Library Header Image Library Header Image

Preparing for Quantum: A CISO's Roadmap to Resilience


Posted on in Podcasts

Cyber at the Top

Quantum computing is no longer a distant threat. It is now a present-day concern for security leaders who must protect data that could be harvested today and decrypted tomorrow. In this episode, Noopur Davis, Chief Information Security and Product Privacy Officer at Comcast, cuts through the hype to explain what quantum resilience really means for enterprise security programs. She shares a practical roadmap for getting started now and tackles the harder organizational challenges: making the business case to executive leadership and helping teams develop the skills they'll need for this shift. Whether your organization is just beginning to think about quantum readiness or looking to accelerate progress, this episode offers clear, actionable guidance on where to start.

Access the Video Version and Bonus Clips of Select Cyber at the Top Episodes with Your Free RSAC Membership

Your RSAC™ Membership also includes AI-powered summaries, historical Conference presentation slides, Group Discussions with peers and experts, plus more. Watch Now >>

Podcast Transcript

Welcome to the RSAC Cyber at the Top podcast, where security leaders across industries share the strategies, hard lessons, and real experiences shaping modern cybersecurity and AI. Insights are grounded in community and built for every level of profession.

Quantum computing has long been viewed as a future breakthrough. But for cybersecurity leaders, its implications are already here. The potential for quantum systems to break today's encryption standards introduces a new kind of risk, one that challenges how we think about data protection, how we think about long term security, and also resilience.

In this episode, we'll explore what quantum resilience means for today's enterprises.

What's real, what's hype, and what actions do CSOs need to take now to prepare?

I am absolutely thrilled by being joined by the amazing Noopur Davis, chief information security and product privacy officer at Comcast. Together, we'll unpack the evolving quantum threat landscape and share practical insights on how organizations can begin building quantum ready security programs today. So, Noopur, thank you so much for being here.

Thank you so much for having me here. I'm very excited about this conversation.

It's a great one. It's a very timely one. People are thinking about it. It's top of mind. And maybe just to start off, can you give us a quick overview of your role?

Yes. So Comcast is a is a is a huge and very diversified company. So, you know, some of our big brands are Xfinity, you know, which is broadband, video, mobile, home security. About half of the US broadband traffic flows through our infrastructure. And then we have NBC, you know, which is the new studios and all of, the, entertainment.

We have Universal Studios, which is the movie business. We have Universal Parks, which is the you know, they're doing amazingly well. We have Sky over in Europe that does huge entertainment and sports company but also infrastructure. Oh, we have things like DreamWorks.

So it's a very, very diverse Just throw it in.

Oh, things like DreamWorks.

It is. I yeah.

Amazing property. Yeah.

It is. It is a very diversified company. And so we are the nation's critical infrastructure. And in that role, we do take that very seriously and try to make sure that we are doing the right things wherever possible.

And you've got such a diverse estate. Like you mentioned, critical infrastructure, but you've also got physical things like the theme parks and the movie studios.

It'd be great to just get your perspective on how should security leaders think about the timeline for quantum threats being something that's real and material.

Yeah. You know, that's a really good question because when you think about it, the current US government directions is, like, twenty thirty five time frame. Right? All government systems should be quantum ready by then. Right? And that seems like a long time, but it's not Because, you know, I already feel like we're behind, and we started about a year and a half ago on a formal quantum process, shift to quantum. The time it will take, you know, through every layer of the organizational architecture to to really get quantum ready, it feels like a long time, but it really isn't.

You know, I just remember, I'm sure you do too, the switch from DES to triple DES to AES.

So many systems, so many that have these standards and protocols just kind of hard coded in.

And my question to you is, and this is really just as advice to another CISO, two thousand thirty five, like you said, feels like it's a ways away.

But and it still feels abstract to, I think, a bunch of security leaders.

Why should CISOs be paying attention to this right now?

You know, your example was really right on. Our SHA-one to SHA-two fifty six, that was a decade long shift and we're still not done, right?

PQC is much, much more complex, right? It's touching a lot of asymmetric primitives and protocols and hardware and supply chains.

And it is because of the complexity that CSOs need to start thinking about this now and really hopefully have already started to think about it.

