
The Identity Thread by Entrust · 2026-07-09 · 55 min
Key moments - from our scoring
Substance score
66 / 100
Five dimensions, 20 points each
The White House's recent executive order on quantum readiness has compressed timelines for federal agencies to transition to post-quantum cryptography, driven by accelerating quantum computing development from tech giants like Google and Microsoft. Dr. Ed Mayes from U.S. Customs and Border Protection, Alice Fakir from IBM Federal, and Michael Kleiman from Entrust discuss the dual challenge: quantum computers threaten to break encryption via Shor's algorithm and harvest-now-decrypt-later attacks within 2-3 years, while enterprise-scale cryptography migration typically requires a decade. The conversation reveals that cryptography is embedded throughout all systems - from traffic control infrastructure to firmware signing and digital signatures - making piecemeal upgrades ineffective. Dr. Mayes shares CBP's proof-of-concept experience with post-quantum algorithms, discovering that performance impacts were smaller than expected but that crypto agility, device constraints (like PIV card chip capacity), and certificate interoperability across on-premises, hybrid, and cloud environments create intricate dependencies. The speakers emphasize that federal agencies must move beyond asset-count approaches toward integrated enterprise-wide orchestration, working collaboratively with vendors across compute, storage, and network infrastructure to understand real-world deployment challenges.
Quantum computers with cryptographically relevant capability are expected by 2028-2029, just 2 years away, according to accelerated hardware timelines from Google, Microsoft, and U.S. government quantum initiatives. Enterprise-scale migration takes significantly longer than 2 years, making immediate planning and pilot projects essential.
Adversaries are already collecting and storing encrypted data today, planning to decrypt it once quantum computers become available. The executive order accelerates the NIST timeline because the pace of quantum advancement is faster than previously expected, compressing the window before this threat becomes real.
Cryptography is embedded throughout all systems - applications, protocols, firmware, digital signatures, PIV cards, and validators - so upgrading individual assets fails unless the entire ecosystem simultaneously accepts post-quantum algorithms, or adversaries can forge signatures using non-updated validators like operating systems.
CBP found that post-quantum algorithms showed less performance impact and latency than expected, but uncovered unexpected complexity: cryptography is intertwined throughout applications and tools, calling other services in hidden ways, and constraints like PIV chip storage, certificate dispersal, and vendor coordination across on-premises, hybrid, and cloud environments require deeper planning than anticipated.
Crypto agility is the ability to switch cryptographic algorithms as new vulnerabilities are discovered or better algorithms emerge. Agencies must support multiple algorithms simultaneously during transition (old and new), handle different certificate types across hybrid environments, and ensure all validation systems enforce post-quantum requirements or risk enabling quantum-based forgery attacks.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers substantive technical ground - harvest-now-decrypt-later attacks, Shor's algorithm, crypto agility, PKI strategy, and the complexities of cryptographic infrastructure migration - but much of the discussion is explanatory rather than novel. Dr. Mayes provides some concrete learnings from CBP's proof-of-concept work (latency surprises, the pervasiveness of cryptography), but the core insights are fairly well-established in security circles. The discussion of prioritization and the blocking-and-tackling nature of most organizations is useful but not deeply original.
we discovered as a whole was you, you, you, you know, you go into something and you start notice, like unraveling a ball of yarn and you think, you know, where all the strings go, right? But what you find out with, you know, uh, cryptography, right, and encryption is, it's everywhere.
organizations have got to start moving faster uh, and thinking broader uh, when it comes to here's what good looks like and here's what the capabilities are that they need to have in place to deal with the threats of the day.
The framing around post-quantum cryptography readiness is timely given the recent executive order, and Dr. Mayes's anecdote about CBP's cloud journey parallels are reasonably illustrative. However, the core arguments - the urgency of quantum threats, the need for crypto agility, the importance of workforce development, the concept of zero trust - are well-trodden in the security industry. Alice's mention of China's quantum key distribution leadership is valuable context, but overall the episode recycles established frameworks without significant contrarian or first-principles thinking.
this is a threat, uh, where we are now that unlike anything that we've seen in probably 50 years, we've been living using the same sort of encryption techniques for the past 34 years.
there's good news here and that is that the technology exists.
Dr. Ed Mayes is a strong guest - Deputy Assistant Commissioner at CBP with direct operational responsibility for cryptography migration and clear evidence of hands-on leadership. Alice Fakir brings IBM's federal security services perspective and NIST collaboration credibility. Michael Kleiman, as VP of Data Security at Entrust, has vendor-side expertise but is also the show's producer, which introduces a conflict-of-interest dynamic. The guests are substantive practitioners, though Kleiman's dual role slightly weakens the perceived independence of analysis.
Dr. Ed Mayes, Deputy Assistant Commissioner, Infrastructure and Support Services and Chief Enterprise infrastructure officer at U.S. customs and Border Protection.
Alice Fakir, senior partner and Vice President of cybersecurity services for IBM's US federal market.
The episode includes concrete details: CBP's 50 million patches per year, the 2028-2029 quantum compute capacity timeline, summer 2026 endpoint readiness from a vendor, 4-5 trillion in trade commerce handled by ACE, IBM's $10 billion quantum investment, and Executive Order 14,409. Dr. Mayes's 'hello world' proof-of-concept and mainframe decryption example ground the discussion. However, many claims lack supporting data: the scale of harvest-now-decrypt-later threats, specific metrics on crypto agility implementation difficulty, and concrete numbers on the migration cost and timeline are absent.
we did our first proof of concept, right, with uh, using the early NIST algorithms, that sort of thing. And we uh, literally put like an envelope around an application, a small application. Right. Um, and we, you know, we wanted to verify that we could transmit data information from a quantum encrypted environment to um, another device.
