HNDL
Harvest-Now-Decrypt-Later Exposure: Why Algorithm Counts Are Not Enough
Understand HNDL exposure, Mosca X+Y>Z, data lifetime, harvestability, attack paths, and why post-quantum risk needs more than flat crypto inventory.
HNDL is a data-risk problem
Harvest-now-decrypt-later risk exists when sensitive data can be captured today and still matter when a future cryptographically relevant quantum computer exists. That means the risk depends on data lifetime, harvestability, attacker reachability, and the time horizon for migration.
Use Mosca X+Y>Z to prioritize
Mosca framing helps teams reason about whether the data confidentiality lifetime plus migration time exceeds the time until quantum capability. RelixQ models this as an exposure window rather than treating every RSA or ECC finding as equal.
- X: how long the data must remain confidential
- Y: how long migration and remediation will take
- Z: estimated time until the relevant quantum threat is practical
- Exposure window: the dated risk window created when X+Y exceeds Z
Attack paths make HNDL actionable
HNDL findings become more useful when they are connected to endpoints, applications, data assets, owners, score impact, and release gates. That is the RelixQ Enterprise wedge: turn HNDL from a concept into an operating workflow.