Quantum computing poses a serious threat to current encryption standards, driving organizations to prepare for the post-quantum era. In this blog, we outline how rising risks are reshaping testing, performance planning, and cryptographic transition strategies.

Why Today’s Encryption Isn’t Ready for Tomorrow

Encryption has long safeguarded data privacy, with algorithms like RSA-2048 built to resist brute-force attacks for millennia. But rising threat sophistication is accelerating the need for stronger, next-generation security.

As cryptographic methods grow more complex, greater compute power is needed to resist decryption by advanced adversaries. An accelerating arms race is now unfolding, complicated by the looming threat of quantum computing technology, which is poised to upend current cryptographic standards.

Quantum computing could allow hackers to perform complex decryptions within hours, rendering existing encryption methods ineffective. We are even seeing attackers harvesting encrypted data with the intent to decrypt it later, once quantum computing capabilities become more accessible. (In an earlier blog, we described how to address emerging cybersecurity threats lying ready to wreak network havoc.)

As quantum computing threatens to break current encryption standards, NIST has introduced post-quantum cryptography (PQC) to safeguard data against these emerging risks.

Driven by the urgent need to protect sensitive data, financial and government institutions are moving quickly to adopt PQC ciphers and guard against quantum-era threats. While financial organizations aim to secure transactions, government agencies focus on protecting classified data and preserving national data sovereignty.

Not Just Stronger Keys—A New Security Mindset

Deployments aren’t as straightforward as simply implementing new standards. Quantum-safe cryptography requires careful planning, thorough testing, and strategic implementation, demanding that organizations assess their readiness to adopt the new algorithms.

The longer keys and increased computational overhead of PQC ciphers place greater demands on firewalls, load balancers, and other middle-box security solutions in a distributed enterprise network. Without sufficient capacity, network performance and latency can be negatively impacted.

VIAVI is partnering with organizations eager to optimize the middle-boxes and security controls capacity to meet the demands of PQC algorithms while maintaining the performance and latency levels required by applications and expected by customers.

In these engagements, we help organizations answer three critical questions:

  • Is our end-to-end security stack ready for PQC adoption?
  • What impact does PQC overhead have on performance and latency?
  • How does PQC behave in a hybrid cryptographic environment?

Once these answers are known, planning for implementation can begin.

Establishing Clear Strategies to Prepare for PQC

As standards and regulations evolve, and as organizations recognize the urgent need to secure network and data transactions, many are beginning to develop clear strategies for PQC adoption.

All too often, new technologies are implemented without sufficient testing. It’s only after deployment that organizations realize latency is too high or devices can’t handle the changes, resulting in unplanned and disruptive rollbacks.

To avoid these issues, initial implementation steps should include:

  • Risk assessments.  Identify cryptographic algorithms and protocols vulnerable to quantum attacks. Determine which components require upgrades and assess the impact of quantum threats on the network. Use this analysis to create a mitigation plan.
  • PQC testing. Prioritize evaluation and validation of quantum-safe cryptographic methods to ensure they can be deployed effectively on existing security infrastructure. Test PQC impacts on security, network performance, and latency and resolve issues prior to deployment.
  • Roadmap. Develop a readiness timeline and roadmap that includes governance adjustments, training programs and crypto agility preparedness. These are essential to supporting a smooth and successful PQC deployment, as highlighted in Cisco’s vision for PQC .

How PQC Testing Informs Decision Making

As an integral part of PQC implementation, testing provides the empirical data needed to make the best business and technical decisions for supporting current and projected traffic volumes. It also verifies the effectiveness of mitigation tactics and helps identify gaps and risks while addressing challenges related to validation, scalability, interoperability, and performance.

A comprehensive PQC test plan should incorporate:

  • Next-gen firewall performance. Firewalls are subjected to emulated encrypted data and handshakes to evaluate the impact of PQC and traffic demands on throughput and latency. These results are then compared with the performance of other algorithms. Based on the findings, teams can determine whether to upgrade existing firewalls or consider alternative solutions. The new firewall should then be tested to confirm it meets required latency and performance.
  • Interoperability testing. In a hybrid deployment where one side supports PQC and the other does not, test for interoperability to ensure seamless communication. For example, if the client side adopts PQC but the application does not support it, adding PQC may not be advisable.
  • Scale testing: Single instance PQC testing in a live network doesn’t reveal its real performance impact. Only network-scale lab testing exposes how PQC encryption truly affects performance.
  • Security protocol effectiveness. Validate that security protocols detect and block attacks as intended. Integrate PQC algorithms into diverse applications and threat scenarios to emulate realistic traffic during testing.

The risks posed by quantum computing are no longer theoretical. Proactive planning for PQC is the only way to ensure long-term data security.

VIAVI CyberFlood and TeraVM test tools are already being used by early adopters to test AI-driven security optimizations with both supporting the emulation of PQC ciphers. These tools allow organizations to assess the performance impact of PQC algorithms on evolving security infrastructure, right-size their networks, and address implementation complexities with confidence.

Learn more about PQC testing in our solution brief.

About The Author

Senior Director of Security Product Management, VIAVI

Close