Corelight Bright Ideas Blog: NDR & Threat Hunting Blog

Post-Quantum Cryptography: The Upgrade Nobody Asked For | Corelight

Written by Josh Porto | Sep 25, 2026, 11:18:37 PM

Post-Quantum Cryptography (PQC) is the security equivalent of showing up at the airport and discovering TSA changed the rules overnight again: Laptops out, laptops in, shoes off, shoes on, and declare your shampoo like it’s contraband uranium. You can argue with the signage, but the plane is still leaving, and compliance is not optional. The good news is you don’t need a physics degree, a quantum computer, or a wellness crystal to deal with it. You just need a simple mental model and a plan to keep you from having to learn what PQC stands for during an outage call.

Explain PQC like I’m in a war room

Adversaries are collecting encrypted data today and betting that tomorrow’s math will be able to decrypt it. Post-Quantum Cryptography (PQC) is new encryption math designed to remain secure even if powerful quantum computers emerge later. It is not “quantum encryption.” It is not a countdown timer to the apocalypse. It’s not even a new cryptocurrency (It’s 6 years old). It’s a practical migration: Replacing or augmenting parts of today’s encryption algorithms so that “harvest now, decrypt later” becomes a lot less attractive. Exactly nobody wants their frosted-tip Myspace photos, GeoCities pages, or AOL Instant Messenger away messages dug up and read a decade later just because encryption didn’t age well.

The great glacial PQC migration

Most organizations won’t flip to PQC compliance overnight. You’ll notice it first in the places where crypto shows up in daily life: TLS handshakes start looking a little different, some negotiations get bulkier, and your environment becomes a mixed bag of clients and services that support the new stuff and others still living in 2016 with Internet Explorer (RIP) as their default browser. Your baselines will notice before you do.

The reality of the rollout is that PQC is already arriving in a very unglamorous way: Half-and-half. Some clients will support the new crypto; some will not. Some services will upgrade early; others will cling to legacy defaults like a safety blanket. For a while, your environment will negotiate encryption like it’s ordering off two different menus at once, and that awkward middle phase will make baselines look “weird” if you are not expecting it. The key is to treat hybrid behavior as a migration symptom first, and only a threat signal after you’ve ruled out “we’re upgrading things.”

The mercifully unsexy truth about PQC

Even if the encryption math changes, the cybersecurity reality doesn’t: Defenders can still hunt encrypted traffic by its shape, not its payload. PQC will make handshakes chunkier and cipher names weirder, but it does not erase the fundamentals. Connections still have endpoints, timing, frequency, destinations, certificates, and “this is not normal” fingerprints. In other words: Attackers can change the wrapping paper, but the package still leaves footprints.

The entire PQC situation fits in a 2×2, no quantum theatrics required:

  You have encrypted-traffic insights You don’t have encrypted-traffic insights
Before PQC Life is good. You can hunt: Fingerprints + handshake/cert metadata + behavior. You’re flying blind and hoping the payload fairy shows up.
After PQC Life is still good. You can still hunt: Same game, new math. The “shape” is still there. You’re still flying blind with fancier encryption. Congrats on the upgrade.

Line-rate decryption meets line-rate billing

Every time encryption gets stronger, someone will float the idea of line-rate decryption. It sounds like the intuitive thing to do, like “we’ll just see everything.” Then Finance kicks in the door with a spreadsheet and the facial expression of someone canceling the companywide picnic.

Decrypting all network traffic at scale is usually a compute bonfire with a budget problem. The math does not add up, and the minute you hit capacity, you are back to blind spots. That said, targeted decryption in high-value locations still makes sense for many organizations aiming to reduce specific cyber risks. Beyond those critical chokepoints, the practical answer is to stay excellent at encrypted-traffic visibility: Metadata, fingerprints, certificates, behavior, and clean pivots to evidence. Don’t chase the plaintext fairy.

Sleeping soundly with PQC

PQC is a long migration, and we are preparing now so it will be boring later. Boring is the goal. Boring means no midnight incident call where everyone learns what PQC stands for in real time. PQC is not a reason to panic, but it is a reason to pay attention. Your job is not to become a cryptographer. Your job is to keep your environment observable while the crypto underneath it evolves.

Treat PQC like any other infrastructure upgrade: Plan it, baseline it, measure it, and make sure your security program still produces evidence you can pivot on. Math will change. The investigation still needs a story.