The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Hacker Valley Studio
Hacker Valley Studio artwork

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

Hacker Valley Studio · 2026-08-12 · 31 min

0:00--:--

Key moments - from our scoring

Substance score

52 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber12 / 20
Specificity & Evidence10 / 20
Conversational Craft10 / 20

Michael Fasulo, Senior Director of Portfolio Marketing at Commvault, breaks down the quantum computing threat landscape and why organizations can't afford to wait on post-quantum cryptography (PQC) adoption. The conversation centers on the "harvest now, decrypt later" attack pattern - where nation states and sophisticated threat actors collect encrypted data today, banking on quantum computers to decrypt it in the future. Fasulo estimates commercially viable quantum machines could arrive within four years, much sooner than the 10-20 year timelines analysts previously quoted. He highlights that government executive orders, NSA pivot to "forge now, trust later" messaging, and massive quantum funding demonstrate this is no longer theoretical. Target sectors include critical infrastructure, government agencies, financial services, oil and gas, and organizations with operational technology (OT). Commvault's approach centers on crypto agility - a framework allowing organizations to switch encryption algorithms on the fly as NIST certifies new post-quantum standards. For sensitive data like biometrics, government IDs, and long-lived records, the stakes are highest since compromised data has multi-decade value. The episode covers TLS 1.3 requirements, cryptographic discovery challenges, data at rest versus in transit protection, and why hyperscalers like Google and Zoom are already upgrading infrastructure.

Key takeaways

  • →Quantum-capable decryption could be feasible within four years, not 10-20 years, making immediate PQC adoption urgent rather than speculative.
  • →The "harvest now, decrypt later" threat targets long-lived sensitive data like biometrics, government documents, and financial records that remain valuable for decades after collection.
  • →Critical infrastructure and government agencies are primary targets, but financial services, oil and gas, and organizations with OT systems face significant quantum-era exposure.
  • →Crypto agility - the ability to switch encryption algorithms without service disruption - is essential since no single post-quantum standard will remain secure indefinitely as quantum capabilities evolve.
  • →Organizations must conduct cryptographic discovery to inventory existing encryption methods and understand their data footprint before deploying post-quantum protections across data at rest, in transit, and in use.

Guests

Michael Fasulo

Topics in this episode

Post-Quantum Cryptography (PQC)Crypto agilityNISTShor's AlgorithmHarvest now decrypt laterMicrosoft SentinelTLS 1.3CommVaultRSA SecurityAES-256

Questions this episode answers

What is harvest now, decrypt later and who targets it?

Harvest now, decrypt later is a cyber threat where adversaries collect and store encrypted data today, planning to decrypt it once quantum computers become available. Nation states, critical infrastructure, governments, financial services organizations, and those with long-lived sensitive data like biometrics are primary targets.

How soon will quantum computers break current encryption?

Michael Fasulo estimates commercially viable quantum machines capable of breaking current cryptography could arrive within four years, based on government investment, quantum company funding, and algorithm optimization trends - significantly sooner than previous 10-20 year estimates.

What is crypto agility and why does it matter for post-quantum cryptography?

Crypto agility is the ability to switch encryption algorithms without service disruption. It matters because as quantum capabilities evolve and NIST certifies new post-quantum standards, organizations need to pivot quickly; no single algorithm will remain secure indefinitely.

Are hyperscalers like Google and Zoom already protecting against quantum threats?

Yes, hyperscalers are upgrading to TLS 1.3 and deprecating legacy protocols as a substrate requirement for eventual post-quantum algorithm deployment, preparing their infrastructure for the transition even though full PQC rollout is still pending.

What types of data are most vulnerable to harvest now, decrypt later attacks?

