Risk & Strategy / Breach Scenario Simulator

What this is for: Compare classical vs quantum-enabled breach cost (per-event and annual expected loss) with HNDL exposure.

What a good answer looks like: A scenario your own incident team recognises. If nobody in the room says "that is roughly what would happen", the inputs are wrong, not the model.

Worked example: Your industry, data retained for 10 years and a migration that takes 3 years: the classical and quantum-enabled breach costs update together, and the Mosca verdict says whether migration is already late.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Choose your industry sector and region, the data type you hold and the years of stored data: the classical and quantum-enabled breach costs update together, and the Mosca's theorem verdict says whether migration is already late.
GRC / Risk & Compliance
Set Years of Stored Data to your retention period and the migration time to your plan: the HNDL exposure factor and the Key Findings give the risk-register entry its likelihood and impact, with the IBM 2025 baseline cited on the page.
Industry Sector:
Scenario Inputs

Industry baseline (, global): $4.4M average total breach cost — IBM Cost of a Data Breach 2025. This total already includes detection, notification, lost business and reputational damage, so those are not added again.

Region:
0.25×1.00×4×
1 yr5 years25 yrs
1%9.3%50%

Default reflects the selected organization size — Cyentia IRIS 2025 anchors per organization size (Figures 6 and 7 of the report). The tiers sit close together because IRIS 2025's finding is that they have converged: small-firm risk has more than doubled since 2008 while the largest firms' has fallen. Drag the slider to override.

Data Sensitivity & Planning Horizon
What kind of data is at HNDL risk?

Shelf life: 10 years — how long this data class stays damaging if later decrypted. Assumption — no single authoritative source; adjust to your own retention/sensitivity policy.

5 yrs10 years20 yrs

Also the window used to look up CRQC-arrival probability below.

0%6%12%
Quantum Assumptions

Two separate ingredients: (1) harvest-now-decrypt-later amplification — once a quantum computer exists, a breach exposes years of accumulated harvested data, decayed by how long this data class stays sensitive; and (2) the probability a CRQC exists within your planning horizon, from the Global Risk Institute's 2025 expert survey. The headline expected-loss figure blends both — it does not assume a CRQC already exists.

5%30%100%

Amplification (decay-adjusted): 1.98× · decay factor 0.75

Cost if a breach occurs, assuming a CRQC already exists (single-loss expectancy):

Classical Breach

$4.4M

average × severity

Quantum-Enabled Breach

$8.8M

If CRQC exists — includes decayed HNDL exposure

Additional Quantum Risk

$4.4M

98% increase over classical, if CRQC exists

Expected annual loss blends the classical and quantum-enabled cases, weighted by the probability a CRQC exists within your 10-year horizon (41%, consensus scenario) — this is the figure that belongs in an ROI model, not the fully quantum-conditional number above.

Classical — annual expected loss

$413K

Quantum-weighted — annual expected loss

$579K

Range across CRQC-arrival scenarios (GRI 2025 survey bounds) — not a single point estimate:

Low (32%): $542KCentral (41%): $579KHigh (50%): $615K

Present value of the 10-year quantum-risk delta at 6% discount: $667K

When does migration need to start? (Mosca's theorem)

If (data shelf life) + (migration time) exceeds the time until a CRQC exists, you are already too late.

x — shelf life

10 yrs

3 yrs

z — median CRQC year (consensus)

2038

Already 1 year(s) late: migration should have started by 2025 to protect general customer/employee pii created today through the median CRQC arrival year.

Cost of waiting 2 more years to start: +$59K in present-value quantum-risk exposure.

How the quantum breach is built

Classical: $4.4M × 1.00 severity = $4.4M

Shelf-life decay (10yr General customer/employee PII): 0.75×

HNDL amplification: 1 + min(4, 5yr × 30% × decay) = 1.98×

Quantum SLE: $4.4M × 1.98 = $8.8M

CRQC probability within 10yr horizon (consensus): 41%

Blended ALE: $413K × (1 − 41%) + $8.8M × 9.3% × 41% = $579K

Calculation Methodology

Baseline: the industry average total breach cost (IBM Cost of a Data Breach 2025), shared with the ROI Calculator and Cost Model Explorer — one source, no drift. It already includes reputational and lost-business costs, so those are not added separately.

Severity: scales that average up or down for your scenario, instead of a flat per-record cost that would grow without bound.

HNDL amplification: 1 + (years × exposure factor × shelf-life decay), capped at 5×. Decay is linear to zero at the data class's shelf life, using the harvested corpus's average age — a simplification, not an exponential curve.

CRQC probability: looked up from the Global Risk Institute 2025 expert survey curve for the chosen planning horizon. This is a simple cumulative-probability difference, not conditioned on a CRQC not already existing today — a simplification that is negligible for near-term reference years.

