Women in Cyber, Agentic AI Security and the Quantum Readiness Wake-Up Call | RSAC 2026
Live from RSAC 2026, Techstrong Gang brings together Alan Shimel, Jon Swartz, Christine Nidle, Vibhuti Sinha and Lakshmi Hanspal for a wide-ranging conversation on some of the biggest cybersecurity issues facing the industry right now.
The panel begins with the new Women in Security documentary and a candid discussion about representation, access and advancement for women in cybersecurity. From there, the conversation shifts to one of the biggest themes emerging at RSAC: securing agentic and autonomous AI systems in a world of growing identity sprawl, machine credentials and expanding attack surfaces.
The gang also takes on quantum readiness and why post-quantum cryptography is no longer a far-off concern. As quantum capabilities advance, organizations need to start preparing now for the long transition to quantum-safe security.
Transcript
Hey everyone, welcome to RSA Live Techstrong gang. I've been wanting to do this live, a gang show, and we've never really had the opportunity. Well, we do live every day, but not on location like this.
And we are here on location, and that's why we're five minutes late, I apologize. But when you're doing it live, things happen, and they happened today. But we're really happy to be here.
Let me introduce you to what I think is going to be a great panel as we kick off. We are going to do something a little different. Well, this is very different to begin with, but one other wrinkle we're going to add today is we might switch our gang members between different segments of today's show.
So don't be surprised if you see different faces and us moving along. But let me introduce you to our gang members for today. To my immediate right, making her world debut- ...
on video coverage, our friend Christine Nidle. Christine, welcome. Thank you, Alan.
It's nice to be here. Thanks for being here. Christine, actually, you're with DigiCert.
I am. Yep, and of course, we partnered with DigiCert on the Quantum Security 25 list, and we speak to Aneet there. We speak to all of the DigiCert people pretty often, but this is Christine's first time here.
We're thrilled to have her. If you caught our earlier live coverage, you know this next gentleman, Rabudi Sinha, Chief Product Officer at Saviynt. Rabudi, thanks for sitting in here on the gang.
I hope you're going to have fun. And then, a familiar face on the end, our Bureau Chief, man in Silicon Valley, Senior Editor John Swartz. Always great to have John.
Thanks. How are you? I'm good.
It's great to be here. I don't know if you live here, Christine, or if anybody who's lived here, we had a major heat wave for about five days where it was in the 90s. Really?
Record-setting temperatures, so you came just the right time. Well, coming from Florida, it's- Oh, I know. It's hard for the connection.
We have dry heat though. No, but I could feel the no humidity, and it's very welcome. But- ...
anyway, moving from weather to John, you did an interview yesterday- Yep ... with two women- Mm-hmm ... about a major new film that's being premiered here at- Yes ...
RSAC, but will also be available, I understand, on Amazon Prime. Yes, that's correct. What's that about?
" It's five years in the making. There are a number of reasons why it took long. There was funding, there was maybe the political climate.
It was a work in progress, and basically what they found in this documentary, which debuts today at 4:45 at the AMC Metreon, which is across the street here at Moscone Center area. And it will be, as you said, Alan, it will be on Prime later this month. It's about this long slog, long, slow slog, and haven't we heard this before, of women in technology, specifically cybersecurity, which is a very troubled spot, I think, in particular.
And they mentioned that progress had been made over the last decade from about 11% of the workforce to about 25% are women, which I found that number optimistic. Maybe high to me, but that's what they came to the conclusion of. And they talked about a lot of things, a lot of things that are improving, including allyships, which involve people, specifically men, who are helping women on site and helping them in their career so they aren't slotted and stuck in the same spot and the same kind of dead-end jobs or positions they've often been relegated to.
So, very fascinating presentation, and I hope it does well. They actually also told me there's a book there that they're part of called "The Rise of the Cyber Women, Volume II," and there are multiple chapters, at least 15 chapters on women and their journeys. And they just, in a sense, they're talking about building and retaining females in the cybersecurity industry, and it's gotten better.
We've talked about this. I remember being part of a project years ago where the major companies all talked a big game and didn't deliver nearly what they said they would. And despite the political climate, I'm encouraged by this, and they are, too.
