Preparing for Post Quantum Security With F5 Labs
Tech Talks DailySeptember 02, 2026
3707
25:1823.15 MB

Preparing for Post Quantum Security With F5 Labs

What if your website already supports post-quantum cryptography, but nobody inside your organization knows how, why, or which provider controls it?

I speak with David Warburton, Director of F5 Labs Threat Research, about new F5 research examining post-quantum cryptography across the world's top one million websites. According to the research discussed in our conversation, 54% now support PQC. It is an encouraging sign that preparations for future quantum threats are entering mainstream infrastructure.

That figure is also easy to misread. David explains that much of the adoption comes from cloud and CDN providers enabling hybrid post-quantum protection for their customers. A smaller business could therefore appear better prepared than a large enterprise simply because its provider activated the technology automatically. However, that customer may have little understanding of the chosen cipher, the protection applied elsewhere, or the dependencies created around a small number of technology companies.

David says the adoption rate looks very different when major CDN providers are removed from the data. This raises an important question about whether businesses are developing their own post-quantum security capabilities or temporarily benefiting from decisions made on their behalf.

We discuss why current deployments combine established cryptography with newer post-quantum algorithms. This hybrid approach protects compatibility while browsers, APIs, operational technology, IoT devices, and older enterprise systems catch up. It also carries performance costs through larger cryptographic material and increased network traffic. David argues that crypto agility matters because organizations need the ability to change algorithms, certificates, and encryption methods as threats develop.

The conversation also moves beyond encrypted traffic. Harvest now, decrypt later attacks involve collecting sensitive information today so it can potentially be decrypted when capable quantum computers arrive. David believes authentication and digital identity could create an even greater concern. A quantum computer able to produce valid certificates could potentially impersonate trusted websites, signed software, devices, or firmware.

Legacy infrastructure remains one of the largest barriers. F5 Labs found that roughly one in ten leading websites lacked TLS 1.3 support, preventing them from supporting current hybrid PQC connections. David also explains why Germany and France may trail countries including the US, UK, Australia, Ukraine, and Singapore, despite strong national policies. Factors include digital sovereignty concerns and the concentration of older manufacturing and operational systems.

For leaders beginning this work, David recommends speaking with suppliers, establishing internal ownership, reviewing business continuity plans, and creating a cryptographic bill of materials covering certificates, algorithms, libraries, applications, and devices.

I'd love to hear your thoughts. Does your organization know where its cryptography lives and who controls its post-quantum readiness?

Useful Links

[00:00:04] What if the small business down the road from you is better prepared for quantum attacks than a global corporation, simply because its website provider switched protection on automatically? While F5 Labs found that 54% of the world's top 1 million websites all support post-quantum cryptography, or PQC as it's known in the industry.

[00:00:29] Now that sounds reassuring, but the number hides a very heavy dependence on just a handful of cloud and CDN providers, along with ageing systems that cannot support some of the required protocols. Well my guest today is David Warburton, Director of F5 Labs Threat Research, and he will explain today what Harvest Now decrypt later means, why identity could become the bigger quantum target,

[00:00:58] and how leaders can begin finding every certificate, library and supplier dependency before urgency inevitably turns into panic. Quantum security might sound like science fiction today, but today's conversation will turn it into a practical business question about data, infrastructure and time. But enough from me. Let me introduce you to David right now. So thank you for joining me on the show today, David.

[00:01:27] Can you tell everyone listening a little about who you are and what you do? Absolutely. I'm David Warburton. I'm the Director of F5 Labs Threat Research. We're a small team that primarily performs data science. We look at huge, huge amounts of data sets collected by F5 distributed cloud services, external honeypots around the world, and what we really do is try and dig into the data to try and uncover the attacker trends, see what the bad guys are doing, see how their behaviors are kind of changing. We work with lots of different teams within the company, including product research.

