Zero trust was built for people, and the fastest growing population on the enterprise network now has no pulse. David Hughes explains how HPE adapts the architecture for devices, workloads, and agents, and why the network itself is becoming the security team's sensor.
Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security.
Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team.
What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach.
How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal.
Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later.
Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team.
This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing
GUEST
David Hughes, SVP and GM of SASE and Security for Networking at HPE
On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/
RESOURCES
Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
HPE: https://www.hpe.com/
HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings
KEYWORDS
david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting
Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin
[00:00:00] Sean Martin: David Hughes.
[00:00:10] David Hughes: Yes.
[00:00:11] Sean Martin: How are you?
[00:00:11] David Hughes: I'm good.
[00:00:12] Sean Martin: We are in Las Vegas for, I don't know, a little show that brings a bunch of hackers together.
[00:00:18] David Hughes: Yes, absolutely. Black Hat.
[00:00:19] Sean Martin: Black Hat. It's a good week. How's it been for you?
[00:00:22] David Hughes: Been very busy and really interesting.
[00:00:24] Sean Martin: Yes. Good conversations.
[00:00:26] David Hughes: Yes.
[00:00:26] Sean Martin: Yeah. Anything stand out for me, from something that you had a chat with somebody?
[00:00:31] David Hughes: Um, well, I mean, there's, there's so many things to choose from, but you know, I think that a lot of the, um, a lot of the shifts are obviously being driven by AI, the adoption of frontier AI for good, for bad,
[00:00:45] Sean Martin: right.
[00:00:46] David Hughes: Um, you know, finding the right balance between, um, adopting AI, um, you know, in terms of the CIO and driving the business, but also protecting, um, the enterprise, right? And, uh, finding the right place to be there [00:01:00] is a big challenge for a lot of companies.
[00:01:01] Sean Martin: I love it. So tell me about your role at HPE.
[00:01:04] David Hughes: At HPE, I lead the SSE and security business inside the HPE networking business.
[00:01:11] Sean Martin: Alright, so you get to talk to all kinds of cool people.
[00:01:14] David Hughes: Um, yeah, I think so.
[00:01:17] Sean Martin: They get to talk to you and cool people. Cool person as well. Let's, um, let's give folks a quick rundown of HPE, 'cause people probably see it as a hardware vendor, maybe see it in networking. Mm-hmm. May or may not recognize security is a big pillar. Um, so maybe an overview of all the stuff that you
[00:01:39] David Hughes: Yeah. So, you know, I think just very briefly, HPE is obviously known for its server and compute business, and that's a, that's a part of it. We also do storage. We do, uh, management systems for, um, virtualized and containerized infrastructure. Um, and then to kind of, my area, about a third of the business now that we've merged with Juniper, is um, around [00:02:00] networking. And then our networking business, we organize with kind of four pillars, um, campus and branch, which is all about wired and wireless LAN. There's data center switching for both the traditional data center and for AI. There's our routing infrastructure solutions team, which is, you know, it produces the routers that are used throughout the internet by most major cloud providers, um, big enterprises. And then the fourth pillar is SSE and security, the one that I lead,
[00:02:26] Sean Martin: right? So as you are engaging with prospects and customers, I'm sure you get to hear all kinds of stories of what they're trying to accomplish, and I think you have a unique perspective, um, beyond what a lot of the other vendors on the show floor have in terms of the availability and the performance and the ability to actually drive and deploy innovations across the organizations. Obviously safely and securely. Given your role and your, your pillar, um, so what are some of the things you're hearing [00:03:00] where organizations are really pushing the envelope, pushing the boundaries on innovation to really transform what they're doing?
[00:03:07] David Hughes: Yeah, so I think that, you know, one of the things as HPE, we've got a very broad portfolio. So we're talking with customers across everything from compute, through storage, through networking, looking at, across all the things they're doing with AI. And I think one of the common themes is people are trying to work out how to push hard and adopt AI. Um, but at the same time be able to make sure that they are protected and not exposing themselves to undue risk. Um, you know, another kind of balancing act is, um, from the networking side. The networking team's always responsible for, you know, performance, giving users a great experience, um, um, the security teams there, protecting those users, protecting the company's data, and, um, often the two things are pulling maybe in slightly different directions, right? And one of the opportunities we [00:04:00] have with HPE is to help the different parts of the IT organization align and work together. So as we think about security, we've got a security portfolio, but we're also embedding security thinking in everything we're doing in a network to make the network a, um, sensor for the security team. Okay. And an enforcement point for the security team.
[00:04:21] Sean Martin: Right. And obviously the, the, uh, maybe we'll touch on the, the PQC stuff, the security of the, the devices that all this stuff is running on too. Um, I wanna stick with kind of the, the operations, what teams are trying to accomplish. 'cause I think, I don't know if it's right or not, but when we look at the CIA triad, confidentiality, integrity and availability, availability often in my experience gets dropped. Mm-hmm. And performance is key. Certainly it, the CIO and the IT folks, networking folks try to provide the, the performance
[00:04:57] David Hughes: Yes.