So I'm happy that we had them on yesterday, and we look forward to the continued progress. tv or on our OTT channel. You could check it out.
Christine, not to pick on you, but you are the woman on the panel here, and you're a longtime tech industry insider. I am, yes. How do you feel about it?
Well, it's funny because when I started my career, I'm going to date myself, but it was 1998. That was 28 years ago. Yeah.
I remember WITI, Women in Technology International. Mm-hmm. And coming out of college, my first job out of college was Check Point Software, cybersecurity, and we had a female CEO.
" Well, it- Sure ... I figured out it's because we're- Took a good look around- Yes ... " Yeah.
Now I know. And so it was a big push for a number of years, and after a while I thought, "Well, there's probably some equilibrium," because maybe it was just because of the industry that I am, which is in corporate communications, and there were a lot of females- Yeah ... in that industry.
But it's come kind of full circle again because I've been seeing, okay, so we've had this push over the last 20 years, but we're still not there yet. Right. So I'm really excited to see the movie this afternoon.
So the one thing I should have mentioned earlier was that AI is playing an interesting part in the advances of women in cybersecurity. WhatThey found in the documentary, which is directed by ah Yvette Freeman, was that women are faster at adopting and using and exploring AI, which has given them an advantage, an added advantage in terms of their skills. So they were encouraged by that, and they were also encouraged by more support from men and women within the industry.
I don't want to be too cynical, but the numbers could be higher and we also talk about STEM. And one of the things that they did with this documentary, they've been going from city to city across the US and Canada, at least 20 different places. And they are going to be reaching out to colleges and high schools, and I think that's really important that you go to the education system and appeal to young women.
And they're getting a lot of young women and getting a lot of kids, daughters of some of the women who are in the industry, which I find very encouraging. John, I just want to add one more point here. Like when we talk about this very topic, it has always been about diversity.
Yeah. And I think we are missing the broader picture here that when you untap or when you're not tapping this big percentage of your population, you're not just hurting the diversity, you're hurting the security posture- Yes ... the business resilience, and not only for your organization, but for the country- Yes ...
as a matter of fact. So- I- ... this should no longer be a diversity conversation anymore.
No. Great. And look, general population, right?
Women represent, what, about 51% or something like that. Mm-hmm. It's close.
If it was 51%. Yeah. When you discount that lot, and I think this is exactly what you're saying.
Yeah. When you discount that chunk of your population, what breakthroughs are you missing? What genius are you missing?
What innovation are you missing because you're not tapping into it? And who loses? Not just the women who don't get the job.
We all lose as a result of that. And it's an excellent point. I'm glad you said, used the word diversity because like a diversity of viewpoints, diversity of opinion, diversity of ideas.
Right. And when you have people who look alike, and I'm talking about older white males who predominantly run the industry or populate it, they tend to think alike or look alike, and it's good to have people with other viewpoints. Yeah.
And that not only helps your company, first and foremost, because you're going to appeal to a larger customer base perhaps, and it's a work in progress. That's all. I'll tell you something else though, too, and first of all, I feel compelled that to say, you know what?
I've been in a little bit longer than you, and Vrudhi, you've been in also 25 whatever years, right, John? You've been around. Mm-hmm.
There has been progress. Let's not... Yes.
We should acknowledge. When I first started, I think the number was something like 7% or 8% Mm-hmm ... in security, we didn't call it cyber, were women.
According to what I saw in your interview, John, it's up to almost 25% now. 25, yeah. Which is huge, right?
It's 25%. But as I say, when you have a majority of your population that's twice that, then there's still a lot of work to be done. You brought up STEM.
The fact of the matter is, more young girls go into STEM than boys. Hmm. For whatever reason, we're doing something wrong, they don't finish STEM, or when they do finish their schooling, they don't take that STEM education and training they got and go into the workforce with it.
And with all due respect, I have the utmost respect for PR and communications people, but I do feel we've done a terrible job of slotting women, "Oh, you're a gal. Oh, yeah, we're going to put you in marketing. We're going to put you-" Yeah, that's what the two guests yesterday, they were frustrated by this idea that predominantly was marketing, and it was just these kind of stereotypical roles.