Long-lived, immutable data like biometrics (ocular scans, face scans), government-issued IDs, Social Security numbers, bank account numbers, and ground schematics are most vulnerable because they retain value for decades and cannot be changed if compromised.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode delivers moderate substance on post-quantum cryptography fundamentals and organizational readiness, but relies heavily on general principles (harvest now decrypt later, crypto agility, cryptographic discovery) that are already well-circulated in security discourse. While the historical Deep Crack analogy is effective, much of the content amounts to rephrasing the same core threat and solution narrative without novel tactical depth or surprising claims.

storage is cheap, so it's likely that they're keeping it in a store for a long term
crypto agility is super important too

Originality

9 / 20

The thinking is competent but largely conventional. The guest repackages NIST guidance, standard threat vectors (government, critical infrastructure, financial services), and widely-known concepts (harvest now decrypt later, crypto agility, TLS 1.3 readiness). The four-year timeline estimate is presented as original insight but lacks rigorous backing beyond pattern observation. No contrarian angles or first-principles questioning emerge.

I would say it's probably going to be in the four year time frame
crypto agility is super important too

Guest Caliber

12 / 20

Michael Fasulo holds a senior director title at Commvault and clearly has enterprise customer engagement experience, but he functions primarily as a vendor spokesperson rather than an independent practitioner with proven execution in cryptography or quantum defense. He discusses conversations with customers and boards rather than shipping real solutions or deep technical implementation. His credibility is bounded by his role.

a good amount of customers. Uh, I can certainly tell you that the trajectory has been a lot closer than we've expected
I get to have some of those conversations

Specificity & Evidence

10 / 20

The episode lacks concrete numbers, named customer examples, or detailed case studies. References are vague ("executive orders," "conversations with C suites," "certain hotspot areas") or historical (Deep Crack, RSA cracking proof of concept with unstated bit rate). No specific timelines for NIST certification, no metrics on adoption rates, no named vendors beyond Commvault itself and oblique references to hyperscalers. The organizational readiness advice is procedural rather than evidenced.

There was an article not too many months ago where they took the RSA in a very infancy form. I forgot the bit rate it was at
a lot of boards that we talk to still think that this is in the science fiction category

Conversational Craft

10 / 20

The host asks straightforward setup questions that allow the guest to deliver prepared talking points rather than probing for tension or specifics. Questions like "What's the current state of post-quantum cryptography?" and "Walk me through capabilities" are predictable. Few genuine follow-ups challenge vague claims (e.g., the four-year timeline gets accepted without pushback on methodology). The conversation is friendly but lacks the friction that would surface deeper insight.

So walk me through some of the, I guess, the lessons that you all leave behind
So it sounds like if organization, uh, wants to use commvault, you all are going to help them inventory

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B61%
  • Speaker A39%

Most-used words

data39quantum20start20security14sure14commvault13later12today12sensitive11algorithms11decrypt10customers10government9deep9michael9conversations8

Episode notes

What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open? That's the threat behind "harvest now, decrypt later," and it's closer than most people think. Ron Eddings sits down with Michael Fasulo, Senior Director of Portfolio Marketing at Commvault, to talk about where post-quantum cryptography (PQC) really stands in 2026. They discuss "harvest now, decrypt later," the specific industries quietly racing to prepare, and why a commercially viable quantum machine might only be four years away. Ron and Michael trace the journey from a 1998 hack to today's quantum race, and the good news is there's still time to get ahead of it. Listen to hear where the real opportunity is, and how to start building your defense today. Impactful Moments00:00 - Introduction01:40 - Rewind: the 1998 Deep Crack story04:10 - Michael Fasulo and the current state of post-quantum cryptography in 202605:05 - Harvest now, decrypt later: do people really have the storage to do this?06:10 - Where is this actually happening? Nation-states vs.

Full transcript

31 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: When it comes to, uh, pqc, you always hear something called harvest now, decrypt later. Who else will be a target when it comes to that type of approach?

Speaker B: Critical infrastructure, and then obviously the government. It's going to be part of that attack chain. This is going to be a larger exposure later on when these viable quantum machines are available to these threat actors.

Speaker A: Are we currently behind? Should we have been working on this yesterday?

Speaker B: It's very much a yesterday issue that we should have been doing it. A lot of boards that we talk to still think that this is in the science fiction category. Category. Once we start to see these exposures, you don't want to be on the receiving end of it. It's not too late.