I do about 50 million patches a year, right? 50 million.
Host Ken Cadet asks open-ended setup questions and allows guests to speak at length, which builds narrative coherence but limits interrogation. Follow-ups are rare and mostly affirmative ("Right", "Absolutely"). There is minimal pushback or productive disagreement. When Dr. Mayes claims vendors should improve software quality and asks why industry doesn't help, Michael Kleiman validates rather than challenges. Alice's point about learning fast by failing is left unexamined. The conversation feels more like curated perspectives than a sharp journalistic or analytical interrogation.
Absolutely. Um, Alice, where are you seeing things across, um, across the federal government?
Right. Um, M. Michael, maybe talk a little bit more about where this is headed and what kind of challenges we're seeing out there.
Computed from the transcript - who did the talking, and the words that came up most.
Organizations are facing a new kind of security challenge: one defined by compressed timelines, emerging risks, expanding trust boundaries, and competing priorities. That urgency is only increasing. Recent White House Executive Orders make clear that quantum isn’t a distant concern: the U.S. is accelerating quantum innovation while setting firm timelines to transition critical systems to post-quantum cryptography. In this episode, leaders from IBM, U.S. Customs and Border Protection, and Entrust cut through the hype to focus on what matters now: where to prioritize, how to balance immediate risks with long-term transformation, and what it takes to prepare for a future where machines act autonomously and cryptographic trust must continuously evolve.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Quantum computing is poised to spur scientific advancement. And as longtime listeners of this podcast will know, it's also poised to break today's encryption, leaving huge swaths of data and communications unprotected. That future is arriving faster than many expected, with tech giants like Google and Microsoft recently announcing accelerated timelines for quantum readiness. And on June 22, the White House defined a timeline for the federal government's transition to post quantum cryptography, while making strategic investments to spur quantum innovation. So how should government leaders think about these changes? And what capabilities will matter most? Hi, I'm Ken Cadet, and this is the Identity Threat. Today we have three guests to help us think this through. First, very pleased to welcome Dr. Ed Mayes, Deputy Assistant Commissioner, Infrastructure and Support Services and Chief Enterprise infrastructure officer at U.S. customs and Border Protection. Dr. Mayes, thank you so much for joining us.
Speaker B: Well, first of all, thank you for being here. I think this is a really important topic. Um, we often use the term, uh, or terms that look at massive, um, events that might happen in our lives. This is one of those seminal moments, I think, for us. Um, computing is changing, the risks are growing, and we want to be on the forefront of providing some sort of defense and using the new capabilities that will come out of this. So it's a great time to be alive. And thank you for having me on your show.
Speaker A: I'm very pleased to have you here. And then, um, also joining us is Alice Fakir, senior partner and Vice President of cybersecurity services for IBM's US federal market. Alice, welcome to the Identity thread.
Speaker C: Thank you for having me, Ken.
Speaker A: Thanks for being here. And of course, we welcome back Michael Kleiman, who is leading development of AI security and post quantum cryptography solutions as Vice President of Data security, um, at Entrust. Welcome, Michael.
Speaker D: Great to be back as always. Thanks, Ken.
Speaker A: Thanks for being here. So, big topic, as you said. Um, incredibly important. Um, uh, and doctor Mates, we'll start with you. Um, let's start with where things stand today. Um, in light of the recent executive orders on quantum readiness, uh, for federal agencies. This was, we're recording this, um, on June 24th, um, just announced a couple of days ago. Uh, what are you seeing right now, um, when it comes to cryptography post quantum readiness, how do you see those overall risks and opportunities?
Speaker B: Well, definitely the risks are there right when you start to look at what's happening in the world with respect to, you know, harvest now, decrypt later. Um, but I will tell you, this is a great opportunity for us to make a leap ahead Right. Um, whether it's uh, with actual quantum computing or with uh, post quantum cryptography. Uh, so this is a great opportunity for us to strengthen our defenses and figure out how to solve problems with new technology. Right. So it's a double edged sword, you know, uh, the readiness we have to be aware of, we have to be prepared for, I use a phrase with my team. Right, because you always want to generate a sense of urgency. This is a threat, uh, where we are now that unlike anything that we've seen in probably 50 years, we've been living using the same sort of encryption techniques for the past 34 years. They're everywhere. They're in our cell phones or in our laptops or in our satellites.
Speaker A: Right.
Speaker B: Um, and now those things are at risk from the perspective of being broken or having the encryption being broken. So, you know, what do we do? Uh, I think the key thing is making sure that everybody's aware and has a sense of urgency to do something about it. I grew up and I, and do say grew up. I spent a lot of time in my life inside the United States Marine Corps. Right. Uh, before coming to cbp. And one of the phrases that we use, uh, back there was, you know, we need to be the most ready when the nation is the least ready. And I think that is where we need to be. And that's where I'm focused on, or where I'm focused on with respect to defending our networks, defending our applications, making, uh, sure we add, uh, both CBP and DHS already, you know, when that challenge comes.
Speaker A: Absolutely. Um, Alice, where are you seeing things across, um, across the federal government?