[00:04:58] Sean Martin: And the experience. [00:05:00] Um, but it's also critical that those things stay up and running from a security perspective.
[00:05:04] David Hughes: Mm-hmm.
[00:05:04] Sean Martin: Availability. So how, I guess is where I really, I'm going. So you mentioned the user experience.
[00:05:11] David Hughes: Yes.
[00:05:12] Sean Martin: Users aren't just humans anymore.
[00:05:14] David Hughes: No.
[00:05:15] Sean Martin: Right. They're spinning up personas and agents with skills that extend them as employees and partners and customers. Um, how does that world look now and how has it changed where, yeah, networking and availability and, and security have to adapt to
[00:05:32] David Hughes: Yeah.
[00:05:33] Sean Martin: that new frontier?
[00:05:34] David Hughes: Yeah. So, you know, one thing is about thinking about it as in terms of human and non-human identities, right? And so, um, for a long time, you know, we've, uh, as a, as a company talked about, yes, there's the human identities and, and securing them with things like zero trust network access is very important. But we also need to think how we apply zero trust to, um, IoT devices, all of the streaming video coming off those cameras or electronic [00:06:00] door locks. And so that's an important class of non-human identity. But as you call out, you know, I think the, the kind of number one conversation around identity is around identity for those agents,
[00:06:11] Sean Martin: right?
[00:06:11] David Hughes: And so ideally what we believe is you wanna take the, um, ZTNA architecture that works for people and adapt it for non-human identity. So first for, um, IoT devices, for workloads and for, and for agents. And with that you can put your agents in the sandbox, you can make it so when an agent is accessing resources, it can only see the subset that it's supposed to. So it doesn't see the rest of the network. It's seeing a network that's only got, only exposed, um, with the things that it should be able to, um, use and utilize.
[00:06:50] Sean Martin: So I've had a few chats over the years
[00:06:53] David Hughes: Yep.
[00:06:53] Sean Martin: with Juniper. And then now with HPE, we, we chat with, uh, Mounir. Yes. [00:07:00] Not too long ago. And great work that he and the team, and your team.
[00:07:02] David Hughes: Yeah. He's part of my, he's part of my team.
[00:07:03] Sean Martin: So yeah. With the research lab and everything there.
[00:07:05] David Hughes: Mm-hmm.
[00:07:06] Sean Martin: So give folks an overview. What's going on with that and maybe some of the changes that you're addressing to, to, uh, tackle the world of AI. And then maybe we'll talk about. Yeah.
[00:07:17] David Hughes: So you know, I, um, one of the, um, one of the big things we announced earlier in the year is HPE Threat Labs. So, um, Mounir's team from Juniper, um, forms the core of that Threat Labs and, you know, it's really, we are investing in with the rest of the cybersecurity community to make sure we're all pooling resources to, uh, share information about threats, to, um, research what's going on, to obviously improve our products, but to benefit everyone overall as well. Um, you know, I think that the, for us, um, this year we've also been introducing on the next gen firewalls a bunch of AI focused, um, capabilities in terms of, of first [00:08:00] observability, but then also, um, governance in terms of what, uh, services employees are able to use based on their role. Um, and then, um, going deeper into sessions, looking at what's going on there, looking at the prompts, looking at the responses, making sure people aren't cutting and pasting in information, uh, they shouldn't.
[00:08:21] Sean Martin: Right.
[00:08:21] David Hughes: So, you know, that's a, that's been a major focus for us. Uh.
[00:08:25] Sean Martin: One, two different ways we can go. I'll, I'll let you kind of choose your own adventure here. I wanna touch on PQC.
[00:08:30] David Hughes: Yes.
[00:08:31] Sean Martin: Um, I also want to touch on kind of the full experience of working with HPE. So should we do PQC first?
[00:08:39] David Hughes: Um, yeah, yeah,
[00:08:42] Sean Martin: yeah. Let's, I'm interested in, in what you're seeing there. Again, I think that's gonna be an innovation that hits us. And it's also an area that brings a lot of risk when it comes to fruition. Mm-hmm. From a cryptography perspective. So what are, what are you and the team doing, uh, relative to, to that?
[00:08:59] David Hughes: Yeah. So, you [00:09:00] know, um, AI is the thing that's top of mind for people 'cause the threat's right here and now, but the kind of next thing, next wave coming after that one is, um, the, uh, post quantum cryptography or quantum computing, which breaks current cryptography, which really forces people to, uh, move to new, uh, new ciphers. Um, the threat obviously doesn't just start on quantum day one, whenever that is, uh, it's, it's existing today. As people harvest data, it can come back and decrypt that later. So, um, we do think it's, uh, something that the cybersecurity teams need to be keeping in mind and need to be planning for. At HPE, we are moving aggressively across, um, all of our product lines to introduce quantum resistant and quantum safe, um, capabilities. So hardware, software, hardware, hardware and software. Um, you know, we've already [00:10:00] launched, uh, stuff, so this year and you know, more through the coming quarters. So it's a major initiative for us. I think the, um, the degree of risk and the degree of priority maybe varies by industry. Um, but it's, uh, it's a, it's a very important topic and maybe one that is, um, some people want to put it aside. Let's get to that later. Right. Um, but for us, you know, I think it's really important that yes, we need to be leveraging AI to find and fix vulnerabilities ready for this kind of big, um, post Mythos wave.