Speaker A: What's going on? Hacker Valley Fam. Welcome back to the show. It's your host, Ron Eddings. And right now most people are caught up in the world of AI agents and trying to outsource their work and business. And they're missing something that's even more important. That and that's stopping the prying eyes of data and transit. If you haven't already heard, there's these things called quantum computers. And analysts were saying that they were 20 years away and now analysts are saying, no, no, no, they're 10 years away. And my guess for this episode is saying, no, they're four years away. So without further ado. Roll the intro.

Speaker B: Who says tech can'?

Speaker A: It's time for the Rewind. July 17, 1998. A, ah, civil liberties nonprofit called the EFF enters a contest run by RSA Security. The challenge was to crack a message encrypted with destination. The 56 bit encryption standard that have been protecting the US banking, government and corporate data for over 20 years. They built a machine for the contest and it cost them around $250,000. They called it deep crack and it found the key in under three days. The message underneath, once they decrypted it, it literally said, it's time for those 128, 192 and 256 bit keys. That's a good one by RSA Security. Here's what that meant for actual people, not just the cryptographers like RSA Security. And EFF DES was something that wasn't just academic. It was used for ATM transactions, government communications, corporate VPNs. There wasn't a lot of people online in 1998, but two decades of security got unraveled in just under 56 hours. And it was all by an organization that was a nonprofit that only had A six figure budget to complete the challenge. Within a year, the federal government formally moved on from just 56bit des to triple des. And not long after that, the whole industry migrated to AES, which is a standard that we still use today. When it comes to this challenge by RSA Security, the lesson wasn't really about des. It's that secure has an expiration date and that expiration date is never really announced in advance. And that's the exact shape of the conversation and interview that we're about to jump into. Except for this time, it's all about quantum computers and they have a much greater capability than that $250,000 device. Deep crack the stakes. They've never been higher because pretty much everything we use has an IP address and touches our WI fi routers or the Internet. So without further ado, let's jump into the interview today. My special guest is Michael Fasullo, senior director of portfolio marketing at Commvault. And Commvault was gracious enough to sponsor this episode. Big shout outs to Commvault. Uh, but most importantly, Michael, welcome to the show.

Speaker B: Thank you for having me. It's going to be awesome, ah session today.

Speaker A: It's going to be an awesome session. I wanted to start off with a question. What's the current state to post quantum cryptography? What does that mean in 2026?

Speaker B: Yeah, so a good amount of customers. Uh, I can certainly tell you that the trajectory has been a lot closer than we've expected and there's a lot of good traction that we've had with not only how organizations can start to prepare for, but really activate some of those plans that they've been building. Uh, I know AI is getting lots of funding, but we've had lots of good deep conversations with C suites on getting funding for qu them, especially in certain hotspot areas and verticals, uh, where they have long term sensitive data, which is really, you know, what you want to defend against today. So it's uh, certainly been increasing in the velocity and we're starting to see funding really coming through on the customer end.

Speaker A: If you are in the PQC world of any of any state, you always hear something called harvest now, decrypt later. Do people actually have the storage like companies? I would imagine that they do because I heard that Facebook is literally monitoring every action that their users are doing. So that means like anything that you open up on your computer is being monitored, but then it's being shipped off to the cloud. So people definitely have the bandwidth and the volume to not only store it, but now it sounds like to even transfer it.

Speaker B: Yeah, that's right. And look, storage historically has been cheap and maybe not so much today, especially with some of the supply chain issues that we've seen. But consuming cold cloud storage, um, is relatively affordable. So if folks are in the business of harvesting now, certainly, um, that data is kind of sitting in storage where they're going to hopefully, or hopefully not hopefully, um, mitigate some of these attacks and not be able to decrypt that later. But again, storage is cheap, so it's likely that they're keeping it in a store for a long term.

Speaker A: Have you heard of any events or activities that. I mean, everybody goes to coffee shops. Is this happening at your coffee shop? Like, are people going there with their, you know, wireless antennas and, and sniffing down data to hopefully decrypt it later?