[00:01:56] So that's been a lot of kind of AI research recently as well, and including this proactive TILIA scan looking for PQC deployments that I'm working on at the moment. Well, it's a pleasure to have you join me today. And there's a lot I want to talk about and a lot I want to cover, because if we can't scroll down our news feed, there's a lot of doom scrolling, a lot of bad news about how the bad guys have got the edge. And I don't think we talk enough about some of the great work that's going on. And one of the things that set off my tech spidey senses around you and your work was your research found that

[00:02:25] 54% of the world's top 1 million websites now actually support post-quantum cryptography. And when I read that, I thought, why are we not shouting about this? We all we ever hear is the bad stuff. It sounds like remarkable progress. But do you think we're genuinely starting to get ahead of the quantum threat, or does that headline number hide an even more complicated picture? I'm hoping for some good news. Yeah, I think it's very complicated. And certainly when you dig into the numbers, it does, you know, that headline number does sound very positive and it is positive.

[00:02:54] And like you said, we should absolutely, you know, praise the progress that we've made so far. But it does hide, it does potentially paint a more positive picture than really is the case. I think for a lot of companies, technology providers are switching on PQC by kind of default for their solutions, which is fantastic. But what it really means is that a lot of companies aren't being super proactive in their deployment of PQC. They're just waiting for, say, technology providers to switch it on for them.

[00:03:21] And then you have other complications, things like digital sovereignty with the kind of questions coming on, you know, for many different companies and countries around the world wanting to reduce their reliance on US tech firms. So perhaps they're not quite, they're not adopting PQC as quickly as others. And the other big one I would highlight at the moment at the top of this is that so many people have focused on the immediate threat of Harvest Now, Decrypt Later, which is, to be fair, the more immediate pressing concern, right?

[00:03:47] The idea that a threat actor, whether it's a large nation state in a few years' time or a really well-funded organized crime group that's running perhaps a PQ, a quantum computer as a service, they could collect data now and decrypt in a few years. But when QDay is here, when we finally have quantum cryptographically relevant quantum computers, by far the biggest threat is going to be to authentication and identity. The idea that a quantum computer could create a digital certificate that doesn't just look

[00:04:15] good, it's completely valid and 100% accurate and becomes indistinguishable from, you know, certificates we use on the web to sign code, to sign firmware and so on. And from that point of view, we're far less prepared, I would say, as an industry. Yeah. And if we take a little look under the hood, another fascinating finding is much of the adoption is being driven by cloud and CDN providers that are effectively switching PQC

[00:04:40] on for customers and maybe they're even unaware of it. But could a small business unknowingly maybe better prepared for quantum threats than some of the huge multinationals simply because the infrastructure provider happens to use it and has ticked the boxes for them? Yeah, that's absolutely the case. And that's absolutely what we're seeing in data so far, to be honest with you. Now, being better prepared, a smaller company being better prepared than a larger company, again, there's nuance in the answer. On the face of it, yes, because they rely

[00:05:10] on a CDN whose switches are on and suddenly every website deployed by that CDN or fronted by that CDN is protected by the PQC cipher or algorithm that that CDN provider selects. The problem with that is, though, that that small company doesn't really get a say in which PQC cipher is used or which key strength quite often. They may not know much about why or how it's being used. And it also means that they don't really know how the rest of their infrastructure is protected or not.

[00:05:35] So what we're seeing is actually a huge spike in PQC readiness in. So we scan the top 1 million sites across the web. Now, millions are really big number, you know, without sale when it's state the obvious. But sites between 80,000 and around 220,000 had a massive uptick in PQC readiness. And I think that's the sweet spot for a lot of CDN providers. They kind of capture that that mid, that small to mid kind of enterprise market. So some firms, a lot of companies or domains,

[00:06:05] domain names between, say, one and 80,000 actually, in many cases had a worse adoption. But those companies are more than likely far bigger companies that are being more proactive and looking at the whole PQC projects collectively, looking at not just the front end website, but the back end infrastructure, east west traffic, they're looking at authentication and so on. So yes, absolutely. Some small mid companies on the face of it seem better prepared. But I would say their experience, their knowledge, their preparedness is probably worse than those larger companies.

