Interactive supplement

Cost of delay explorer

Ranking classical hacking risk and post-quantum risk on one list, in dollars lost per year of waiting.

Data sent over the internet today can be recorded now and unlocked later, once a quantum computer exists. Whether that matters depends on how long the data must stay secret, whether it can be recorded, and whether a hacker would have taken it first. This page lets you change each of those and watch the ranking move. Every input is explained in the margin as you touch it.

Two clocks, one piece of data

A piece of data is exposed to two threats at once. A hacker might take it, at some unknown moment. A quantum computer might arrive, at some unknown moment. The quantum computer only adds a loss if it arrives while the data still matters and the hacker has not already taken it. The orange area below is that chance.

When a quantum computer arrives
The formula behind the orange area

For an asset, the cost of waiting one more year has a classical part and a quantum part, both in dollars per year:

CoDc=λV

CoDq=rh∫0LfQ(t)e−(λ+ρ)tdt

Here V is the loss if the data is exposed, λ the hacker rate, r = τV the value that newly flows each year (turnover τ), h the share that can be recorded, L the years the data must stay secret, fQ the chance density of the quantum computer arriving, and ρ the discount. The factor e−λt is the chance the hacker has not struck by time t: the race. Everything is proved in the methodology notes.

Choose a system

Four public systems, each described by a short list of kinds of data. The values are assumptions read from public documentation; nobody supplied real figures. You can edit any of them further down.

Assumptions nobody can know for sure

When a quantum computer arrives

0%

The ranking

Assets ranked by cost of delay, with classical cost to the left and quantum cost to the right
RankAssetCost of delay per yearTotalAgainst a hacker-only list

Classical: hackers take the data, to the left. Quantum: recorded now and opened later, to the right. Bars are on a log scale from $1k to $40M; nothing is drawn below $1k. Select an asset's name to see how its numbers were made.

Where the order changes

Nobody knows the date a quantum computer arrives, or the right discount. If the order is the same everywhere below, those guesses do not decide anything. If it changes, that boundary is the uncertainty that matters. Entries that differ from the first row are underlined.

If the inputs are wrong

Every input is a rough band. This re-draws all of them 2,000 times, each within a sensible range, and counts how often each conclusion survives. It runs in your browser and takes a second or two.

How far each input is allowed to wander
InputRange used
Lossup or down by half a band (a factor of about 3)
Hacker rateup to twice or half
Years of secrecyup to 1.5 times or a third shorter
Recordable shareplus or minus 0.1 (a zero stays zero)
Turnover (the weakest input)up to three times or a third
Quantum arrivalthe faster or slower view, equally likely
Discountanywhere from 0% to 7%

These ranges are themselves assumptions. See the statistics notes.

Edit the assets

Each row is a kind of data. Select any field and the margin explains what it means and how to choose. Everything above updates as you type.

Editable list of assets

What this does not show

  • The inputs are assumptions drawn from public documents. No organisation supplied data, and nothing here has been checked against real incidents or migrations.
  • The weakest inputs are turnover and the recordable share. No published source gives them for these systems.
  • The arrival curve is fitted through two published points and extended beyond 15 years, where most long-lived data sits.
  • It scores secrecy only. Data being changed or made unavailable is a different risk.
  • Hackers and quantum computers are assumed to act independently.
  • Being first in this ranking means being first in the model. Use it to see how a ranking behaves, not to set a real budget.

The scoring maths on this page is a JavaScript port of the Python reference implementation and is checked against it on 577 values. It runs entirely in your browser; its code makes no network requests and sends your inputs nowhere.