The ITSPmagazine Podcast

Post-Quantum Readiness Starts With the Infrastructure You Buy Today | A Brand Briefing at Black Hat USA 2026 with Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE | Hosted by Sean Martin

Episode Summary

A problem first described in 1994 now sits inside a three year window, and the data being stolen today is already being saved for it. Recorded on location at Black Hat USA 2026, this conversation walks through what post-quantum readiness asks of security leaders before the machine that breaks RSA ever arrives.

Episode Notes

Post-quantum cryptography was in conversation after conversation at Black Hat USA 2026, yet Larry Lunetta of HPE walked part of the show floor and counted a single reference to quantum. Where the topic shows up, and where it does not, says something about who is expected to solve it.

Why does a problem described in 1994 matter now? Larry Lunetta points to Peter Shor, who asked what would happen to RSA if a different kind of computing technology existed. What changed since then is the trajectory. Five years ago cryptographically relevant quantum computing looked like a 10 to 15 year phenomenon. Larry Lunetta now puts it as soon as three years out, with the original algorithm improved, qubit hardware advancing, and classical supercomputing pulling the timeline in alongside it.

The exposure starts before any of that arrives. Larry Lunetta describes harvest now, decrypt later, where an attacker collects RSA-encrypted data today and waits for the machine that can open it. Data that carries no consequence when it leaks this year can be read later, which puts long-lived information like identity records and medical data at the front of the queue rather than in a later phase.

HPE puts a three part journey in front of customers. Cryptographically aware asks which data is most sensitive, where it lives, and whether it is protected sufficiently. Cryptographically planning reaches into the refresh cycle, so that new network, server, and storage purchases already implement PQC-relevant algorithms. Cryptographically nimble accounts for the fact that no cryptographically relevant quantum computer exists to test against yet, which makes the ability to change algorithms and firmware quickly part of the design.

Who owns the conversation inside the business? Larry Lunetta puts the CISO at the center of gravity, with CIOs becoming aware and boards engaged where GDPR governs customer and private information. His advice for security leaders is to broaden the conversation toward infrastructure and operations, and to make encryption and PQC readiness a question asked during procurement rather than after it.

This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

GUEST

Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE
On LinkedIn: https://www.linkedin.com/in/larryathpe/

RESOURCES

Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
HPE: https://www.hpe.com
Post-Quantum Cryptography overview: https://www.hpe.com/us/en/what-is/post-quantum-cryptography.html
HPE technology leadership in quantum: https://www.hpe.com/us/en/about/technology-leadership-quantum.html

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

larry lunetta, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, post-quantum cryptography, pqc, quantum computing, harvest now decrypt later, rsa encryption, cryptographic agility, ciso, crypto agility, nist post-quantum standards, it infrastructure security, encryption, data protection

Episode Transcription

Post-Quantum Readiness Starts With the Infrastructure You Buy Today | A Brand Briefing at Black Hat USA 2026 with Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE | Hosted by Sean Martin

[00:00:00] Sean Martin: Larry Lunetta, how are you?

[00:00:11] Larry Lunetta: I’m doing great. Nice to be here.

[00:00:13] Sean Martin: It’s a pleasure to meet you, my friend. We’re in Black Hat in Las Vegas.

[00:00:17] Larry Lunetta: Yes.

[00:00:18] Sean Martin: Black Hat USA 2026. I have to say, I’m surprised. The number of people talking about post quantum computing and cryptography. It’s overwhelming.

[00:00:30] Larry Lunetta: Yeah.

[00:00:30] Sean Martin: All over the place.

[00:00:31] Larry Lunetta: It’s because it’s no longer theoretical, right?

[00:00:34] Sean Martin: Yeah.

[00:00:35] Larry Lunetta: I mean, it started way back in the 1990s where a scientist named Peter Shor took a look at cryptography and said, well, the RSA algorithms work great, and in fact, they still work great today. If I start to hypothesize a different kind of computing technology that turned out to be quantum computing. The attributes of quantum computing and the ability to represent many states at the same time, providing incredible parallelism. All of a sudden, those RSA algorithms look very vulnerable. Now you say, okay, that’s 1994, right? Or 30 years? 32 years later. Why now? Well, it’s taken a long time for quantum computing and particularly what’s called cryptographically relevant quantum computing to be on the horizon. And what was, you know, five years ago, a 10 to 15 year phenomenon. You roll forward five years and now it’s, could be as soon as three years.

[00:01:36] Sean Martin: Right. Yeah, it’s right around the corner. It can be the year before we know it.

