Most Internet-Facing Systems Unprepared for Quantum Cryptography Threats
Despite growing awareness of quantum computing risks, nearly 90% of SSH servers globally remain vulnerable to future quantum-enabled attacks due to slow adoption of post-quantum cryptography (PQC) standards. The root cause lies in inadequate vulnerability management and configuration practices — organizations lack full visibility into their cryptographic asset inventories, making it impossible to prioritize or plan migration effectively. This matters because adversaries may already be harvesting encrypted data today using 'harvest now, decrypt later' strategies, meaning the window to act is shorter than most assume. The uneven progress across IT and cyber-physical systems further amplifies risk, as legacy operational technology (OT) environments are notoriously difficult to update. A structured, multi-year migration plan backed by rigorous asset discovery is urgently needed.
Tactical Insight
Immediate actions
- Conduct a full cryptographic inventory to identify all systems relying on quantum-vulnerable algorithms (e.g., RSA, ECC, classic Diffie-Hellman).
- Prioritize internet-facing SSH servers and VPN gateways for PQC-readiness assessment and expedited upgrade planning.
Long-term improvements
- Develop and execute a phased post-quantum cryptography migration roadmap aligned with NIST PQC standards (FIPS 203, 204, 205).
- Establish a crypto-agility framework so cryptographic algorithms can be swapped without requiring full system redesigns.
- Maintain a continuously updated asset inventory that tracks cryptographic dependencies across IT, OT, and cyber-physical systems.
Detection & monitoring measures
- Deploy network monitoring tools capable of identifying deprecated or quantum-vulnerable cipher suites in active use.
- Integrate cryptographic posture checks into regular vulnerability scanning workflows and report findings to executive leadership.