What if your website already supports post-quantum cryptography, but nobody inside your organization knows how, why, or which provider controls it?
I speak with David Warburton, Director of F5 Labs Threat Research, about new F5 research examining post-quantum cryptography across the world's top one million websites. According to the research discussed in our conversation, 54% now support PQC. It is an encouraging sign that preparations for future quantum threats are entering mainstream infrastructure.
That figure is also easy to misread. David explains that much of the adoption comes from cloud and CDN providers enabling hybrid post-quantum protection for their customers. A smaller business could therefore appear better prepared than a large enterprise simply because its provider activated the technology automatically. However, that customer may have little understanding of the chosen cipher, the protection applied elsewhere, or the dependencies created around a small number of technology companies.
David says the adoption rate looks very different when major CDN providers are removed from the data. This raises an important question about whether businesses are developing their own post-quantum security capabilities or temporarily benefiting from decisions made on their behalf.
We discuss why current deployments combine established cryptography with newer post-quantum algorithms. This hybrid approach protects compatibility while browsers, APIs, operational technology, IoT devices, and older enterprise systems catch up. It also carries performance costs through larger cryptographic material and increased network traffic. David argues that crypto agility matters because organizations need the ability to change algorithms, certificates, and encryption methods as threats develop.
The conversation also moves beyond encrypted traffic. Harvest now, decrypt later attacks involve collecting sensitive information today so it can potentially be decrypted when capable quantum computers arrive. David believes authentication and digital identity could create an even greater concern. A quantum computer able to produce valid certificates could potentially impersonate trusted websites, signed software, devices, or firmware.
Legacy infrastructure remains one of the largest barriers. F5 Labs found that roughly one in ten leading websites lacked TLS 1.3 support, preventing them from supporting current hybrid PQC connections. David also explains why Germany and France may trail countries including the US, UK, Australia, Ukraine, and Singapore, despite strong national policies. Factors include digital sovereignty concerns and the concentration of older manufacturing and operational systems.
For leaders beginning this work, David recommends speaking with suppliers, establishing internal ownership, reviewing business continuity plans, and creating a cryptographic bill of materials covering certificates, algorithms, libraries, applications, and devices.
I'd love to hear your thoughts, so does your organization know where its cryptography lives and who controls its post-quantum readiness?

