up:: For Business Leaders MOC

What of our company’s data is at risk?

Ask one question about anything your organization holds: if a competitor or a foreign intelligence service could read this 8 years from now, what would it cost us?

That question sorts an entire estate, and it produces a much shorter list than people expect. Most operational traffic is worthless to somebody opening it in a decade. A trade secret, a board packet, a litigation file, and a customer database are not.

The useful part is that for a large share of it, the law already tells you the lifetime. Records you’re legally required to retain are records an adversary has time to wait for.

The short version:

  • Retention law defines your priority list. If regulation says keep it 7 years, that’s a 7-year exposure you didn’t choose.
  • Trade secrets have no expiry at all, which makes intellectual property the longest-lived category you own.
  • Communications archives are the densest single target, because they concentrate everything else into one searchable corpus.
  • Customer data converts an internal loss into a regulated breach with notification duties and liability attached.
  • This has already happened at scale. One documented campaign took data from 141 organizations across 20 industries.
  • Most day-to-day operational traffic is genuinely fine, and saying so is what makes the rest credible.

Which nine families matter?

1. Regulated records, where the law sets the clock

The easiest category to defend a priority call on, because you don’t have to argue about the lifetime. Somebody already legislated it.

  • Health information. Patient records, claims data, clinical trial results. U.S. health-privacy rules require 6 years of compliance documentation, state medical-record retention often runs longer, and the clinical facts stay true for a lifetime.
  • Financial and securities records. Broker-dealer records carry 3-to-6-year retention under SEC Rule 17a-4, certain corporate records are kept for the life of the enterprise, and audit workpapers carry 7 years under the Sarbanes-Oxley implementing rule.
  • Legal records under privilege. Litigation strategy, internal investigations, settlement talks, outside-counsel communications. Privilege makes these valuable precisely because they were never meant to be seen.
  • Government and defense material. Classified information runs on declassification horizons of 25 years, extendable to 50 or 75 for the most sensitive categories.

Source: 45 CFR § 164.316(b)(2)(i), govinfo.gov; 17 CFR § 240.17a-4, govinfo.gov; Executive Order 13526 §§ 3.3(a), 3.3(h).

2. Deals, strategy, and negotiations

A sharp expiry pattern: catastrophic sensitivity for months to a few years, then sudden decay once the deal closes. It stays on the list because that window regularly exceeds the time an already-collecting adversary needs.

M&A pipelines, due-diligence rooms, valuation models, board packets and minutes, competitive bid pricing, negotiation positions with suppliers and unions and regulators, and unannounced product or restructuring plans.

The bid-pricing case is the sharpest. A rival who reads last cycle’s numbers reprices every future cycle against you.

3. Intellectual property and R&D

The longest-lived commercial category you own, because trade secrets have no expiration date at all. A formula, a chip layout, or a manufacturing process stays valuable exactly as long as it stays secret.

Trade secrets and proprietary formulas, drug-discovery pipelines and pre-patent research, semiconductor designs and process parameters, proprietary source code including the security-relevant parts an attacker reads for flaws, and training data and model weights for proprietary AI systems.

This is the category with documented precedent at scale. The economic-espionage campaigns uncovered between 2011 and 2013 exfiltrated intellectual property from at least 141 organizations across 20 major industries in one campaign alone, running to hundreds of terabytes. The then-director of the NSA described the losses as “the greatest transfer of wealth in history.”

That happened when theft required active intrusion into each network. Passive collection lowers the cost of the same appetite.

Source: Mandiant, “APT1: Exposing One of China’s Cyber Espionage Units,” February 19, 2013, mandiant-apt1-report.pdf.

4. Communications archives

The densest single target in most estates, because an email archive concentrates every other family on this list into one searchable place: deals, legal strategy, credentials pasted into threads, HR matters, and years of candid internal reasoning.

Executive and board email retained for a decade under litigation hold, secure-messaging history for legal and leadership teams, compliance-journaled communications in regulated firms, and support tickets and CRM logs holding customer confidences at scale.

Once decrypted, the harm compounds rather than adds. A single message embarrasses somebody. A decade of correspondence profiles them.

5. Customer and personal data

Anything you hold about other people converts a quantum decryption event from an internal loss into a regulated breach, with notification duties, liability, and identity-theft harm downstream.

Customer databases, know-your-customer files, loyalty profiles, and usage histories. The sensitivity lifetime here belongs to your customers rather than to you, so you can’t shorten it by deciding it matters less.

6. Financial operations

Treasury flows, payment instructions, payroll, banking credentials, and interbank traffic.