Speaker C: I actually want to, want to touch on something that Dr. May said and walk the conversation back just a minute for our audience, which is around the risk question. Um, you know, I don't know that we've spent enough time explaining why this executive order is so important and why this administration, which I commend, um, is driving a more aggressive timeline around this is because we're seeing such rapid advancements in technology. The qubit scale and the theoretical power of Shor's algorithm create real risks for us, um, you know, in this, in this domain of being able to break encryption. So, you know, just for the purpose of explaining very high level, Shor's algorithm, um, is capability that allows for, is built specifically for quantum computing, that allows for mathematical computations to be solved simultaneously. Um, whereas with traditional computers it's one at a time significantly slower. So this, this additional processing allows for the machines to find prime factors and solve these complex mathematical problems exponentially faster. Um, we've also got the challenge of the fact that we've gotten accelerated hardware roadmaps. As you mentioned early on. Tech giants like Microsoft have pulled their scalability timelines forward. Um, there's also initiatives within the US government to try to drive accelerated abilities for a uh, more durable quantum computer to be used. The drive to accelerate the development of a durable quantum computer coupled with the fact that we've got um, traditional computers operating alongside, uh, the ability for the quantum computers to break their encryption is compressing this timeline. So when we look at how do we evaluate um, this harvest now, decrypt later concept, it's that this is happening much much, much sooner. We're expecting by 2028, 2029 to actually have quantum compute capacity. So that's two years away. And the migration for the enterprise at scale is going to take significantly longer than two years. We're starting to see that. So back to your question about what are we seeing in the federal landscape? We're seeing that um, this is a challenging problem because it's a whole of enterprise technology approach that needs to be taken. You have um, right now an understanding of what the bill of materials needs to be which is driven by the executive orders and mandate. But the reality of that is if you're looking at these assets from a asset type count perspective and using that approach to modernize your enterprise, it, it's a very, it's going to fail because you really need a whole of enterprise integrated view of how these capabilities, technologies and assets all work together in order to make sure that they are orchestrated to operate when Q day comes.
Speaker A: Absolutely. I mean you do a really good job of like helping us understand um, the depth of the threat and the urgency, um, and it is going to take a long time. Right. Um, M. Michael, maybe talk a little bit more about where this is headed and what kind of challenges we're seeing out there.
Speaker D: I'll ah, start with Dr. Mace and what you just said is um, when I walk down the street with my kids, what we do talk about is you go to the stoplight and the control system behind that stoplight, uh, is um, covered with cryptography every, everywhere you look. Um, it is. This is a fundamental technology and a fundamental capability that is embedded in every single thing that global society operates on. And it is uh, it's hidden fabric that is essential for secure everything uh, and for the lives and the technology and the services that we uh, that we all depend on. Alice, what you just said is spot on right, Ken, in the last episode that we recorded, um, with Herant from who's the CEO of uh, Blue Qubit is a quantum ah, computing infrastructure company. Uh, these are geniuses who build quantum computers. At the end of the day the message is that um, uh, this is real. Uh, quantum computers aren't fantasy and it's not science fiction. This is technology that exists and the threat that we've been talking about and the timelines that we've been talking about around the transition to quantum safe cryptography that keeps those street lights operating. M. Uh, there have been debates for the last decade on okay, do I need to care about it in my lifetime? Uh, and when you talk to the businesses geniuses who are building quantum computers, the answer is um, you better start caring about it because the pace of advancement of this technology is moving at a rate that is much faster than anybody experienced, anybody expected. Um, and that's being echoed not just by uh, Google who you know, runs, you know, they effectively operate the Internet, uh, to a large extent, but in the executive order that just came out and that is um, it was, it was a uh, pairing of executive orders. One was it is critically important for the US government and the us, the United States to nationally be a leader in the development of quantum computing. And it was, there was an order that was uh, specifically focused on increased uh, investment around quantum computing and uh, quantum sensing and quantum workforce development. Uh, and uh, uh is a recognition that this is critically important technology for the future. The parallel order is the one we're going to talk about today and that basically says the guidelines that were put out by NIST only what, a year ago, uh, 18 months ago or uh, they aren't aggressive enough and those timelines need to come in because the pace of change in quantum computing is accelerating. And I think the you know, uh, Alice, you said it a second ago, right? In the enterprise context, what's reality? And reality is that um, cryptosystems are the hardest things to change because there is an interoperability, uh, challenge um, that touches all aspects of technology. And um, we talked about uh, um, briefly, HarvardNow decrypt later attck as being one key problem. But uh, uh, I was just speaking to an analyst from IDC yesterday about the trustnow, uh forged later problem of uh, digital signatures. And digital signatures being a key area of focus of the executive order is this isn't just about hey, can I replace my code signing or my firmware signing and my identity systems with post quantum identities? This is what are all of the systems that do validation on those things, can they see, you know, here's a uh, post quantum algorithm and can I enforce that? I am only going to accept those because if, you know, the Windows operating system accepts classically signed code signing and post quantum, uh, signed uh, uh, code signing certificates at the same time just using it as a simple example. The, the answer is that if there is a cryptographically relevant quantum computer and there is a bad actor who is using this to forge a signature, essentially, unless that Windows operating system has been updated, validation is going to fail. Right? And the attack that we need to protect against is uh, is going to be possible. And I think they, you know, I think uh, for the people listening to this podcast, if you're focused on, you know, uh, PKI and post quantum and uh, and crypto infrastructure, the, the challenge is, is a um, super complex one in terms of every touchpoint I've got in applications, the protocols, the crypto that's being used, the configurations across all of this and Nutritional, uh, and Dr. Mayes, I see you smiling and then like you've been doing this real time and I like, I want to hear your experience on this. Uh, because this is what takes a decade, uh, for organizations to change their crypto systems and why um, moving faster is a, you know, it is a security imperative for uh, everybody, not just the federal government.