Yeah, it is. They were inside the box, and that is changing. I'm going to compliment somebody who's just passed away.
So Jesse Jackson did a big push on this about 2014, and he worked with us. I was at USA Today, and he worked with us, and he got Apple, Google, Twitter, and Facebook all on the same panel as Stanford to talk about this. And they had their chief diversity officers who they had all hired, and they did make progress.
The irony is that all four of those people were gone from their jobs within a couple of years- Mm ... due to frustration of... But that was a different political climate.
That was during- Yeah ... the Obama administration. So there has been this anti-DEI backlash, whatever you want to call it.
So it is a struggle. It is a challenge like any industry. The media industry, we have nothing to brag about.
When I was working in the newspaper industry, it was predominantly white male. So we focused on tech only because it's such a high-profile industry in this area. Look, I remember, so 100 years ago, I went to law school.
Mm-hmm. And my class in law school was the first class that had more women than men. Now, my son just graduated law school last year.
Wasn't even close. Many more women than men. So in other fields, we have seen that pendulum swing.
Mm-hmm. The whole thing with DEI, I understand both sides of the argument. I have my feelings on it, but I'm not here to preach.
Or maybe I am. No, I'm not here to preach. But here's the thing.
I don't think you hire someone just because of who you are, but you don't not hire them- Mm-hmm ... because of who they are. And II'm afraid that happens all too often.
Alan, there are two other points I wanted to highlight. One, the awareness of what cybersecurity really entails, that is still lacking a lot. Yeah.
If you leave aside the tech companies and the Silicon Valley and if you go to the other parts and the other segments of the nation, there's still a perception that cybersecurity is all about hacking and coding, and that's not true. Just like any other domain, cybersecurity has multiple facets, and whether it is women or men, they can be a part of that. They don't have to be nerds to do that or be a part of cybersecurity.
That awareness is still lacking a lot. Yeah. Yeah.
And second thing is, I think the support which organizations have to do to elevate women in cybersecurity still has not gone to that level which it should have been. No. Yeah.
Let me close... I'm sorry. Go ahead, John.
A shout-out to Deb Shryock because she is a pioneer, and I remember when she and Carol Bartz were the high-profile- Mm-hmm ... CEOs out here. And, anyway, just- Yeah.
She's a- ... memory down, tripping memory lane. Yeah.
Just one last point, Alan, if I may. Sure. So I joined Digicert a couple of years ago, and when I look at companies that I'm going to work for, that I'm going to represent and work with the media and liaise, I look at their leadership panel, okay?
And I want to see women on their executive leadership team, and I was glad to join Digicert. Deepika Chauhan is our chief product officer. Lakshmi Hanspal is- Who's going to be on here.
Yes. She's right behind us. Yep.
Our chief trust officer, which is a CISO plus plus. Yes. Think of all the responsibilities of a CISO plus compliance and standards.
That's her chief trust officer, so she's going to be on next. Yeah. And so it's always welcoming to see that, and I think a lot of women in my shoes, in my position, also look at that when they're joining companies.
I agree. You know what? Because it's not just having women working, but it's also the glass ceiling aspect, which is what you're hitting on.
Look, check out this film. If you're not here, if you're watching this, you're probably not here. But if you don't get a chance to see it in RSA.
Probably can't read this, but- Right ... this is like a flyer for it. But look for it on Amazon Prime.
And here's the thing, whether you're a man, a woman, non-binary, whatever, we all can try to lend a hand to the next generation of people coming up, no matter how they identify, what they look like, what gender, right? We want the best and the brightest, and I always love that about technology because we have that ability. Anyway, hey, we're going to take a break.
We're going to transition to topic two. Christina is going to switch out for one of these leaders at Digicert that she mentioned. She's right here, and we're going to be talking a little bit about some more RSA news.
So give us about a minute as we transition in. You're watching Techstrong Gang live at Moscone West at RSAC Conference. Hey, everyone.
We're back here live for Techstrong Gang segment two. Though we do it live every day, it's different when I'm sitting in the studio, and John's at his house, and it just flows. When you're live on site like this and you're switching people in and out, I feel a little bit like Lucy when the truck- This is like your show of shows with, Imogene Coca and- And Sid Caesar ...
the great Sid Caesar, right? But, John, you and I are the only ones here who even know what you're talking about. Wait, we're the only ones who know what we're talking about.
