
Encrypted Data Today Is Tomorrow's Loot

Introduction
The G7 Cybersecurity Working Group has issued a warning that quantum computers could eventually break the encryption methods in wide use today. In an interview with Börsen-Zeitung, Antonio Paolo Mecci, CISO, Head of IT, and Data Protection Officer at DSwiss (SecureSafe), explains what "harvest now, decrypt later" actually means technically, and how financial institutions should decide where to act first.
Key Takeaways
- Attackers do not need a quantum computer today, only storage. They record RSA and ECC key exchanges now and decrypt them once a capable quantum computer exists, with no alarm raised in the meantime.
- The Mosca inequality (confidentiality period plus migration time versus years until a cryptographically relevant quantum computer) helps institutions prioritize which systems are genuinely urgent.
- System age is a poor proxy for risk. Confidentiality duration, migration time, and interceptability of the connection matter more.
- Recommended migration order for banks: transport layer first, then public key infrastructure, then code signing, then hardware.
- Crypto resilience currently has no single owner in most banks. CISO, CIO, and procurement mandates need to be consolidated rather than left to compete.
- Nearly a third of the 3,383 major IT incidents reported under DORA last year originated with third-party vendors, making supplier crypto readiness a genuine blind spot.
Mecci explains that attackers do not need quantum hardware to start the attack. Payload data is protected by AES and is largely quantum-resistant, but the key exchange at the start of a connection, typically RSA or elliptic curve based, is vulnerable. Attackers record entire sessions, from data center leased lines to payment traffic, and store terabytes of data for years until a quantum computer can decrypt it. The unsettling part is that no breach alert ever fires.
To judge urgency, Mecci points to the Mosca inequality, developed by cryptographer Michele Mosca. It weighs three variables: how long data must stay confidential, how long migration will take, and how many years remain until a cryptographically relevant quantum computer exists. If the first two numbers together exceed the third, an institution is already behind. The G7 expert group's working estimate places that quantum milestone around the mid-2030s, roughly a decade out, meaning data stolen today with a ten to fifteen year decryption horizon is effectively lost already.
He pushes back on the common practice of prioritizing systems by algorithm age, arguing that old does not mean insecure and new does not mean safe. The three Mosca variables are the real yardstick. For sequencing, he recommends banks start with the transport layer, where harvest now, decrypt later is most acute and hybrid key exchange is already standard in browsers, followed by public key infrastructure, code signing, and hardware last.
On governance, Mecci notes that no single role currently owns crypto resilience at most banks. He argues for consolidating three mandates that otherwise compete: the CISO as risk owner, the CIO for implementation, and procurement for vendor contracts. On third-party risk, he cites DORA's latest annual report showing that close to a third of major reported IT incidents originated with suppliers, and recommends institutions demand a cryptographic bill of materials from vendors, with a fallback plan if a supplier cannot provide one.
On convincing the board, Mecci is direct that there is no credible figure proving total data loss within ten years, and inventing one would be dishonest. A more persuasive approach is a risk map showing which critical systems and data could be exposed in five to ten years, translated into euros through potential production outages, fines, litigation, and reputational damage.
👉 Read the full article on Börsen-Zeitung:
https://www.boersen-zeitung.de/finanzen-technik/verschluesselte-daten-von-heute-sind-die-beute-von-morgen
Published on: boersen-zeitung.de, September 14, 2026
Interviewee: Antonio Paolo Mecci (interview conducted by Franz Công Bùi)
Conclusion
The interview reframes post-quantum urgency as a sequencing problem rather than a single deadline. Mecci's core argument is that institutions already at risk today from harvested data won't see a warning sign, so the Mosca inequality and a clear governance owner matter more than reacting to system age or waiting for a definitive threat date.

.png)


