Cyber

Anticipatory collection

Strategy of capturing encrypted streams or files today, storing them without attempting to read them, and waiting for a machine able to decrypt them to become available.

Definition

The attack is passive, silent and undetectable, since nothing is broken and the victim generally never learns the copy exists. Its insurance reach belongs to this risk alone and has no equivalent: for a whole category of data the triggering fact has already occurred. Exfiltration took place, under a policy written years ago, it produced no observable damage, and it will produce damage a decade later. No other cyber exposure has this structure, in which the event, its discovery and the loss are separated by ten years or more. Quantum risk is therefore not a cyber risk in the sense the market gives that word, it is a long-tail risk disguised as a cyber risk, and development length is precisely what puts insurers in difficulty.

Example

The stock of contracts written between 2015 and 2030 holds a burden whose size nobody knows, and which no future exclusion will erase since it is already constituted.

Related terms
Also known as

harvest now decrypt later, moissonner maintenant déchiffrer plus tard, HNDL, store now decrypt later