But anyway. But that's okay. That's why we love you, John.
So our second segment is about some news that was released yesterday. But George Kurtz, the CEO of CrowdStrike, I believe is actually speaking... Did he speak yesterday or today?
No, I don't remember. Yeah, I don't know. They- But it's in our Techstrong newsletter, if you haven't signed up for it.
But anyway, CrowdStrike made a big announcement around redefining cybersecurity for autonomous AI, both generative and especially agentic. And the thing about it is, and this is why I think it's important, right? They're saying, look, the front line for AI security is becoming the endpoint, which is a big...
Let's face it, we all kind of soured on antivirus and endpoint security 15, 20 years ago, and the action was all in the cloud or AppSec, application security, except for maybe the people in identity. But even identity became sort of a cloud security thing. But with people running AI on their Mac Minis, on their endpoints, this whole idea of, you want to call it shadow AI, or you want to call it on-the-edge AI, but securing that is a new battleground now.
That's the new front in this war. Wondering, Vibhuti, obviously, this is something in your wheelhouse with identity because that's one way we're working on it. What do you think?
Is CrowdStrike on the right track here? Alan, I will only say that, one, autonomous AI is real, and when you look at endpoints, that's one part of the problem. You will have interactive AI, and you will have autonomous AI.
When you look at the endpoint vertical, it is only looking at the interactive AI, and that needs to be secured, and identity becomes-The biggest pillar in ensuring that that security is done. But then there are other parts of agents, which technologies from Amazon, when Microsoft people are building and they are running on your compute layer they're not necessarily on your endpoints, they're sitting on your servers, they're sitting on your compute clusters. That's also a problem you have to solve for.
So I would say that CrowdStrike, first of all, a big shout-out to them. They're a big, very strategic partners of us. They are doing this right, and they're looking at the endpoints.
But it is endpoints as well as autonomous agents, which will be the surface you need to protect. Let me introduce you to our new gang member who came in for our second segment, and I'm going to mess her name up because live, I don't have all my notes in front of me. Lakshmi?
Hanspal. Hanspal. Lakshmi, well, why don't you introduce yourself?
I'm the chief trust officer for Digicert. Digicert is a critical infrastructure provider. We have many of our customers here at RSA and our partners as well, and it's great to be here, Alan.
It's great to have you here. So Lakshmi, who better than Digicert to answer this question? Because all of these, and I think both of you have this in common coming from the identity business, both of you realize the need to identify these autonomous agents and control their access, and whether we give them certificates and unique identity identifiers.
6 million, excuse me, 160 million instances running across its customer base with 1,800 distinct AI applications. But I know Digicert gathers stats, too. What are you seeing?
Alan, I have one word for you, sprawl. Sprawl. Absolutely.
So I think the speed, velocity, and pace at which either interactive AI- Mm. Or agentic AI is being deployed in organizations, it is leading to a gap in visibility, a gap in a control plane- Yes ... for these AI machine identities, what we would call.
And for AI, identity needs to be at the core. Assertions, as in authorization, needs to be enforcement, and governance as a foundation. Yeah.
Without which we, organizations that are thinking about it, that are thinking about identity and assertion and governance as built-in, not bolted on, they are the ones that are able to enable their businesses to move at the speed they want to, without breaking the faith of their customers. And when you do something like that, what we call intelligent trust, which is verifiable credentials, visibility, attributable assertion, and governance on top of that, then customers choose you, regulators respect you, and partners want to work with you. I love it.
So glad you came in. That was really well put. That was powerful.
They encapsulated. This is kind of like a Shadow IT play in a sense. There is a Shadow IT aspect to that.
And it's interesting that CrowdStrike did this, and the timing of this show is interesting to me because a lot of the people we talked to yesterday have been here for a couple of weeks. They went to GTC last week in San Jose, and Nvidia opened the fire hose in terms of what could be done with AI. But that also opens up the fire hose for what could go awry.