And when you think about, you know, modern cybersecurity, it is underpinned by, you know, these, cryptographic algorithms, our certificate systems that underpin so much of our security, our token systems that underpin so much of our security. So all of that is impacted by PQC, by post quantum computing. And so that is why we need to start thinking about it now.

I hear many people talking about quantum resilience. Like that's the goal, that's the destination, that's where they want to get. When you talk about quantum resilience, what does that actually mean in practice for an enterprise?

So you know, you'll hear the term quantum agility a lot. And the way that we think about it is, you know, NIST approved the first quantum algorithms in August of twenty twenty four. You know, this included key establishment signatures, so, you know, a complete set. However, we do know that between now and whenever relevant quantum computer is ready, there will be changes.

You know, in the past, NIST has released things that were then you know, cryptography was broken. So quantum agility means that we need to get ready so that as this journey starts, we are ready to accommodate whatever new algorithms are established and approved. So, you know, we're starting with the SAT that are approved by NIST today.

They will likely change. There might be more that come in that are more suitable for certain performance constraints.

So as this evolves in the next few years, we've got to have that agility, that capability to change the core cryptographic underpinning on the fly.

So that's what agility means to us.

That's great. I mean, it's a it's a very different architectural approach to just moving from thing a to thing b. It's more like we're moving from thing A to thing B, but B could change to C quickly. C could change to D and to E and to F.

Exactly. There could be multiple you know, we know we're here today. We know that when we get to the destination that we'll be ready for the quantum computer. How what is going to happen between now and then? You know, there's just a lot happening in this space, and we've got to just be agile.

We, at Comcast, build and run our own public key infrastructure, our PKI. We operate at huge scale, so that system has delivered, you know, one point five billion certificates to date. We run our own token systems, and, you know, the token systems, you know, we do about eight hundred million a week, you know, some some ridiculously large number. One of the journeys that we've been on is full lifecycle management of those certificates.

You know, how do we take every certificate in the company, whether it's public or private, and put it you know, first, you have to find it and then onboard it onto our full life cycle management. So, you know, they're autorotated, autodiscovered. So so that is, in a way, that first step. Right?

Like, do you know where just your search are. Forget all the other crypto assets. Right? So we have, you know, an approach which has three components.

You know, the discovery and onboarding to the right systems is the first of those steps.

Makes sense. Like if you don't know what your crypto inventory is, how do you move forward? How do you even figure out where to progress? And I'm wondering, if you had to think about priorities, which part like, which part of the enterprise is most at risk in a post quantum world? Is it data, identities, communications? How should folks think about that?

You know, for a company like ours, it it really is almost at every layer because let me let me give you an example. Right? The network protocols today are cryptographically dependent.

So, you know, the the the fundamental network protocols that our networks run on. So, yeah, that is super important.

We have close to a hundred million devices in our customer homes. So and those devices have full cryptographic chain of trust from a a safe boot to tamper resistance. Then if you just move up, you know, our API security, and APIs are everywhere, you know, depend on cryptographic tokens. So I think it's it's really hard to pick where.

So and then, you know, you go to third parties. We're very dependent on third party. You know, there are Broadcom chips in our devices. There are other so, you know, if you if you think about it, right, it's certificates. It's code, it's library, it's network protocols. You know, our our fundamental protocol that cable systems run on DOCSIS has a cryptographic component.

It is very pervasive. The ecosystem, it's hard to isolate one part of the ecosystem and say, this is the most important.

Gosh. I mean, just the way that you talk about it, the estate is so profound. It's just baked into so many processes.

Yes. Exactly. Exactly.

Yeah. And I'm I'm just I'm just curious. I'm thinking about, you know, somebody listening to this. They're a CISO.

You're well down the journey. Right? And you're, you know, you're you're doing the inventories. You're kind of understanding where to go and how to bring agility in.

But for a CISO that hasn't even started thinking about this yet. Right? God, two thousand thirty five. We've got password problems right now.

How should they start? What are the first two to three steps that you think that they should take?

Yeah. I think I think the three steps that that we have in our program, you know, three pillars apply to everybody. It's just, you know, our scale is bigger and more complex. Right? So our three steps are, you know, the first is crypto discovery.

