Preparing for Quantum Threats: The Future of Cybersecurity with Jennifer Leggio
Jennifer Leggio, SVP of Marketing and Revenue Operations at QuSecure, focusing on the importance of modernizing encryption practices in light of quantum computing. She explains how quantum computing differs from traditional methods and poses risks to current encryption. The concept of cryptographic debt is introduced, stressing the need for companies to update their encryption assets. The session emphasizes the urgency for businesses to prepare for quantum threats and comply with government regulations.
Transcript
Hey everyone. Welcome back here to Text Drug tv. I got one of my favorite people to talk to us today.
You probably, well, some of you may know her, some of you maybe don't know her. I don't know. I know her.
I feel like I know this woman since she graduated high school. Um, but she's my friend, Jennifer Legio. She is the newly minted SVP of Marketing and Revenue, revenue Operations at a company called Q Secure.
And, um, before I say hello, if you're interested in Q Secure at our Black Hat coverage, I actually did a really great interview with, uh, co-founder Field CTO of of Q Secure, Dave Krautheimer, Krautheimer, Dave, look up Dave K on our black, uh, uh, black Hat coverage. And you, I strongly encourage you to watch that right after watching this. Jennifer, how are you?
It's good to see you, my friend. I know. It's good to see you too.
I'm doing good. I'm excited. I'm excited to be here.
And I was, I'm always happy to see you. Absolutely. So, I, I, you know, I was being facetious.
You weren't in high school when I met you. Uh, but You I was in my twenties though, so it was a long time Ago. You were, well, yeah, you were, you weren't even at the end of your twenties.
Yeah. You know, you were closer to the beginning of your twenties. It's been, it's been 25 plus years, something like that's a long time.
Yeah. And, and you know, Jennifer, for those who aren't familiar, maybe with your arc and an arc that it is, tell us, give us a little bit of your story. Oh, just my story.
Um, so I never thought I would get into technology, though. I was always a bit of a technology geek. I started going to journalism school and was working in newspapers.
And then I ended up getting a job at a small agency that focused on taking cybersecurity companies outta Delta, the market at an agency. Um, and then I did that for a bit and went on to a little tiny company that everybody called for to who, uh, Uhhuh employee number 80, which is now Fortinet, which is a Goliath, and worked through their IPO. And then I went to Sourcefire where I ran corporate marketing and corporate communications, um, through our acquisition by Cisco, which at the time was a unicorn.
It was a biggie at that time. Yep. Not as big these days.
Uh, Well, but That's, uh, In today's dollars it's still big, but go ahead. It's still big. It's still big.
But yeah. And, uh, and then I did, that's when I embarked my, uh, my, uh, former CMO and still mentor Mark Solomon. Uh, sure.
Pushed me outta the nest and said, you're gonna be a CMO, you do more than comms and, and corporate marketing. And started a CMO journey, um, uh, working for some great companies like Clarity and Flashpoint. Um, and then I, uh, I, you know, I, I, uh, went back to work for Marty Rush for a while, um, for source fire integrity.
Um, they had some headwinds and they had a marketing team like most companies during that, during early 2024. And then I had the opportunity to try, do, try my, I dream of Chief Operating Officer, um, and love the company. I've been an advisor to the company Title Cyber, they're fantastic.
Um, but I hated the job, even though I wanted it for so long because I missed marketing and missed the revenue operations part of it. The, like really digging in the data and helping sales move the needle more hands-on and what I was doing there. And then I just kind of took a little respite.
I worked for an agency that I loved and used for years, WT Communications, doing part-time fractional work. And Q Secure was a client of mine there, and I'll kind of stopped there 'cause there's obviously more to come since I started full-time. But that's Absolutely, That's my arc.
And I've done a lot, obviously in the security community, a lot of speaking, and, you know, just, I just, uh, recorded a different podcast or different podcasts came out yesterday where I talked about how you, you and others, Mike Rich were so helpful in getting me to know the community and how important it is to know the technology in order to be successful in the marketing role. And, and that's done really well. So thank you for that.