And I don't mean to be a doomsday sayer, but there are a lot of things that are going to be discovered. There are going to be things that are going to be broken in terms of AI agents, in terms of orchestration of AI, and companies are learning that and addressing it. And there is this push to get into agentic AI as fast as possible.
So this is, in a sense, kind of an opportunity for the security market based on what not just Nvidia, but others are doing, especially the enterprise software companies- Sure ... who all have their conferences coming up in Las Vegas in a couple of weeks. So, there's a great opportunity for them.
Great. And John, I would just say, to add to what Lakshmi just mentioned, if you are an organization who are trying to retrofit what you have been doing with your identities previously, that model is not going to work. No.
The biggest shift, what has happened is all the types of identities which you had, whether it is human or non-human, they have been deterministic in nature, which means you designed and you defined what they're supposed to do, and that's what they're doing. Agents, they learn, they react, they adapt. That is the biggest shift which has happened, which means that you have to basically answer three questions.
Number one, John, to your point, can you find them? Yes. And how you put it rightly, that sprawl is the means to control that.
So the first question you have to answer is can you find them? The second one is can you govern them? Which means how are they coming into your ecosystem?
Do you have an onboarding? Do you have an off-boarding process, a registration process? Just like when I join an organization, I'm created in an HR system.
What is the HR system for agents? And the last one, which is the hardest one, is are they doing what they're supposed to do? If you solve all these three, then you're in a good spot.
Otherwise, you have a problem to look at. I just want to add a little bit. You touched upon that, the ephemeral nature- Yes ...
of agents. It's spin up and spin down. The identities cannot be handled by systems that were designed for humansFor servers- Right ...
for cloud workloads, for microservices, and what we would call tech before 2022. Yeah. Sometimes I get a little alarmed by what some of the pioneers are doing.
And I think about Meta. So there are these two things that are happening with Meta, a couple things. There was an OpenClou incident, but then there was also rumors of them scaling back their workforce.
And then I read about this project, and The Wall Street Journal wrote about this, Mark Zuckerberg's going to have a chief of staff AI agent report to him. And sometimes things are just moving too fast, and I think of the possibilities of the upside. I'm sure he's thought it out, and he's infinitely smarter than I'll ever be.
But to me, it also just raises these little red flags. And, I think AI is going to do wonderful things. 95% of what they'll do will be wonderful, and make our lives easier, make us more productive, make us smarter.
But I always wonder, and this is where you all come in, to safeguard and to guardrail against the things that don't go well or things that go awry. Right. What both Vibhuti and Lakshmi said, I think, let me put my Shimmy spin on it.
Ah. We all talked about shadow IT when cloud came up, and a developer could whip out a credit card and spin up a couple of instances. They never shut them down, of course, right?
And we did have a different kind of sprawl there. We had all of these instances that were orphaned. But they weren't ephemeral.
As a matter of fact, they became permanent when they shouldn't have been permanent. Mm-hmm. But that also made them easy to find.
" With AI, it's a lot harder because of the ephemeral nature of it, because what was there a moment ago is gone. So how do I know what fingerprints did it left? What footsteps did it leave?
What repercussions did it create? And that's going to be a much harder thing to regulate, right? That's why it's so important that we identify them at the moment of inception so that we can trace these things.
Because otherwise, we're not here to play detectives, not at this scale. We don't have enough detectives. So it's critical.
And that's one part of the problem, Alan, which is the ephemeral nature. But the other part is, even if you are able to detect the ephemeral agents, are they doing what the boundaries what you have created for them? Mm.
That's where the real challenge is. Even if you define the boundaries for your agents, they're going to act autonomously, they're going to do something different. So monitoring and understanding what they're doing in real-time, that's the biggest shift, the challenge what organizations have to solve for.
What are they? What are they doing? Yes.
How do you trust their outputs? Mm-hmm. Which are other agents that they're communicating with, right?
There's a collaborative nature. There's a connective tissue fabric- Mm ... of these within any ecosystem.
And so governance is oversight across all of this. I can tell you organizations that are winning today and will continue to win tomorrow are not just defending the systems they have, they're not just relying... The dependency is not just on systems they had today and before, to secure the technology of agentic AI, interactive AI, generative AI, and agentic AI.
