Privileged, Confidential, and Already Readable: What Quantum Means for Law Firms
- Patrick Bryden
- 7 hours ago
- 5 min read
A law firm's most sensitive files are more exposed than most employees realize. Not in some distant scenario, but right now, in the ordinary course of business, most are likely accessible to bad actors today. A firm's most sensitive deal documents, litigation strategy, and client intellectual property are stored in plain, readable form in its document systems and email, available to anyone who gets past the security perimeter.

With the advent of quantum computing, this risk is accelerating and bringing it front and center in the boardroom. Headlines warn that powerful new machines will one day break the encryption that businesses rely on. That threat is real, and the timeline is getting shorter, but it pulls attention toward a distant problem and away from a closer one. Before anyone needs a quantum computer to unlock a stolen file, they can often just read it, because the file was never truly locked in the first place.
Why This Lands on Legal Before Most Industries
Law firms are keepers of other people's secrets. It's one of their main value propositions. A firm can hold M&A terms before they are public, litigation posture before it is filed, and patent applications before they are granted, as well as regulated client data across finance, healthcare, and energy. And of all the information, the most important perhaps is that much of it carries a relevance window measured in decades, not news cycles.
That combination, information that is highly sensitive, long-lived, concentrated in one place, is exactly what "harvest now, decrypt later" (HNDL) targets. The idea is simple: bad actors steal data today, store it, and wait for quantum computers powerful enough to crack it open later. Nation-state actors are documented doing this against secrets with decades of shelf life, and Google named the same threat when it accelerated its own move to quantum-resistant encryption.
Two developments in early 2026 shortened the runway and brought the risk even closer. Google moved up its own deadline for switching to quantum-resistant encryption to 2029. Days later, researchers at Caltech showed that breaking today's encryption may require far less computing power than experts had assumed — the estimated horsepower needed has dropped roughly ten-thousand-fold over the past two decades, and it keeps falling. The U.S. government, meanwhile, has finalized the new encryption standards firms will eventually adopt and set a 2035 deadline for its own systems.
The Threat Most Firms Miss: Harvest Now, Read Now
Now for the part that the quantum conversation buries. At most firms, the everyday protection around a sensitive document isn't on the document at all — it's the perimeter around it: access controls, network boundaries, folder permissions. All of it rests on one assumption — that once someone is inside the boundary, they can be trusted with what's there.
That assumption breaks constantly.
This can take the form of a compromised credential, a misrouted email, an over-permissioned integration, a departing associate with a synced drive, or an AI tool indexing a matter folder — none of these require a quantum computer. They require getting inside once. When the boundary is the only defense and the file beneath it is unencrypted, an intruder (or a wayward AI tool) can read everything the moment they arrive.
Most organizations assume encryption solves this, and they would be forgiven for thinking so. The encryption most firms use solves a different problem: it protects the data while it sits in storage, then decrypts the file whenever someone needs to open it. The protection stops exactly where the risk begins. Every safeguard so far — the boundary, the network, the storage — guards the space around the document, not the document itself. That is the line between perimeter-based security and data-centric security: one protects where the file lives, the other protects the file. The latter is critical for data security in 2026.
Legal AI adoption is starting to magnify all of this. Copilots and matter-aware assistants do not just move documents: they ingest, summarize, correlate, and act on them across systems. Every new tool is another opportunity for privileged information to surface in a summary or an answer it should never have reached, reaching past the firm's walls at scale, pulling from documents that were only ever guarded by those who could open the folder. If the underlying documents remain broadly readable, AI amplifies exposure at the same rate it amplifies productivity.
What is the difference between "harvest now, decrypt later" and "harvest now, read now"? Harvest now, decrypt later assumes data is encrypted, so adversaries steal it and wait for quantum computers to unlock it. Harvest now, read now describes the more common reality: sensitive files that were never encrypted at the content layer, so an intruder past the perimeter can read them immediately. No quantum computer required.
What This Means for Firm Leadership
For a managing partner or general counsel, this should no longer be treated as an IT line item — it sits front and center with firm leadership. At Confidencial, we call this the Trust Premium: the reason clients entrust a firm with their most sensitive matters instead of keeping them in-house. That premium rests on a promise — that the firm's most sensitive matters stay confidential and its data is handled with care. A perimeter alone cannot keep that promise.
Protecting that premium doesn't mean waiting for the quantum problem to be solved. There are really two clocks running. One is the multi-year effort to make the firm's core systems quantum-resistant; the other is the exposure that exists today, well before any quantum computer arrives. The move is to treat them separately. The systems overhaul starts with taking inventory: know what sensitive data the firm holds, where it lives, and which matters carry the longest confidentiality window. Protecting the documents directly is available now and does not depend on that program finishing.
When do law firms actually need to act on post-quantum cryptography? Now — but not the way most vendors frame it. Overhauling a firm's core technology systems to be quantum-resistant is a five-to-ten-year project, so the planning starts today even though the machines themselves are years away. Protecting the documents directly is different: it can be done immediately, and it does not have to wait for that larger overhaul to finish.
The distinction matters most at the firm's edge. Inside the firm, encryption bound to the data is the last line of defense. Outside it — the moment a file is shared with co-counsel, a client, or a vendor — that same encryption is the first and only one.
How Confidencial Approaches It
Confidencial protects unstructured data, such as documents, files, and AI inputs, with selective encryption that travels with the file. Protection is bound to the content itself, so a privileged document stays encrypted whether it sits in iManage, moves through email, lands in a counterparty's inbox, or reaches an AI pipeline.
If a file is stolen or misrouted, the damage is contained: unauthorized readers get unreadable data, not client secrets. Access can be controlled and revoked after a file has left the firm, and every access leaves an audit trail — the evidence that compliance and risk teams increasingly need to produce on demand. Security teams across North America and firms subject to GLBA, HIPAA, and state privacy regimes use this content-layer approach to close the gap left by the perimeter.
The same logic applies to any professional services firm that holds concentrated, long-lived client secrets — accounting firms with audit workpapers and tax positions, advisory firms with deal data.
The vertical changes; the exposure does not.
The Question to Bring to Your Next Risk Review
The right question is not only "how do we migrate to post-quantum cryptography?" It is "where is our privileged data readable today, and how do we reduce that exposure at the document itself?" The next time someone says the firm's data is encrypted, press on what that actually means: encrypted where, readable by whom, and secure until when? Start there, and the quantum timeline becomes a planning input instead of a panic.




Comments