up:: For Business Leaders MOC

Who is liable when this fails?

Nobody knows, and that’s the accurate answer rather than an evasive one. No court has ruled on a case where data encrypted years ago was decrypted later by a quantum computer, because it hasn’t happened yet.

What exists is a set of adjacent rules and rulings that will be argued by analogy when it does: securities disclosure duties, breach notification statutes, vendor indemnity clauses, insurance exclusions, and the ordinary negligence standard of what a reasonable organization was expected to be doing. Each of those was written for an event with a discoverable date, and this one doesn’t have one.

Not legal advice

This is general education about how liability has been allocated in comparable cases. Whether any obligation attaches to your organization is a determination you make with your own counsel.

The short version:

  • 4 parties could carry the cost: your organization, the vendor whose product held the encryption, your insurer, and the people whose data it was.
  • The record shows it lands on the 4th. Equifax exposed 147 million people and settled for at least $575 million, while the people in the file received credit monitoring and a permanent exposure.
  • A dated obligation is the thing courts will reach for. Deadlines already exist in writing, so “nobody told us” stops being available as a position after those dates pass.
  • Insurance was written for break-ins with a discovery date, and a harm that surfaces a decade after the copying sits awkwardly against nearly every clause in a cyber policy.
  • What you attested to matters as much as what you did. A carrier has already rescinded a policy over a security answer the insured couldn’t substantiate.
  • The open questions are structural, so they’ll be litigated once and then settled for everybody at once.

Who are the parties, and what does each one owe today?

PartyWhat they’d be argued to oweWhat’s actually settled
Your organizationA duty of reasonable care over data you hold, plus every dated obligation in your own contracts and certificationsThe obligations are settled and dated. Whether missing them causes a specific later loss has never been tried
The vendorWhatever the contract says, which for most products is a warranty of conformance rather than a promise of future cryptographic strengthAlmost nothing. Most agreements predate the question entirely
Your insurerThe losses the policy covers, subject to its exclusions and its retroactive dateCyber policies are built around an event discovered inside a policy period. A delayed harm has no tested precedent
The people in the dataNothing. They carry the lossConsistently the party that absorbs the harm and recovers the least

The 4th row is the one that repeats across every case in the record, and it’s why the question is worth answering before an incident rather than during one.

What does the documented record show about where the cost lands?

Three cases, none of them quantum, all of them the shape this argument will take.

A breach of 147 million people resolved as a corporate line item. In 2017 attackers exploited a known vulnerability in Equifax’s online dispute portal and, over roughly 2 months, exfiltrated records on 147.9 million people, including Social Security numbers, birth dates, and addresses. In 2019 the company settled with the FTC, the CFPB, and the states for at least $575 million. The overwhelming majority of those people were never Equifax customers, had entered into no agreement with it, and had no mechanism to opt out of being in the file. A Social Security number is far harder to replace than a password, so the disclosed information stayed disclosed.

Source: Federal Trade Commission, “Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach,” July 22, 2019, FTC press release.

**A 1.4 billion under its property policy. The insurers declined, invoking the standard exclusion for hostile or warlike action by a government, on the grounds the attack was attributed to Russia. A New Jersey appellate court held in May 2023 that the exclusion didn’t reach a cyberattack on a non-military company, and the parties settled in January 2024, more than 6 years after the loss.

Source: Merck & Co., Inc. v. ACE American Insurance Co. (N.J. Super. Ct. App. Div., approved for publication May 1, 2023), opinion; settlement reported January 2024, Insurance Journal.

A policy voided over a single answer on an application. In Travelers Property Casualty Co. of America v. International Control Services, an insurer moved to rescind a cyber policy after the insured attested to using multi-factor authentication that turned out to exist in only 1 location. The policy was rescinded by stipulated judgment in August 2022, which unwinds it as though it never existed.

Source: Travelers Property Casualty Co. of America v. International Control Services, Inc. (C.D. Ill., filed July 2022; rescinded by stipulated judgment August 26, 2022), Insurance Journal report.

Read together, those 3 describe the mechanics of the argument you’d be having: the settlement lands on a ledger the affected people never appear on, the outcome turns on clause language drafted for a different world, and your own written answers about your controls become the ground you have to defend.

