3D render of a quantum computer
– Getty Images

Quantum computers threaten to decrypt the Public-key algorithms that protect confidential data. For many organizations, securing against the quantum threat has become synonymous with post-quantum cryptography (PQC). The National Institute of Standards and Technology (NIST), and equivalent international bodies, have selected new algorithms, vendors are wiring them into TLS stacks, and security teams are preparing for certificate rotations and compatibility testing.

The prevailing assumption is that PQC will be a drop-in replacement: swap RSA and ECC-based key exchange and digital signatures for PQC, update the PKI, and carry on. But algorithm replacement does not fix architectural weaknesses, it only changes the math.

Quantum risk is not only about replacing algorithms, but also about architecture. The issues keeping CISOs awake are architectural ones: data that could be intercepted and stored for future decryption, cryptographic sprawl that no one fully understands, and the increasingly blurry boundaries of zero trust and multi-cloud.

PQC is necessary. But PQC alone does not secure the physical link, simplify key exchange, or solve cryptographic lifecycle management.

Across carriers, financial services, and critical infrastructure operators, a more layered approach is emerging, combining PQC with stronger key management and hardware-based protections to reduce attack surface, simplify cryptographic operations, and remove long-term trust dependencies. Cybercriminals are already stealing long-lived data today for future decryption, a tactic known as harvest-now, decrypt -later. Intelligence agencies warn that encrypted traffic captured now, including medical and financial data, could be decrypted once quantum machines mature.

Securing networks at the photonic layer

Most quantum security conversations start with software. KETS Quantum Security begins at the fiber.

“We build quantum key distribution systems and quantum random number generators,” said Francesco Raffaelli, CTO at KETS. “Quantum key distribution (QKD) enables the production and distribution of cryptographic keys to secure critical data for banks, hospitals, and energy grids. And our random number generators create true randomness at very high speeds. People do not realize it, but randomness is the backbone of privacy.”

QKD uses the quantum state of photons to generate symmetric keys. If an attacker taps the fiber, the quantum state collapses, and interception is detected in real time. Where PQC strengthens the mathematics of cryptography, QKD strengthens the physical medium through which data travels.

KETS has reduced these optics to integrated photonic chips manufactured using standard silicon photonics processes, the same industrial foundries that manufacture smartphone components.

“When people hear quantum, they imagine something expensive and exotic,” Raffaelli said. “We use the same semiconductor processes as consumer electronics.”

Recent trials, including a government-funded project with BT, tested silicon-photonic QKD systems and hardened the operational layers surrounding them, from management software to the physical enclosure. The company is also participating in industry efforts to independently evaluate QKD deployments, a step intended to support interoperability.

While KETS focuses on high-value and long-haul environments, its work illustrates a broader point: quantum-safe networking will not be achieved through software alone. In some scenarios, the physical layer will also need to evolve.

Removing the public key from the attack surface

If KETS focuses on securing the physical link, Arqit targets the most exposed element in modern cryptography: public-key exchange.

“The best cybersecurity comes from doing simple things right,” said Daniel Shiu, CTO at Arqit.

Public-key cryptography is the internet’s trust anchor. PQC introduces new algorithms, but the architecture remains the same: two parties that have never interacted engage in a public-key exchange. That initial handshake is the step quantum computers are expected to break.

Arqit replaces that exchange with symmetric-key agreement mediated through a cloud-based service. The two endpoints never exchange keys directly. Instead, they authenticate to the same service and derive matching symmetric material.

“Even if we have never met, we enroll with the same service and use it to mediate our agreement,” Shiu explained.

Symmetric cryptography is inherently resistant to quantum attacks because increasing key size preserves security. For operators and carriers, the appeal is operational: integration does not require replacing existing infrastructure. Symmetric keys can be inserted into existing IPsec VPN tunnels using the standards-based RFC 8784, allowing deployment without a major network redesign.

Because symmetric keying is lightweight, keys can be rotated continuously, which aligns naturally with zero-trust security models. Instead of relying on long-lived certificate chains, every connection can be re-evaluated.

“Active authentication lets you do much finer-grained security,” Shiu said. “You do not persist trust for years.”

Arqit’s approach does not replace PQC. It reduces an organization’s dependence on public-key cryptography at the network layer, which is the part of the architecture most vulnerable to harvest-now, decrypt-later attacks.

Making migration possible

If KETS reinforces the physical layer and Arqit rethinks key exchange, the next challenge is managing cryptography at scale. That is where automation and cryptographic lifecycle management become essential.

Even with new hardware and new cryptographic key architectures, many organizations cannot start a quantum security program because they do not know where cryptography is used in their environment.

“Most enterprises do not even know what cryptography they have, or where it is,” said Silvio Pappalardo, chief revenue officer at SandboxAQ. “You do not know what you do not know.”

SandboxAQ focuses on automating cryptographic discovery across applications, services, certificates, APIs, and keys. In many organizations, this work would otherwise require consultancy engagements and manual auditing. Automation can simplify that process, allowing certificate rotation and cipher replacement to be planned and tracked.

“The first scan overwhelms customers,” Pappalardo said. “We find vulnerabilities to today’s brute-force attacks, not just quantum risk.”

At enterprise scale, migration also involves governance. SandboxAQ recently extended its collaboration with EY US. SandboxAQ provides automation and telemetry, while EY manages program governance, regulatory alignment, and change control.

Quantum migration also intersects with device constraints. Not every endpoint can absorb PQC’s computational load, especially in IoT, customer-premises equipment, and embedded systems.

“Devices often have limited compute, memory, and power,” said Bernard Vian, general manager at SEALSQ, a PQC chip and secure-element vendor. “They must maintain compatibility with existing infrastructure while preparing for quantum threats.”

SealsQ expects most organizations to move through transitional layers rather than adopt in a single step.

“We enable companies to start by implementing PQC first in their IT systems,” Vian said. “Then integrate quantum-resistant chips into future product generations to complete the migration.”

PQC will not arrive everywhere at once. Migration will be staged, layered, and uneven across infrastructure and devices.

The quantum-safe network will be layered

For years, the industry framed quantum protection as a binary choice: PQC versus QKD, mathematics versus physics. Operators now see quantum safety as a sequence of architectural decisions.

KETS focuses on securing the fiber itself. Arqit reduces reliance on public-key exchange. SandboxAQ addresses cryptographic sprawl and the lifecycle challenges that hinder migration. Vendors such as SEALSQ highlight that edge and IoT environments will require hybrid approaches for years to come.

These technologies do not compete. They interlock. Quantum resilience will not arrive as a single product or a single upgrade cycle. It will arrive as architecture.

A single algorithm, chip, or platform will not define the quantum-safe future. It will be determined by the ability to make cryptography adaptable.

There is no quantum-safe product. There is only quantum-safe design.


This article first appeared in the SDxCentral Quantum Supplement.

To read more on

  • Quantum network security
  • Quantum-safe encryption
  • Cryptographic sprawl

Read the full Supplement. Simply register.