Enterprise security teams that deployed post-quantum key exchange in their IPsec tunnels gained real protection against the harvest-and-decrypt threat — but left a second attack surface untouched.