Speaker A: How are you thinking about that? Given the urgent priority and given that it almost, you know, for many, it feels like we might be behind in terms of the timelines, um, that we're trying to get to the uh, readiness we're trying to get to, uh. How are you feeling like the posture of the agency, um, is right now or how are you thinking about it?
Speaker B: Well, I think we are behind, um, but I think we're ahead of most and it's a relative thing. Um, and what I'll tell you is that we started looking at this a few years back, um, and we did our first proof of concept, right, with uh, using the early NIST algorithms, that sort of thing. And we uh, literally put like an envelope around an application, a small application. Right. Um, and we, you know, we, we wanted to verify that we could transmit data information from a quantum encrypted environment to um, another device. And that device just happened to be a mainframe that was actually ready, right. Uh, to do quantum decryption at the time and early, I think, uh, probably about two years ago and you know, it was kind of a school project if you will. We just wanted to see what we didn't know. And, and we transferred some data and most iters and computer scientists, your first application or your thing that you use as a teaching tool is hello World. So we did hello World. And, uh, it worked. But what we learned along the way was this. And one, you don't know what you don't know. Because I went into this thinking I understood, you know, one, how the applications would respond. I was thinking that there would be a high level of latency, um, and that we would see a huge performance hit on, on some of the hardware. And I was surprised, right, there's some lessons learned there because we produced a document that kind of showed that, uh, the latency was not as bad as we thought or in some cases did not exist, which was very surprising for me because I, you know, you know, worked with my team really closely saying look for this, look for that. And a lot of the things I was looking for, uh, didn't appear right. Um, and as a matter of fact, the newer algorithms appeared much more efficient than some of the things that we have today. So, um, that was a really good thing. But the big thing that I discovered, we discovered as a whole was you, you, you, you know, you go into something and you start notice, like unraveling a ball of yarn and you think, you know, where all the strings go, right? But what you find out with, you know, uh, cryptography, right, and encryption is, it's everywhere. And almost every application, every tool has some and it's calling others from other places sometimes. And it's much more complex than you would think. And I, and I was, I was definitely naive when I started this thinking. You know, I know it well. I, uh, learned a few lessons along the way, um, and was humbled quite a bit. Um, so I, but from that we learned a lot. And I'll tell you the journey that we're on now. Uh, we have a, a, a proof of concept that's underway. We're going to wrapper, uh, a couple of applications that we've identified internally, uh, between myself and, uh, Jay Alessandro, who's our deputy assistant commissioner for software, and all the teams that support us now internally, one of the things we're doing as a group, whether it's compute or storage or network, um, all the vendors that we have that are on board here are participating and learning as we go. How would we go about doing this? And we gave ourselves about a year to figure this out because one of the things that we kind of understand is, you know, we've got an on prem presence inside of our data center. Um, we've got hybrid presence and we've got a massive cloud presence inside of a couple of hyperscalers. Right. So we're not going to be able to do this ourselves long term, but what we can do is figure out what it would take and what it looks like so that we go into this development or this sort of, you know, technology, um, migration, um, smartly. So that's one of the things that we're doing here. And you know, it's really good because, you know, we're all looking at it together. I was at a, um, certain vendor about two years ago and one of the things I learned, you know, this is a vendor that produces, you know, um, end user hardware, right? Like laptops, desktops, those kinds of things. And um, you know, we were asking about, you know, when is this, when is your, you know, compute going to be quantum or post quantum ready, right. And the answer is well around summer of 26 we should have some of the first capability rolling out, right? But that was a while ago and we're like, my gosh, that's, we'd love to see it sooner, right? Because one of the things that we've got to figure out is, you know, what is the size of that encryption, right? When it's now on a device, will things like our, um, if you're in ah, Department of War, your CAD card or you're in cpp, uh, your PIV card, what does that little chip do? How much data can it hold? How does it interact? All these are questions, these are basic, you know, authentication sort of questions, um, that we have to understand. And you know, the vendors that provide us certificates and such, right. How do we operate with them? How do we disperse these across our network? You know, and then there was some challenges. I mean this is huge, right? There's some challenges that are along the way, you know, uh, crypto agility, right. You know, algorithms will come and algorithms will change, right? That is, that is, you know, the challenge of being in a highly erudite sort of world. Right? People are smart and they're going to overcome, figure out things, uh, and then, you know, um, ah, as Michael mentioned, you know, how do you deal with, you know, sort of multi environments where you may have older sort of certificates and newer. Right. Um, sort of know, not just crypto agility but also bootstrapping and acceptance. This is a, you know, this, this is a complex problem and, but we are thinking about these things and we're investing in these things now. Um, when I look at the, the ecosystem that of our, our environment, you know, our compute environment, storage network. No, we're talking to all the major players that are with us. Right. Um, and we're doing that because we're on this journey together. Right. Um, and if we're not, uh, we're all going to fall short. So it's really important that we understand what this means and how things interface. Is there network congestion that gets called? Is there a sort of drag on compute? I mean it's huge.
Speaker A: Right.
Speaker B: Um, and by the way, uh, we've been comfortable since probably the 80s using the encryption that we have. Right. Uh, so this is new and, but you know I, I think there's a um, an old proverb that says may you live in interesting times. And we are living in interesting times. But I, I wouldn't trade it for the world. Right. There's going to be incredible things that are coming. You know, we're only talking about the threat here. Right. Um, you, uh, know, Alice was talking about quantum and what it can do. So some of the problems that it's going to solve for us or allow to solve. Right. You know, things that we've been attacking problem wise, you know, with high performance computing for a long, long time and we've made some progress but quantum is going to open that door. The other thing that's going to change for us is we're looking at like uh, quantum networking with coupling. Right. You know, secure comms for the first time, real secure comms. So the future is exciting. I'm working on a product and project uh, on quantum sensing right now. Um, and you know, with the, I think it's the Reedberg atom and how it works and how you determine what something is, um, at a distance. You can't, you know, if you're, if you're a computer scientist, an IT person, a technologist in general, this is a great time to be alive and to get involved.