Don't f*g me. It's all you, you know, you talk about yes, being able to talk the talk when it comes to the technology's important, important for marketing communications as well as everything else. But, you know, Jennifer, I I will tell you, and I don't mean to embarrass you, but the thing about you that I remember all these years is how hard you work at no, no matter what it was.
Whether it was making the security bloggers Meetup party successful by being the only one between me and Mike and Rich and Martin, to actually do the work to make that thing work. We had menus, we had photographers when people walked in, there were lists there, it was organized to everything that you do, no matter what company, whether it was for or net or Source Fire or Integrity or Forcepoint or any of these, you outwork most of the other people I've run into in, in, in this world. And that's really your superpower.
I, I know you have other powers, but you know, there's no substitute for it. So all of this is well deserved and, and good for you. Thank you.
I appreciate That. Let, let's talk about Q Secure and your role there. Let, let's, as I mentioned, I, I had a chance to meet with Dave k over in Black Hat.
And, you know, the interviews there that, that interview was about 30 minutes. But I think David and I spoke for an hour or more to tell you that you off camera, just he was great. Have a lot in common.
We had a lot of good time. We laughed a lot, we talked a lot. But assume people out here don't know Q Secure.
Tell 'em, tell 'em what it is. Well, um, I came in as, like you said, SVP of Marketing and Revenue Operations. And I had consulted with them for two months as fractional marketing, doing fractional marketing for, um, before I joined full time.
And Q Secure, um, does post quantum cryptography. Um, and they have a phenomenal platform that allows, um, companies to, even if they're, you know, a lot of companies are saying, well, we're not ready for quantum migration. We're not ready to be get quantum safe.
But there's a whole part of what we do around, um, discovering your encryption. Is it up to standard, getting it modernized, getting it safe for, from, you know, forget what's coming with Quantum. But most organizations through acquisition and, and, um, just ciso after ciso after ciso, 'cause that's a high turn job, have just inherited so much.
They don't even know what they have going on. 'cause there's no, you never hear like an encryption architect at a company or anything like that. But really focusing in post, uh, quantum migration.
And it was the brainchild of Rebecca Kraemer, who is, um, Dave's daughter and also the CEO and co-founder of the company. Um, that, you know, she worked with, um, I wanna say the US Air Force coming out of, of school and Stanford and yeah. Out of kind of Stanford.
And it turned into this company because the, the need that is so pressing because quantum computing is coming and we aren't protected, most aren't protected, I should say some. We have clients that are, um, and, um, for me personally, you know, I've worked with some amazing innovators, amazing folks like Marty Resh and Josh Leitz and Galena and Tova and other folks. But everything that they were building was to threat that already existed.
We're we're helping people modernize their cryptography now for any threat that's out there, but also most important migrate to be quantum ready, quantum safe. So when quantum computers are available to those hackers that are just sitting there waiting for 'em, they don't have to worry about that. They don't have to worry about the keys to the Kingdom.
So I feel, Jen, I feel the need that I, I need to do some groundwork here. Sure. Some foundation building, a lot of people hear the term quantum computing.
They hear things like Q Day post quantum cryptography. What exactly are we talking about? You know, for most of us, we've just heard, oh, it's five years out.
It's five years out. Every five years, it's still five years out. Well, that's changing drastically, right?
We, we are on the cusp of this. But for those who don't understand it, first of all, go watch Dave's interview with me. 'cause he does a much better job than I ever could.
I'm no quantum person. I, I did stay in the Holiday Inn Express last night. So let me, let me give this a shot where, where computers are binary things are one or zero, one or zero, right?
That's how basically computing works, right? Binary computers. And today, CP used what we call 64 bit, which is twice as much as 32 bit computers, right?
So the way computers work today is they take 64 bits of data at a time, and each one of those bits is a one or a zero, right? So it's 64 1 0 0 1, 0 0 1, 1 0 0, right? 64 1 0 zeros in quantum computing.
It could be one the other or both at any given time. So where traditional computing is done by bits and bytes in quantum, you have this concept of a qubit. Mm-hmm.
And a qubit, again, could be a one or a zero. It it, it's fluid if you will. And where, so a regular computing, you know, CPU chip, a 64 bit chip has 64 bits that are either one or zero.