Expected annual loss: blends the classical and CRQC-conditional cases, weighted by that probability — not the old model's assumption that a CRQC already exists.

Present value: the annual expected-loss delta is discounted as a level annuity over the planning horizon — an approximation, not a year-by-year integration of a growing risk curve.

Mosca's theorem: compares data shelf life + migration time against the median CRQC arrival year to flag whether migration is already overdue.

Educational estimates for planning. Actual costs vary widely by organization size, geography, and regulatory environment.

References

Key Findings

•

A CRQC (cryptographically relevant quantum computer) has a 41% chance of existing within the planning horizon (consensus scenario, GRI 2025) — the probability-weighted expected annual loss for the sector is $579K.

•

Migration is already overdue: it should have started by 2025 to keep the selected data class protected through the median CRQC arrival year.

•

62 critical/high-severity quantum threats currently target this industry.

What This Means for Your Business Case

Cost of Inaction

Every year without PQC migration increases your exposure to quantum-enabled attacks. HNDL (Harvest Now, Decrypt Later) means adversaries are already collecting encrypted data that will become readable once quantum computers mature. The longer you wait, the more historical data is at risk.

Value of Early Action

Organizations that adopt PQC early benefit from reduced breach risk, compliance readiness, and crypto agility. The migration cost is a one-time investment; the breach cost savings compound annually. Early movers also gain competitive trust signals and avoid the rush when quantum deadlines approach.

Compliance context: 191 compliance frameworks apply to your industry. Non-compliance penalties amplify breach costs through regulatory fines, audit requirements, and potential loss of operating licenses.

The Other Quantum Risk: Forged Signatures

Everything above models confidentiality risk — data harvested today, decrypted later. Quantum computing threatens a second, independent property: authenticity. Once a CRQC can break a signature scheme, it can forge NEW signatures going forward — but it cannot forge a signature that was already validly created in the past.

Code & firmware signing

Malicious updates accepted as authentic

Financial transactions

Forged authorization on payments or trades

Document & contract signatures

Repudiation — forged signatures are indistinguishable from real ones

TLS server authentication

Impersonated servers pass certificate validation

Why this splits your migration priority in two:

HNDL — migrate key establishment NOW

Data is being harvested today. Every year of delay adds another year of exposed historical data — there is no "catching up" later.

Forgery — migrate signatures by CRQC-day

Not retroactive — only NEW signatures after a CRQC exists are at risk. Still urgent, but the deadline is the CRQC arrival date itself, not today.

This split is exactly what the US federal PQC executive order encodes: key-establishment migration by 2030, digital-signature migration by 2031 (Executive Order 14412, June 2026).

Deliberately qualitative — no dollar figure is modeled here pending a citable fraud-loss baseline for forged-signature incidents.

Breach Scenario — Export

Export the breach scenario as markdown, PDF, or DOCX — also saved to your Command Center Risk Artifacts.

How this number is built

1. Cost of one breach today (SLE). The industry-average total breach cost from IBM's Cost of a Data Breach Report 2025, multiplied by your severity setting. IBM's figure already includes detection, notification, lost business and reputational damage, so no separate reputational term is added on top — that would double-count. The per-sector IBM figures are cited but unverified: the report is registration-walled, so only its landing page has been read. When the two other financial sources behind this suite were opened in full, three of their five figures turned out to be wrong — treat these as an assumption, not a sourced baseline.

2. How much of the harvested corpus still matters. Freshness is integrated across data aged 0 to 5 years against the general customer/employee pii shelf life of 10 years. Old data contributes less; a corpus older than its shelf life saturates rather than dropping to zero, because its freshest layer always still counts.

3. Quantum amplification. Those freshness-weighted years times your HNDL exposure setting, damped so it approaches but never reaches 5× the classical breach. The damping is smooth, not a hard ceiling — a hard one erased all difference between high-exposure profiles.

4. Weighting by whether a CRQC exists at all. Steps 1–3 give the cost if a machine capable of breaking today's keys exists. The expected annual loss blends that against the no-CRQC case using the GRI 2025 survey's arrival curve — currently a 41% chance within your planning horizon.

5. Present value. Summed year by year, each year carrying its own cumulative arrival probability, then discounted. Not one horizon-wide probability applied flatly to every year — that charges year one for a risk it does not yet carry.

Shelf-life figures are labelled assumptions rather than cited standards for four of the five data classes. The arrival curve is one expert survey, not a forecast. Treat the output as a structured argument, not a measurement.

Try it

Set Years of Stored Data to 10 and migration time to 3 years. What does the Mosca verdict compare?

Next step

Next in Risk & Strategy: Cost of Inaction Analyzer

Cost of Inaction Analyzer is the next Risk & Strategy tool in the Command Center.