[00:06:35] And I would imagine that kind of concentration also creates somewhat of an interesting dependency, because if a handful of tech providers are responsible for a large proportion of global PQC adoption, are we solving one security problem while potentially creating another concentration of risk there? I think, I mean, what's interesting is, again, looking at the data that I've got is there's one or two large CDN providers, and you can probably guess who they might be, currently

[00:07:04] really to support the one hybrid PQC cipher, which so far as we know, is fine, it's secure. But what we're seeing is over the past year, a small uptake in a different hybrid PQC cipher, a SEC P256. And that is being only selected by those companies that are being very deliberate and proactive. Now, those companies that rely on the CDNs to enable PQC for them may not get a choice. In fact, when I remove the CDN providers from the data, the data looks almost completely different.

[00:07:34] We jump from a top 54% adoption across the top 1 million. It jumps to 80% in that 20 to 220,000 kind of bucket. But it drops as low as 20%. If I remove those CDN providers, the average across the top 1 million was only 20 to 30%, significantly lower. So it's a huge, huge kind of decline. But as I said, it really means that the people that are relying on those CDN providers are not being proactive, they're not kind of engaging, and sometimes don't have the

[00:08:00] ability to select which ciphers they need. The SEC P256 cipher have seen some adoption. We believe it's because of things like FIPS compliance that kind of mandate certain types of ciphers, certain key sizes. So I would say it's a bit like, and I have to hold my hands up, I'm not a mechanic, I know very little about kind of cars. I'm completely reliant on my mechanic in the garage to kind of fix my car. I know nothing about it, which is great for me. But actually, if I have a problem and the garage is closed, I can't do anything about my car. And it's the same kind of

[00:08:28] problem we've got is it's fantastic to be able to rely on technology providers, CDNs to help deploy things for us. But if we don't invest some of our own time and effort in learning why we need to deploy things and maybe what the right choice is, then I would say that creates a risk in the business. So if almost every PQC enabled website you studied is combining that existing cryptography with post-quantum approaches, while none, interestingly, have moved entirely to PQC or very few,

[00:08:54] why is this hybrid approach currently preferable? And what would need to happen before organisations could more confidently rely just on post-quantum cryptography alone? I suspect we're a long way from that at the moment. I think we are. I think we're a really long way, to be honest with you. And, you know, the hybrid approach we've got at the moment, for those that aren't familiar, the current hybrid PQC adoption across the web is to not have your browsers say to the server, I'll use traditional or classical

[00:09:20] crypto or PQC. I'll use both. So those algorithms are using both at the same time, which has pros and cons. The benefit is you get the dual combined strength of both of those ciphers. So both of those, the hybrid and classical, would need to be cracked for your session to be broken, which is very, very unlikely. But it also means significantly larger key sizes, more, you know, more network and bandwidth traffic. And that provides problems as well. So I think in the top of a million, it averaged

[00:09:47] out to about 0%. We literally saw one or two, maybe a dozen sites that had pure PQC, so that just had MLChem as a kind of encryption cipher, which again, in a million, it averages out to about 0%. But we are so far away because there are so many things that would need to happen to get there. Ultimately, you need, for any two people to have a conversation, we need to talk the same language. It's the same with cryptography. Both parties need to understand the same protocols, need to

[00:10:14] understand the same ciphers and support things. Now, browsers aren't too bad. You know, the likes of Chrome, Firefox Safari, they get updated by the browser developer or publisher, and everyone gets updated very, very quickly afterwards with auto-updates. But that's a far cry from all the devices we have out on the internet, with the business-to-business API calls, IoT devices, OT devices. Many of these older

[00:10:38] or kind of remote devices possibly can't be upgraded or can't be updated easily. So they'll be lagging for a long time. So I think it's going to be likely that we'll need a kind of hybrid approach for a long time. And if you look at a lot of the recommendations from NIST, from ANSI in France, BSI in Germany, everyone's really focusing on this crypto agility. So yes, quantum computing is this kind of looming threat. That's the thing we need to really focus on. But the way you solve that is having agility