So it's 64 squared. That's how money, that's so much data it can do in one cycle, right? 64 squared, big number 64 times 64, you, you could do the math qubits.
It's actually two to the 64th power and a pure qubit, and I'm not gonna get into one mgs a pure or not, but two to the 64th power. So that's two times two times 2 64 times. If you take that out, as Dave told me, in black hat, that actually equals about the total computing power, uh, ingested or performed in the world for a year Yes.
In one cubit. So it renders anything that couldn't be brute forced before easily like child's play. So our RSA encryption 2 56 bid encryption seconds if maybe minutes at the most to break it.
I mean, there's other uses for quantum computing mm-hmm. Than just security, right? Of course there's all kinds of weather patterns and science and protein folding and all these amazing things.
But when we look at it from a security point of view, anything that we have used, encryption four is, is child's play or a quantum computer. And we are, as I said before, on the cusp of commercially available quantum computers. IBM has basically planted the flag that I think they're gonna have their first commercially available quantum computer, I wanna say 20 28, 20 29, 29, something like that.
Yep. There are others. There's companies like IQ and there's so much, this is becoming a world unto itself.
And then I, I'll mention one other thing, Jenna, and I'm gonna let you talk more about Q secure. Here's the real, like double whammy combined quantum computing with ai. Yes.
And it's like world gone wild, right? I mean, it's a, it's just a whole, you know, it's a whole new thing. So that, that's the backdrop here.
Right? Now, here's the good news. You, there's companies like you that are out here already saying, Hey, we, we see this coming.
We know what it is. Right? We know what it's gonna be.
Here's what you can do to future proof yourself. Right? Every C-level exec I ever knew always wants to future proof.
Yep. I set it up for you, Jen. You run with it from here.
Yeah. I wanna touch a load on what you said. You know, it's, um, you know, they talk, they talk about, you know, Q Day, whatever day that is, that the quantum computers are available, but you're also starting to see some movement from some of the bigger cloud providers trying, you know, we talking, putting Quantum in the cloud and all of that as well.
0, there's, they're requiring every company or uh, companies have a cryptographic cryptographic bill of materials to CBO M by basically just end of next year, January 1st, 2027, um, the White House has put out executive orders that keep pulling the requirements for contractors and other agencies working with the government to be quantum ready. Earlier and earlier, I believe the latest one was 2027. Um, we've got all other nation states, five Eyes Nation states that are pulling in their own deadlines.
And now there's the National Quantum Security Migration Act that's in the conver, and I may have hope I didn't say that right. That's in discussions right now for this year. It's going to put, potentially put standards in place because the threat is looming.
Um, and, you know, it's, um, you know, you know, I don't wanna step on your toes with some of the stuff we talked about pre-show, but you know, a lot of these, it's not just nation states though. It is nation states. There are a lot of big adversary groups out there, as we well know, um, that are harvesting this kind of data now and their breaches knowing that they can't encrypt it, unencrypt it now or do decrypt it now.
But they will be as soon as they have that quantum power. And this story, this whole story was fascinating to me because, you know, I was consulting with Q Secure, I met Rebecca, the CEO and co-founder through a mutual connection at RSA, and it was to meet and greet. And I really liked her.
And I was like, you know what, let me, let me do some fractional stuff. I wasn't ready to leave the agency. They weren't really ready to hire someone internally.
And we worked for a couple together for a couple months, and I learned a lot more about life weight. I heard Garrison, um, uh, Kent Bus or CTO, he was talking about cryptographic debt and it's like product debt, but your cryptography and layers and layers and layers of that and how can you possibly know without doing discovery of that. And it was like, that's a big security story.
We should be, we should be talking more about. Um, and so that caused j So I, I'm gonna stop you one second. Define crypto cryptographic debt for us, Essentially, it's like it's having a backlog or not having a backlog, a a lack of discovery and understanding of all the cryptography you have.
And it's not just passwords, it's certificates, it's creds, it's all kinds of things that are protected with those, those mechanisms, right? And, and getting your algorithms are your algorithms up to date? Is your encryption up to standard?
And so I joined Qsq for two reasons. I begged, I was like, Becca, I I need to come work for you. Um, I love what you guys are doing.
