RQRelixQ

HNDL

Harvest-Now-Decrypt-Later Exposure: Why Algorithm Counts Are Not Enough

Understand HNDL exposure, Mosca X+Y>Z, data lifetime, harvestability, attack paths, and why post-quantum risk needs more than flat crypto inventory.

HNDL is a data-risk problem

Harvest-now-decrypt-later risk exists when sensitive data can be captured today and still matter when a future cryptographically relevant quantum computer exists. That means the risk depends on data lifetime, harvestability, attacker reachability, and the time horizon for migration.

Use Mosca X+Y>Z to prioritize

Mosca framing helps teams reason about whether the data confidentiality lifetime plus migration time exceeds the time until quantum capability. RelixQ models this as an exposure window rather than treating every RSA or ECC finding as equal.

  • X: how long the data must remain confidential
  • Y: how long migration and remediation will take
  • Z: estimated time until the relevant quantum threat is practical
  • Exposure window: the dated risk window created when X+Y exceeds Z

Attack paths make HNDL actionable

HNDL findings become more useful when they are connected to endpoints, applications, data assets, owners, score impact, and release gates. That is the RelixQ Enterprise wedge: turn HNDL from a concept into an operating workflow.