[00:10:34] Sean Martin: Right?
[00:10:34] David Hughes: But beyond that, we also need to be thinking about that post quantum future.
[00:10:39] Sean Martin: Yeah, absolutely. So I'm glad we covered that first, 'cause I think it, it folds well into how, I wanna ask the question about the, the experience. So clearly, uh, networking folks and IT are tasked with delivering an experience for typically customers
[00:10:56] David Hughes: Yes.
[00:10:57] Sean Martin: but also employees.
[00:10:58] David Hughes: Mm-hmm.
[00:10:58] Sean Martin: But they [00:11:00] often get left out of the, of the scenario of what about me and my own experience.
[00:11:04] David Hughes: Mm-hmm.
[00:11:04] Sean Martin: And I think there, there's something to be said by the, the breadth and depth of what HPE provides that I'm gonna guess makes their lives easier when, as they're, yeah, budgeting and buying hardware and, and setting up networks and supporting teams, doing all the things they need to do with AI and other software. And also tying in the, the risk level and, mm-hmm, threat levels. So it, you mentioned earlier, so maybe describe a little more kind of the experience of IT and security working together. Yeah. And the benefit of doing that with HPE and all that you have to offer?
[00:11:43] David Hughes: Yeah, so, you know, uh, kind of fundamental vision is around self-driving. So self-driving network and, um, you know, self, um, protecting infrastructure. We've got to move there because of the rate at which [00:12:00] threats are moving. For, um, for us, allowing the networking team and security team together is really about shared visibility so that you've got, um, equal access to information. And even though you may be using a different console, you may have different personas, you really want to be able to utilize all of the information that's at hand. So, um, a big piece of what we are doing is using agentic mesh. There's agentic technology in each of our offerings, whether it's how we manage storage, how we manage compute, how we manage networks, or how we manage our security, um, products. Um, having those mesh together so that as we are looking to root cause, you know, problem might come in, I'm having trouble accessing this app. It must be the wifi. So it starts out as a wifi problem, right? Um, but it may turn out that as we go through, no, it's not DNS, that would be one possibility. It's
[00:12:52] Sean Martin: It's always
[00:12:53] David Hughes: DNS, you know? Yeah. That's a joke. Perhaps it's, you know, the, the security team made some change to policy and [00:13:00] that's been rolled out on the firewall and now that person is being blocked from doing what they wanted to do. Maybe it's the right answer, maybe it's not. But the, the key here is it starts out as an app problem, a user experience problem, um, but it finds its way to security. And we wanna be able to automate that RCA and have that cross domain troubleshooting happen as fast as possible, and then ideally automatically remediate. So, you know, I think we, we, we've made a lot of progress on the networking side with, um, with our Marvis AI technology. Um, you know, in terms of being able to, I automatically identify problems, even cross domain, not just in the network. And by tying in with what we're doing in security and other parts of HPE, we're gonna be able to broaden that, that value proposition. And so that, that sharing, sharing of data, but also the agent, um, exchange of information [00:14:00] is something that we believe is gonna help all those teams work, um, better together.
[00:14:05] Sean Martin: So, final word, 'cause I like this, uh, this concept of self-healing and, and, and autonomous recovery. Mm-hmm. So how, call to action for the CIOs and the CISOs listening to this, how can, how can they come together and connect with you, uh, with, uh, a story that's going to enable you to help them succeed?
[00:14:29] David Hughes: Yeah, well, uh, we've, we've got obviously got a big, a big sales force, lots of partners, so I think, I think most of, um, most of 'em will know how to reach out to us. But we have a worldwide team of SSE and security specialists, so we, um, you know, well known in compute, well known in networking. Maybe lesser known in security, but we absolutely wanna be a partner with the CISO. And so I'd really encourage them, um, to reach out to their HPE rep or partner and then get connected [00:15:00] with our SSE and security team because, uh, we'd love to engage with the CISO and explain with them, um, how, uh, with our overall portfolio, we can help with some of those, um, thorny problems that are across domain.
[00:15:13] Sean Martin: Thorny problems. They're always there.
[00:15:15] David Hughes: Yeah.
[00:15:16] Sean Martin: And hopefully you can help clear 'em out.
[00:15:17] David Hughes: Okay. Thank you.
[00:15:18] Sean Martin: David. Appreciate your time.
[00:15:19] David Hughes: All right.
[00:15:19] Sean Martin: Thanks so much.
[00:15:20] David Hughes: Thanks.
[00:15:20] Sean Martin: Thanks everybody for watching and listening. Stay tuned for more coming from ITSPmagazine here at Black Hat.
[00:15:25] David Hughes: Thank you. Awesome.