"Many organisations have yet to grasp the true scale of the challenge."
Kieran B., Head of Security Engineering at Bridewell
Following the publication of Forescout’s blogpost “PQC Adoption Gaps: 90% of Systems Are Still Not Quantum-Safe,” Kieran B., Head of Security Engineering at Bridewell, commented:
Forescout’s finding that the overwhelming majority of systems remain quantum-unsafe is concerning, but it should not be a surprise. It aligns closely with what we see in the field and with our own research into the critical national infrastructure sector, where the gap between perceived and actual readiness is stark: around 90% of organisations describe themselves as moderately, highly or extremely prepared, yet 54% have either not reviewed or did not understand the government guidance on the subject. In other words, many organisations have yet to grasp the true scale of the challenge — which makes assessments like this a useful prompt for honest reflection rather than alarm.
The single most important step is to start with discovery, because you cannot protect or upgrade what you do not know exists. We recommend building a cryptographic asset register as the foundation. That analysis should go beyond simply cataloguing the algorithms in use today; it should capture what each one protects, the value and sensitivity of that data, and how long the protection genuinely needs to hold. Together these factors allow organisations to produce a prioritised, risk-led migration plan. Encouragingly, this journey does not require a wave of new procurement to begin. Existing network monitoring platforms such as Forescout and Nozomi, alongside software inventory and CMDB tooling, can surface much of what is needed, and open-source scanners for TLS readiness and static code analysis can be used alongside the commercial software organisations have already deployed.
Expectations should be managed, however: remediation may be difficult and costly work, and progress will not be uniform. Legacy systems, operational technology and IoT devices are likely to prove the hardest to migrate — many will not support a direct algorithm upgrade at all and may ultimately need to be replaced. That is precisely why starting sooner matters. Understanding the scale of the task is itself a significant undertaking, and with advances in both cryptographic algorithms and quantum processor development moving quickly, the day a cryptographically relevant quantum computer arrives is likely to come sooner than many expect. The organisations that begin their discovery work now will be the ones best placed to act in time.