Individual transactions decay quickly. The patterns stay valuable: years of payment flows map out suppliers, margins, customer concentration, and cash position. That’s competitive intelligence with a long shelf life.

7. Infrastructure secrets

A mixed-lifetime family that punches above its retention period, because these secrets unlock other data rather than being the prize themselves.

Credentials and API keys captured in transit, long-lived cryptographic key material, network architecture and VPN configurations and firewall rules, asset inventories, and incident-response communications, which are a map of exactly where you’re weak and how you respond.

Rotation shortens the life of credentials in theory. Observed reality in most estates is that a great many secrets are stale and unrotated.

8. Sector-specific operational data

SectorWhat’s exposed
Energy and industrialControl-system telemetry revealing grid topology and process detail, on the longest-lived hardware in any estate
TelecommunicationsInterconnect and signaling traffic, which aggregates everyone else’s communications metadata
Healthcare and pharmaRegulated records and R&D combined in one estate
Automotive, aerospace, spaceTelemetry and command links on platforms that outlive their cryptography by design
Financial infrastructurePayment and clearing flows, dense with both money movement and personal data

9. Public sector

Diplomatic material, defense logistics, census microdata, and law-enforcement files. Governments run the longest confidentiality horizons of any data owner, which is why they treat each other as primary targets.

How long does each family stay valuable?

FamilyStays valuable forWhat sets the clock
Trade secrets and IPIndefinitelySecrecy itself, with no legal expiry
Health recordsA lifetimeClinical relevance, plus a 6-year documentation floor
Customer personal dataYour customers’ lifetimesTheir exposure, not your retention policy
Classified and defense25 to 75 yearsDeclassification horizons
Litigation and privileged materialMatter lifetime plus yearsRetention rules and the durability of the facts
Securities and broker-dealer records3 to 6 years, some life-of-enterpriseSEC Rule 17a-4
Communications archivesAs long as the archive existsLitigation hold and compliance journaling
M&A and strategyMonths to a few years, catastrophicallyThe deal window
Credentials and session secretsDays to yearsRotation policy, and rotation reality
Routine operational trafficDays to weeksNothing. This is the part you can de-scope.

What can you honestly leave off the list?

This matters as much as the rest, because a risk assessment that flags everything gets ignored.

  • Short-lived operational data. Session tokens, telemetry, cache traffic, and routine chatter whose sensitivity dies in days. It’ll be decrypted eventually and it won’t matter.
  • Properly rotated secrets. A credential rotated monthly is stale long before any machine exists. The caveat is the word “properly.”
  • Already-public information. Marketing material, published filings, open datasets. Decrypting a copy reveals at most that you sent it.
  • Anything already moved to the new encryption. That’s the mitigated state the whole exercise is driving toward.

The de-scope list is also your triage engine in reverse. Shortening retention, rotating faster, and moving the long-lived families first are the three moves that shrink your exposure fastest.

What do you do with this?

  1. Sort your data by how long it stays valuable, using the families above. This is the step that makes everything else fundable, because it converts an abstract risk into a ranked list.
  2. Start with the families where the law sets the clock, since those need no internal argument about lifetime.
  3. Find where the cryptography actually lives. You can’t protect what you haven’t located, and most organizations discover this is the hard part. See What should my doctor and bank be doing.
  4. Delete more. Retention you kept because nobody decided to stop is exposure you chose to carry.
  5. Ask your vendors for dated commitments, because a large share of this sits inside products you can’t modify. See What can I not fix myself.

Questions people ask

Isn’t all of our data encrypted already? Yes, and that’s exactly the mechanism. It gets copied while encrypted and stored until the encryption can be undone. The exposure is in how the keys were agreed rather than how the contents were scrambled.

How is this different from a normal breach? Nobody enters your systems, nothing is detected, and no notification duty attaches. See Will anyone tell me if it happens.

Which family should we start with? Whichever combines a long lifetime with high consequence. For most organizations that’s intellectual property, communications archives, and regulated customer data.

Is our industry actually targeted? Attribution for any specific dataset is unprovable from outside. The documented record shows IP-rich and infrastructure sectors taken at industrial scale when it required active intrusion, and passive collection is far cheaper than that was.

What if we’re small? The same nine families apply, and your inventory is genuinely tractable in a way a multinational’s isn’t. That’s an advantage.

Where to go next

Go deeper into the technical detail

The technical catalog, with every retention citation, is What Data Is Vulnerable to Harvest Now, Decrypt Later.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.