Speaker A: No, it's really interesting um, to hear you talk about this because I, you know, I think we talk a lot. You just in sort of this. Overall the quantum transition must, you know, must happen. But just the details of what needs to happen of just you know, like you said, like just you know, performance, you know, what impact does it have on performance and storage and all those things. It's uh, networking. That's very uh, uh, it's really interesting to hear you talk just high to low on this stuff. Um, it's incredible.
Speaker B: If you look at the wall behind me, you'll see everything that you know I'll just tell you when we talk about, you know, network and storage and compute, we talk about, you know, what's happening with AI and the AI impacts. So I sit across the hall from uh, Sunil Madagari and he's our chief technology officer and we have what I call whiteboard wars, probably after 7:00pm Right, when, when he's in town and what we're trying to figure out, we're trying to forecast what's coming and what we should be thinking about. Um, I tell anyone that will listen about who we are as an organization, meaning the Office of Information Technology Technology at cbp. I tell them we're not, we're not and can't afford to be our grandfather's oit, right, where you produce basic stuff, right? That uh, world is gone. If you're going to be in this environment, you've got to lead and lead from the front or, you know, we don't provide the, the services and capability that our officers and agents and you know, America writ large needs. Look at what just happened with the tariffs, right? We are, you know, uh, changing code on the fly to be able to respond to executive orders, right? And then other things change and we have to, in this case, have to give some of that back. Right? Those, how do you secure that? You know, if you want to look at potential, you know, where people would attack, right? That would be those kinds of places. And I say this, and not just kiddingly or jokingly, we need to be the most ready when the nation's the least ready. Because, you know, we call things black swans, right? Oh, this is an anomalous event. Normally a black swan is an event that's been building over time, but we've not been watching. Quantum is coming and we have been watching. Now it's up to us to not only watch, but. Right. But to engage.
Speaker A: Absolutely. Well, um, that's a good way to put it. And I would love to hear, Alice, I'd love to hear how what you hear from Dr. Mays as well as what you're hearing from other, um, agencies and how they're engaging in this challenge.
Speaker C: There's a lot to be said for um, Dr. Mays and his team being a little more advanced in leading edge and exploration of this technology. It's very different. Um, and to his point about um, the Black swan things building, it just reminds me about the old days of machine learning, um, and how that was just a very complex process. And uh, now we've got a very democratized AI capability at everyone's Fingertips. And we're starting to see a path for Quantum to do the same. Uh, IBM's invested $10 billion, it's a big $10 billion bet on uh, establishing fault tolerant quantum computer. Um, we are also supporting the first foundry in the United States for manufacturing these massive superconducting quantum chips. Um, there's a lot to be said for understanding that technology is going to be advanced and there are incentives for technology to advance. Um, when we look at what's going on across the federal landscape, we don't have a lot of forward leaning, um, architects of our future if you will, in this space. And you know, I want to walk it back, uh, to just touch on the high points of the most recent executive order. This is The Executive Order 14, 409, uh, securing the nation against advanced cryptographic attacks. Like what the government is doing is pulling these migration deadlines forward. Um, and it's a very bullish strategy to force uh, accountability not just within the government but in industry as well. We are responsible industry. Um, and it outlines some of the challenges and criteria for not being compliant. For example, if industry comes to the table, we may lose contracts with the government if we're not, um, you know, we don't have developed a crypto agility framework, meaning we're not ready to swap out the algorithms. Um, when that, you know, the time comes for the enterprise integration. Um, you know you'll face, uh, they're very specifically called out, delayed authority to operate and loss of future federal awards. Um, but there's certainly a funding bottleneck. Um, you know, agencies are going to have to reprioritize their funding to support this. I recognize that's creating immense operational pressure on personnel. Um, there's a lot of embedded IT infrastructure and a lot of legacy infrastructure that's impacted. Uh, and so where we're trying to establish is a roadmap, um, and hit the high points first so that we've got a long ranging understanding of how we're going to manage the systems, um, long term.
Speaker A: These systems are in an environment where there are certainly cybersecurity threats, um, everywhere. Um, Quantum's obviously a major transition, but all these threats are being accelerated by AI. We've got uh, nation state attacks, we've got all sorts of attacks on identities. Um, you know Michael, with and Alice, you talked a little bit about, you know, how to prioritize these, prioritize um, the resources that are needed to take care of all of this. Um, Michael, maybe talk a little bit about what does it mean for, with all These security challenges converging, um, how organizations are trying to balance preparation for you know, the quantum, the post quantum risk, um, along with all these other things that are kind of converging at the same time.
