Why is this a bigger problem that just "deploy new encryption keys and revoke the old ones" If that is a big problem, then focus on that because keys can leak in any number of ways and it's something you need to be able to handle. I'd be surprised if they are not routinely rotated fairly frequently regardless.