[00:11:07] around cryptography. And that's the one thing I think people haven't had for decades is they deployed a web server, they've slapped a certificate on there, and they've left it alone for 10 years. And that's literally been the case with five and 10-year certificates. I wish I have still found a few 10-year certificates floating around the web, which is quite scary. But we're going to shorter and shorter love certificates. So that's encouraging us to have automation around our cryptography deployments, which is good news, because it means that if we

[00:11:34] have a fully automated cryptographic stack for our application, if we kind of abstract the cryptography from the application layer, handle it somewhere else, fully automate, it means that it could be quantum computers tomorrow, it could be super AI intelligence in a few years' time. Whatever the threat is, we have a very quick way of kind of automating, rotating keys, swapping cyphers, changing certificates, which means we can kind of adapt much more quickly. And you mentioned a few moments ago about it being a looming threat. And I do suspect we will have

[00:12:04] a few people listening that when they hear of quantum computers capable of breaking today's encryption, it still feels distant to many business leaders, almost like sci-fi. And I've been hearing about this for years, but nothing's happened yet. So for those leaders listening today, just how serious is this harvest now, decrypt later threat for their organisations and maybe holding information that needs to remain confidential, not just for years, maybe even decades?

[00:12:30] Yeah, absolutely. That's the thing. And it's a very, very difficult one to talk about because it's so nuanced again. The threat is very real and it's very, it is looming. It's certainly the current latest prediction of Q-Day is around 2029. Whether that comes to pass or not, we don't think it'll be much later if it's not 2029. Think about the project implementation timescales that it takes to upgrade whole technology stacks. Again, if you think about every place that you have a cryptographic

[00:12:55] touchpoint from web servers to internal origin servers, from east-west traffic, you know, prod, pre-prod, test dev, cloud, on-prem, you have so many different places, including cryptographic libraries built into code, perhaps, that you've done. So just identifying and upgrading all of those things is a huge mammoth task that could take years. But to have a reality kind of check, when we have quantum, cryptographically relevant quantum computers, it's not like, you know, it's going to take around

[00:13:24] about five to seven days to break one session key. So in fairness, we are not going to have a situation where everyone's traffic is being decrypted in real time on the wire. That's not going to happen, at least not for many, many years. You know, that may come in the future. So I would say it's likely going to be those more targeted industries. It could be cloud providers in particular. We often see with kinetic wars, intelligence agencies from countries that are engaged in the kinetic war will

[00:13:51] quite often go after login and authentication details for cloud providers. So cloud providers, service providers will be, you know, a large target. Anyone with highly sensitive information could be healthcare data or government industries. So it's worthwhile to have a level check because, yes, it will take around a week. But you're never going to know. That's the problem. You will never know if your traffic is being collected and decrypted until it's too late. So we have to appreciate as

[00:14:19] well that, you know, I think when I first joined F5 about almost 15 years ago, we were still in a place where only logins were encrypted. We've come a long way in those kind of 15 years. You know, we've now finally realized that everything that we do online has to be encrypted all the time. So, you know, think about that from the reverse. Would you be okay with having suddenly all of your traffic completely unencrypted again and just trusting and hoping that it would be okay? Probably not. So I think it's very likely that you do need to take, you know, a very risk-based

[00:14:47] approach. Let's be kind of pragmatic about it. It won't be all of your traffic all the time decrypted immediately. I think organizations need to look at the most sensitive data. As you said, look at the kind of cover time for information. So not all of your sensitive, not all of your data will be relevant in 5, 10, 50 years time. Passwords hopefully will be rotated every year or every few months or every year or so. Credit card numbers should be cycled every few years. So that's

[00:15:12] too bad. Things like API or tokens, for example, might be long-lived. There'll be actual personal data that could be valid and sensitive for decades to come. So looking at what data is most sensitive and the touch points and exposure points of those data is what's, you know, useful to focus on. But yeah, I think it's very useful to have a kind of level head when it comes to the HNDL threat. I think the biggest risk, the biggest problem for most companies is just implementation time. It's

