The “CTO++”: DigiCert’s Lakshmi Hanspal on Transforming Trust into Infrastructure
The cybersecurity industry is hurtling toward a massive collision of quantum computing, shrinking certificate lifespans, and an explosion of agentic AI, forcing organizations to rethink the very foundation of digital trust. Broadcasting live from RSAC, Techstrong’s Alan Shimel sits down with DigiCert Chief Trust Officer Lakshmi Hanspal to discuss why trust can no longer be treated as a mere compliance checkbox, but must be embedded as core infrastructure to secure the enterprise. Hanspal breaks down her “CTO++” role and offers a pragmatic roadmap for CISOs struggling to balance the intense pressure of AI adoption with the critical need for cryptographic agility and verifiable machine identities.
Transcript
Hey everyone, we're back here continuing our live coverage from RSAC. We are in Moscone West. We're facing out right into where people are walking, heading to sessions and keynotes, and so you get the live version of this.
I'm going to continue speaking with Lakshmi Hansdal. Lakshmi is the Chief Trust Officer++ at DigiCert, and I think that's a great place where we're going to start. So I've heard of chief trust officers, but not the plus plus.
Tell us what's special about... Well, what is a Chief Trust Officer++? What is the role there?
What are your responsibilities? So within the industry, this is an up-and-coming role, right? And companies like DigiCert have seen the need for such a role earlier than others.
So just a bit, how do we consider the journey of trust? And having been three decades in the industry, I've seen trust transform from a compliance checkbox to- Yes ... a competitive advantage.
What excites me is when trust is treated as infrastructure. Okay. It's the foundation on which everything else runs.
So when we build it in every single layer, customers choose us, regulators respect us, and partners want to work with us. And what that means from a role of chief trust officer is, I call it CISO++ and CTRO, so Chief Trust Officer++ , because the ability of the plus plus is you have all the operational responsibilities. You clearly have the board mandate and the board responsibilities in terms of risk and protection.
But you have two or three other responsibilities that are sort of unique. One, to work with industry standards, regulators, policymakers, not just in defining policies, but in influencing the stance that they could take. Yeah.
Because we are the voice of the practitioner. If someone says, "Hey, we need to do this," and let's say it's one of the root programs, and that could be draconian. " The second is being a customer advocate.
How do we enable our customers to be in the best trust posture possible? Not just because they have access to a unified platform, but are they using it to the best of their abilities? And the third is in terms of influencing the industry thought leadership on how we need to be thinking about, we're going to be talking about quantum compute.
We're going to be talking about AI. Some of these topics are scary for practitioners today. They don't know where to start.
How do we influence and give them some sort of mechanisms to start with? I feel this is a really good... I was going to save it for the end, but as long as you brought it up already, let me mention it.
I mentioned it over at Techstrong Gang as we ended. We are debuting a new podcast that we're doing with DigiCert called, uh- "The Signal". "The Signal", excuse me.
From AI to Quantum. It starts, I think we're scheduled for April 16th is the first one. Lakshmi's going to be on it.
I'm going to be hosting it. If this is the kind of stuff that she just spoke about, this plus plus, check it out. We're going to have it live.
Well, it'll be recorded, but it'll be on all your favorite podcast channels, whether you're an Apple or a Spotify or a YouTube person, or on Techstrong TV, or on our OTT channel, or on the DigiCert websites as well. And we have a whole first season of runs that we're planning on right now, so I want to come back to that. Lakshmi, we spoke earlier about that "Harvard Business Review" article, and you need to prepare for Quantum.
It was funny. In preparation for our interview today, I did a quick first Google search, and then, of course, an AI search, of news here at RSAC 2026 regarding Quantum. And I was shocked by the lack of news.
And I get the reason why. The agentic AI is just suck- It's top of mind for- It's top of mind to bottom of feet. It's the whole thing.
It's hard to get anything else in here. But I know DigiCert had some announcements, some things they're doing. Wanted to ask you about that, and then let's look beyond RSA and about what DigiCert specifically is doing.