What makes this different from an ordinary breach?

Four features, and each one breaks an assumption a liability rule depends on.

  1. There’s no intrusion. Copying encrypted traffic off a network takes nothing and breaks nothing. No system is entered, no alert fires, and no forensic artifact is left behind, so there’s no incident to investigate.
  2. There’s no discovery date. Breach statutes, insurance policies, and disclosure duties all run their clocks from the moment an organization knows. If the copying happened in 2026 and the reading happens in 2036, an argument about which year the loss occurred has no obvious answer.
  3. There’s no notification duty. U.S. state breach laws and sector rules are triggered by unauthorized acquisition of personal information, and every one of them was written with an intruder in mind. See Will anyone tell me if it happens.
  4. The obligation was dated in advance. This is the feature that cuts against a defendant. Retirement schedules and migration deadlines are published, dated, and public, so an organization arguing after 2030 that the risk was unforeseeable is arguing against documents in the public record. See What do regulators expect.

Does our vendor contract cover this?

Almost certainly not in the way you’d want, and this is worth checking rather than assuming.

Most master services agreements warrant that a product conforms to its documentation and that the vendor maintains industry-standard security. Neither promises the cryptography inside the product will still be strong in 2035, and neither commits the vendor to a dated migration.

The practical consequence is that a large share of your cryptographic exposure sits inside products you can’t modify, under contracts that don’t oblige the supplier to fix them on your schedule. Your leverage is at purchase and at renewal, where a dated commitment can be written in.

What the contract usually saysWhat it obliges the vendor to do
”Industry-standard security measures”Meet a moving, undefined bar, interpreted after the fact
”Conforms to documentation”Work as described, with no forward-looking cryptographic promise
”Commercially reasonable efforts”Try, without a date
”Post-quantum support in [named release], by [date]“The only version that gives you an enforceable timeline

See What can I not fix myself for how to get the 4th row into an agreement.

What actually reduces our exposure?

Five moves, and 4 of them are documentation rather than technology.

  1. Know what you can prove. Every security representation you’ve made to an insurer, a customer, or a regulator is a claim you may have to substantiate years later. An encryption attestation with no inventory behind it is the exact shape of the Travelers case.
  2. Read your retroactive date against your longest-lived data. A policy that covers breaches first occurring after a given year, held alongside records that stay sensitive for decades, is a structural gap worth raising with a broker and coverage counsel. See Does our insurance cover this.
  3. Get a dated commitment into vendor renewals. A roadmap statement is a promise. A contract term is an obligation.
  4. Put the exposure in the risk register with its source. An entry naming the instrument, the date, and the owner survives staff turnover and audit questions in a way a verbal understanding doesn’t.
  5. Start the inventory. An organization that knows where its cryptography lives is in a different evidentiary position than one that never looked, both before a regulator and before a jury.

Questions people ask

Has anyone ever been sued over this? No. There’s no case involving retroactive quantum decryption, because no such decryption has happened publicly.

Could directors be personally exposed? Directors owe oversight duties over known, material risks, and a dated public deadline is the kind of fact that makes a risk known. Whether that reaches personal liability in any given case is a question for your own counsel, and it’s a live enough concern that boards are asking it.

If our vendor’s product is the weak link, is it their problem? Legally it depends entirely on your contract, and practically it becomes yours, because the customers and regulators come to you first. You can pursue the vendor afterward with whatever the agreement gives you.

Does encrypting the data protect us legally? It has historically been a strong position, since many notification statutes carry a safe harbor for encrypted data. That safe harbor assumes the encryption holds. Its behavior after the underlying algorithm has been broken is untested.

Are we safe if we met the deadline? Meeting a dated obligation is a substantially better position than missing it. It doesn’t retroactively protect data copied before you migrated, which is why the timing of the migration matters as much as the fact of it.

What about data our customers gave us before any of this was known? That’s the hardest category, and it’s the one Equifax illustrates. The people in the file made no decision, carry the loss, and have the fewest ways to act.

Who inside our company owns this question? In practice it sits between the general counsel, the risk function, and the CISO, and the common failure is each assuming one of the others is tracking it.

Where to go next

Go deeper into the technical detail

The technical treatment is When Crypto Fails, Who Actually Pays and Cyber Insurance.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.