Not all data has the same lifetime.
Some information loses value quickly. A temporary schedule, a routine notification or a short-lived operational message may only need protection for a limited period.
Other information remains sensitive for years.
In space research, this can include technical documentation, research outputs, system designs, software details, partner communications, infrastructure information, operational procedures and strategic project data. The value of this information may not disappear once a project milestone is reached. In many cases, it can remain important across future research, technology development, industrial cooperation or public-sector planning.
That changes how security should be designed.
If data needs to remain confidential for a long time, it is not enough to protect it only against today's threats. Organisations must also consider whether the protection applied today will still be adequate in the future.
This is one of the reasons post-quantum security has become a practical concern.
Harvest now, decrypt later
A major risk often discussed in the context of quantum computing is "harvest now, decrypt later". The concept is straightforward: an attacker may capture encrypted information today, store it, and attempt to decrypt it in the future when more powerful technologies become available.
The attacker does not need to break the encryption immediately. They only need the data to remain valuable long enough for future decryption to matter.
For many everyday communications, this may not be a major concern. For sensitive research data, technical designs, government-related information, critical infrastructure documentation or strategic technology development, the confidentiality period can be much longer.
Space research belongs firmly in this category.
Projects often involve advanced technologies, specialised infrastructure, international collaboration and data that may support future missions, systems or capabilities. Some information may also be connected to broader economic, scientific or security interests. Protecting it requires a view of risk that extends beyond the current year.
Classification and data lifecycle
Long-term confidentiality begins with classification.
Organisations need to identify which data has lasting sensitivity. This is not always obvious. A single document may seem harmless on its own but become sensitive when combined with other information. Metadata, system diagrams, test results, configuration details or internal communications can reveal more than intended.
Classification should therefore consider context, not only content.
Useful questions include: how long should this information remain confidential? Who would benefit from accessing it? Could it expose systems, partners or future work? Would disclosure affect trust, competitiveness, safety, security or research integrity? Does it relate to infrastructure or technology with a long lifecycle?
The answers help determine the level of protection required.
The next step is to understand where the data travels.
Long-term confidentiality is not only about storage. Sensitive data may move through email, file-sharing platforms, APIs, research networks, cloud environments, backup systems, collaboration tools and partner communication channels. It may be processed by software, copied into logs, stored in archives or shared with suppliers.
Every movement creates exposure.
A secure communication strategy must therefore look at the full lifecycle of the data: creation, transmission, processing, storage, sharing, backup, archiving and deletion. Protecting one part of the path while ignoring another can leave the wider environment vulnerable.
Encryption, key management and crypto-agility
Encryption remains essential, but it must be supported by good key management.
Data encrypted with poorly managed keys is not truly protected. Keys must be generated securely, stored appropriately, rotated when needed, revoked when trust is lost and protected from unauthorised access. For long-term confidentiality, organisations also need to consider whether the cryptographic mechanisms in use today will remain suitable over the required protection period.
This is where crypto-agility becomes important.
A system that can adapt its cryptography over time gives organisations more control. If standards change, vulnerabilities are discovered or post-quantum migration becomes necessary, crypto-agile systems can be updated more effectively. Systems that are rigid or poorly documented are harder to protect over long periods.
For space research, this matters because technology lifecycles can be long. Infrastructure, data archives and collaboration frameworks may remain in use well beyond their original design assumptions. Security decisions made today can shape risk for years.
Access control, monitoring and archives
Long-term confidentiality also depends on access control.
Sensitive information should not be broadly available simply because it belongs to a project. Access should be based on need, role and responsibility. Privileged access should be reviewed. External sharing should be governed. Partner access should be documented. Departing users should be removed promptly. Service accounts should not become uncontrolled back doors into long-lived data.
The longer data remains sensitive, the more important these controls become.
Monitoring and auditability are also required.
Organisations should know when sensitive data is accessed, transferred, modified or shared. This does not mean creating unnecessary surveillance or operational burden. It means having enough visibility to detect misuse, investigate incidents and demonstrate that sensitive information is being handled responsibly.
For multi-partner research environments, this visibility should be agreed carefully. Partners need trust, but they also need clarity about accountability.
Backups and archives deserve particular attention.
Archived information is sometimes treated as inactive and therefore lower risk. In reality, archives may contain some of the most sensitive long-term data in an organisation. Backups can also create hidden exposure if they are poorly protected, retained for too long, stored in multiple locations or encrypted with outdated mechanisms.
Long-term confidentiality planning should include backup encryption, key management, retention rules, access control and recovery procedures.
The same applies to logs and metadata.
Communication systems often generate logs that may include addresses, identifiers, timing information, system names, error messages or operational patterns. Even when message content is protected, metadata may reveal relationships, workflows or infrastructure details. For sensitive environments, metadata should be handled with care.
Suppliers and the post-quantum transition
Supplier and partner dependencies must also be considered.
If sensitive data is shared with external systems or processed by third-party platforms, long-term confidentiality depends partly on their controls. Organisations should understand where data is stored, how it is encrypted, who can access it, how long it is retained, how it is backed up and what happens when the partnership or service ends.
Contractual terms and technical controls should match the sensitivity of the data.
The post-quantum transition adds another layer to this planning.
Organisations should identify which long-lived data is currently protected by cryptographic mechanisms that may need to change. They should prioritise communication paths and archives where confidentiality requirements extend far into the future. They should engage suppliers about post-quantum roadmaps. And they should avoid designing new systems that are difficult to upgrade.
This does not mean every system must be transformed immediately. It means organisations should understand the risk and build a realistic migration path.
The COSMOS-SECURE perspective
COSMOS-SECURE is focused on secure communication in space research with precisely this long-term perspective. The project recognises that protecting communication today is not enough if the information remains valuable tomorrow.
Future-ready security must account for the lifetime of the data.
For organisations involved in space research, the practical starting point is clear.
Identify data with long-term confidentiality requirements. Map where it is transmitted, stored and shared. Review the cryptographic mechanisms protecting it. Strengthen key management. Limit access. Protect backups and archives. Assess supplier dependencies. Build crypto-agility into communication systems. Include post-quantum readiness in security planning.
Long-term confidentiality is not a single control.
It is a discipline that combines architecture, governance, cryptography, operations and partnership management.
Space research depends on the ability to cooperate securely over time. That cooperation requires confidence that sensitive information will remain protected not only during active work, but also years into the future.
Today's communication systems must therefore be designed with tomorrow's risks in mind.