Deepika Chauhan, DigiCert | DigiCert Trust Summit
DigiCert’s chief product officer Deepika Chohan delves into Digicert’s suite of products, focusing on DigiCert One—a platform addressing various digital trust challenges across web presence, workforce, content, software, and devices. Deepika discusses the evolving landscape, emphasizing the complexity brought by multi-cloud infrastructure, remote workforce, and diverse applications. She highlights the importance of crypto-agility, centralized governance, and inventory tracking.
Transcript
This is Textron tv. Hey, everyone. We're back here, live in Las Vegas at the DigiCert Trust Conference at the Resort World in, in Las Vegas.
And I mean, it's been an amazing day. We're getting a little bit, you know, on the other side of the afternoon. We have a few more great interviews for you to tune in on, though.
I want to introduce you right now to Deepika. Char Char. Yep.
Deepika is the Chief Product Officer at DigiCert. And, and we were talking off camera, it's funny, we've been doing interviews since seven 30 in the morning, Las Vegas time, and it is, it's almost a quarter to three Las Vegas time. I don't think we've spoken about DigiCert products at all.
We, we've spoken about everything from some very big, big topics, but you know what, it's a DigiCert conference. I think it's time. We, we talk a little bit about DigiCert product.
Um, for those who don't know the DigiCert platform, and correct me if I'm wrong, Dipika is, is DigiCert one? That's correct. DigiCert one is, represents not just the platform, but also the suite of products digital offers to solve different kinds of digital trust problems.
Because digital trust is a very wide area, and you can talk in terms of solving digital trust in the context of web presence or workforce or content or software or devices. So our product portfolio has these products to solve and address those specific customer use cases. Got it.
And so the, you know, but it en as you mentioned, it encompasses a lot, a lot of different areas. You know, I think when most of our audience, and we have a very technical audience that's watching this, I'm sure, but when they think about DigiCert, we think of digital certificates. We think about web certificates, right?
I, I got my little lock symbol, you know, H-T-T-P-S or maybe we think about personal certificates, right? I'm Alan, and this certificate on my email, you know, kind of proves it. We're, we're at, you know, when we talk about a concept of digital trust, there's more to the certificates than those things though.
But how do you take a concept like digital trust and translate that into a product suite, right? And how, how, and that's your job, right? So let, let's talk a little bit about that and then what products manifest themselves out of that.
Yeah. Um, so Alan, first, you're not the only one who sometimes associates DigiCert with T-L-S-S-S-L or web certificates, right? Uh, because that is where DigiCert has always had very strong leadership.
However, over the past few years, actually many years, there's been added complexity to the enterprise. And that complexities coming because there's so many more applications that the enterprises have. The PKI architecture that the customers have is really much more complex because you're talking about multi-cloud infrastructure, you're talking about complexity where the workforce is not just coming to work, but there are remote workforce as well.
So you talk about this added complexity with many more devices, many more users with different kind of behavior as well as many more servers and applications. So it's not just the customer problem in this case is not just about, oh, do I get a certificate and install it on the server? They also wanna able to solve the challenge around crypto agility is what they, uh, often refer to it as that, as a customer, do I have a view of all the certificates and not just for servers, not just web certificates for my servers, my users and devices, do I know when something is expiring?
Because if I don't take care of it, it's gonna have outages. I can't tell you how many customers, almost every single customers that we talk to has this problem of outages that they refer to. Even some of the biggest companies, and this is out in the news, they have the challenge where they've had outages where they say it's because the certificate expiring.
So what do the customers need? It's not just the certificate. In addition to that, for digital trust, they wanna know where all my inventories 'cause very often for customers, they don't know what they don't know, and they wanna know the book of record, the inventory.
And once they know what are all my assets protected by certificates, then they have centralized visibility and they can provide the management and automation for that because they know when something is expiring or how to do zero touch automation for your users or servers. And this is essentially crypto agility. I mean, you referred post quantum crypto, um, if you have to go on post quantum crypto, you know, the number one challenge companies will wrestle with, they don't know what all their assets are.
So the keeping track of the inventory is the number one step. Yeah. And this is where, so that's only one of the products I'm talking about?
Yeah, No, that, that's one piece. It happens to be one of the first pieces. Exactly.
So the first pieces is DigiCert Trust Lifecycle Manager, along with DIG Cert Central provides a full stack solution for crypto agility and to manage all the sort effects across user servers and devices. Then this is, this is very often the challenge that the IT groups have, which is to reduce the risk. However, when you move to product security side, this is, if you have conversations with your OM manufacturers, the number one thing they care about is that the device that I'm manufacturing, how do I make sure it's not counterfeit?
How do I make sure it's secure? And this really matters in some industries. Uh, like the example I gave earlier today was around continuous glucose monitor or infusion pump, because over there counterfeit devices are really dangerous.
It's life and death. It's life and death. And patient safety is based on digital trust.
So manufacturers wanna make sure that this tamperproof identity and digits iot trust manager, a device trust portfolio is helping that at the time of manufacturer, it's imprinting the tamperproof identity in form of birth and operational certificates. Yeah. Moving from the device, then it's not just about the device, it's also the software which is going on the device.
You know, like you wanna make sure that the software is secure, there's no malware, there's no vulnerability, and then you wanna provide non-repudiation around it because you wanna make sure that the software which is going on the device is secure and it cannot be tampered with. And they don't, they know where it's coming from. Yeah.
So even over there, it's not just about that though. It's about, you know, many of these manufacturers, like there was an example that, uh, they were talking about. For example, one of the biggest, uh, bbr was talking about one, uh, their company.