Not just the technology and the problem to solve and getting ahead of the problem, but the ethos and the values of the company, which transitions into my next reason is that they're so confident that addressing that cryptographic debt and doing that inventory and discovering those assets and getting those modernized or up to speed is that they're offering free discovery for folks. Whether they're, they think they're ready for quantum or not, that's something they have to do to get more secure. They're offering that.
They feel so strongly they're offering that really, really, uh, for qualified for qualified companies. Of course. Like if it's like you're Bob Soda shop and you got two people that might not fit, You know, but I don't think you gotta worry, you've got too much, right?
Yeah. And so that showed so much to me of like how much the, the founders and how much the people that have been there for so long, they might as well be founders believe in this, that they're willing to do that. And then of course, you know, there's other parts of of what we do that, you know, obviously we're a company, we need to make money and so on and so forth as part of doing that PQC migration.
That just said a lot to me about the values and that the, the biggest thing to me that I always say to marketers is everybody has to care about the end state, which is securing data users, customers, people, you know, 'cause that could affect people in their, in their day-to-day lives. If, if it's a big financial institution that's not, you know, sure. Ready with our cryptography, Not, not to mention the government stuff.
Gotta gotta care about that. Yeah. Yeah.
I mean, you're talking stuff like nuclear weapons codes, right? Nothing too important. Um, nothing that Important.
Yeah, just hand that over. Yeah. Yeah.
But you know, the, the, so this, but this, as much as quantum represents new, you don't leave your common sense and experiences at the door. Right. A tenant of security is, you can't defend what you don't know you have.
Right. So before we could start talking about quantum proofing your, your encrypted assets, no matter where they are or what they are, you gotta know where they are and what they are. Right?
Right. And, and so just the idea, I, you know, this reminds me if you remember when, when API security first got hot, I was during COVID four years ago, people had no idea how many APIs they actually had. Um, which what was talking to who, what was being transferred.
And then all of a sudden they started, like people like CloudFlare started doing, uh, surveys. 57% of all of the traffic on the internet is API to API. Right.
It wasn't, you know, and so it, everyone was like, it blew their mind and no. And then they got serious. It's the same thing here.
I don't care whether it's BitLock or on your laptop, encryption in the cloud, encryption at rest, encryption in transit, your two factor stuff. Everything, your password, it's all encrypted. Ev every time you go on a website and we get the little lock thing and we see the s at the end of the HTTP, it's encrypted.
And, and so I just want people out there to realize how big an issue this is. If poof one day, that's all wide open, right? If you don't get out in front of this and you've been warmed, we warned we had, we have enough time.
You mentioned nist so full disclosure, I was a judge. I, I think I am again this year for DigiCert's World Quantum Day or whatever they call it. And I'm a judge for their, for their hackathon or for, for that.
I've been following the NIST regs as they went all through draft and, you know, and finally got adopted. This is one where we, for once, this is the first time in my life in security, we got out ahead of something or we're trying to Yeah. Companies like Q Secure leading the way here.
That's on our list, by the way. Is it? Yeah.
Yeah. Good for you. Um, I highly recommend it, but, you know, shame on anyone who doesn't take advantage and, and gets caught, you know, a day late and a dollar short here.
'cause it's not gonna be pretty. Um, so I gotta put it to you though. Where can we sign up for free quantum readiness?
com. Um, and we have, um, you can request a demo. There's a direct calendaring to our, uh, technical team or, uh, just fill out any of the forms that we have on there.
Contact me through LinkedIn. Um, and, uh, if you're interested in learning more about, um, you know, we'll go, we go through a validation process, of course, to, to just make sure it's a fit, um, and can learn more about, um, you know, getting, um, getting, you know, access to the, the free, you know, the, the module for discovery. Um, and Excellent.
You know, of course we're gonna talk to you about the other things we do that they will ultimately need. But you know, it's, um, yeah, just contact me, go to our website, ping Dave, kay Ping, Becca. Sure.
You know, we're, we're all pretty responsive. We're all over this. We don't, it's startup life.
We don't sleep. We're, we're looking for leads all the time. But it keeps you young man, it keeps you the blood flowing.