Speaker B: Yeah, I mean, look, it's, it's probably not happening at coffee shops. Um, you know, you're probably dealing with like nation states and, and other like larger hacker groups. But you know, I, I always go back to the fact that obviously in the business that we're in, you kind of see a lot of these breaches and threats and they always talk about exfiltration. And when I think about exfiltration, it's like, I hope they're not harvesting that data now to decrypt it later. So, you know, it's, it's going to be part of that attack chain. Um, so every time I kind of see that in the news, I always wonder if this is going to be a larger, you know, exposure later on when, you know, these, these viable quantum machines are available, uh, to these threat actors. If we're going to start to see, you know, super sensitive data get leaked after the fact or re. Ransomed, uh, depending on their tactics. So it's, it's certainly viable, but it's probably not happening in a, uh, in a coffee shop. And then, you know, not to, you know, spread any kind of conspiracy or whatnot, but every time you start to see like, you know, fiber optic cables getting cut in the, in the ocean or you see these large Internet trunks kind of going down for some weird reasons that they can't explain. I always wonder if there's like, you know, next level, um, m, you know, like espionage type of thing going on where there's starting to steal data directly from these types of things. So, um, you know, probably not a coffee shop, but probably m a much more sophisticated operation.

Speaker A: You know, even though it's probably not happening at a coffee shop, I'VE been the person that has been at a coffee shop collecting traffic, using wireshark and seeing. All right, is. Can I see the data in clear text at the time? No, I couldn't because it was still being encrypted by. There was still some, uh, level of security by the wireless router itself, but I at least collected it. And luckily for everyone at the coffee shop, I didn't have the intention to try to do something with that with it after the fact.

Speaker B: Yeah, yeah. And look like we do that as kind of a proof of concept to make sure all the headers and things are all using pqc, like, um, algorithms. So, yeah, certainly, uh, you're kind of a leg up and, and identifying that, you know, people are using, you know, existing algorithms for classical machines or, you know, if they're using our product, you can certainly sniff those packets and see the PQC headers. So.

Speaker A: So like you mentioned, maybe nation state, you know, targeting other governments would be interested in. Harvest now, decrypt later. Who else will be a target when it comes to that type of approach?

Speaker B: Yeah, I think, uh, we have a couple of hotspots at least from the conversations that I have. Government, uh, is certainly one of them. Uh, and if you look at all the executive orders, uh, especially in the last month or so, uh, that at least the US government has signed, there's still a lot of stuff going on in emea. Um, you know, governments are paying attention, uh, and they're making sure that these requirements are extended to other things like critical infrastructure. So I think those are your two big hotspots. Critical infrastructure and then obviously the government, uh, financial services. We have lots of conversations with financial services organizations and then I think the two kind of surprising ones are oil and gas and organizations that have a lot of ot. Um, OT poses a particular, uh, challenge for quantum threats. Not necessarily harvest now, decrypt later, um, but certainly in that same, um, realm of understanding how they're going to defend their OT devices against quantum threats in the future. So certainly, uh, an interesting bag of conversations, uh, that we have kind of broad spectrum.

Speaker A: The last few cybersecurity jobs that I had, we were heavily into the SaaS space. Like all of our apps were SaaS based. And I would imagine that, you know, when it comes to pqc, it depends on the applications that you're using. So, like looking at things like Zoom, um, looking at things like your Google Mail, like, are those things implicated right now?

Speaker B: Yeah, yeah. And look like even with the hyperscalers and if you're noticing a lot of not like PQC based talk track, but you would see notices about upgrading to TLS 1.3 and deprecating some of the legacy protocols. And something like TLS 1.3 is a requirement for post quantum algorithms. So reading the tea leaves, a lot of these organizations had no choice but to uh, really further uh, the tech stack with things like TLS 1.3 to make sure that it's primed for when we need to deploy post quantum algorithms and making sure that the substrate and the network are all ready for these larger, um, packets and certificates, um, and having the compute to make sure you can process them. Uh, it's not just flip the switch like it has been in the past where it's like, all right, we were using triple DES and now we're going to use something else. It was like, all right, just what the algorithm. Um, that's no longer the case. So there's a lot of intricate details that need to be updated and upgraded. Um, and then depending on how the landscape evolves and how algorithms like Shor's and quantum machines become more powerful, it's not unlikely that we'll see even the underlining math like lattice for the algorithms that will probably talk about today. Um, you know, if that gets cracked, you need to have alternatives. So NIST has been really looking at the situation that we had with Psych, which was, you know, an algorithm that went a couple rounds before it was cracked, uh, by a classical machine. Um, you know, there needs to be a plan A and a plan B and there's probably needs to be a plan C just in case because everyone's going to have to pivot. And that's why crypto agility is super important too.

