Growing PQC at the edge belies deeper quantum-readiness challenges
Summary
While a majority of top websites now support post-quantum key exchange, this progress is largely driven by CDN providers enabling the feature by default rather than organizations upgrading their internal infrastructure. This means that many enterprises may still be vulnerable to harvest now, decrypt later attacks on their internal connections.
IFF Assessment
The article highlights that current 'post-quantum readiness' is superficial, with internal infrastructure remaining vulnerable to future quantum attacks.
Defender Context
Organizations need to look beyond superficial PQC adoption at the network edge and focus on upgrading their entire technology stack, including internal systems and applications. Defenders should prioritize inventorying and securing all cryptographic elements, especially those handling sensitive data, to prepare for the eventual threat posed by quantum computing.