Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Beneath the quantum hype: how to build cryptographic resilience (Page 5)
Cyber resilience

Beneath the quantum hype: how to build cryptographic resilience

Quantum is coming - but not everything you encrypt today will still matter tomorrow. Rik Ferguson explains where to focus and how to build cryptographic resilience that lasts.
October 22, 20257 Mins Read
Post-Quantum Cryptography - a digital padlock with a quantum sigil on the front.

There is a lot of noise around post-quantum cryptography, or PQC; and with noise comes confusion. Confusion often leads enterprises to either panic prematurely or procrastinate dangerously. So, let’s get one thing straight: the risk is real. But the way we talk about it – and more importantly, the way we act on it – needs a course correction.

The risk is real, but it’s not uniform

Yes, state-driven attackers are already harvesting encrypted traffic in bulk in what is known as harvest now, decrypt later (HNDL) tactics. The objective is simple: crack it open later, once quantum computing can break today’s public-key cryptography. This is not science fiction; it’s espionage in slow motion. But that doesn’t mean every encrypted packet you send today is a ticking time bomb.

We need to ask a basic question: will the data still matter by the time it is decrypted?

For most transient data, such as web traffic, session tokens, or authentication credentials, the risk from future decryption is minimal. These artefacts are typically short-lived. Even if a state-driven actor captures and decrypts them years from now, they are likely to have already expired. Their value is time-bound – or it should be.

If that’s not true – if an environment allows static credentials, long-lived sessions, or unmanaged tokens – then it has already lost the security battle, regardless of the algorithm in play. That is not a cryptographic failure; it’s a procedural failure. The root cause is operational, not mathematical. The remedy is rotation, expiry enforcement, and access discipline. These are hygiene issues, not quantum ones.

On the other hand, data at rest is different. Intellectual property, financial transactions, legal documents, and sensitive healthcare records can retain value for years. That’s what makes them a prime target for harvest-now, decrypt-later operations. This is where the post-quantum conversation needs to be anchored.

Visibility first, always

Before any migration to PQ-safe algorithms begins, enterprises must gain clear visibility. The ability to detect and assess quantum-unsafe cryptography across the network provides what many organizations currently lack: real-time, asset-level insight.

You cannot govern what you cannot see. And you cannot prioritise without context. For instance, a TLS 1.2 handshake using RSA-2048 might look dangerous, but if it’s protecting short-lived traffic in a hardened enclave, it’s a red herring. Conversely, an outdated FTP server quietly archiving merger documents is a strategic liability.

That context – knowing where cryptographic risk resides and what it protects – is everything. Scanning for unsafe algorithms is not about panic; it is about mapping your exposure with clarity. This is where the security conversation must mature. Detection reveals risk. Governance owns it. Without process discipline, crypto hygiene, and lifecycle control, visibility becomes just another dashboard. With them, it becomes a force multiplier.

Recent Forescout research paints a picture of just how uneven that visibility still is.

Support for post-quantum cryptography in SSH servers, for example, is growing but slowly. Only 8.5% of all SSH servers currently support PQC, rising to 26% among OpenSSH deployments. TLS 1.3 adoption, which enables PQC, has stagnated at 19%, while reliance on TLS 1.2 (which does not support PQC) has actually increased from 43% to 46%.

This signals that unmanaged and legacy devices are being left behind. IoT, OT, IoMT, and network equipment lag significantly behind traditional IT assets in PQC adoption. The result is a fragmented cryptographic landscape and a growing visibility gap between managed and unmanaged assets.

Contextual risk management beats cryptographic panic

Let’s not pretend that PQC is a silver bullet, and let’s not pretend adopting it is trivial. The transition will be long, complex, and filled with false starts. It will demand crypto agility, disciplined key lifecycle management, and architectural flexibility. That means updating libraries, enabling algorithm negotiation, auditing dependencies, and preparing systems to swap cryptographic modules as standards evolve.

But technology alone won’t solve this. Most enterprise risk still stems from poor inventory, stale secrets, and lack of cryptographic accountability. That is a governance issue, not a maths problem.

Industry data shows how uneven the journey already is. Sectors dominated by unmanaged or embedded devices – for example, manufacturing, oil and gas, and mining – show the lowest PQC adoption rates. In contrast, professional and business services are leading the way. The takeaway is clear: PQC migration is not a technology race; it’s an asset management challenge.

A pragmatic strategy includes:

  • Classify data by longevity and sensitivity: if it won’t matter in 12 months, you’re fine. If it will matter in 12 years, you are not.
  • Audit where and how that data is stored: don’t limit yourself to the cloud. Look in backups, archives, endpoint storage, and shadow IT.
  • Instrument your infrastructure: use a trusted solution to detect legacy cryptography, flag downgrade risks, and map exposure across your environment.
  • Design for agility: build key rotation and algorithm swapping into your newly deployed cryptographic frameworks from day one.
  • Embed governance: document key ownership, set expiry dates for encryption, use envelope encryption where appropriate, and educate teams on what ‘quantum-safe’ actually means.

Quantum-safe does not mean quantum-proof; it means ‘resistant to known attack vectors as best understood today.’ That definition will evolve. The crypto stack must be able to evolve with it.

The real value of detection

There is a critical shift happening in enterprise cybersecurity. We are moving from static, compliance-based control models to dynamic, contextual risk awareness. Visibility is less about box-ticking and more about enabling the right decisions. Knowing where weak cryptography resides tells you where outdated policies live. Knowing what cryptography protects tells you what is truly at risk.

Detection, in this case, is diagnostic. It reveals how much control there really is. If you don’t know which algorithms are running in your environment, you’re not managing encryption; you’re assuming it.

The ability to map unsafe cryptographic usage across IT, OT, and IoT gives security leaders a baseline they can act on – not only for monitoring but for planning, prioritising, and building the roadmap to quantum readiness. That is what separates visibility from actionable intelligence.

Fix what matters first

Security leaders have seen this movie before. We’ve lived through the rush to zero trust, the buzz around blockchain, and the noise about AI in cybersecurity. In some cases, we’ve even lived through Y2K compliance! Each time, there has been a need to cut through the buzz and focus on what actually moves the needle. Post-quantum is no different; the stakes may be higher, but the principle is the same.

Success doesn’t start with algorithms. It starts with assets, with process, with context. Ask the right questions: what data matters, who can access it, how is it protected, how often are protections renewed, who is accountable?

If you can answer those, you’re already ahead. If you can’t, your first step isn’t post-quantum migration – it’s regaining control of what you already have.

Start by educating your teams on NIST’s ‘Migration to PQC’ guidelines, which map directly to CSF 2.0 and NIST SP 800-53. Build and maintain an inventory of assets that do or do not support PQC, and correlate that with contextual data about sensitivity and exposure.

The path to resilience begins with awareness and ends with disciplined execution. Quantum may be the catalyst, but resilience will come from visibility, governance, and disciplined execution.

The author

Rik Ferguson is VP Security Intelligence, Forescout

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleOperational resilience in retail: why consumables management is a key area
Next Article Beyond awareness: engineering resilience against Shadow AI

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A digital twin test bay showing a large screen displaying a virtual boiler model synchronised with the physical unit during operational testing.

International cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis

July 29, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?