up:: For Press
For a business audience
Everything a piece for business readers needs, in the order it’s usually needed. Two threads carry most of the substance: what happens to a company’s intellectual property, and what happens to the infrastructure underneath commerce that nobody sees until it fails.
What’s the story in one paragraph?
Every company holds records that must stay confidential for years and in some cases forever, and those records are crossing networks today under encryption scheduled for retirement. Somebody can copy that traffic now and read it once a capable machine exists, which means the exposure is created on the day the data is sent rather than on the day the machine arrives. Deadlines already exist in writing, and for most companies the binding date arrives through a certification, a contract clause, or a customer’s security requirements at renewal rather than through a regulator. The first step, producing an inventory of where a company’s cryptography actually lives, defeats most organizations that attempt it, and a large share of the estate sits inside purchased products the company can’t modify at all.
What are the 5 most important things?
- Trade secrets are the longest-lived asset a company owns, and they have no expiry date. A formula, a chip layout, or a manufacturing process stays valuable exactly as long as it stays secret, which makes intellectual property the category with the most to lose from retroactive exposure.
- This has already happened at industrial scale, when it was far harder. One documented campaign exfiltrated intellectual property from at least 141 organizations across 20 industries, running to hundreds of terabytes, back when every intrusion had to be worked by hand. Passive collection removes that labor cap.
- Your deadline is in paperwork you already signed. It arrives through certifications, contract clauses, and customer security requirements at renewal, and it usually attaches to a specific product line or account rather than to the company as a whole.
- Most of the estate belongs to vendors. A large share of the cryptography in a typical enterprise sits inside purchased products on release schedules the buyer doesn’t control, so the timeline isn’t the company’s to compress.
- What to do about it is a sequence, and it starts small. Fund a scoped, time-boxed inventory of your most sensitive systems, because nothing can be priced or prioritized before it. Name one accountable executive senior enough to move budget across teams. Sort your data by how long it has to stay confidential, since retention law already sets that clock for a large share of it. Get dated commitments from vendors written into contracts at renewal, where the leverage is. And put the exposure in the risk register with its source and owner, so it survives staff turnover.
What’s the intellectual-property exposure?
The sharpest version of the business story, because the asset has no expiry and the precedent is documented.
Trade secrets, proprietary formulas, drug-discovery pipelines, pre-patent research, semiconductor designs and process parameters, proprietary source code, and the training data and model weights behind proprietary AI systems all stay valuable for exactly as long as they stay secret. There’s no legal expiration to run out.
The precedent is the part that resists dismissal. Economic-espionage campaigns uncovered between 2011 and 2013 took intellectual property from at least 141 organizations across 20 major industries in a single campaign, running to hundreds of terabytes. The then-director of the NSA described the losses as “the greatest transfer of wealth in history.”
Source: Mandiant, “APT1: Exposing One of China’s Cyber Espionage Units,” February 19, 2013, services.google.com.
What makes that number the relevant one: every intrusion in that campaign required breaking into a specific network, escalating, finding the plaintext, and moving it out, one victim at a time. That labor is what capped the damage at 141 organizations. Recording encrypted traffic needs no break-in and no per-victim effort, scales to everything crossing a collectible path, and cold storage costs a fraction of a cent per gigabyte per month.
What’s the infrastructure underneath commerce?
The second thread, and the one that explains why this reaches every sector at once.
The same mathematics does 2 jobs across the whole economy. It keeps data confidential, and it proves that a party is who it claims to be. Payment authorization, interbank messaging, supply-chain data exchange, software update signing, and the certificates that let any 2 systems trust each other all rest on it.
That produces 2 distinct exposures on 2 different clocks:
| Confidentiality | Trust | |
|---|---|---|
| What fails | Recorded data becomes readable | Certificates, tokens, and signing keys become forgeable |
| Direction | Backward, reaching everything already collected | Forward, from the day a capable machine exists |
| Live now? | Yes, the collection is present-tense | No, nothing can be staged in advance |
| Business consequence | Retroactive disclosure of anything long-lived | Credible impersonation of a company, its software, or its transactions |
The trust half has already happened once with no quantum computer involved. In 2011 a Dutch certificate authority was breached and the attacker minted at least 531 fraudulent certificates, using 1 of them to intercept the email of roughly 300,000 people. The certificates were mathematically valid and every browser displayed a padlock.