[00:15:41] finding out where are your cryptographic touch points, how long is it going to take to work with your vendors to upgrade all those, you know, touch points to make sure they're PQC ready. Your agentic AI might not be secure even with real-time data and proper guardrails, but Denodo makes sure your business has every avenue covered. By placing all your data platforms under one

[00:16:05] AI data layer, your business can reach semantic consistency safely and securely. So get your agents on the same page by visiting denodo.com and you can learn more about how to start trusting your agents to make business decisions. But now back to today's guest. And if we look at the bottom of the scale, things can get quite worrying there. I think there's around one in 10 landing leading

[00:16:32] websites apparently don't even have the modern web security foundations required to support PQC. So what does it, does that suggest that the biggest obstacle to quantum readiness isn't quantum technology at all, but the same legacy infrastructure and technical debt that we've been talking about for years now? Precisely. Yeah. Tech debt, I think, is still the biggest problem. I think, I mean, in some cases, absolutely, it's devices, it's technology that literally it's too old, perhaps. You know, companies are sweating their assets. The device is sat in the corner of the

[00:17:01] dusty part of the data center can't be upgraded, they're too old. Some people just don't have this kind of crypto agility mentality when it comes to TLS or encryption. They don't think about constantly upgrading to new cibers and protocols or switching off the old ones. So the 10% you mentioned is specifically related to TLS 1.3. So you need TLS 1.3 to be able to even try to perform PQC or a hybrid PQC kind of connection. Without that, you can't do it. And for most stacks, I would say

[00:17:30] TLS 1.3 is, I'm forgetting my timescales now, I want to say 12, almost 15 years old. TLS 1.3 has been around a while. So if you have tech that can't support a TLS 1.3, there's perhaps a bigger problem there, to be honest with you. But yeah, and what's interesting is that that 10% of sites that are missing TLS 1.3 isn't just reserved for those sites in the bottom of the 1 million. We see that 10% average pretty much across the whole of the 1 million websites. And I think one of the most

[00:17:57] surprising things in the research for me was some of the geographic differences with the, I think the US, UK, Australia, Ukraine and Singapore all performing strongly. But the big surprise for me was Germany and France that were lagging despite having national policies in place. So what does that tell us about the difference between governments announcing quantum readiness strategies and organisations actually implementing them? Yeah, it really is interesting, as you said, because

[00:18:23] France and Germany are actually very proactive when it comes to their kind of policies, their recommendations, their guidance. I think there's two factors that I kind of see that suggests why they're lagging behind. One is this kind of growing concern over digital sovereignty and worry about the reliance and use of US technology. When we think CDN, when we think of large SaaS companies, it's almost exclusively or very commonly US providers that we think of. And so lots of European nations,

[00:18:52] lots of countries around the world are concerned about digital sovereignty, they're now coming back from this assumption that we'll just deploy or they will deploy services and applications on the world's largest CDNs, for example, because they want regional or EU-based providers. So one of the reasons that lagging behind is because they're not just jumping on the world's largest CDNs to deploy their websites. The other one is that actually those countries have had some of

[00:19:20] the largest manufacturing industry sectors or companies in the world for a very long time. So they, you know, they're not digital native, they are companies that have traditional manufacturing plants with lots of operation technology, on-prem data centres, they're responsible for their own kits. And if you actually look at some of the industries and sectors, we find in our scans that the manufacturing industries in particular lag about the same. They're about 35-40% adoption compared to some other industries at around 60%. So I think it's both the kind of companies that we're seeing

[00:19:50] in those countries and also this reluctance of not deploying on US tech and wanting to keep things more within EU borders. And if we have a CIO or a CISO listening who's currently done virtually nothing about post-quantum security, we've delivered a few wake-up call moments today. What should they be doing on Monday morning? How do they identify where the vulnerable cryptography exists, understand which suppliers

[00:20:16] they are heavily dependent on and prioritise what needs changing first and avoid turning PQC into another expensive compliance exercise, which is not what it is about at all. Any advice that you would leave those people listening? Lots, but I'll try and keep it succinct and kind of practical and useful. I think one of the first things you could do in parallel is call and talk to your vendors. You know, they will all have,