There's just so many different business units. So you also need centralized governance. And in the centralized governance, you wanna be able to say who can sign, who has approval rights, what cipher to use, what crypto to use.
And so there's a centralized governance, and this is where, um, DigiCert software trust manager is providing the capability. Yeah. So as we are moving, we talked about device and counterfeit devices, then we move to the content and the ai, everybody's talking about ai and how do you know something is real or something is fake?
Well, this is where for content creation creators, content authenticity comes into play. How do I know that picture I'm seeing on Facebook is actually real? How do I know the video is real?
How do I know that the document I'm signing is real? I mean, one of our, um, uh, interesting use cases is an engineering firm wanted a notary like capability where we could, they needed a third party to validate the document signature. Well, this is where content authenticity is around all these kind of medi media.
And DigiCert has a document trust manager, which is essentially about providing that third party validation that a notary like services provide. And you can put a seal on it, a digital seal, um, a e-signature on it, which is validated. Like if you're signing it, we know and we are validating that you are Alan Mm-Hmm.
And then we are also putting a timestamp because for these things, it's not just about who's signing, but when was it signed. Understood. So it's, And in addition, we have also ADNS product, which is about scalability of the entire enterprises and availability.
So as you can see, there's a wide speed of product, but essentially the underpinning is it's providing digital trust. What are you talking about? Web presence, securing workforce, securing cloud infrastructure, or you're talking about securing devices and software you're producing or the content that you're producing.
That was fantastic. I I really, I mean, I knew already most of this, but I think our audience really appreciates that. You know, a concept that's come up a few times in our discussions today is this notion of what should the role of a DigiCert or a digital trust provider be?
Should we teach people to fish or give them fish or a little of both? Yeah. And you know, IIII, I will tell you the truth, I was always in the teach people to fish.
Right. Because I, I think ultimately just feeding people fish is very hard. Yeah.
Right? You, you run out of fish Yeah. And you run out of, it doesn't scale.
Yeah. Teaching people the fish scales. But, you know, a lot of people we've spoken with today said, no, I think we're better off just giving them fish so it gets done.
So it's frictionless and they can move on with their life's work, if you will, given DigiCert's scale scope of, of Yeah. Product. I think you have to teach them to fish and not give them fish.
I think I'm somewhere in mid middle. You're the middle. I'll tell you why, and I'll tell you why.
Okay. So we are providing from API point of view and the entire portfolio digital trust products. However, we have to respect our customers because they know exactly the problems they're solving.
When we look at our customers, they're trying to solve digital trust problems. Um, digital trust is strategic imperative. It cuts across all functions, whether you're on IT or security, whether you're in compliance or legal product or DevOps.
Everyone is thinking about digital security, and they're thinking from two lenses, how do I reduce risk? How do I make sure I don't have outages or non-compliance or government regulation or attacks and breaches. But then the second lens switches also very interesting, is our customers are innovating.
They're going through digital transformation. They, and for digital transformation, the foundation and is digital trust. So this is where I think partnering with the customers, because they know how to change the outcomes for their customers, talk about critical medical devices, they know exactly what challenges they're running into the ecosystem is running into, and we can share with them what we are seeing from other ecosystem providers.
Where we are expert is in the digital trust aspect, but this is this partnering where they may not have the core competence in this, in this space, but they may, they have the core competence in exactly the customer problems which needs to be solved. So when the two come together, this is where you see some of the innovation. And this is what I find very exciting.
So I wouldn't say like, we know all the answers, and I wouldn't say that the customer knows all the answers. It's when we are working together hand in hand trying to solve unique problems Yeah. And innovative problems where we are learning from each other.
We are partnering to partnering together to give something really compelling to the customers and the end users. Yeah. And, and, and that another reoccurring theme we see is, you know, today's customers, today's end users are demanding.
Yeah. They, they, they want easy, frictionless, trusted Yeah. Solutions.
And when it, when something doesn't work, that web browser doesn't load, or they can't, you know, make a transaction, you don't get a second chance. Right. So this is why it almost has to work flawlessly.
Yeah. At the same time delivering that trust. Right.
It's, it's, it's not easy. I, I can't agree. It was easy.
Everyone would do it. Yeah. I can't agree more with you because this is where security and user experience are so important.
Yeah. Whether it's for the end users or even whether it's the engineerings, uh, department within your organization. Because if you impose security, it doesn't take as long as you make it so seamless, so automated or so easy from a consumption point of view, if you make it onerous and cumbersome, something gets, It's not gonna work.
Yeah. And so I think very often, you know, if you're designing perfect technical solutions, that's not enough. The user experience has to be sitting at the core of it.
Agreed. Listen, we're about out of time. I want to thank you for coming up to meet with us here at Tech Trunk today, and thank you and all the digit search team for a great, great trust conference this year.
You know, this is the first time we're back in person since before Covid here. And it's just been so great to come back and, and you know, you forget how, especially when we talk about a category like digital trust you, it's good to be in person. Right?
You get more of that trust than you do, you know, over Zoom or something. I can't, I'm so happy to be able to have Yeah. In person conversation with you.
So thank you so much for your time. Thank and your Questions. Okay.
Dika Shahan. Shahan. Say it for me Better.
Dipika Shahan. Dipika Shahan, chief Product Officer at DigiCert here at DigiCert Trust. We're gonna, I think we still have another maybe, uh, interview or two to round out our coverage for today.
So we'll be back in just a little bit with some more stay tuned. But for now, we're taking a quick break.