Speaker A: So if I was still working in the enterprise, you know, my boss, maybe the CISO or someone else will come to me and say, hey, I need you to investigate this PQC thing because our board says it's important and we need to start preparing for it. So I go to Google, type in PQC providers and I'd probably come across commvault. So walk me through some of the, I guess, the lessons that you all leave behind and uh, some of the capabilities that you all provide.

Speaker B: Nobody else in our space was kind of talking about PQC and Apple was talking about delivering it as part of imessage and that was enough. Throughout that process we were looking at how do we make a durable process that if things start to change, we can make sure that we continue to protect Our customers. Because remember, these capabilities are for your most sensitive data, your data that may live forever. Uh, so if you think about ocular scans or face scans, these are immutable things that can never change. It can't change the characteristics of my face. So, you know, securing that data needs the utmost, uh, security and trust, uh, that our customers expect from us. So, you know, going down that path, uh, it was certainly a journey. And you know, we had to do a lot of hard work because no one had done that in our space before. So we decided we were going to have a crypto agility framework in the process in the product. If we had a switch, you know, an algorithm overnight, we'll be able to do it. Um, you know, a lot of us here, you know, keep our finger on the pulse with nist. You know, as algorithms are changing, as they're getting certified, as they're going through the different stages, you know, we make sure that, you know, we can, we can switch on the fly and start to, you know, re encrypt our network traffic so that we could defend against these threats as we move forward.

Speaker A: So it sounds like if organization, uh, wants to use commvault, you all are going to help them inventory all the different, uh, cryptographic algorithms that they're using for communication. So if I'm using custom, uh, application, I'm going to have that in some type of inventory. I'll be able to make informed decisions based off of what comes out, whether it's a quantum computer or a weakness or a vulnerability in an encryption library.

Speaker B: Yeah. So for not wide sweeping. Right. And I think that's the current challenge that the landscape has today. It's how do we do wide sweeping cryptographic discovery? Um, because we touch data, it's very easy for us to understand the data footprint that we have at our disposal. Uh, we have some telemetry tools and security tools that exist in the stack that allow us for the things that we do touch to be able to supply that. Then obviously our data retention policies that you need to secure your data with are well known within the product too. So you could use a lot of that to drive some of the decisions that you're going to have. Uh, for the data that we do touch, for everything else, that's going to be your shadow. It, um, I'm sure on a couple sessions you guys have talked about shadow AI because that's kind of happening behind the scenes. You're going to need different tools in your toolbox to discover and figure out how you're going to classify and corral that. So that discovery process kind of falls a little bit outside of our product. But you know, for the data that we do touch, certainly it's going to be within our wheelhouse. We'll be able to identify and then obviously provide you with all the deep details on how we're going to secure that. You know, with traditional data at rest, uh, algorithms like AS256, still very valid as a quantum resistant algorithm for data at rest. And then obviously PQC for anything that's kind of traveling over the wire. And then the other thing that we do supply is the capability to run and protect like confidential, ah, compute. So if you're super concerned about data in use cases, uh, we certainly support those capabilities too for our highly sensitive customers, um, we can run and protect those particular instances and the data that runs on that. So for us we got the entire sweep of data at rest, data in transit and data in use on lock.

