Navigating Data Security in the Age of Quantum Computing with NetApp’s Gagan Gulati
Transcript
Hey everyone, it's Alan Shimmel. Welcome back here to Tech Drunk tv. I'm happy to introduce you to our next guest.
His name is Goin Gulati. Goin is the SVP and GM for data services at NetApp Garin. Welcome to Textron tv.
It's great to have you on here. Thank you, Alan. Thank you very much.
It's my pleasure. First, I gotta ask you, I see a whole bunch of trophies back there. I assume it's not for data services, but is someone an athlete or what's going on?
My son, who's 12, he's a geography geek. He is a second in the country right now, uh, for national geography B. So good achievement this year.
Last year he was third, so he is definitely climbing up the ranks. Good for him. Congratulations that as a parent, you know, nothing, nothing makes you prouder.
So good. Good for him and good for you. Huge honor.
Huge. Um, well we've, so we've got a little bit of background on you. You have a son who's a geography kinda expert, but Gogan, how did you come to be the SVP GM for data services here?
Let's hear a little bit about your past. Yeah, so, um, my last 15 years have been all in security and compliance. I was at Microsoft for 16 years, and out of which, after the first six years in Windows, I moved to Azure and moved to Azure Security and Identity Group.
And so that's how the journey started. I helped with a lot of the key management work that we did. Rights management, slowly moving into data security, data compliance.
So that was the first decade. And after that, I joined a startup for two years as a chief product officer working on, um, security and compliance. Again, it was a, it is a financial compliance company.
And from there onwards, I ended up joining, uh, NetApp. And NetApp. You can see, uh, you know, we are the most secure stores on the planet.
So the last two and a half years, uh, of my being at NetApp as the VP of VP and then the SVP of GM and NGM of data Services has been to really take the lead on bringing NetApp, um, as the most secure storage on the planet, helping our customer with cyber, you know, cyber resilience, right? From everything encryption all the way up to, uh, backup disaster recovery, ransomware protection, and so much more. So it's been a, it's been an amazing journey and, uh, you know, we have put NetApp, um, which is, you know, on the map for that.
So it's been, it's been a long journey the last two and a half years. But, um, but data services at NetApp is all about that, and I'm very just happy and proud to be where I am right now. Excellent.
Excellent. So, goin wanted a well, before we jump into our topic of discussion, you, you know, you mentioned NetApp, the most secure storage. A lot of our audience knows NetApp.
You know, for me, NetApp really started as network attached storage. Mm-hmm. Right?
Na uh, back in the day I was, it started a hosting company. I sold it to a company that was a roll up in hosting and what we then called a SP application service provider. And we had a lot of NetApp, we had a lot of NetApp boxes, you know, we were, we were hosting Lotus Notes, if you remember, back to those days, right.
And man, could that thing, that thing would chew up, spit out data, you, you just couldn't have enough storage for your Lotus Notes databases and stuff like that, but crazy. Um, but today's NetApp is not just those network attached storage devices, it's not even just secure storage's. There's a lot to it.
If you wouldn't mind give people sort of a picture of today's NetApp. Yeah. So, sure.
NetApp, NetApp is a, we call it the intelligent data infras company. End of the day. It's all about data, and your data always resides on an infrastructure.
And, and that's where NetApp takes a premium. Um, you know, you know, podium location, if you wanna call it on that. Um, today's NetApp is about helping customers with four big, um, imperatives, right?
From data center transformation as it's happening. Um, you know, journey to cloud, and I'll walk through that. Uh, cyber resilience, we talked about it, you know, making sure your data is always safe.
And of course, you know, uh, the top of mind for everybody is, uh, the AI innovation side of the house and how, um, you know, it's all about data when it comes to ai, right? So data and compute, you put them together and, and the magic happens. And the way we have gone about the journey is that, of course we have our big enterprise storage business.
That's what we call it, the storage that you see, um, in the data centers. Um, we also have a very big presence in, uh, cloud storage. So NetApp is the only, um, company that actually has native storage called, for example, in Azure, we have Azure NetApp files.
Um, so it's sold by Azure and built in collaboration with Azure and NetApp because our customers love it and they want to have that storage, our storage and infrastructure available in Azure. Similarly, in AWS we have native storage. So it's not something you buy from the marketplace or you just take a virtual copy.
