Forescout Launches PQC Dashboards as Research Shows Only 6% of SSH Servers Support Post-Quantum Encryption

Key Takeaways

Real-Time PQC Detection: Forescout introduces the first network-layer solution capable of identifying non-quantum-safe encryption ciphers in real time across managed, unmanaged, and evasive devices.

Widespread Exposure Confirmed: New research reveals just 6% of 186 million internet-facing SSH servers currently support post-quantum encryption, highlighting significant harvest-now-decrypt-later risk.

Integrated Platform Capabilities: The Forescout 4D Platform combines detection, segmentation, threat intelligence, and control to help organizations analyze quantum-exposure risk and prioritize remediation across IT, OT, IoT, and IoMT environments.

Forescout has launched new Post-Quantum Cryptography (PQC) dashboards and the supporting patented technology to analyze quantum-exposure risk across IT, OT, IoT, and IoMT environments. Announced July 17, 2025, the solution continuously analyzes the cryptographic ciphers supported by connected assets, scores them against post-quantum safety standards, and surfaces exposure through platform visibility and executive reporting. The release coincides with fresh data from Forescout Research – Vedere Labs showing minimal global adoption of quantum-safe methods and underscoring the need for continuous cryptographic posture assessment.

Real-Time Cryptographic Cipher Analysis and Risk Scoring

The technology, invented in 2023 and patented in 2024 under US12010210B1, operates at the network layer to examine encryption usage without agents. It identifies whether devices support or actively employ quantum-vulnerable algorithms—even when assets attempt to obscure their identity or posture. This data powers the new PQC dashboards and risk exposure management features, enabling asset filtering, cryptographic inventory tracking, and prioritized risk scoring.

Supporting research from Vedere Labs provides concrete benchmarks:

  • Only 6% of 186 million SSH servers accessible on the internet support quantum-safe encryption.
  • Among OpenSSH implementations the share exceeds 20%, yet three-quarters of observed versions predate PQC support.
  • Adoption of the NIST-standardized ML-KEM algorithm surged 554% from October 2024 to March 2025 but remains below 0.1% of servers.
  • Less than 20% of global communications use TLS 1.3, currently the only TLS version with native PQC support.

OT, IoT, and IoMT devices face particular challenges, often requiring firmware updates or hardware replacement before full PQC migration is feasible.

4D Platform Delivers Quantum-Safe Security Assurance

The Forescout 4D Platform translates detection into operational outcomes through a four-pronged strategy of detect, enforce, mitigate, and control. Detection supplies real-time cryptographic posture visibility. Enforcement leverages eyeSegment for network segmentation to isolate critical systems. Mitigation draws on Vedere Labs threat intelligence to target policy responses at rogue or misconfigured assets. Control limits traffic from high-risk devices to reduce immediate exposure.

The approach supports organizations building the cryptographic inventories recommended by government guidance while maintaining business continuity. It is particularly relevant for hybrid environments where legacy and unmanaged assets complicate large-scale algorithm transitions. By delivering both granular visibility through PQC dashboards and interim protective controls, the platform enables measured progress toward post-quantum resilience without requiring immediate rip-and-replace of existing infrastructure.

Find out more here.

Further articles, reports, and the latest quantum computing news may be found at The Qubit Report.

Related Articles

Get The Qubit Report delivered straight to your inbox.

Sign up to receive our newsletter and other reports.

We keep your data private and share your data only with third parties that make this service possible. Read our privacy policy for more info.