Speaker A: If you're in this space. One thing that I would be very comfortable with, especially with someone like you all commvault, the one rule that they teach you in every university, every organization is don't roll your own. You gotta provide, uh, you gotta work with a vendor or an existing library piece of technology. So congrats to you all for being in such a, uh, defensible space. You know, I know that everyone right now is so hot and bothered with the AI SoC. So I love the fact that you all are kind of like approaching security from I think fundamental standpoint. Like the first fundamental piece is knowing thyself. But then it's like, all right, after I know myself, how do I make sure that if I need to share something with someone it's not going to be tampered with or discovered in the adverse, uh, ways or adverse consequences.

Speaker B: Yeah, no doubt. And I bubble that all down to trust, right? Uh, like these capabilities are what customers trust us with. And again, if data's the lifeblood and you're dealing with highly sensitive data, you gotta have trust in your vendors. And the other great part about our platform and how we approach partners is we don't try to solve every single problem ourselves. Um, where partners have best of breed capabilities and solutions, um, we have deep integrations and sometimes they're bi directional integrations. So when you talk about soc and you know, um, Microsoft Sentinel is a great example, right? Like we have a bidirectional integration with Sentinel. We can push telemetry out of our platform into their platform. We have runbooks that can Orchestrate recoveries and clean rooms on our end. So you know, we, we don't try to solve every single problem ourselves. Uh, where we have best of breed tools. We, we try to do like deep integrations that deliver uh, a lot of customer value, especially across Personas.

Speaker A: I have a gut feeling and this is just from my own experience and things that seem on the news and all around and even just going down these deep dark rabbit holes of especially that AI has been leading me down. Um, but I have a feeling that someone has this capability already, which makes it even more important. I would not be surprised if there was a nation state that had some level of decrypt capabilities. Uh, we've already seen this before with uh, our own United States government ssh and being able to tackle uh, some of the weaknesses of the protocol. So I would imagine that that's, that happens. Like is there news that comes out that the word that exposes weaknesses in protocols as of late?

Speaker B: Yeah, I mean look, there was um, there was an article not too many months ago where they took the RSA in a very infancy form. I forgot the bit rate it was at. Ah, it was in the, you know, maybe double digits and they were able to crack it as uh, like a proof of concept. Um, you know, so look, that brings validity that it's, it's possible. Right? Um, you know, if you want like the, the fasulo hot take on when I think the, a commercially cryptographic viable quantum machine is going to be available. I would say it's probably going to be in the four year time frame. And uh, I say that not completely baseless. Uh, I'm sure there's plenty of people like you're strict tripping. But you know, uh, let me, let me, let me unpack that just a little bit. Um, so look, governments signing executive orders, that means they're taking it seriously. Uh, the NSA recently talked about one of the other parallel, uh, threats of Forge now, um, trust now, Forge later threat. So them kind of pivoting. I think they're, they're really understanding how this is going to play out in the field. Uh, you're seeing the US Government at least um, investing in these quantum machines for quantum supremacy, uh, which is important from both a uh, defense and innovation, uh, standpoint. You're seeing the stocks of these quantum companies um, continually travel, uh, upward and you're seeing a lot more quantum hitting the news cycle, hitting the hyperscalers, uh, showing up at events. So I think those become kind of the way for us to say there's an influx of money, um, they're getting best of breed talent, uh, into these companies. You're seeing uh, some pockets of innovation throughout the world, both in China, uh, certainly in Europe and even in Canada, uh, lots of focus on these things. So with that I think you're going to start to see the technology start to increase. You're going to see cubic count go through the roof. I think you're going to see algorithms like shores be consistently optimized. And then with that influx of cash, I think you're going to hit that crossroad of algorithms being better, faster, machines being more capable. And it's going to bring that 20 year, 10 year um, timeline down to around 20, 30 where I think someone's going to have one of these things where it's Q day is going to be the reality of when these machines are going to be available in someone's hands where they'll be able to do something. All those things kind of working together. It's really important that you know, people start that journey sooner rather than later. And hopefully they're already down that journey. And that's why we as uh, Commvault kind of took that seriously. So it's one less thing that you know, our mutual customers need to, you know, really consider. And for us touching sensitive data, um, it was a no brainer for us to kind of put that out there. So protecting that was one less thing our particular customers need to not have to worry about as much. And then obviously we have a tooling that kind of helps them down that journey. So uh, it's our promise.

