August 27, 2026
The Perfect (Outsider) Trade
Every public company has a small, well-known list of people who are not allowed to trade before certain dates. The CEO. The CFO. The board. Outside counsel. It's a list built on the assumption that if you keep material, nonpublic information inside a small, trusted circle, you've contained the risk.
That assumption depends on one thing: the information actually staying inside the device of the person who's allowed to have it. Increasingly, it doesn't.
A board pack, a phone, and an airport
Board materials today move through portal apps on personal tablets, laptops and smartphones - M&A terms, earnings ahead of the release date, restructuring plans, sometimes days before the meeting itself so directors can prepare questions. The distribution is convenient and increasingly standard practice.
It's also increasingly exposed. A director travels to a board meeting or a conference. Their device sits on an open hotel or airport network, or crosses a border where customs authorities can lawfully image a phone without a warrant. Either way, an adversary within range, or with checkpoint access, can replicate/copy the device's encrypted data without the director ever knowing it happened.
They don't need to break the encryption that day. They just need the copy. That's the entire premise of harvest-now-decrypt-later (HNDL): store the ciphertext, wait for the tools to catch up, decrypt later at their convenience. And later is not far from today.
Insider trading, without an insider
Here's where it gets uncomfortable. Every person legally entitled to that pre-announcement information is barred from trading on it. But the adversary who quietly copied it off a director's device was never on the restricted list, never signed a blackout agreement, and never touched an email server or an internal network that anyone monitors.
When the encryption eventually falls, through cryptanalytic progress, a leaked key, or simply enough compute, they have clean, dated, material nonpublic information and no restriction on using it. They trade. There is no tip-off to trace, no insider to name, no compliance log that shows anything happened. The compromise occurred at the device layer, long before the trade, far from the systems anyone was watching.
Regulators built insider trading enforcement around a network of relationships and disclosures. This attack doesn't touch that network at all.
Why this isn't a future problem
It's tempting to file this under quantum computing and worry about it later. That's a mistake, for two reasons.
First, the harvesting is happening today, on today's infrastructure, regardless of when decryption becomes economically feasible. Every board meeting, every conference, every border crossing is a collection opportunity that doesn't wait for the threat model to mature.
Second, the decryption timeline is compressing. AI-assisted vulnerability research and exploit generation are shortening the distance between “theoretically breakable” and “actually broken” faster than most governance conversations have caught up to. The management assumption behind “we'll deal with this later” was built for a slower adversary than the one that now exists.
The fix isn't better encryption. It's not having the data there at all.
The standard response to this threat is to harden the endpoint; stronger containers, better key management, more aggressive remote wipe, etc. All of that assumes the board pack has to live on the device in the first place. It doesn't and it shouldn’t.
With a mobile isolation model, board materials never leave the server. The director's device renders a pixel stream - nothing cached, nothing synced, nothing to image at a border crossing or copy over an airport, hotel, Starbucks network. If a device is lost, searched, or compromised outright, there's no archive sitting on it waiting for a future key. The session ends; the data was never there to begin with.
That's not a marginally better version of encryption. It's a different premise; one where the sensitive information stays exactly where the company's own trading policy assumed it would: with the people who are actually accountable for it.
The companies that get ahead of this won't be the ones with the strictest blackout calendars. They'll be the ones that stopped assuming the device in a director's pocket was ever a safe place for the information to sit.
Recent articles
Security
August 20, 2026
Filed First, Invented Second
A researcher's laptop doesn't need to be hacked to leak a breakthrough. It just needs to be copied on a conference WiFi or imaged at a border crossing, then decrypted years down the line, by whoever files the patent first.
Security
August 18, 2026
The Signal Paradox
Signalgate exposed a real problem: audit and access control aren't the same thing. Here's how regulated organizations should think about secure messaging.
Security
August 13, 2026
If You're Not First, You're Last
Your endpoint security is running on a Talladega Nights quote.