Source: Fox-IT, “Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach,” 2012, enisa.europa.eu.
Which numbers are sourced and safe to use?
| The figure | The accurate wording | Source |
|---|---|---|
| $7.1 billion | Projected cost of migrating priority U.S. federal civilian systems 2025 to 2035, excluding national security systems, labeled an initial projection with high uncertainty | OMB, July 2024, OMB report |
| 141 organizations across 20 industries | Intellectual property exfiltrated in a single documented campaign | Mandiant, services.google.com |
| 28.9% of sampled configurations | Share of Nginx TLS configurations published on GitHub specifying an RSA key exchange with no forward secrecy. A corpus of 8,443 files rather than a scan of live servers, and the authors include a commercial post-quantum vendor and the funding bank | Balaji et al., 2026, arxiv.org |
| 147 million people, $575 million | Equifax exposure and settlement, most of them never customers | FTC, ftc.gov |
| ~$1.4 billion | Merck’s claimed NotPetya losses, litigated over a war exclusion and settled January 2024 | NJ opinion |
| ~$9.14 billion | U.S. cyber insurance direct written premium 2024, down about 7%, its first contraction | NAIC, naic.org |
| December 11, 2027 | Full EU Cyber Resilience Act obligations, binding manufacturers worldwide selling into the EU | eur-lex.europa.eu |
| January 1, 2027 | Post-quantum required in new U.S. national security system acquisitions, reaching vendors through procurement | NSA, media.defense.gov |
| $575 million to 15 million euro or 2.5% of turnover | The settlement and penalty ceilings that bracket the regulatory exposure | FTC; EU CRA summary |
| 850 billion | Projected global economic value from quantum computing by 2040, a consultancy forecast rather than a measurement | Boston Consulting Group, July 18, 2024, bcg.com |
What will business readers ask?
| The question | The page that answers it |
|---|---|
| ”Where do we even begin?” | Where do we actually start |
| ”Why not wait for AI to settle?” | Why not wait until AI is under control |
| ”What of our data is actually at risk?” | What of our company data is at risk |
| ”What does this cost?” | What does this cost |
| ”Who’s liable when it fails?” | Who is liable when this fails |
| ”What can’t we fix ourselves?” | What can I not fix myself |
| ”What do regulators expect?” | What do regulators expect |
| ”Does our insurance cover it?” | Does our insurance cover this |
| ”How do I explain it to the board?” | How do I explain this to my board |
| ”What do I ask my security team?” | What should I ask my security team |
| ”How does this work, technically?” | What is technically happening to our systems |
| ”What if we’re small?” | What if we are a small business |
| ”What about law firms?” | What if we are a law firm |
| ”What about hospitals?” | What if we run a clinic or hospital |
| ”What about schools?” | What if we run a school or university |
| ”What about M&A diligence?” | What if we are investing or acquiring |
Which errors draw corrections?
- “Companies just need to buy post-quantum software.” The algorithms are free public standards. The cost is labor, coordination, and replacing equipment that can’t be updated.
- “There’s a standard per-company cost.” Cost varies more between 2 similar-revenue companies than the revenue does, which is why the inventory has to come first.
- “The $7.1 billion figure tells you what a company will pay.” It covers a decade across an entire federal civilian government and excludes national security systems.
- “Cloud providers handle this.” Providers migrate their own infrastructure, and a substantial share of encryption choices stay on the customer side of the shared-responsibility line.
- “Insurance covers it.” No published standard market clause names cryptographic obsolescence as either covered or excluded.
Go deeper: the technical layer
The pages below are the version written for security leaders and practitioners, with every primary source intact. These are what a CISO or a risk officer would actually be working from.
Section indexes: Doing the Work MOC · Migration Architecture MOC · The Human & Organizational Side MOC · The Mandates MOC · Quantum Risk Models MOC
Where to go next
- For Business Leaders MOC is the full executive route, with all 9 pages.
- Every figure and where it comes from carries every number with accurate phrasing.
- The primary documents behind every claim is the annotated source index.
- For Press is the full index.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.