It's like you go to Azure and you choose our storage and you use it like, it's so good and so popular. So we have one in AWS we have one in Google, it's called GC NV, uh, Google Cloud, NetApp Volumes. So we had our storage in cloud, you know, our cloud, our storage is available in all three, the top three hyperscaler clouds.
Of course, our enterprise storage business is pretty big, but that's like the starting point. We have an amazing platform. We call it our, um, data platform that sits on top that provides all the right value.
The internal name is on tap and our burning system. And on top of that, we have the data services group. My group that provides a lot, most, I would say, if not all, of the intelligence for the infrastructure that's belong, which is the data infrastructure.
And that is basically that helps drive all the four customer imperatives, uh, transformation, data centered transformation, cloud transformation, cyberresilience and ai. So we do a lot of work in helping our customers be more from, particularly in my group and cyber resilience, getting their data infrastructure ready for ai. So there's a lot of work that we do over there.
Um, a lot of innovations, but that's what NetApp is. Wherever there is data, a lot of data that is NetApp because you require that infrastructure, intelligent infrastructure to, uh, really go after and, uh, you know, make yourself productive, make yourself more secure, et cetera. So that's what NetApp is, uh, for, you know, for our viewers and for our customers.
Excellent. That was great description. Thank you, Gargan.
If it's okay, I'd like to turn now to our topic of discussion. You know, recently, IBM announced that they're building a whole new data center in Poughkeepsie, New York to house their first generation commercial grade quantum computer. And I'm, I'm blanking on the, uh, the, I, it's not Stryker.
There's a, there's a name for this new, this platform. They're, they're coming out with very shiny like kind of box big boxes and stuff, but Starling, Starling is a name Starling. That's it.
Yeah, exactly. But whether you believe they're gonna have it in 2029 or not, look, Microsoft invented a new claims to 'em, have invented a new form of matter for their quantum chip, and Google has their willow chip and we're, we're hearing much, so much more. Quantum is gonna be real, and it may not be 20, 30 or 40.
It may be even before or Q day, right? Q day's coming when, oh my God, all of our encryption could be broken like that, right? What are we going to do to keep our data safe?
Yeah. People are now getting real about, Hey, we gotta start preparing for Q day. We need to have data resilience for a post quantum world.
I'm sure this is something that NetApp is, is investing in thinking about already taking action. Tell us a little bit about it. Yeah, I mean, I think as, as you said correctly, the quantum, the post quantum word is real, is coming, is gonna become a reality.
We know that. Um, and the way I think about it, a lot of us internally think about it is as it becomes more real, it is gonna have a lot of implications on all kinds of computing that we humans do. Uh, and of course there are gonna be many other forms of computing that we are not gonna talk about in your, in this session, but there is definitely capabilities in terms of what the bad guys will do or the good guys should defend themselves against in terms of encryption and decryption, right?
Because it's all about security. It's all about protecting the data. And in today's world, as you know, every bit that gets transferred over internet, doesn't matter whether it's over TLS, you know, it's S-T-D-P-S something we use today.
Um, data that's sitting at rest or data that's sometimes in, even in motion, right? Like we, like when it's being transferred, gets encrypted with algorithms. And the idea typically is that these algorithm will encrypt a date on one side and you have the capability to decrypt it on the other side.
And there are standards defined NIST standards defined for that. Uh, R-S-A-A-E-S standards, encryption standards defined for that. And all of that exists in today's world.
Um, and now if you look at, look at it from the angle of, well, can you break these algorithms? Can a, can a bad guy come in in between when data is in motion or when there's a, let's assume a malware attack happening in your company or, or otherwise, or can I take a discount of a computer or from a data center, can I take it and can I decrypt it with the key? These operations are typically very hard to perform because it requires a lot of compute to go and decrypt it if you don't have the key, right?
That's what this algorithm about. So generally, we feel safe in today's word, right? When somebody says, oh, just send you data over HTPS, or don't worry, even if somebody takes out a disc from a data center with your most important data or from your laptop or computer, uh, generally speaking, we feel pretty good because we know that these encryption algorithms are solid and it's not the worth the money or the VI to be able to decrypt them sensitive data.
But that's gonna start changing, right? When the, when the post quantum word arrives. So IBM saying, startling will be as ready as a data center in New York in 29, 20 29 is an example.
Yes. Example. And what, what, what they're basically saying is that they're gonna turn the game upside down when it comes to decrypting or encrypting.
