Insight · Framework

Mosca's Inequality

Risk Modeling 6 min read Every CISO should know this

One line of arithmetic decides whether your data is already exposed to the quantum threat. It's simple enough for a board slide and rigorous enough to drive a migration plan.

X + Y > Q

If this holds, you are already too late.

The three variables

Named for cryptographer Michele Mosca, the inequality reframes quantum risk as a race between how long your secrets must last and how long you have to protect them.

XShelf life. How many years your data must remain confidential — driven by regulation, contracts, IP sensitivity, and privacy obligations.
YMigration time. How many years it will take your organization to discover, prioritize, and re-encrypt everything with quantum-safe algorithms. Almost always underestimated.
QQuantum clock. How many years until a cryptographically relevant quantum computer exists. Uncertain, but the expert range is roughly a decade — and it can only get shorter.

Why the deadline is closer than it looks

The trap is treating Q as the deadline. It isn't. The real deadline is Q minus Y — the last moment you can start and still finish in time. If migration takes seven years and a quantum computer arrives in ten, you have three years to begin, not ten.

And there's a second, harsher point. Because of harvest-now-decrypt-later — adversaries recording encrypted traffic today to decrypt once quantum hardware matures — data with a long shelf life is already exposed. A record that must stay secret for twenty-five years, captured today, will be readable long before that window closes. For that data, the inequality was violated the moment it crossed the wire.

Every other cryptographic vulnerability has a patch. Harvested ciphertext does not — you cannot un-send traffic an adversary already holds.

A worked example

Consider a hospital system:

X = 30 yrs (patient records) Y = 7 yrs (migration) Q ≈ 12 yrs (quantum)

X + Y = 37 years, comfortably greater than Q ≈ 12. The inequality is violated by a wide margin: data protected today can be harvested now and decrypted well before the migration is even complete. This organization is not facing a future risk — it is facing a present-tense one, and the only lever it fully controls is Y.

Applying it to your organization

  1. Estimate X per data class. Treaty and health records skew high; ephemeral session data skews low. One number for the whole enterprise hides the risk.
  2. Be honest about Y. Migration is a multi-year, cross-team program touching PKI, protocols, hardware, and vendors — not a software patch.
  3. Treat Q as a range, not a date. Model a pessimistic and an optimistic Q, and plan to the pessimistic one.
  4. Prioritize where X + Y most exceeds Q. Those systems migrate first.

Because Q is shared across every organization but X and Y are yours alone, the inequality is ultimately a statement about the two variables you control — and how little time is left to act on them.

Test the inequality on your own data

Our interactive risk model lets you move X, Y, and Q and see the verdict instantly — then we turn it into a tiered migration plan.

Open the risk model