[00:01:42] Larry Lunetta: It can be. That’s why organizations, it’s very top of mind for organizations now, and the way we counsel our customers is, you know, this is a journey. And there are a number of steps you need to go through, but you need to start today.

[00:01:58] Sean Martin: Okay. Right. We’re gonna get into those steps. I want to, is it when people probably hear of quantum computing, mind blowing, right? If you try to figure it out, at least for me anyway, you throw cryptography in there, which is another subject that can be difficult to understand.

[00:02:17] Larry Lunetta: You’re absolutely right.

[00:02:18] Sean Martin: And you mix those together and it’s like, I’ll deal with that later. Because it’s too much going on. So maybe in layman’s terms, you know, what that looks like and why it’s important to understand it.

[00:02:29] Larry Lunetta: Let’s start with cryptography. We don’t realize how much encryption is part of our daily lives. You know, it’s part and parcel of almost everything we do with it. It’s about identity, right? It’s about data control and protection. It’s about financial transactions. Things like Bitcoin, you know, all wrapped up in this idea of encryption, which is basically using a code to obscure what the real information is. You can go all the way back to the middle ages of the different kinds of codes that were used, and as I said,

[00:03:02] Sean Martin: and in a way to see it if you need to,

[00:03:05] Larry Lunetta: you. Yeah. You can reverse it.

[00:03:06] Sean Martin: Right.

[00:03:06] Larry Lunetta: If you have the key.

[00:03:08] Sean Martin: Exactly. Which is given than a blockchain in some sense.

[00:03:11] Larry Lunetta: Yeah, that’s true. But there’s still encryption, right? As part of the transaction, and as I said, the basic encryption algorithm that we all use today is called RSA. It’s either 1024, 2048. It relies on the combination of two prime numbers and a key, but once you have that, everything flows nicely. And it’s extremely difficult to peel that apart. Computationally, you can’t brute force

[00:03:39] Sean Martin: Right.

[00:03:39] Larry Lunetta: the decryption. The decoding of an RSA algorithm with classical computing. I mean, it would take centuries. I mean, it’s mind boggling. HPE makes the most powerful supercomputers in the world, and even those aren’t up to cracking RSA code. So that’s the encryption side, right? So now the quantum side relies on physics that started with Einstein, quantum mechanics, where matter doesn’t operate in classical particle physical waves. It operates as waves and net net. There’s something called a qubit,

[00:04:17] Sean Martin: right?

[00:04:17] Larry Lunetta: And a qubit has a property called superposition. And superposition simply means that there’s a wide range of probabilities between zero and one that that qubit can hold at any one time. Now, this is past my pay grade now, but if you know what you’re doing with that, it, like I said, gives you a tremendous amount of parallelism that introduces this idea that you can crack an RSA code.

[00:04:43] Sean Martin: Right. Shortens the timeframe from decades to,

[00:04:47] Larry Lunetta: in some cases, hours, weeks and hours.

[00:04:50] Sean Martin: Right, right. So those two together, and I guess the end result, if and when that happens is somebody can reverse and see.

[00:05:02] Larry Lunetta: That’s correct.

[00:05:03] Sean Martin: Because they create the key

[00:05:05] Larry Lunetta: to

[00:05:05] Sean Martin: unlock, right?

[00:05:06] Larry Lunetta: That’s right. And it has two implications today. One is obviously everyone’s encrypting data. They’re storing it. You don’t wanna leak it, right?

[00:05:16] Sean Martin: Right.

[00:05:16] Larry Lunetta: But if you leak it today and there’s no quantum computing, no harm, no foul. But there’s this idea of harvest now, decrypt later,

[00:05:27] Sean Martin: right?

[00:05:28] Larry Lunetta: where the attacker is just loading up RSA encrypted data waiting for cryptographically relevant quantum computing to show up. So, you know, one of the things we counsel our customers is that you have to focus on the critical information that may be safe today, but if it’s leaked or you get hacked, you know, could create a problem in the future.

[00:05:52] Sean Martin: And some might think that data three or five, four years from now may not be relevant, but that identity sticks around for quite a while.

[00:06:03] Larry Lunetta: Maybe it’s too late for me, but I’m sure you wouldn’t want your social security number or your medical records in the clear. Right. So that’s really the challenge.

[00:06:11] Sean Martin: Yeah, exactly. So let’s go to the journey now of organizations need to start thinking about this and preparing. So what are the three steps and maybe give a little overview of each.