Yeah. So, I want to say that there are a couple of changes coming at us in the next 18 months. Yeah.
The cumulative of those changes outweighs what we've seen in the last 18 years- Years ... Alan, and I've been in this industry for 30-plus years, so, I have not seen the volume of change and the compression of time, the shrinking window. The velocity.
Yeah. The velocity as well as the shrinking window in with these changes are coming our way. So a couple of things.
There are a lot of cryptographic agility changes coming our way. Certificate lifespans are shrinking. We need a better way to automate because this is no longer humans...
Organizations can no longer run on a spreadsheet and a prayer- No ... The second is there are NIST standards. You mentioned quantum compute.
We have finalized NIST standards on being quantum safe readiness or readiness towards post-quantum compute and algorithms that help you get there, and adoption of those algorithms. And the third is, of course, AI. Right.
And agentic AI, identity at the core, assertion as enforcement, governance as foundation. These three changes are coming at organizations all at once, so some of the messages are getting lost. The foundation for post-quantum crypto or post-quantum readiness, the way I see it, is cryptographic agility.
And what does that mean? It's not just to do it once, but the ability to do it again and again, but not rewriting your entire tech stack or redoing- Yeah ... your entire infra stack every time you need to make a change.
Can't do this. Yeah. Can you do it in a way that is more agile, but you help your business move with the velocity they want while preserving the faith of your customers?
There's another issue here, though, and it's scale. We were talking earlier on "The Gang," and we had the fellow from Saviynt, and I had interviewed him before, and we mentioned some CrowdStrike data. 160 million.
160 million. That's a drop in the bucket. That's true.
As sure as I'm sitting here, from what I've seen, and I'm like you, I play practitioner, do my thing with it. We are going to measure the amount of agentic AI agents that are in use within the next two years in the billions, if not tens of billions. Right?
Because I think we're all going to have literally dozens of agents, sub-agents, identities that are doing our bidding. We saw this when we moved from human identity to the very first machine identities, right, with certificates. We saw a bigger explosion, IoT, the billions of IoT devices that need identity.
" Non-human identities again. Right, and those are ephemeral because containers come and go in seconds. That's right.
We have been pressed to scale to that at each one of these points. Now we're at the next point, which is another scale issue of how do we identify, how do we manage the identities of billions of not only agents that are ephemeral, but they're intelligent. They're- They're learning ...
not deterministic. Yeah. They're learning.
How are we going to do that? It's scary. Yeah.
How are we going to do this? So I think you said scale. Right.
The sprawl. Yes. And it's scary.
Right. The three S's right there. Yeah.
Okay. This is another wave of technology, AI, agentic AI, generative AI, interactive AI, that is coming our way. It is going to be embraced.
It's our ally. It's going to be a year of efficiency for many organizations using AI as well. When we think about how do we get up, just to get a handle around this, while not being the office of no to the business.
No, you can't do it, because the business is going to continue, and our customers want to adopt it as well. I think a couple of things. One is don't wait for full visibility.
You can't protect what you can't see, but it doesn't mean you don't protect what you can see. Agreed. So start with what you know, start with what you have while trying to discover all the assets that are there, cryptographic assets, certificates, as well as your agentic workloads that are there.
And then the second aspect of this is prioritize it. Go after your crown jewels first, and then systematically go through the others. So it's a matter of rinse, repeat through every crown jewel asset that you have.
And the third is make sure that governance and oversight, what are these agents? How are they verifiable? Intelligent trust is about verifiable identities with agents, attributable assertions, as in what can they do?
Who you are, what can you do? How do I trust your output? That's the governance aspect of it.
If these three questions can be answered for every agent, ephemeral or not, then organizations can scale with AI within their enterprise. That's the hope. Let's hope it comes out like that.
Lakshmi, I have to apologize because we've got more people waiting to move in here. I want to thank you for coming. " You were a lifesaver because we needed someone who brought what you brought to it.
" Don't miss it here on Techstrong TV. We're going to continue with our coverage here live at RSAC. We're in Moscone West.
We'll be back in just a minute.