Um, and that's the word that we need to get ready for, um, right. As a, as a, as a as, as as tech people as humanity, right? Because we, we don't want to make, we wanna make sure that the bad guys are not going to be able to take these, um, new, uh, supercomputers if you wanna call them, or post quantum crypto computers and be able to start decrypting every sensitive data that you may have, that you may have stored somewhere.
And that's where post Croom computing comes in. I'm gonna stop here for a minute, but I just wanted to kind of give that background in terms of what we should, what we should prepare for, what the word is preparing for knowing it's coming, whether it's 20 29, 20 30, 20 25. Um, it is coming.
Absolutely. Now, here's the good news, right? I always like to give a little good news For a change or government and industry has been working together for a while, knowing that this day was coming, that Q day was coming, and for instance, NIST has put out post quantum algorithms Yes.
Right? That would, uh, help, you know, make our encryption not, uh, breakable and stuff like that. A lot of the, excuse me, a lot of the certificate providers out there, digital certificates Yes.
Are already including these post quantum algorithms as as, as part of their certificates. A lot of the publishers, the Googles and so forth of the world are starting to say, Hey, you need to replace your certificates more frequently. Yes.
So that we can incorporate the latest kind of post quantum, uh, yeah. You know, post quantum, uh, technology into them. Yes.
So we are, we are getting ready, we are preparing at some level, but for people watching this gaga, how, what, what should they be doing? Yeah. So I think, look, you're absolutely right.
So the good news is that, as you said, NIST has published standards. Um, and for example, um, they have one of the standards is just pure encryption, like fifths 1 42 a s or 2 56. Mm-hmm.
Um, or for code signing, like you said, there is the, um, fifths 2 0 4 MLDS, um, you know, signing algorithm that you're gonna need to go use, or I use the MLKM for key encapsulation, and I'm, I'm using these terms, you know, the audience doesn't need to know all of them, but generally speaking, the idea is what, what we have been asked to do correctly. So, and everybody's moving in that direction, is that you, we, from a, from an organization perspective, you gotta look through all your in infrastructure, your code signing infrastructure, your data encryption infrastructure, your key infrastructure, and you're gonna look back and basically say, are these encryptions algorithms that I'm using, are they post PQC, post quantum graphy certified, and have been as a standard, have been, um, certified to be PQC, uh, secured essentially, right? Post quantum cryptography secure.
And that is the key thing. For example, at NetApp, for example, you know, we announced a lot of this recently, um, as well, and we've been working on that, that for data addressed on any of our infrastructure and anywhere storage, we have a S 2 56 enabled address and the customer can go and use a ES 2 56 to start encrypting and making sure the data is encrypted with a 2 56. Similarly, with code signing similarly with key encapsulation, um, over a period of time so that when the PQC word hit 2029 plus, you know, it's gonna take a few years, we are ready.
The, the customers are ready. Their, uh, their infras is ready to be able to tackle, um, these problems that of, you know, uh, a, you know, a bad guy coming in, stealing your data and them being able to decrypt it, right? That's what the word has to prepare for.
So whether it's Google, uh, and, you know, there are in Infras companies and, you know, there are, um, big hyperscalers of course, that are moving in that direction, influx com data infras company like ours that has taken the lead and basically said, we have these algorithms now available, but the organizations have to go take, play the role they have to go there, there is a, there is a, there is a, they, they have to take the premier role, their com, their security officers have to put a mandate to make sure to look around and see where their data is, for example, and where their keys are, and be able to therefore then go and say, I mandate this. We mandate as a company that we need to use post quantum cryptography to, uh, to make sure that we are safe when the time comes. I love it.
Uh, absolutely. Kagan, we only do these for 15 minutes. We're outta time already.
But let me ask you, it goes quickly, um, for people who wanna stay on top of this, and I think everyone really needs to be thinking about this. Can you give us a few, I mean, obviously we should go to nist. Yes.
Right? And, and they're post quantum, uh, uh, information, NetApp, is there a place on the NetApp site we can stay abreast of what you guys are doing on this? Yes, absolutely.
com, click on Cyber Resilience. And we have a lot of information about what we at NetApp are doing about PQC, about what PQC generally speaking is. How can our customers or, you know, anyone be secure, um, and, and protected from what's coming their way.
So there's a lot of information available, you know, and I just feel proud to, to be working at the most secure storage, uh, company on the planet. And we have a lot of information for our customers and our prospects and anybody who wants to go to read about. Thank you.
Gagan Kagan, Gulati, SVP GM Data Services, NetApp here on Tech tv. We're gonna take a break. We'll be right back.