Speaker A: Love it. And like you said, four years is not that long of a time away. If you look at your driver's license, you pull that out is probably longer than four years away. So if someone were to get that, and that's just one example. If you work at a major corporation, a lot of major corporations take employees from all across the world and they're all sending them their passports. They gotta send those two forms of identification. Passport and Social Security number or passport and birth certificate. Goodness gracious. Like if, if someone was outside of the office just sniffing and capturing all that HR data, I mean it'd be a gold mine. Maybe some of those things would be. And documents will be expired after four years or even 10 years, but some of them will still be active. You know, a lot of people have bank accounts for 20 years, 30 years. You know, a lot of loans are 30 year loans. That account number isn't changing and neither is your Social Security Number either.

Speaker B: Yeah. And, and some of those things are, are a little easier to rotate. Right. And you know we, we hear about like Social Security fraud and those types of things all the time. But you know, when you start to get into like biometrics, um, where those things are somewhat immutable, it's just like how, how are those organizations that use those, that data for identification really securing those things? Uh, and you know, luckily I get to have some of those conversations. So um, you know, for them that use Commvault, I know least them protecting the data as it's moving in transit is, is protected with pqc, uh so it's a lot easier to sleep at night. But when you think about those types of things or you know, even like ground schematics of where natural gases, um, you know, those are highly sensitive things. So when we work with our customers we always open up with where is your most, you know, highly sensitive data that is long lived because that's really the hotspot for harvest now, decrypt later as I'm sure AI is going to be, you know, producing sensitive data to um, whether they be trade secrets or things that need to be patented, um, you know that's going to kind of fall into that bucket also.

Speaker A: So I mean I put all my data into Chad GPT. Everything goes in there.

Speaker B: We'll have to talk about that in another show.

Speaker A: Are we currently behind? Like, is it like should we have been working on this yesterday or is today actually like a really good time?

Speaker B: Yeah, I mean I get that argument. Like look, I don't have really long term sensitive data and then you start to have those conversations and they're like, oh yeah, maybe I do. Um, so usually we, we have that conversation like day zero right before we even like directly engage and talk about tactical things and stuff. Um, you really want to get that footprint and that's why it's really important to not only involve it or even the security team. Right? You want to have legal, you want to have ops, you want to have leadership, uh, you really want to get that good survey. And it's not that it's not too late. Uh, we can certainly start to get that ball rolling. Uh, cause now is better than waiting for threats to go through. And once we start to see these exposures, um, you don't want to be on the receiving end of it. And if you look at the catastrophic damage that was done for someone like Jaguar Lambrover, uh, and the impact it had even on the local economy, um, you don't want to be that guy. So it's very much a yesterday issue that we should have been doing it. And if you're not down that path, um, let's have a conversation and start it, uh, whether you're a commvault customer or not. Right. Like, there's all kinds of discovery aspects and classification that you could be doing today. And obviously, our goal is to make sure that customers are protecting their data. And obviously we have a tool set that aids in that. But, you know, securing these things is of the utmost importance. So happy to help where I can.

Speaker A: What's the one thing that, you know, someone that's concerned about this challenge and problem space, what's the one thing that they could do next week to be a very valuable first step?

Speaker B: Yeah. Depending on where you sit in the organization, I always recommend that you start to have those conversations now. Talk to your CISOs, talk to your CIOs, and try to get some advocacy at the C suite. Because again, a lot of folks, a lot of boards that we talk to still think that this is in the science fiction category. Uh, so getting some advocacy and buy in and then again, taking pragmatic approaches, not about deploying tools or buying tools out the gate, really doing cryptographic discovery. Understand where your sensitive data is, understanding your crown jewels. Like, what does it take to really bring back your minimum viable business? These are things that you can do. M adjacent to doing quantum, uh, protection and resiliency and start there.

Speaker A: One thing that's going to be much easier after you get that buy in, like Michael's talking about is just calling Comm Vault. So, Michael, I wanted to give you one last opportunity to share exactly what commvault does and how would someone, you know get in contact with you all the fastest?

