{"id":9959,"date":"2026-10-08T19:05:00","date_gmt":"2026-10-08T19:05:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9959"},"modified":"2026-10-08T19:05:00","modified_gmt":"2026-10-08T19:05:00","slug":"growing-pqc-at-the-edge-belies-deeper-quantum-readiness-challenges","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9959","title":{"rendered":"Growing PQC at the edge belies deeper quantum-readiness challenges"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column \">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">The quantum threat is becoming an increasing concern for security leaders, but many may be mistaking protection at their website\u2019s front door for quantum readiness across their business.<\/p>\n<p class=\"wp-block-paragraph\">More than half (54%) of the world\u2019s top 1 million websites now support <a href=\"https:\/\/www.csoonline.com\/article\/654887\/11-notable-post-quantum-cryptography-initiatives-launched-in-2023.html\">post-quantum<\/a> key exchange, according to research from F5 Labs, an encouraging statistic given that just 27% of CISOs in a June <a href=\"https:\/\/kpmg.com\/us\/en\/articles\/2026\/cybersecurity-technology-risk-survey-ciso-resilience.html\">KPMG survey<\/a> said they are actively implementing post-quantum cryptography (PQC).<\/p>\n<p class=\"wp-block-paragraph\">But F5 Labs\u2019 <a href=\"https:\/\/www.f5.com\/labs\/articles\/2026-state-of-pqc-on-the-web\">State of PQC on the Web<\/a> study found that much of that apparent progress comes from content delivery network (CDN) providers switching on protection, rather than organizations upgrading their own infrastructure for what 38% of CISOs see as top high-impact emerging threat, according to KPMG\u2019s survey.<\/p>\n<p class=\"wp-block-paragraph\">\u201c54% sounds like we\u2019re halfway to a quantum-safe web, but we need to be clear about what we\u2019re measuring,\u201d says David Warburton, director of F5 Labs. \u201cMuch of that support comes from CDN providers switching PQC on by default. Remove Cloudflare-hosted sites and the figure drops to 22%.\u201d<\/p>\n<p class=\"wp-block-paragraph\">F5 Labs looked only at the website\u2019s front end without accessing an enterprise\u2019s application servers behind the CDN \u2014 for example, Akamai, Cloudflare, Amazon CloudFront \u2014 or determining whether their internal traffic uses PQC.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThose internal connections could potentially be an even bigger target for harvest now, decrypt later attacks,\u201d Warburton says.<\/p>\n<p class=\"wp-block-paragraph\">Or as Serhii Nikolaichuk, founder of The Capital Index, an engineering firm that builds attestation systems, puts it, everything behind what the CDNs have turned on, \u201cthe hop to the origin, service meshes, VPNs, SSH, and code signing, is invisible from outside, and that\u2019s where enterprise readiness actually lives.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Beyond the edge<\/h2>\n<p class=\"wp-block-paragraph\">Independent experts back F5 Labs\u2019 broad conclusions, warning that true post-quantum readiness requires upgrading every layer in the technology stack.<\/p>\n<p class=\"wp-block-paragraph\">Edge adoption is meaningful progress, but it is not a reliable measure of enterprise readiness, according to Anastazija Pa\u017ein, senior cybersecurity consultant at management consultancy Deloitte.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCDN-enabled PQC provides genuine protection for the client-to-edge connection,\u201d says Pa\u017ein. \u201cThe limitation is that this protection does not automatically extend to the origin server, internal APIs, service-to-service communications, or enterprise PKI.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Post-quantum adoption is moving fastest where it can be enabled centrally, and one reason for this mismatch is that implementation guidance has only recently started to catch up with the core standards, says Ben Packman, chief strategy officer at PQC specialists PQShield.<\/p>\n<p class=\"wp-block-paragraph\">\u201cNIST finalized its first PQC standards in 2024 while the IETF, for example, only published the standard defining hybrid post-quantum key exchange mechanisms for <a href=\"https:\/\/www.csoonline.com\/article\/564852\/security-vs-visibility-why-tls-13-has-data-center-admins-worried.html\">TLS 1.3<\/a> in August this year,\u201d says Packman.<\/p>\n<h2 class=\"wp-block-heading\">Technical debt<\/h2>\n<p class=\"wp-block-paragraph\">Reliance on legacy technologies combined with other dependencies mean that the quantum cryptography upgrade path is far from trivial.<\/p>\n<p class=\"wp-block-paragraph\">Organizations have older clients, partner integrations, and change-control processes that make it difficult to upgrade everything quickly. Many vendors haven\u2019t yet updated their products to support PQC, either.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe 54% figure measures PQC key exchange support. PQC certificates aren\u2019t yet available for the public internet,\u201d notes Warburton. \u201c<a href=\"https:\/\/www.ietf.org\/archive\/id\/draft-ietf-plants-merkle-tree-certs-03.html\">Merkle Tree Certificates<\/a> should help desktop and mobile browsers, but plenty of other environments will need PQC certificates, and their much larger size will cause problems.