[00:20:41] they should all be able to kind of articulate their plan, their strategy for enabling PQC on existing technology or future or coming, you know, plans technology. So one thing is make sure you engage your vendors early, bring them into the conversation. The other thing I would say is, you know, treat this seriously, you know, don't just give it to one person to run around with, but create a kind of working group within the companies that own this and give it high and relevant priority. One way that they could approach this in terms of first steps, because ultimately you need to

[00:21:09] identify where all the cryptographic touchpoints are, and there'll be far more than you realise, unfortunately. One good way to think about this is from a business continuity kind of plan. Imagine your data centre failed and you had to stand up on your secondary data centre tomorrow. Think about all the certificates that would need to be moved or copied. Think about the different kind of keys that we need. So that, so following BCU plans can actually be quite a good way to, if you're completely unaware of where to start, quite a good way to kind of start that kind of mapping,

[00:21:38] that plan of mapping out where your touchpoints are. The term CBOM or cryptographic materials is being used increasingly in the industry because again, you can't secure what you don't see or what you don't know exists. So just having a detailed list of all the keys, certificates, ciphers, algorithms, whether it's in code, whether it's in vendors, whether it's in software, is all essentially very useful. There are some tools that have been developed to kind of help you identify those. You can use traditional web app scanning,

[00:22:07] vulnerability assessment kind of tools that could just scan looking for open SSL ports. That can be a good way to just identify the kind of web traffic that may not really help you with east-west traffic internally. And also it's unfortunately not going to do much from a kind of code point of view. If you're an organisation that develops your own applications and uses cryptographic libraries or hopefully not, but kind of rolls your own crypto and creates your own libraries in your own code, all the kind of code will need to be audited to look for crypto that as

[00:22:33] well. So, but from a starting point, talk to your vendors and create the kind of internal working group and consider your business continuity plans. Lots for people to take away there. And of course, we're only scratching the surface. So for anyone listening, I will include a link to the research we've referenced today and your LinkedIn profile as well. But anywhere else you'd like me to point everyone listening to keep up to speed with your work at F5 too? I think the link you're going to provide Neil is probably, you know, the main thing. What users will find if they go there at

[00:23:02] f5.com slash labs is last year's report. I'm literally putting the finishing touches to this report that will be out in the next few weeks. So I'd encourage those listeners to go to the F5 labs website, sign up for the newsletter and you'll be alerted when the new report comes out. And there we have it. Post quantum security is becoming mainstream, but adoption is heavily reliant on just a few tech providers and many organisations are taking a cautious approach. So I'll include links to everything that we've mentioned there. And I want to hear from people

[00:23:31] listening. Is legacy tech remaining your main barrier? Is it, where are you located? How is your, your region performing compared to other areas in the world? Love to hear from you. This is a dialogue, not a monologue. So I'd love people to keep this conversation going, but more than anything, just thank you for starting it today. Thanks again, David. Thanks, Neil. I think David offered a reassuring message today without giving anyone permission to ignore the problem because quantum

[00:23:58] computers won't decrypt every internet session overnight, but organisations, they might need years to find and replace cryptography that is buried across multiple websites, APIs, code and cloud services, not to mention ageing devices. And his Monday morning advice, I think was incredibly cool too. Talk to your suppliers, form a working group, use business continuity plans and locate cryptography

[00:24:27] touch points, create a cryptography bill of materials. And I also love that mechanic analogy that he shared there. Outsourcing maintenance can work beautifully until that garage closes and nobody inside the business knows what to do. So thank you to David and F5 Labs for making post-quantum security understandable. And remember, you can follow the research and newsletter over at f5.com slash labs.

[00:24:52] And over to you, has your organisation started mapping its cryptography or is quantum readiness waiting for somebody else's inbox? Let me know. TechTalksNetwork.com. But that's it for today. I'll be back again tomorrow with another guest, but thank you for listening. Bye for now.