Logo
Back

The Hidden Cryptography Risk Report: A Practical Brief on Cryptographic Risk and How to Act on It

20 July, 2026

An iceberg above the waterline represents the cryptography an organization can see, while a much larger network of keys, certificates, and signatures lies hidden beneath the surface.

Executive Summary

Organizations today rely on cryptographic foundations they cannot see, do not track, and cannot confidently upgrade (a.k.a Shadow Cryptography). This makes cryptographic risk one of the least visible yet most operationally critical threats in the enterprise. The arrival of post-quantum cryptography (PQC) will not simply introduce new algorithms; it will force organizations to replace the invisible infrastructure that underpins authentication, confidentiality, and trust across every system.

This guide explains how cryptographic risk accumulates, why PQC migration is different from every previous transition, and what organizations must do now to avoid an unmanageable, deadline-driven crisis.

The Risk You Cannot See

Enterprises are running critical operations on cryptographic infrastructure they cannot fully account for, and that invisibility is itself the risk.

Cryptography underpins almost everything:

  • Digital identities (people and things)
  • Application authentication
  • Financial transactions
  • VPNs and TLS
  • Protected data at rest (storage, databases, laptops)
  • Cloud workloads
  • API calls
  • Database connections
  • Code signing
  • Digital signatures on workflows, documents, contracts

However, basic inventory questions often remain unanswered:

  • What cryptographic algorithms are being used?
  • Where are they used?
  • Where are the assets protected by cryptography (data, signed contracts, signed emails, etc.)
  • Who owns them?
  • Who can change them?
  • How long do they need to exist (and be protected)?
  • Are they quantum-vulnerable?

Because cryptography is deeply embedded and often configured implicitly, teams can operate mission critical systems without visibility into the cryptographic decisions beneath them. For example, a large share of the world's web servers relies on OpenSSL for SSL/TLS encryption.

An iceberg diagram showing business processes and systems and applications as the visible layer above the waterline, with cryptographic infrastructure forming the much larger hidden layer beneath.

How Cryptographic Risk Accumulates

In most enterprises, cryptographic risk does not explode suddenly, but it accumulates silently.

Key contributors include:

Unknown Assets
Certificates exist in legacy systems, embedded devices, outdated appliances, digital signatures, and shadow IT.

Manual Processes
Hand-managed keystores and certificate lifecycle workflows introduce drift, inconsistency, and permanent configurations.

Diffused Ownership
No single team owns cryptography end to end, so responsibility becomes fragmented.

Incomplete Inventories
Even organizations with inventory programs, based on traditional security tools, rarely capture:

  • self-signed certificates
  • embedded firmware crypto
  • proprietary protocols
  • third-party managed keys

Risk builds silently until a migration or incident forces everything into the light — all at once.

A five-step risk snowball: isolated keys, hidden dependencies, vulnerable integrations, and exposed data at rest compound into a total migration burden.

The Supply Chain and Third-Party Dimension

It is tempting to treat cryptographic migration as an internal project. In practice, most of an organization's sensitive data moves through partners, providers, and networks it does not control. A quantum-safe organization connected to a quantum-vulnerable supplier, payment network, or cloud service is not quantum-safe.

Dependencies include:

  • COTS hardware and software
  • Third-party application developers
  • Cloud KMS and HSM providers
  • Payment processors
  • Authentication providers
  • Document signature providers
  • Telecom operators
  • IoT vendors
  • Open-source libraries

Even if your internal systems are fully safe, a single vulnerable cryptographic dependency can compromise the end-to-end chain of trust. This surfaces most painfully in due diligence: even today, before quantum, a deprecated algorithm like MD5 in an acquired company's stack can derail a deal.

Put simply, cryptography is only as strong as the weakest system in the trust chain, upstream or downstream.

A supply-chain trust graph showing how a single legacy-cryptography node, such as an external API, breaks an otherwise PQC-enabled chain from CDN and origin app through to end-user data.

Why Migrations Always Take Longer Than You Expect

Cryptographic migrations consistently exceed timelines because:

  • Crypto is deeply embedded in places nobody remembers.
  • Applications break in case of major root certificate transitions or new critical extensions.
  • Dependencies rely on deprecated algorithms.
  • Third-party systems cannot be upgraded on your schedule.
  • Testing environments do not match production crypto behavior.
  • Teams underestimate the volume of in-scope systems.

Even classical migrations from SHA-1 or RSA-1024 took years for organizations that had far simpler architectures than what exists today.

PQC migration is larger by orders of magnitude.

The Quantum Threat Makes It Existential

Quantum computing does not add a new kind of risk. It removes your ability to recover from the cryptographic weaknesses you already have.

Most security failures can be walked back. A breached system gets patched, credentials get rotated, and you move on. Encrypted data that gets decrypted works differently. Once someone reads data you encrypted years ago, there is nothing left to fix. The exposure is done.

That is what makes the timing matter. This is not a risk you can wait to address, because for long-lived data the damage happens the moment the encryption gives way, not the moment you notice.

Nation-State Actors Are Already Collecting

Nation-state adversaries are performing Harvest Now, Decrypt Later (HNDL) operations today:

  • They intercept encrypted communications.
  • They store data they cannot currently decrypt.
  • They wait for quantum capability to mature.

This includes:

  • Diplomatic and military traffic
  • Enterprise VPNs
  • Cloud workloads
  • Intellectual property
  • Health and financial records

Even if quantum decryption is years away, the window to protect long-lived data has already passed.

A Harvest Now, Decrypt Later timeline: data encrypted today is mass-harvested from 2025 to 2027, a quantum threshold is reached between 2028 and 2030, and decryption at scale follows from 2030 onward.

The Cost of Waiting

Every month of delay makes migration harder and more expensive.

Waiting causes:

  • short migration windows
  • pressure to swap algorithms hastily
  • increased reliance on temporary exceptions/mitigations
  • costly emergency program mobilization
  • lack of a security architecture
  • inability to test adequately

Proactive migration is manageable, orderly, and controlled.

Late migration is chaotic and driven by external deadlines.

What Makes This Migration Different

This is not like moving from SHA-1 to SHA-2, or from RSA-1024 to RSA-2048.

PQC migration is unique because:

  • It is entirely related to the organization's risk management.
  • It touches every connected system.
  • Systems can be prioritized, but none is out of scope.
  • Algorithms behave differently.
  • Protocols and message sizes change.
  • Interoperability requires both sides to support PQC.

PQC is not a drop-in replacement. It reshapes architectures, performance assumptions, and protocols across the entire enterprise.

The durable answer is crypto-agility: designing systems so algorithms and keys can be replaced as standards evolve, without re-architecting each time. Agility, not any single algorithm, is what keeps an organization ready as the standards continue to change.

Trust Now, Forge Later: The Digital Signature Time Bomb

Unlike HNDL (Harvest Now, Decrypt Later), digital signatures introduce a second quantum threat:

Trust Now, Forge Later (TNFL)

Signatures validate:

  • contracts
  • software updates
  • identity documents
  • workflow approvals
  • authentication assertions
  • certificates and certificates authorities

If quantum computers can forge signatures, adversaries will be able to:

  • impersonate devices and websites / web services
  • tamper with code
  • forge contractual evidence
  • bypass identity controls
  • rewrite historical records

This is the most underestimated quantum risk because it compromises the integrity of organizational trust itself.

Have a question about our services or products?