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Certificate management also represents a technology obstacle.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you\u2019re still provisioning certificates manually, you\u2019re going to face serious challenges when <a href=\"https:\/\/www.csoonline.com\/article\/4097721\/how-cisos-can-prepare-for-the-new-era-of-short-lived-tls-certificates.html\">47-day certificate lifetimes<\/a> are enforced,\u201d Warburton concludes.<\/p>\n<p class=\"wp-block-paragraph\">The PQC-readiness gap is particularly striking in sectors handling sensitive, long-lived data. For example, only 35% of government and telecommunications websites in the study supported post-quantum key exchange.<\/p>\n<h2 class=\"wp-block-heading\">Industry differences<\/h2>\n<p class=\"wp-block-paragraph\">Government and critical infrastructure organizations tend to have more long-lived operational technology, self-hosted systems, and slower procurement cycles, creating additional challenges for quantum readiness.<\/p>\n<p class=\"wp-block-paragraph\">Across F5 Labs\u2019 wider sample, more than one in 10 responding websites still lacked support for TLS 1.3 \u2014 a prerequisite for the post-quantum key exchanges that F5 tested.<\/p>\n<p class=\"wp-block-paragraph\">F5 argues that while protection at a website\u2019s public edge is a valuable step it fails to establish whether an organization\u2019s servers and internal applications are quantum ready.<\/p>\n<p class=\"wp-block-paragraph\">However, Chris Hickman, CSO at digital trust infrastructure vendor Keyfactor, says that F5\u2019s figures fail to reflect the full scope of PQC preparations.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor example, the leading industries for full PQC readiness include financial, telecommunications, and government, with healthcare starting to accelerate efforts more rapidly,\u201d Hickman says. \u201cAgain, I believe the difference in this result is a web focus versus organizational initiative, of which the web is only one element.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Financial institutions and critical infrastructure operators are increasingly addressing PQC through cryptographic inventories, risk assessments, and migration roadmaps. But planning maturity should not be confused with deployment maturity, Deloitte\u2019s Pa\u017ein says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFinancial institutions face complex dependencies involving HSMs [hardware security modules], payment infrastructure, PKI, and third-party services,\u201d says Pa\u017ein. \u201cTelecommunications providers must consider large-scale network infrastructure and interoperability. Industrial environments introduce additional challenges through long-lived operational technology, constrained devices, and limited opportunities for disruptive upgrades.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Pa\u017ein adds: \u201cConsequently, organizations with relatively mature cybersecurity governance can still face substantial implementation challenges.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Preparing for PQC<\/h2>\n<p class=\"wp-block-paragraph\">Organizations should embark on their upgrade path to PQC by first carrying out an inventory of their existing use of cryptography, prioritizing data that must remain confidential for years, and planning upgrades to the systems that will take longest to change.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat means looking beyond your public website to internal applications, APIs, VPNs, identity systems, and embedded libraries,\u201d F5 Labs\u2019 Warburton advises. \u201cBuild a cryptographic bill of materials and make sure someone owns the process of keeping it up to date.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Enterprises should proceed by removing legacy dependencies, enable hybrid PQC where they can, and automate certificate management. \u201cYou need to be able to change algorithms and certificates without turning every update into a major infrastructure project,\u201d Warburton adds.<\/p>\n<p class=\"wp-block-paragraph\">Deloitte\u2019s Pa\u017ein concludes: \u201cMeaningful enterprise readiness assessment should examine whether an organization understands its cryptographic dependencies, has prioritized assets according to quantum-related risk, and can replace vulnerable algorithms without major architectural disruption.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The quantum threat is becoming an increasing concern for security leaders, but many may be mistaking protection at their website\u2019s front door for quantum readiness across their business. More than half (54%) of the world\u2019s top 1 million websites now support post-quantum key exchange, according to research from F5 Labs, an encouraging statistic given that [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9960,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9959","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9959"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9959"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9959\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9960"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9959"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9959"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}