[00:06:23] Larry Lunetta: And we really, it’s thinking and acting, right? So it’s a three part journey that we work with our customers on. The first one is being cryptographically aware. Which data is most sensitive? Where is it? Is it protected sufficiently? And you know, just making sure you prioritize your IT investments along the lines of, as I said, protecting that information. Then the next step is cryptographically planning, and that’s not just putting, you know, a set of paper on the shelf and saying, here’s what I’m going to do. It’s also looking at, as you refresh your IT infrastructure, it could be your network, your servers, your storage that you acquire, products that are already implementing PQC relevant algorithms. So, you know, it’s not just standing pat. And again, vendors like Hewlett Packard Enterprise, we have introduced a wide range of products that have new types of encryption algorithms that are intended to be resistant to PQC.

[00:07:28] Sean Martin: Okay. And the third step,

[00:07:30] Larry Lunetta: a third step, that’s being cryptographically nimble. So you also want infrastructure that can be updated quickly, because there isn’t a quantum computer yet available to test all of this. Now, while there’s smart people like NIST and other government agencies and a lot of, you know, cryptologists who study this problem, have recommended new algorithms, until we actually get a cryptographically relevant quantum computer, we’re not really gonna be able to know if it works or not. So you want to be able to turn that infrastructure, be very nimble around the algorithms, the firmware, and everything else that underpins your encryption environment.

[00:08:09] Sean Martin: ’cause you might have to pick a new system, new firmware, new keys, I don’t know what else.

[00:08:14] Larry Lunetta: All of that’s in play.

[00:08:15] Sean Martin: Yeah.

[00:08:16] Larry Lunetta: But again, the basic infrastructure, like we have a server family which uses a custom ASIC to enforce the encryption for the server environment. Because it’s our own ASIC, we can move it very quickly. We can make the changes necessary as the movie unfolds, if you’ll

[00:08:36] Sean Martin: Right. So let’s dig in a little bit into each step, because somebody listening and watching this might say, what does it mean to be aware?

[00:08:46] Larry Lunetta: Right?

[00:08:47] Sean Martin: What am I not doing today that I need to start thinking about for tomorrow?

[00:08:50] Larry Lunetta: A lot of customers are looking to folks like us to really do a very deliberate service around PQC to address the issues I just talked about. So we have experts that will come in, work with the customer, understand their data environment, what their encryption environment looks like, and start to set them up for the next several phases that are coming. So it’s a, and we’re not the only one. There are, you know, services out there that will help customers sort of sort through the headaches that you just talked about. How do I figure this all out? Right? So that’s a very specific, tangible thing that people do.

[00:09:29] Sean Martin: Okay. And in terms of actions, I guess maybe I’ll frame it this way, the conversations within the business, who’s leading them? Is it the CISO?

[00:09:47] Larry Lunetta: That’s a great question.

[00:09:48] Sean Martin: Is it business leader? Is it the CEO? Who has their hands on all this?

[00:09:49] Larry Lunetta: So the CISO is certainly front and center,

[00:09:52] Sean Martin: right?

[00:09:52] Larry Lunetta: Right. Because a lot of the craft that makes our head hurt, you know, the CISO and presumably their team,

[00:09:59] Sean Martin: they know cryptography,

[00:10:01] Larry Lunetta: understands that. Right.

[00:10:02] Sean Martin: Maybe not the quantum,

[00:10:05] Larry Lunetta: all they need to know is when quantum shows up, they have a problem and they have to prepare for it. Right. But they’ll probably understand quantum as well.

[00:10:13] Sean Martin: Okay.

[00:10:13] Larry Lunetta: But now it’s starting to get higher level in the organization. Certainly CIO is gonna start to be aware. And if you’re in places like Europe or GDPR is an issue in protecting customer information and private information. That’s a board level issue,

[00:10:30] Sean Martin: right?

[00:10:31] Larry Lunetta: So we’re no longer seeing, you know, PQC so far on the horizon that people are going, oh, I don’t have to worry about it now. It’s really bubbling up to very high levels in the organization, but I think the CISO is the center of gravity.

[00:10:43] Sean Martin: Yeah. And do we have a sense. So I’m not asking you to predict, pull out the magic eight ball. We don’t even know when it’s gonna happen, something that will crack the code, if you will. I’m hoping we have enough time in between now and then to be ready. Do we have a sense of what it takes to get an environment ready for this? Is it all the way down? It’s down to the hardware.

[00:11:11] Larry Lunetta: Yeah. It’s a great question.

[00:11:12] Sean Martin: Starting, starting plan your CapEx right now.

[00:11:16] Larry Lunetta: But that’s where, you know, a vendor that’s got, you know, flexible encryption environments so you don’t have to swap out hardware all the time. You can put new firmware in, things like that, but your question is, you know, how soon is this gonna hit? You know, that’s a little bit uncertain.

[00:11:34] Sean Martin: Yeah.