Speaker D: Really this is a great time to be in this space. And I know, you know, and actually the uh, uh, I'll start with that because um, I was encouraged really with the executive order, uh, on the focus around workforce development, um, because in a uh, past life I actually was on a board here in the Bay Area focused on workforce development, um, uh, here, uh, in um, in and around security, uh, IT and uh, healthcare, uh, technology. And um, it's super important. We need the skills, um, uh, available in more people to go after the problems of the day. And it's an exciting space. Technology is evolving so fast, um, that it's a privilege when you are a technologist to be able to work in an environment like this. And uh, you know that, that totally resonates with me. And the reality of uh, what Alice just said is like you know what, uh, there are a lot of organizations that are just simply. They're, they're not as far ahead as uh CBP is and as forward looking and we need, we need to bridge that gap. And you know the, the funding challenge is an important starting point. Right. Which uh, Alice, you just said is ah. I um, remember being at a NIST conference um, on PQC three years ago and people were saying hey you know what? I've, you know this transition to post quantum is uh, it's a huge undertaking. Where do I get the budget for it? And you know, everybody in the room was sort of looking at each other and asking, asking effectively the same question is um, I don't have a dedicated earmark budget for doing this thing. How do I make progress? And I think this really gets Ken to your question is when we look at the. What are all those changes that are happening in technology? Well uh, there are pros and cons. There's the positive side and the negative side. I'll start with the negative side is that the threat landscape is accelerating like never before. The emergence of agentic AI, uh put in the hands of bad guys is a threat like we uh, have just never experienced as a world and as security professionals than ever before. And what's the practical implication of this is the use of agentic AI to uh, discover 0 uh day vulnerabilities, um, to automate uh, the exploit development to um, take uh, advantage of those things and to automate commercialization of those Exploits actually put it in the hands of the bad guys who want to make money. Here's a product that I can use to go uh, and uh, do my evil doings. That is uh, capability that um, the world is seeing real time becoming available in a very concerning way. Right. The good news is we've got um, the likes of Anthropic saying I can use the same technology for good, discover those zero days, do responsible disclosure. Let the uh, developers of technology actually understand where they've got vulnerabilities so that they can get patches out to organization uh, a whole lot faster. And this was, this is a topic of conversation uh, at um, the keynote address at rsa, uh, uh, earlier this year with um, uh, Patrick uh, Opit from jpmc. He was talking about you know, uh, the speed of, the speed of patching needs to catch up to this, this pace of change. So like you've got um, uh, you've got, that is the starting point, like the threat landscape itself is um, putting a premium on uh, what are the defenses that we've got in place. And uh, before we started we were talking about this uh, briefly but uh, um, the principles of having a zero trust architecture are the right ones, right? Encrypt all of your data, use strong identity to protect your systems. Cryptography is the gold standard for both of those things. Right. And so um, the requirements for organizations in a world where the threat landscape is increasing is to apply the state of the art technology in the best way possible so that they can lean in. And as Dr. Mays just said is like organizations need to, and security organizations, they need to be at the tip of the spear. They can't be uh, uh, back on their heels, uh, or because you can't rely on the law of large numbers anymore being a defense in a world where bad actors can scale their attacks. The second thing is when you take the positives, organizations are saying hey, how do I use agentic AI to transform my business and transform my operations? Well if you take the same principle and say hey, I need to use um, cryptographic identities to actually protect my deployment of uh, agentic AI, well what happening is the um, challenge that every organization of any size has been facing has been how do I get a handle around the cryptographic assets inside my organization to begin with? And those are, where's the crypto being used? What are the protocols? What uh, are the algorithms that are being used? Where are all the identities across the organization? And this is why um, the call for industry for years has been start with an inventory. Start with discovery. What the heck you got so that you can start prioritizing this stuff. Add agentic AI into the uh, uh, into the equation. And now the scope of that problem is um, orders of magnitude bigger. And uh, you have the operational challenges that come along with, well, do I have the tooling in place for automating this stuff? Uh, do I have the right policy setting capabilities so that I can uh, enforce change? And then you layer on the transition to post quantum at the same time. And so for any organization of scale, really it is, you know, when you come back to how do I solve a budgeting problem, how do I solve a prioritization problem? Yeah, I think what we're seeing is that organizations can't address these things by the ones. This is uh, taking a very strategic view of what's the infrastructure that I need in order to support my cybersecurity strategy going forward. Do I have the right tooling in place? Do I have the right capabilities in place? And if I don't, which basically is true for everybody, everyone's in sort of the same boat. Is, um, cryptography in particular has been a technology that has been uh, deployed as needed in individual applications as they are getting built out and generally has suffered from a failure of systematic, intentional. Here's infrastructure that I need in order to support the foundation of my cybersecurity strategy. This is putting a premium on uh, PKI strategy, uh, and cryptographic strategy and re architecture for the future. And that's not tackling one of those problems. It's tackling multiple of those problems at the same time.
Speaker B: There's one thing that you had mentioned or that I wanted to add to what you had mentioned. Um, you know, everyone's talking. You know, I do a lot of patching, right? I do about 50 million patches a year, right? 50 million. I've got a lot of automation. I've got a ginormous environment. And so it's, I understand. But here's what I, you know, want to point out. You know, people ask me all the time, how can industry help me? And I tell industry all the time, make better software, right? You're sending me vulnerabilities that I gotta patch, right? So I don't take my hand down. Um, but so that's a problem, right? When, if you're, if your software quality, I mean, you should be doing a better job of reviewing your software for challenges, right, that they might have. Whether it's, uh, you know, every morning I actually about three mornings a week, I do our CIO stand up, right? And you see the same sort of challenges every morning. Out of bounds, right? Error, identity error, you know, on and on and on. And it's. Yeah, I wish I could say they were different. They're pretty much the same all the time, right? Different vendor, same problem. Um, which makes me wonder, you know, as we're talking, you know, ways, uh, ahead, right? And everybody has really moved towards open source in a big way, right? Everybody's got the repos, your downloads, uh, what do we, what are we doing so that, you know, we can solve those problems together, you know, that, you know, maybe a problem that occurs or recurs can be solved and shared. The solution can be shared versus. And what I see all the time is, you know, three weeks later, you know, vendor, you know, a saw it one week, I'm seeing it three weeks later. Or at vendor C, they probably have a, you know, some of the same code base, right? Uh, that's open source and, but it's not shared fast enough. And it leaves me, uh, on the other end or IT organizations on the other end, let's say, go and do the patching. I mean, we have enough threats, real threats that are coming from adversaries, uh, versus to have, you know, by having to deal with, you know, these sorts of challenges. So I always say, how can you help me write better code? And I also try to point out if you're, if you're, you know, as we look at AI, right, if you're telling me that you want us to use your AI and I'm looking at the number of vulnerabilities in your code that I'm solving every week. The question is, you know, why aren't you solving your issues first? You know, the old adage of being on the airplane, right? If there's a problem, put your, you know, put your oxygen device on first, right? Because I still wind up having to deal with those issues. Now that's not true of every vendor, right? But sometimes you do feel like, you know, when it's based on scope and scale, that, that you know, you don't want to be the test organization for, you know, code that's being, being pushed out.