But they are making sure that verifiable identity, attributable assertion, and then real-time governance- Yes ... is part of the ecosystem, and it's part of the fabric in which they operate today. So you mentioned sprawl, and I'm wondering, compared to, say, last year, like a CISO, AI agents were kind of a concept.
They were a concept, they were being introduced, they were being talked about. Now it's becoming a practice. Is there a heightened awareness among the CISOs or a heightened, not fear, but concern about how this is all going to play out?
Absolutely. Look, it's not just a year of efficiency for Meta. Yeah.
I think a lot of organizations have adopted the year of efficiency. So we're going to see more of this. And an agent behaving like a chief of staff is part of that efficiency equation.
The heightened awareness, what I am seeing is the ability... See, boards are asking about it, customers are demanding it. Your customers want to ensure that trust is foundational in the ecosystem in which they operate.
So boards, customers, so there's pressure from a number of areas. I'm a practitioner myself, and what I would say to other practitioners is, one of the things that is causing organizational stall today is the concept of 100% visibility or observability. Let me go find, for example, all the cryptographic assets that I have within my environment.
Mm-hmm. So you can't protect what you can't see, but it doesn't mean you have to see everything- Mm-hmm ... to get a start.
Mm-hmm. So start with what you know as you are discovering these are parallel swim lanes. And then, the ability to have agility, to rotate fast, those are the organizations that are able to move ahead.
Or- And Jon- Oh, sorry. Go ahead ... to your point, another interesting trend, what we are seeing is that due to board pressures, organizations are trying to move experimental workloads into production.
Yes. So the security posture has actually gone down. But the actual initiatives have gone down because everybody's busy taking what they have into production and show progress to the board, and that pressure is deteriorating the overall security posture of the organization, which is troublesome.
But this is an old story in security. Yeah. Yeah.
Right? We've- Progress ... we've seen this before.
Yeah. Yeah. We've taken Vicodins for it.
Yeah. So, how- So now... No, I'm just saying.
Yeah. This is true. When cloud came first, SaaS, software as a service, 2006, 2008, right?
Salesforce days. Mm-hmm. So then everything needed to be as a service.
So the cloud was still evolving at that time. And then we got into cloud, and then we got into microservices, and then we got into containers. So we've seen these evolution.
Every evolution led to Vicodin days- Ah ... and then to vitamins. Yeah.
Vicodins then became- From Vicodin to vitamins ... Vicodin to vitamins- Wow ... because- Wow ...
because vitamins can be sustainable, Vicodin is not. Can't. Right?
So we remember that. So AI, we're in the Vicodin days. Yeah.
We will get to vitamins. I truly believe. It will catch up.
I agree with you. It's not just hope. Or- Hope is not a plan.
No. I see the technology. As a practitioner, I see a way that these can be secured and these can be used to secure.
We'll get to vitamins. That right there is the key. Yeah.
We're going to use AI to secure the AI. Yeah. Because that's the only way we're going to be able to do this.
We don't have enough people- So- ... to do it ... conceivably, companies are better at pre-testing their systems, maybe through AI of all things, to make sure that- It's the only way this- It's the only way ...
is going to scale. Okay. You can't scale it with human hands.
It's just not going to work. Yeah. You got to get this AI to be your work- Ally ...
ally. Yeah. And the only difference, what will be, is that you know how to test, how to put the controls for the changed landscape.
If you are expecting that you're going to use AI to put the old guardrails and old controls, that's not going to work for you. Yes. Absolutely.
Speaking of not waiting because the future is coming and it's here, that brings us to our third segment. We're going to take a quick one-minute break. Vibhuti, I know you've got to leave.
I want to thank you so much. You, for the first time on the Gang, you did a great job, man. Thank you.
I appreciate you. Thank you, John. Thanks.
Thank you very much. Vibhuti Sinha of Savviit here. Thank you.
We're going to be back in one minute with our third topic here live on the Gang. We're live at RSA C. Hey, everyone, we're back here live for Techstrong Gang.
And I know we've been running a little late, but you know, you're doing live TV, these things happen. We're back. We're talking in our third segment today about an article I came across in the Harvard Business Review of all things, and the gist of it was you've got to be planning for your quantum or post-quantum future, especially as it relates to post-quantum cryptography, right now.