[00:11:35] Larry Lunetta: But the trajectory is being influenced by a number of things. First of all, the basic, you know, algorithm that was invented in 1994, that’s being improved. So just the amount of work that has to get done has come down. There is much more hardware improvement at the quantum level. Things called qubits. There’s a lot of vendors producing different types of qubits, but it’s not just the hardware. And that’s where, you know, our supercomputing technology comes in. Qubits are gonna be an accelerator to current classical supercomputing. So that means that the workflows, the compilers, the error correction, the management of work between the classical supercomputing environment and the quantum computer are all contributing to this acceleration because we’re making great strides in all of those areas. So this is like Moore’s law on steroids, right? It’s not just the hardware, it’s everything that’s contributing to reducing this window, right?

[00:12:35] Sean Martin: As we wrap up, I was joking a little bit, but with some serious that there it is top of mind

[00:12:40] Larry Lunetta: Yes.

[00:12:40] Sean Martin: for a lot of people.

[00:12:42] Larry Lunetta: Yep.

[00:12:42] Sean Martin: But not a lot of messaging here at Black Hat around this topic. I wonder your thoughts on why that. I’m surprised, ’cause all these companies

[00:12:52] Larry Lunetta: Yeah, I know.

[00:12:52] Sean Martin: Guess what? They have encryption in their products.

[00:12:55] Larry Lunetta: Yeah. So I walked a bit of the floor. I didn’t see everything, but I saw one reference to quantum. I’m surprised. And I think perhaps customers are looking to suppliers and partners like Hewlett Packard Enterprise that do the hardware, you know, the servers, the storage, the networking, the fundamental IT infrastructure as the source of PQC readiness as opposed to adding it into the environment. It’s a different phenomenon. It gets much lower than a bolt on security product.

[00:13:28] Sean Martin: So it’s more the CTO and the CIO, though the CISO has it on their shoulder.

[00:13:35] Larry Lunetta: Well, you know, we’re having a lot more conversations now with the CISO about what our infrastructure is from a security standpoint. You know, we partner with the rest of the security ecosystem. But today, you know, you need that secure foundation, not just for PQC, but in general.

[00:13:51] Sean Martin: Yeah. So let’s close with a bit of advice for the CISO then,

[00:13:56] Larry Lunetta: right.

[00:13:57] Sean Martin: how they can, if they haven’t already started having that conversation, how do they have that conversation, with whom, right. And what are some of the key points they need to pull from their own environment and own programs

[00:14:08] Larry Lunetta: right.

[00:14:09] Sean Martin: to educate the folks that need to make the final call on this stuff.

[00:14:15] Larry Lunetta: So I don’t think there’s a, you know, a huge education process here. I mean, it’s reasonably well understood. You don’t have to be a cryptologist to understand what the challenges are.

[00:14:26] Sean Martin: Right.

[00:14:26] Larry Lunetta: But for the CISO, I think it’s broadening the conversation to the IT infrastructure. You know, the infrastructure and operations groups. How are you buying new servers? How are you buying new storage? What attributes are you looking for in terms of encryption and PQC readiness, right? So it’s that collaboration that I think the CISO needs to start having with the rest of the IT organization.

[00:14:51] Sean Martin: And of course, CISOs own the identity for a lot of this stuff too.

[00:14:55] Larry Lunetta: That’s exactly right. So that’s a point of protection.

[00:14:59] Sean Martin: Right, right.

[00:14:59] Larry Lunetta: You know, that may be a priority for the CISO to say, okay, if I’m vulnerable, how do I protect it and what’s my priority?

[00:15:06] Sean Martin: Alright, so good to chat with you.

[00:15:09] Larry Lunetta: It’s a pleasure.

[00:15:10] Sean Martin: Appreciate your time.

[00:15:10] Larry Lunetta: Thank you very much.

[00:15:11] Sean Martin: Fascinating topic.

[00:15:13] Larry Lunetta: It is.

[00:15:13] Sean Martin: And it could be a little nerve wracking perhaps, but sounds like you guys have a nice three step plan starting with awareness.

[00:15:20] Larry Lunetta: Yes.

[00:15:21] Sean Martin: And yeah, hopefully folks connect with you, Larry.

[00:15:24] Larry Lunetta: Alright. Yeah. We’d love to chat with ’em. And we’re a global company and we have a lot of resources to offer here.

[00:15:31] Sean Martin: Yep. Appreciate it.

[00:15:32] Larry Lunetta: Alright, thanks Sean.

[00:15:33] Sean Martin: So connect with Larry and the HPE team, and stay tuned for more coming here from Black Hat USA.