PQC Intelligence Center

The quantum threat is already reshaping enterprise risk.

We’re here to share our research, intelligence, and real-world data, along with practical guidance to help you identify Post-Quantum Cryptography (PQC) exposures, prioritize risk, and develop a step-by-step transition plan.

Today’s Public Keys Are Tomorrow’s Liability

To establish trust, current encryption technologies like RSA, Elliptic Curve Cryptography, and Diffie Hellman are built on computationally difficult math problems that classic computers can’t break.

One day soon, a sufficiently powerful quantum computer will be able to break the public key encryptions in use today. That milestone, commonly referred to as Q Day, will have significant consequences to network security as we know it.

Read the Countdown to Q Day blog.

See, Understand, Prioritize, Act

Assessing the PQC Problem

To get ready for Q Day, the biggest challenge is to understand where cryptography is used, followed by assessing the impact of replacing it.

The quantum threat touches every organization that handles sensitive data, operates critical infrastructure, or relies on long-lived encryptions.

Industries most at risk

Sector PQC Exposure Risk Key Concern
Government & Defense Critical — hard mandates National secrets with 20+ year sensitivity windows
Healthcare / IoMT Critical — 2% PQC adoption PHI, medical device firmware, patient safety
Manufacturing / OT High — 11% PQC adoption Firmware overhauls required; long equipment cycles
Financial Services High — transaction data Credentials and transactions harvested today
Energy & Utilities High — infrastructure Decades-long equipment cycles; 2030 mandates loom
Enterprise IT Moderate — 42% OpenSSH TLS migration significantly lags SSH adoption

 

Where Things Stand Today

Data from Forescout Research – Vedere Labs based on analysis of more than 186 million SSH servers and global TLS traffic:

Device / Protocol Type PQC Support Notes
IT devices (OpenSSH) 42% Easiest to upgrade; leads all sectors
All SSH servers 8.5% Includes all SSH server types globally
IoT devices 20% 20% of IoT run PQC-capable OpenSSH
OT / network equipment 11% Often exposed online; high-value for attackers
IoMT (medical) devices 2% Lowest adoption; firmware overhauls may be needed
TLS 1.3 traffic (PQC-ready) 19% Only TLS version with PQC algorithm support

To get started with PQC transition, identify core cryptographic vulnerabilities. Then, understand them in context, including IOT and OT networks where risk is concentrated and remediation is slow. Next, define PQC remediation priority for the highest-risk assets. Then, develop a roadmap for replacing the most vulnerable cryptographic systems.

The PQC Lifecycle

See

Find the assets that use PQC-vulnerable protocols like TLS and SSH.

Understand

Understand asset context like location, traffic flow, data sensitivity criticality.

Prioritize

Apply network context to identify and prioritize the risks that matter most.

Act

Systematically reduce exposure thru targeted actions. Repeat.

Current PQC migration roadmaps from governments worldwide mandate transitioning to PQC for critical assets between 2030 and 2035. The migration window is open — but narrowing. And replacing cryptographic systems is slow work.

There are thousands of cryptographic algorithms buried inside firmware, embedded devices, VPN appliances, certificates, databases, authentication systems, applications, and more. Delaying the planning phase increases both cost and risk.

The G7 and NIST have published PQC guidelines and standards that define a starting point along with a roadmap that can help plan your transition to PQC readiness.

G7 and NIST Are Clear: Prepare Now.

Discovery / Inventory

  • Build an inventory of cryptographic algorithms and systems.
  • Identify where non PQC-safe algorithms are used
  • Map this into risk frameworks (CSF 2.0, SP 800 53)

Risk Assessment & Planning

  • Evaluate ALL systems, protocols, and dependencies and classify data by longevity and sensitivity
  • Assess risk and prioritize remediation based on exposure

Migration

  • Tie migration timelines to broader system upgrades
  • Approach PQC as a program, not a one-off project

Continuous Calidation & Monitoring

  • Monitor and validate PQC risk constantly (new assets, configs, traffic)
  • Maintain continuous visibility into cryptographic posture

Forescout’s Patented PQC Detection Technology

Forescout holds a patent for technology that identifies non-PQC-safe algorithms and systems in real time — across managed and unmanaged devices, in IT, OT, IoT, and IoMT environments. Positioned at the network layer, it detects non-PQC-safe algorithms even when devices attempt to hide their identity or posture.

Forescout’s patented technology analyzes the cryptographic algorithms every connected device supports, scores them against post-quantum cryptography safety standards, and surfaces encryption risks across the entire network — regardless of whether a device is managed, unmanaged, compliant, or evasive.

The Forescout Vistaro™ platform delivers a four-pronged quantum-safe strategy:

  • Discover: Patented technology identifies PQC-safe and non-PQC-safe assets in real time, delivering cryptographic posture visibility across hybrid networks.
  • Enforce: Network segmentation isolates critical systems and secure communication pathways.
  • Mitigate: Identify rogue actors or assets and misconfigurations to rapidly target policy enforcement.
  • Create: Workflows that orchestrate remediation.

Building the Business Case for PQC Readiness Investment

Quantum risk won’t be defined by a single breakthrough moment. It will be the cumulative effect of sustained technical progress, investment, and nation-state-level coordination that continues to compress the timeline between the theoretical capability of quantum computers and real-world threat.

The moment a quantum computer can break today’s public key cryptographic systems, the integrity of digital signatures will be at risk. We’re here to help you build your business case for PQC readiness sooner rather than later.

Start with scope and visibility to unlock investment

Start by developing a cryptographic inventory and be prepared for:

  • Unknown dependencies
  • Legacy cryptographic exposure
  • Gaps in vendor and system readiness

These variables make it obvious that it’s going to take time and planning to migrate to quantum-safe cryptographic systems. This can be the the leverage you need to shift PQC readiness from future awareness and concern to an operational priority. It can be helpful to quantify details like:

  • Where does cryptography exist across our environment?
  • Which of these exposures actually matter to the business?
  • What actions reduce risk now, before full PQC migration?
Translate PQC readiness into a defensible PQC business case

Develop a business case that measures PQC readiness by the reduction in cryptographic risk, not just by migration progress.

  • Quantify exposure: where does quantum risk exist today
  • Prioritize action: which risks matter most and why
  • Measure outcomes: how will exposure be reduced over time
Align investment with regulatory accountability

Build your PQC business case with regulatory and standards bodies guidance:

 

Take Control of Your Encryption Risk

Demo RequestVistaro™ PlatformVistaroAI™Top of Page