Speaker D: That's critical. I mean, I think, you know, I'm sure Alice, you'd probably say the same for IBM. Ah, we, you know, we do is you um, know that's not every organization that is, you know, taking security by design development practices into account. Uh, you know, that is leading or organizations who are, you know, uh, hearing that same call, I think have to do that in the same breath. I do think uh, perfection is never going to be attained. And long gone are the days where um, hey, high and critical vulnerabilities can get patched in a corner. Not anymore. And I think we need to make sure that the right tooling is in place to make it easier, um, for um, the uh, adopters of technology, uh, to be able to keep their system safe and uh, to set that as the standard.
Speaker C: Yeah, I'm going at the risk of sounding contrarian, um, not to conflate the challenges with AI and post quantum cryptography, but uh, implementation of a future state PQC environment solves a lot of these problems. It fits well into the zero trust framework. There's a lot of the data protection challenges that go away when you know, you've gotten secure encryption in play. Um, and the theory around um, this velocity that Agentix is creating and the ability to exploit vulnerabilities, it's very, very real and we're in a weird state and time, place in time rather where we are. Uh, our ability to defend has not caught up with how these things are being used offensively but we will get there very quickly. That's the beauty of the technologies that we have at our fingertips. Um, with the Gentix and the fact that it's very creative, it's being used in very creative ways. Not just for bad but for good as well. Um, but my bigger concern is more one of this technology sort of arms race. And we hear about this China, you know, is a, a theoretical threat in that space to us. Um, but it's very real and I think that you know the reality that so the US holds a clear advantage in software based algorithm and standardization. Obviously we've been working with NIST, IBM's been at the forefront of working with NIST on developing those algorithms. The reason there are multiple algorithms as they apply to different technologies. That's very important when you look at this interconnected world that we're in. Um, but China leads the world in this quantum key distribution function. It's a very hardware heavy approach. While we lead in the software, they're leading in this hardware domain where they're using physical fiber optic networks and satellites joined together where they're able to share unhackable keys. Um, they're building uh, their domestic PQC framework while we're still formalizing our um, but the fact that there are, they're leading in particular parts of this technology area means that we really need to be paying attention to how this comes Together.
Speaker A: What I'm hearing is that, I mean obviously Quantum, Quantum is creating huge opportunities. There's also huge risks and there's also a huge opportunity to fix some of these problems. As we uh, you know, as, as this post quantum transition period goes and I think um, the executive orders are only just one more push that um, this ecosystem needs in order to get to where we need to go. Right. Um, maybe, um, looking ahead, um, and maybe we can wrap up with this. Um, so we've seen the clock is being set. Um, what are some of the most important actions that um, leaders can start to take right now? Uh, or let's say, you know, take right now or let's say over the next 12 months as they're looking ahead to those 2030, those 2030 deadlines or those first 2030 deadlines. Um, and maybe um, Dr. Mays, maybe we'll start with you.
Speaker B: Uh, one of the things that we're doing and I, and I think we learned this, you know, um, from when we did our cloud journey. Right. Um, I think we're, we have a pretty mature cloud and you know, we, you know, we're definitely security focused, zero trust. Um, but we're also about you know, capability delivery, you know, you know, high availability civo, making sure our officers and agents have what they need, where they are in the field. Right. Um, and making sure that our major applications, you know, our high value assets are up and running. If you look at like things like the automated commercial environments or you know, which does, you know, uh, 4 to 5 trillion in commerce, you know, trade per year. When people don't think about us, when they think about, you know, trade, right. They think about travel, they think about border security, um, they think about um, ports of entry and those things. But we do a lot, right? But making sure all those applications are up and running, making sure that all the sensors that are guarding the border with those are cameras or other tools are out there. Um, but one of the things I think that we've got to do, and we learned this from the cloud, right, was making sure our people were ready for the change. Um, and I think that's really critical because you know, it's natural for human beings to worry about what this means to me personally, what does it mean to me for my job, you know, will AI and or quantum cause some sort of shift where I am no longer valued? Right. And I think the answer is making sure that we, we bring the people along with the technology. Um, whether that's upskilling New Skilling, um, or whatever you'd like to call it. One of the things that, that I told our team when we first started the cloud journey was, look, you won't be doing the same things as you did in the data center, but there are going to be new challenges and new things that we're going to have to figure out how to do. So whether that was getting them involved in understanding, uh, containerization, kubernetes, uh, I'm talking in 2016, we were doing this stuff, um, to get them ready. The same thing has to happen now. I don't think people need to be a sort of quantum scientist. I think they have to have an awareness of what the capabilities are and what the capabilities can do for you and do for your organization and how to get to the right people and to ask the right questions. Um, I think, uh, we're working with Alice's team, uh, on some of that right now to figure out what that training looks like. Because honestly, I mean, I, I don't know. Right. Um, you know, I've got a physics background, so when you talk quantum to me, but how does that apply? How do we bring our teams along and you know, as we're starting to figure out m. How we develop and this is going to sound a little bit interesting. Right. Right now we're doing, um, building some, some circuits, quantum circuits on, I think it's the IBM System two, uh, right