PQC Business Risk Evaluator
Learned Hand Formula Applied to HNDL and Mosca's Theorem
š Educational Tool ā For informational purposes only
Select an industry scenario to load typical values for that sector, or choose "Custom" to set your own parameters.
1
Mosca's Theorem ā Assess Your Timeline
š Mosca's Quantum Threat Probabilities
Based on Dr. Michele Mosca's 2015 analysis: ~14% probability by 2026 (1 in 7 chance),
~50% by 2031 (1 in 2 chance), with projections of ~70% by 2035 and ~85% by 2040.
Note: These are estimates with significant uncertainty; actual timelines may vary.
ā¦
X = Data Security Requirement
5 years
How long does your sensitive data need to remain confidential?
ā¦
Y = PQC Migration Time
3 years
How long will it take to complete your migration to quantum-safe cryptography?
Combined Timeline (X + Y)
8 years
05101520
X: Data Security Requirement
Y: Migration Time
Quantum Threat Probability
60%
by year 2033
Window End Year
2033
X + Y from now
Migration Planning Recommended
Your combined X+Y timeline suggests moderate risk. Begin planning your PQC migration now.
2
Learned Hand Formula ā Evaluate Investment
āļø The Legal Risk of Post-Quantum Delay
The Learned Hand Formula (from U.S. v. Carroll Towing Co., 1947) states that negligence occurs when
B < PL, where B is the burden (cost) of prevention, P is the probability of harm, and L is the magnitude of loss.
In the context of Post-Quantum Cryptography and the "Harvest Now, Decrypt Later" (HNDL) threat, this means:
if the cost of implementing PQC now is less than the expected loss from quantum decryption (probability Ć damages),
delaying PQC migration could create legal exposure.
ā¦
B = Burden (Cost of PQC Migration)
$500,000
What is the estimated cost of implementing quantum-safe cryptography?
ā¦
L = Loss (Potential Breach Damages)
$15,000,000
What is the potential loss from a quantum-enabled data breach?
<
Expected Loss (P Ć L)
$9M
Probability Ć Potential Loss
Risk/Cost Ratio
18x
Expected loss vs. prevention cost
Higher Risk Profile
Prevention cost (B) is significantly less than expected loss (PĆL). Immediate action is economically and legally justified.
š Learn More: Resources & References
- NIST Post-Quantum Cryptography Project
- NSA's Cybersecurity Advisory (PDF)
- Mosca, M. (2015). "Cybersecurity in an Era with Quantum Computers" ā IEEE Security & Privacy
- United States v. Carroll Towing Co., 159 F.2d 169 (2d Cir. 1947) ā Learned Hand Formula
āļø Legal Disclaimer
This tool is provided for educational and informational purposes only and does not constitute
legal advice, professional consultation, or a guarantee of legal outcomes. Consult with qualified legal counsel
before making decisions based on this analysis. No attorney-client relationship is created by use of this tool.