record, classified document, financial record, private key, or proprietary research project could remain sensitive for decades.
If the data must remain confidential longer than the cryptography protecting it can realistically survive, you have a quantum security problem right now.