I couldn't think of a better person to discuss this with than you, Lakshmi. Why don't you kick it off? Thank you for having me here, Alan.
Just to set the context for some of our viewers, if they're wondering what does quantum readiness mean or what is post-quantum crypto, it's the ability for compute power to challenge or bet or break some of the cryptographic and mathematical algorithms on which our current cryptography is based on, which is primarily prime factorial. And why are they able to challenge it? Because of greater compute power.
So, a cryptographic algorithm is very simple. It is buying you time to be secure. So the cryptographic algorithms of the '60s, '70s, '80s, '90s, 2000s, and now where we are at 2026, the ones we're using today are just buying us time to be secure until they can be broken.
So quantum compute is on the edge of challenging that timeline for these algorithms, and that's why we're talking about that now. And one thing I want to say right off, this is our problem to solve. This is not my kids' problem to solve.
No. This is not the next gen. I'm not going to put it- It's no longer five to 10 years out- Yeah ...
that we've been hearing for the last 20 years. And it's about readiness, not waiting for that to happen. Think of quantum as a Y2K with no date.
Mm-hmm. Hmm. That's a great way to look at it.
And so we have to start preparing for those now because those runways of preparation are not a flip of a switch. They're not days, they're not weeks, they're not months, they are in years. And think about all the legacy and the tech debt that we have in the environment.
All of that adds to complexity and scale with which we want to address it. So quantum safe readiness is the ability or the agility to continue to adopt and adapt to quantum safe cryptographic algorithms. And I used a couple of words there.
I said agility. So that means this is not one and done, but the ability to do it again and again, but without rebuilding your entire tech stack every time you do it. And the way I see it is if organizations and you are not thinking about it today, you're just one algorithmic deprecation from a crisis.
Absolutely. So John, do you want to go? No, this is a totally fa- We've talked about this.
This is above my- Above my pay grade, basically, in terms of a topic. ButI find this so fascinating because it holds a key to so many things in the future. To me, it's kind of like almost like a science fiction story.
Like it's kind of a holy grail of sorts to me. It's hard for me to conceptualize, but you mentioned the long history of this. Yeah.
What is it? You said 20 years? I- So, yeah.
So the current algorithms we use right now, the inception, some of the foundations of those- ... were more than 40 years old. Right?
And the basis of it, and this is what I want us to ground ourselves, any cryptographic algorithm buys you time to be secure. It is not a definitive protection. But there's no hard stop deadline.
Exactly. We don't know how much time it buys you. But we don't know.
But that's good and bad, right? I think. Yeah.
Clearly, RSA algorithm has bought us decades. Mm-hmm. Yeah.
Right? But what we're seeing is we're now on the edge of compute, where some of that is getting challenged, and the way we need to think about the mathematical progression or the solve for these are changing. Okay.
We should mention that, right? This whole conference is built on three guys who came up with algorithms using prime numbers and so forth that allowed us to trust... Well, I don't know if trust is the right word, but it allowed us to encrypt and secure the internet as we know it today.
And whether we're talking about, it was 112, 224, 228- ... 256, 512. 512.
All we're doing is we're just stacking more because it'll take you longer to crack it. We're increasing the difficulty. " We'll increase it.
Then 1024. Right. We'll increase it.
Now 2048. So we're upping the level of difficulty or the complexity, and that buys you more time. But with a quantum computer, that's almost an irrelevant number because the way it attacks that cryptographic cipher, if you will, makes it irrelevant, whether it's 512 or 124 or 2040, it's going to crack it relatively really very fast, and so we need a new way of looking at it.
Now, here's the good news, of course. Right? NIST working with DigiCert- Yeah ...
industry, public, private, we do have post-quantum algorithms in use today, actually. In LPN. Or being rolled out.
Yeah. Matrix lattice, lattice-based algorithms. So lattice-based mathematical model is very different from prime factorial.
And these algorithms are proven, again, this is buying you time, and maybe it can buy us a lifetime. Right. But again, it's buying us time before the next compute wave- Wow ...
then comes and challenges it. So can I ask you, it's kind of a layman's question, but it's like a mainstream reporter question. How has the influence of AI changed this whole dynamic or calculus versus, say, when cloud was the buzz?