now. Right. Um, but you know, we're thinking ahead. We got a group out there that's looking at that. We got a group that's looking at sensing. Right. Um, and looking at how that, you know, at some point someone's going to ask some really good questions about, you know, what can we do with that data? Uh, starting to ask, you know, um, what is, what does a search look like, you know, into that data using these newer techniques. Um, and you know, uh, you know, most of us, me definitely grew up, you know, using um, relational databases, lots of ands and joins. Right. But all of a sudden now, right, with the vectorization and the cool techniques that are going to come out of quantum, you can flatten, you can flatten that thing. And which means your, you know, your processing time goes from way up here down to here. And value, we are going to be driving value. But you know, how do we share that with our people? Um, and also how do we get them not just to be fearful of what's happening, right, because there is a risk out there, but to be excited about being able to deliver newer, faster, um, capability. I'll Use one of my boss's uh, taglines. Right. Faster, better, more affordable and more secure. Right. That's my Sanjeevagwali is tagline, uh, for everything that we do here. Right. Um, but I think it's educating the people. Right. And then working closely with our vendor environment. We're not going to do anything without the vendor environment and everybody has a role whether it's generating um, the encryption certificates or looking at, you know, how the new processing will occur, you know, and new words come into our vocabulary like what's a Hilbert space? Right. Um, and how is that used? Uh, so you know, when you, I think it's educating your people, working with our partners because we're going to have to partner.
Speaker A: Right.
Speaker B: The adversaries that we have have a lot more resources and a lot fewer constraints. So how do you overcome that? By teaming and partnering. And you know, and I, and this is going to sound really odd. As a leader, one of the things that I do is active listening because good ideas can come from anywhere. Right. Um, and as soon as you think you have it all or know it all, um, you get a big surprise. So those are the things that I think are important and investing in the technology. Right. Um, that five year refresh rate that we used to, you know, government built, you know, uh, because it was normal, it met the budget cycles. Uh, I think we really need to probably look at changing that because you know, equipment's going to change faster than it's ever changed in the, in the past. Um, and so we just need to become much more agile in our thought processes and address things that are real. And when I listen to the leadership of our country, um, and I listen to the leadership of dhs and it's all about go faster, get it done. And I think that's where we're sitting, um, at OIT cbp, to make sure that we can do that for our officers and agents and give them something that they can use that will ensure officer safety and mission accomplishment.
Speaker A: Absolutely. And that takes people. Right. I love uh, the focus on the human factor and all this change that's going on. Alice, how about you? Um, advice for leaders, um, key actions you should take, uh, over the next months and next year.
Speaker C: Everything that Dr. May said resonates with me and I want to drive a point home on that. Very simply lean in and don't be afraid to fail. And that's where we're going to make progress. You're going to learn what works, what doesn't work. You can do that Quickly. There shouldn't be. There's always a stigma around the concept or idea of failing. Well, let's just call it learning. Learn fast.
Speaker A: Absolutely. And Michael, I'll give you the last word.
Speaker D: Dr. Mays, you started off with your uh, experience uh, um, in the early work that CBP was doing, uh, was what you found is uh, the key learning there was. You didn't know what you didn't know. Right? Um, and I think this is what we see um, uh every day uh, with our customers, uh, in every sector. Right. And that is that um, by and large um, organizations are um, they're dealing with um, today I think the blocking and tackling types of problems. Uh, um. Do I even, do I even have basic automation in place? Do I even have basic inventory in place? Can I uh, start thinking about resilience, let alone um, uh more forward looking um, capabilities, uh, like talking about crypto agility, uh, and uh, how have I architected my systems. And I think um, the starting point is um, organizations have got to start moving faster uh, and thinking broader uh, when it comes to here's what good looks like and here's what the capabilities are that they need to have in place to deal with the threats of the day. And I'll leave it with Alice. I love the uh, uh one of the last things that you said, which is there's good news here and that is that the technology exists. The same problem of uh, organizations are doing blocking and tackling. They get lit up around ideas like hey, I can actually get. Or uh, I can get notified before a certificate on a production system is about to expire. So that I don't get surprised by this. There's basic stuff um, uh, that exists and there's more advanced stuff that exists. The technology's there, the services are there, the capabilities are there. And um, I think the last word is the good news is there are solutions today. These are not unsolvable problems but it does require um, people making the right prioritization decisions.
Speaker A: Absolutely. The most important priority is to get started. Right. Um, so um, well thank you all. I really appreciate your time on this. I think it's really been a fascinating conversation. I hope uh, everyone has a chance to listen and learn um, a little bit from this. So really appreciate it. Um, Dr. Mays, um, thank you for being here. Alice Bakir, thank you for being here. Thank you for your work um, with IBM. And Michael, thank you as always for being here as well. And thanks all of you for listening um, to the Identity thread by ntrust uh, you can explore more@ntrust.com identity thread and subscribe for ongoing episodes and perspectives from leaders across the industry. And you can reach out to us directly@identitythreadntrust.com Our podcast was produced by Megan Gable and Steven Damone, and if you are listening, um, you can also check us out on YouTube and follow us there, or on Spotify, Apple Podcasts, or wherever you listen so you don't miss a single thread. Thanks for listening and we'll see you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.