Um, Jen, you, you mentioned earlier the, this notion of the bad guys are kinda hoarding car balls of, of encrypted data now just waiting right. Till the day they can encrypt it. And of course, you know, every day that goes by that data becomes older and maybe less useful, but there's still a crap load, a boatload of, of this encrypted data out there.
Yeah. Anything you guys can think of that would help with that, or that's just already that, that cows left the barn. I think the cows left the barn and AVO that you made earlier is that there have been so many of these breaches and data that's been taken, sometimes companies don't even know that had, you know, um, you know, encrypted data in there and, and these, these hacker groups or what have you, you know, couldn't do anything with it then.
And they're holding onto it, but they're also actively harvesting as much encrypted data as they can through different mechanisms. Um, waiting more mo more modern, like encryption that, uh, or I should say, um, uh, more modern efforts to get the latest information waiting for Q days. So, you know, we don't necessarily, um, do anything protect against that.
I mean, that's where you hope that your, your defense and death and all the other millions of security products that you have to try to protect what is no longer the perimeter helps you with those things. Um, but what we can do is help to, um, discover what you have, get it updated so that it's get it quantum safe, mi you know, do the migration help you remediate if anything looks like it's been, you know, accessed. Um, and then build a more resilient cryptographic state moving forward in addition to the quantum readiness.
So, you know, there's not much we can do. You know, we can't really go back in time. What's happened has happened as we've learned what other types of threats like you were talking about with API security, but in terms of getting, shoring you up as best we can now, and then if heaven forbid anything needs updating, getting that updated and then if heaven forbid anything has, you know, happens or ha or will happen or has happened remediating that, mitigating that, there's, it's, there's a whole process involved That's very, very simple.
We had an exec offsite, actually my first day, uh, which was the 11th, um, was the fir my first day of the full-time job. We had an exec office offsite in Brooklyn actually. And, um, oh, cool.
You know, we had, we had talked about like, this is been made to seem overly complex, but it is so simple. It is so simple. You don't need a bunch of people with like roof cases coming in and telling you like all this stuff.
No. You just have to do the thing, you know. So I would just say do the thing, preferably do the thing with us.
You don't do the thing with us, do the thing anyway because you're responsible for protecting people, but do the thing with us. You know, Jennifer says, do the thing with us, you know, and I I, let me throw a little good news on top of it too. NIST and the, and the government has gotten out ahead on this.
Mm-hmm. They've come out with their post quantum algorithms that mm-hmm. Yes.
Your certificates and, you know, a lot of your RSA sort of technology for encrypting stuff can be made quantum proof strictly by upgrade, simply by upgrading your certs. Yeah. But first you gotta know what certs you have.
You gotta know what you got in order to, as I said, you gotta know what you got in order to defend it. Yeah. But it, it's, as you said, it's, it's easy to do.
Once you do that, there's really, I'll say it again, no excuse. Go get this done. Right.
Especially if they're gonna do it, help you do it for free run. Yeah. Um, That's also, not to interrupt you, that's also part of the crypto Yeah.
Addressing the cryptographic debt is updating the algorithms in that process as well, you know, which I can't absolutely to in depth the Dave or Garrison and or Rebecca for that, but, you know, it's, it's fascinating and important. Oh yeah. No, I mean, the way they, you know, they've quantum proofed it with these algos is just, and, and yeah.
That's, that's where my brain, I don't go that high Anyway, Jen, we're about outta time, but I want to thank you for coming on. Of course. Wish you all the best, best, best luck.
You don't need luck. You work hard. Um, but have a great time doing this.
This is like charting a new course through the jungle and you know, you've got your machete in hand. Go do your thing and make it happen. I'm sure great things will, will come from it.
Again. com. Mm-hmm.
And I'm sure we'll be talking more and following Q secure in this path towards q in this March towards Q day. Absolutely. Thank you so much, Alan.
I appreciate it. All Righty. Jennifer Gios, SVP of Marketing and Revenue Ops at Q Secure.
Don't, I'll say it one more time before we leave. Don't get caught late. Go get your, your audit, find out what assets you have that you can protect before Q Day.
This is Alan Shimmer. We're gonna take a break on, uh, text drum tv. We'll be back in a bit.