Has this added even more pressure, more time constraints? When you talk about sprawl, I think about this as like a race against time. Absolutely.
And I think cloud enabled elastic workloads. Mm-hmm. It enabled you to have compute power without huge capital investments.
That was the wave and the era of cloud. Right? And it, in a way, democratized the access to compute.
It wasn't just the large companies with hundreds of data centers around the world that had the compute power. If you were an up-and-coming startup or a midsize company, you could go elastic on demand on how much you wanted. So that was the era of cloud.
Right? Compute power, democratize access to it, and enable faster execution for business objectives. Now, when you think about AI and you layer it, now these are all orthogonals.
Right? There is still cloud today. It's not gone away.
We still have containers. We still have microservices. And so when you add AI on top of this, what AI does beautifully is that it learns and then it infers.
It doesn't just do. So when it infers and it's thinking, then it starts to learn more, and agentic AI has become very cohesive. There's a cohort of agents working together now, and each could be specialized in, someone just understands this part of the mathematical algorithm.
Another agent can be great at the integral calculus part of the algorithm. Right? And there's another agent that just understands the physics associated with processors and semiconductors and the power you need and all of that.
Now you put them all together, you have the brilliant minds, AI minds of physics, you have semiconductors, and then you have math in the room. What are we going to get? A dangerous mind.
A dangerous mind. And that really, to me, is a thing I- That sounds like a TED Talk, actually, the way you laid that out. I would- Yeah ...
go. I'd listen to a speech on that. Listen to that.
Yeah. Well, she's a pretty effective communicator. Absolutely.
But I almost think of it as, to detonate a hydrogen bomb, you got to have a fission bomb. Mm-hmm. Right?
AI is a catalyst, an igniter for what we will see with quantum. It may help us get to Q-Day quicker because it'll help us as we try to develop true quantum computing. But combining those two is a, what's the word?
An explosive mixture, if you will, where both of these are huge accelerants together it's a squared. It's exponentially more. And I think that's what we have to worry about.
I know we're almost out of time. One other aspect, though, of this quantum puzzle we need to acknowledge is, look, there's a lot of bad guys because they're not stupid either. And they are accumulating.
And my mind is blanking on the term. It's harvest now, decrypt later. Harvest now, decrypt later.
A lot of them are harvesting encrypted payloads now with the thinking that, look, Q-Day is going to be here. It's not five or 10 years out. It's maybe a year, two years, three years at the most, if you listen to IBM.
And when that day comes, they're going to have all this encrypted, valuable data, though how valuable it'll be depends how far out in the future it is, but they're going to decrypt that and use it. Now, that data, to me, is sort of like radioactive data. It has a half-life.
Over every certain amount of months or years, that data degrades in usefulness. Diminishing in value. Yes.
But there's so much of it that they've been harvesting. And this is going to be a real problem, because when Q-Day comes, it's not just the good guys who are going to have it. Is China going to have it?
There's been a lot of recent developments in China's quantum. Today or yesterday, I think they announced their own native chip. Yeah.
The C950, I think- Yeah ... if I'm not mistaken. And they're giving other semiconductors a run for their money.
Absolutely. They have indigenous chips for their use, and it's from Alibaba. Yeah.
Don't sleep on that. You can't, because they're going to put a lot of resources, the same way they do in AI. So look, we're about out of time, but the important thing, if you take one thing out of this, what I'd like you to take out of it is you've got to be preparing for a post-quantum world now.
Don't be asleep at the wheel and let this sneak up on you. It's real, it's coming, and you need to be working on thinking about it right now. " This was a little bit of a different gang.
But I do want to mention one other thing. Now, I'm going to announce it here. First time we're announcing this.
We are going to be doing a multi-part podcast, I think it's six or 12 episodes to start, with our friends at Digicert, including Lakshmi, on... It's from AI to quantum and everything in between. And as I said before, it's a volatile mixture of what this could be.
" We're going to take a quick break from the gang here. We're going to come back. I think we're going to talk a little more Digicert.
Then we've got Black Cloak and a lot of other great coverage coming your way. We're live at RSAC in Moscone. "