Harvest Now, Decrypt Later: Dr. Martha Boeckenfeld Highlights Quantum Threat to Sensitive Data

D

Dr. Martha Boeckenfeld

LinkedIn Author

AI Governance & Quantum Keynote Speaker | Board Director & Advisor | Human-Centric Futurist | I help boards & C-suites close the Governance Gap | Host, The Edge of Tomorrow | Ex-UBS · AXA

In a recent LinkedIn post, Dr. Martha Boeckenfeld sounds an urgent alarm regarding the future threat of quantum computing to sensitive data, particularly within the healthcare sector. Dr. Boeckenfeld frames the issue as a critical board-level concern, emphasizing the concept of “Harvest Now, Decrypt Later” (HNDL), where encrypted data stolen today could be decrypted by future quantum computers.

Dr. Boeckenfeld illustrates the stark reality of data vulnerability by contrasting the low cost of stolen credit cards with that of full medical records on the dark market. “On dark markets, a stolen credit card sells for $18. A full medical record sells for $300,” she states, immediately highlighting the high value and unique permanence of personal health information.

“You can cancel a compromised card in sixty seconds. You cannot cancel your DNA.”

The post then delves into a hypothetical, yet plausible, scenario involving a pregnant patient whose raw genomic data is stored by a vendor. Dr. Boeckenfeld explains the HNDL threat: even if the data is encrypted, a future breach could render it vulnerable. “The attackers do not need to read it today. They can store the encrypted files cheaply and wait for quantum computing to catch up,” she warns.

The Board’s Capital Planning Trap

Dr. Boeckenfeld identifies a significant challenge for corporate leadership: the disconnect between when a breach might occur or be exploited, and when budget decisions must be made. She points to insights from a discussion with Steve Suarez® on The Edge of Tomorrow, noting the “capital planning trap.”

According to Dr. Boeckenfeld, boards must proactively address several key questions:

  • Which data must remain confidential for 10, 20, or 30 years?
  • Which systems still depend on RSA and ECC?
  • Which vendors hold long-lived sensitive data?
  • What budget is needed to start migration this cycle?
  • Who owns the deadline at board level?

Quantifying the Quantum Risk

To underscore the urgency, Dr. Boeckenfeld provides several critical statistics. She highlights the substantial average cost of healthcare breaches, estimated between $6.6 million and $7.4 million, and the lengthy average containment time of 279 days. Furthermore, she points out the widespread unpreparedness for the advent of quantum computing, with over 90% of enterprise systems not ready for “Q-Day” and fewer than 7% using quantum-safe certificates at scale.

The timeline for quantum advancements is rapidly approaching, with estimates for breaking RSA-2048 significantly reduced. Dr. Boeckenfeld cites industry and governmental timelines, including Google’s PQC milestones by 2029 and US Executive Order requirements landing in 2030 and 2031. She emphasizes that a full enterprise cryptographic overhaul typically takes three to five years.

“HNDL changes the question from ‘When will quantum computers arrive?’ to ‘Which data are we allowing to sit behind encryption we already know we need to replace?'”

Dr. Boeckenfeld argues that the board’s action must be concrete: inventorying exposures, funding the necessary migration, assigning ownership, and establishing a dated roadmap. Missing the next capital budget cycle, she warns, could force leadership into a rushed, significantly more expensive migration under intense regulatory pressure.

A Call for Proactive Board Action

Ultimately, Dr. Boeckenfeld frames the HNDL threat as a strategic decision for the board, moving beyond the abstract question of when quantum computers will arrive to a concrete assessment of data’s current encryption vulnerabilities. “That is a board decision,” she concludes, posing a crucial question for leadership: “When was the last time an infrastructure deadline moved faster than your capital allocation cycle?”

The insights shared by Dr. Boeckenfeld underscore the critical need for organizations, especially those handling long-lived sensitive data like healthcare, to prioritize quantum-resistant cryptography and integrate it into their long-term strategic and financial planning.

📝 About This Content

This article is based on insights shared by Dr. Martha Boeckenfeld on LinkedIn.

📅 Originally posted on September 8, 2026 | View original post on LinkedIn →