Speaker B: Yeah, so. So obviously, hit me up on LinkedIn. Uh, I love working with customers and prospects and even our partners, uh, all day, uh, as you can tell, or hopefully you could tell, I'm very passionate about this subject matter and building trust, uh, and making sure that, you know, this. This moves out outside of the science fiction realm into, you know, the reality that we're in today. Whoever you are, if you're interested in this subject matter, let's, like, certainly have a conversation.

Speaker A: It's time to at least start. You got to start somewhere. And I think now is a really good time. Michael, I'm wishing y' all nothing but the best. Wishing you nothing but the best. Wishing Commvault nothing but the best. And thank you again for coming on.

Speaker B: Appreciate you Having me M. Thanks again.

Speaker A: All right, so I open up this episode with Deep Crack, a $250,000 machine built by a nonprofit that unraveled 20 years of security in just 56 hours. I keep coming back to that story after my conversation with Michael, and here's why. The parallel that's sticking with me is that Des didn't get weaker over the 20 years. The math didn't change. What changed was the cost of breaking it. It went from unreasonable for anyone to achievable by a nonprofit with a prize budget. That's the exact thing that Michael was describing that's happening right now with Quantum. It's not that RSA or elliptic curve is getting weaker overnight. It's that the cost of breaking them is on a countdown. And that countdown is funded now by governments, hyperscalers, private capital, and they're all pouring in at once. Michael pretty much laid out every budget line item that you'd look for. Executive orders, C suite conversations, Quantum stocks, they're climbing. And hyperscalers. If you look at the details closely, they're upgrading to TLS 1.3 behind the scenes. That's the same pattern that preceded Deep Crack, just with a much bigger budget and also a much scarier target. The data that is getting scooped up right now is real. It's sitting in someone's storage today. It's probably a nation state data center, and there's no contest announcing to warn you that you should finally upgrade your keys. So the question that I can't fully shake, how much have we already sent that's encrypted and it's been over the years and we assume that it's all been safe. How much of that is sitting somewhere waiting for someone to decrypt? I don't think the answer is the panic. I think it's the same instinct that mattered in 1998. It's the same instinct that matters today. And I actually wrote a book on it. It's called Attack Surface Management. You must take inventory and know what you're protecting before someone else forcefully brings that to your attention. I gotta give a big thank you to Michael and the commvault team for helping put this episode together and over also sponsoring it. They had extreme, uh, guts. Because this is a conversation and a topic that most vendors are turning a blind eye to. But Commvault is walking directly towards it. As always, make sure you're subscribed to the Hacker Valley studio wherever you're listening or watching. And with that, we will see everyone next time.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The DoD's "Basic" Cybersecurity Isn't Basic at AllSum IT Up: CMMC News Roundup · on NIST93 / 100
  • The Prioritization Problem: Securing AI While Preparing for Post-QuantumThe Identity Thread by Entrust · on Shor's Algorithm86 / 100
  • Lead-Lag Live | Christopher Gannatti, WisdomTree - The Quantum Computing Investment Case | WQTM ETFLead-Lag Live · on Shor's Algorithm83 / 100
  • Fighting Fire with Fire: How CyberProof Is Automating Cyber Defense with Edy AlmerCyber Sentries: AI Insight to Cloud Security · on Microsoft Sentinel80 / 100
  • Trump's Golden Post-Quantum EO(s)Security Cryptography Whatever · on Post-Quantum Cryptography (PQC)80 / 100
  • Think Like an Attacker: Microsoft Security Exposure Management with Uros Babic [MVP-MCT]M365.FM · on Microsoft Sentinel78 / 100

More from Hacker Valley Studio

All episodes →
  • What's Really Stopping AI From Running Your SOC with Aqsa Taylor64 / 100
  • Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard
  • Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White
  • What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey
  • We Shipped a Tool That Acts Like You. Meet Interceptor.
Explore the best B2B Engineering & DevTools podcasts →
All Hacker Valley Studio episodes →