Compromise
Insecure storage, excessive access or compromised administrative paths expose key material or operations.
Strong cryptography depends on how keys are generated, protected, used, changed, recovered and retired.
For risk management, the question is not only where keys are stored. It is which keys matter, who is accountable, what depends on them and whether compromise, loss or replacement can be managed without unacceptable impact.
Last reviewed: August 2026
If a key is exposed, lost, misused, unavailable or retained longer than appropriate, the security function it supports may fail even when the algorithm remains strong.
Key-management risk spans confidentiality, integrity and availability: unauthorised decryption, fraudulent signing, service outage, failed recovery and inability to complete required cryptographic change.
A key is a security dependency with a purpose, owner, lifecycle, protection requirement and business consequence if compromised or unavailable.
Insecure storage, excessive access or compromised administrative paths expose key material or operations.
Unavailable keys can make encrypted information or dependent services inaccessible.
No accountable team owns lifecycle or risk decisions.
Keys remain active beyond intended periods or after services change.
Too many identities can retrieve or use sensitive keys.
HSM, KMS, vendor or proprietary formats constrain recovery and migration.
Cryptographic transition can introduce new key types, lifecycle rules, platform capabilities and coordinated replacement requirements.
Quantum readiness therefore depends on key-management services and suppliers being able to support controlled change.