It's, you know, where are your cryptographic assets? And you've gotta find that because, again, you can't protect what you don't know or change what you don't know. The second is, you know, okay. You have a list now.

First of all, do you wait till the list is complete? No. You know, that can take forever. If you have a list, what do you do?

You know, let's say you've just started a list and you've got your first thousand, you know, crypto assets. Well, the next thing you've got to do is do some kind of risk assessment because you can't do all of it at once. Right? And so every one of us is going to have to prioritize.

So that's our second pillar is how do you do risk assessment.

And then our third is around enablement. As we change to quantum PQC stature, every algorithm doesn't fit every problem.

So you've got to create a framework where you can do a quantified evaluation of PQC algorithm A against my problem B.

So, for example, there are some solutions that are very sensitive to latency.

There are others that may be sensitive to, you know, other architectural constraints. And so you have to build that capability to test your deployment.

So that is what we are doing. We have a crypto discovery program. We have a risk assessment framework that we've built and open sourced, and it's actually available on the NIST website. It's called CARAF, c a r a f.

And then we are building and will open source, if it's not already open sourced, a program called Quant, which is going to be able to help you do that quantified testing of your solution that you pick.

Now some of the solutions, you're not going to have a choice. Right? Your vendors and suppliers will pick.

Regardless of what, you know, a supplier or vendor does, you're still going to have to do that assessment of, you know, how does this impact my performance, my, you know, my my just, like, the size of the certificate, my memory consumption, and all of that kind of tasks that you'll have to do to make sure that it works in your context.

That's such a great point because it's something that I think people may gloss over and feel like here's a set of algorithms that we're going to move to. But as you say, you've got latency issues, things that really can't afford to even have a multi millisecond delay, for example.

And you know, I'm just winding the clock back to maybe when you started this project.

What other folks inside of the organization did you need to bring in to make this successful? Legal, for example, or engineering or product, or maybe even procurement, because you're talking about third parties and suppliers.

Before we even started, I had this question is, you know, what is the cyber function's role in this whole post quantum journey?

And so I actually sat down with our CTO and our chief network officer and our chief product officer. Chief product officer, you know, builds our products like our devices, for example. CTO, of course, is the classic technology officer role, and our CIO reports to our CTO. And then, of course, our network officer has an amazing, amazingly complex and challenging job.

And so, you know, we talked about this, and and we said, look. You know, as quantum computers become real, you know, there will be product implications and network implications, and our chief technology officer will have to think about, you know, how do I train people and, you know, what are the use cases for quantum compute and and so on.

But as far as, post quantum cryptography is concerned, at Comcast, my team runs most of our authentication, authorization, cryptographical solutions already. So at that point, we decided that, yes, you know, we're going to PQC will be led from my org. So the very first group we formed was a post quantum center of excellence, and that has representation from all parts of the organization.

And, you know, I sometimes struggle with the word center of excellence. You know, it's more like maybe a community of practice, but we're calling it right now COE, Center of Excellence.

And we do have representation from those different groups that you just mentioned.

And part of our team's role is education.

We have a cybersecurity guild at the company, and the guild is really a getting together of people who have shared interests. So these are not just members of my team. These are members of all kinds of functions in the org. Just this week, our Center of Excellence ran a PQC workshop, and I think there were two hundred plus attendees.

We also collaborate with outside. So, you know, we've had speakers from IBM. We have professors from universities who come and speak with us. And you know, when the NSTAC was active, the National Security Telecommunications Advisory Committee, we were leading a post quantum work stream sorry, a PQC work stream in that. So, you know, long way to answer your question saying that it is not just internal collaboration across multiple groups, but a lot of external collaboration. We also work very closely with, like, NIST workshops and so very, you know, engaged in the technology, the standards, the emerging knowledge, policy.

So we look at it from a, you know, very three sixty degree view. Very long answer to your question here.

No, it's a great one because it really gives people a sense of the dimensionality and the scope and the constituents involved in this thing. And it just naturally leads me to another question.

Given how expansive that is, like this is a huge project that's likely to go on for years, how do you convince executive leadership in a firm that this is something we've got to do now, we've got to invest in. It's going to take time. It's going to take all of these parties coming together even though there's no certainty, let's say, of when there is a cryptographically relevant quantum computer. How do you broach that conversation?

