
Your crypto inventory Is a spreadsheet, and it is lying to you

Introduction
No quantum computer today can break a 2048-bit RSA key, and anyone claiming otherwise is selling something. But an attacker targeting a bank in 2026 does not need one, only storage capacity and patience, since traffic intercepted now can be decrypted once a sufficiently powerful machine exists. Given that financial data often needs to stay confidential well into the 2030s, the window for migration is already closing.
Key Takeaways
- Harvest-now, decrypt-later means confidentiality loss has already begun for intercepted financial traffic, well ahead of any working quantum computer.
- Ranking systems by algorithm age is the wrong method. Michele Mosca's formula, confidentiality duration plus migration time, is what actually predicts exposure.
- Survey-based crypto inventories fail because application owners answer from memory, missing forgotten endpoints and hardcoded legacy keys.
- Post-quantum keys and signatures are dramatically larger than classical ones, which breaks assumptions built into decades of payment and networking infrastructure.
- A PQC migration functions as a data governance audit, forcing institutions to finally map where sensitive data flows and how long it must stay protected.
Mecci's argument centers on a simple but underused calculation from cryptographer Michele Mosca: add the years data must stay confidential to the years a system realistically needs to migrate. If that sum outlasts the time left before a cryptographically relevant quantum computer arrives, the system is already behind schedule, regardless of how old or new its algorithms look on paper.
The bigger operational failure, he argues, is how most institutions build their crypto inventories in the first place. Questionnaires sent to application owners rely on memory, which reliably omits forgotten endpoints, legacy protocols, and keys hardcoded into old batch jobs. A defensible inventory instead has to come from machine-driven discovery, including TLS scans, static code analysis, and HSM logs, tied to the classification of the data each connection actually carries.
He also points to a hardware problem that budgets have not caught up with. Post-quantum keys and signatures run far larger than their classical counterparts, which fragments legacy payment protocols and cannot be fixed with a firmware update on hardware built around elliptic-curve accelerators. In a small BSI survey, 89 percent of respondents admitted their migration will take longer than their data needs to stay confidential, a signal that the exposure is not hypothetical but already accumulating.
👉 Read the full article on IT Finanzmagazin:
https://www.it-finanzmagazin.de/ihr-krypto-inventar-ist-eine-excel-tabelle-und-die-luegt-sie-an-247748/
Published on: it-finanzmagazin.de
Author: Antonio Paolo Mecci
Conclusion
The institutions that finish an evidence-based crypto inventory this year still have a workable timeline ahead of them. Everyone relying on a questionnaire is building a migration plan on assumptions rather than evidence, and Mosca's arithmetic makes clear how little room that leaves.




_converted.avif)