Every day, intelligence services siphon off staggering volumes of encrypted traffic as it crosses undersea cables and satellite links, not because they can read it today, but because they are betting they will be able to read it tomorrow. This strategy, known as harvest-now-decrypt-later, treats currently unbreakable VPN sessions as a time capsule of secrets waiting for a future quantum computer to pry open. For enterprises running site-to-site tunnels and remote-access VPNs, that bet is forcing an uncomfortable reckoning with cryptography that has served reliably for two decades.
Classical VPN security rests on Diffie-Hellman key exchange, whether through elliptic curves or finite-field groups, and that math has a single, well-understood weakness: it depends on problems that a sufficiently powerful quantum computer could solve efficiently using Shor's algorithm. No such machine exists yet at the scale required to threaten real-world encryption, but the recorded handshakes do not need one to exist now. They only need one to exist eventually, and intercepted ciphertext can sit in storage for years. Organizations evaluating providers or researching infrastructure options sometimes compare server locations worth knowing about when assessing how jurisdiction and routing affect exposure to interception in the first place, since geography still shapes which networks are easiest to tap. server locations worth knowing about
The response taking shape across enterprise networking is hybrid key exchange: combine the classical algorithms already trusted by auditors and regulators with new post-quantum key encapsulation mechanisms, so that breaking the connection requires defeating both at once. This is not a wholesale replacement of existing cryptography but an additive layer, a hedge against the possibility that quantum computing arrives sooner, or that the post-quantum algorithms themselves harbor undiscovered flaws.
WireGuard's Speed Meets Rosenpass
WireGuard earned its reputation by stripping VPN design down to a lean, auditable core built around the Noise protocol framework and Curve25519 elliptic-curve key exchange. That minimalism is precisely why it spread so quickly through enterprise and consumer deployments alike. But Curve25519, elegant as it is, remains a classical construction vulnerable in the long run to quantum cryptanalysis.
Rosenpass and similar experimental extensions address this without touching WireGuard's core code. They run alongside the existing handshake, periodically exchanging a key generated through ML-KEM, the lattice-based mechanism standardized by NIST, and feeding that fresh post-quantum entropy into WireGuard's symmetric key ratchet. The result is a system where an attacker must break both the elliptic-curve exchange and the lattice-based one to recover traffic, and because the post-quantum key rotates every few minutes, any single compromise has a short shelf life.
IKEv2 Gets a Second Lock
On the IPsec side, the IETF addressed the same problem through RFC 9370, which extends IKEv2 to support multiple key exchanges performed sequentially or in parallel during a single negotiation. Enterprise gateways can now combine a traditional Diffie-Hellman exchange with ML-KEM-1024, the highest-strength parameter set in the ML-KEM family, deriving a single compound session key from both.
This matters for compliance as much as for engineering. Government and defense-adjacent networks operating under the Commercial National Security Algorithm Suite 2.0 need cryptography that satisfies both legacy NIST approval and emerging post-quantum mandates simultaneously. Hybrid IKEv2 negotiation lets gateways meet both requirements without forcing a disruptive, all-at-once migration.
What Comes Next for Enterprise Security Teams
The transition carries real trade-offs. Post-quantum key encapsulation mechanisms tend to produce larger key and ciphertext sizes than their classical counterparts, which can affect handshake latency and bandwidth on constrained links. Standards bodies and vendors are still converging on implementation details, and interoperability between different gateway vendors remains a work in progress.
Still, the direction is unambiguous. Security teams managing long-lived infrastructure, particularly in finance, defense, healthcare, and critical infrastructure, are treating hybrid post-quantum key exchange as a near-term requirement rather than a speculative upgrade. Data intercepted today may not matter in isolation, but decades of accumulated secrets, once decrypted en masse, could reshape what adversaries know about the past.