It is exactly that, is getting like minded people together, so the leaders of of the company. You know, I'm I'm I'm very lucky that my boss has all of product and technology for for Comcast, including, you know, the network, the like, all of it. But you're absolutely right. You know, we we are competing for resources.

Every organization in the world is, and we are no different. You know, we always start small, and that's what we did. And we're still small. You know, it's it's a a small team.

The good news is that because my team also runs those cryptographic systems so, for example, the first adopters of the work that the PQC COE is doing is our PKI team. Right? Because if I can get my PKI system quantum ready, then and I have a parallel work stream going on, you know, nothing really to do with quantum but, you know, of of getting all of my certificates under life cycle management, then, you know, I've solved a huge problem if I can do that. Right? So so you have to think about it.

You know, how do you do something like this with a small team and in a way that you will get the biggest bang for the buck for your first foray into this very complex ecosystem.

I think that's such a great roadmap for internal. Like how do you rally?

How do you get people involved? And how do you get them caring about it and taking action?

And this is going back to something you mentioned earlier in the discussion.

The third parties are such a big part of this too. How important is it to start engaging vendors basically now on post quantum readiness?

Oh my gosh. I can't even tell you how important that is. Now, the good news is that our hyperscalers, Google, AWS, Microsoft, are already on that journey and have started releasing Quantum Ready. You know, Google has Chrome versions that are using the, you know, PQC compliant algorithms.

AWS is, I think, like, twenty seven, like like, literally a year or two away from and and they have parts of their stack that is already supporting. So, you know, if you're working with, you know, the the well known hyperscalers, big companies, you know, they're not waiting for us to ask. Right? They're already on on on the journey.

The the harder bit is the hardware and chip vendors, And the reason that is harder is because it is harder to be crypto agile when, you know, you have that.

And and those cycles are long. You know, those chip cycles and hardware cycles. So that is where if you're a company that is, you know, building hardware and you have chip vendors that you're working with, then, you know, that cycle really should have started already, right, that engagement. The you know, if you're doing custom ASICs and custom, you know, FPGAs and so so so all of that.

And then the other area where there is more worry is the smaller vendors. Right? Is, that's what I worry about more than our our big vendors are are, you know, way down the path, not worried about about that. You know, for there, our biggest thing is how do we use our risk model.

Our risk model basically does two things. You know, it looks at it's called CARAF, crypto agility risk assessment framework. Again, it is open source. So and what it does is it takes an inventory, and it comes out with, you know, actionable priorities. So, we have two axes. You know, one of them is crypto agility. How easily can this asset adopt PQC?

So there, we consider things like what libraries is it using, what protocols does it need to support, what are the vendor dependencies, what is the performance headroom, You know, what are the hardware constraints? So we sort of go that's one axis. And then the other axis is the risk. You know, how critical is this asset? What kind of data is supported by it?

What is the asset lifespan. Because if it's an asset that's about to be retired, has a four year lifespan, then we shouldn't worry about it. Right? And then coming out of it is three actions that we either have to figure out how do we migrate to PQC or we phase it out or we just say we accept the risk and we can't. Right? So and that vendor part that you just talked about is a is a inherent part of that risk assessment framework.

I can I can imagine? I mean, just I'd say just the weight of Comcast is probably helpful in those discussions even with the smaller vendors. And the fact that the demand is coming from multiple places is is great. And it's very, very useful to understand that this is where potentially the long tail is. And I'm I'm curious, have you had to bring any additional skill sets into the organization as you've gone through this process and as you've done this discovery to be able to make this shift successful?

Yes. And can I tell you what the most amazing part of it has been?

So so my team that is leading this for me is a small team. I think everybody on that team has a PhD, and a lot of them are very young. And why am I bringing that up? Is we need people who have that capacity to you know, they they can do research. They can look at a lot of information. They can, you know, translate it to, like, working code. I think that has really helped us.

So we have not gone and hired, like like, you know, amazing quantum luminaries. We consult with them and invite them and, you know, read their papers and and and and look at their work.

Instead, what we have are super smart people who are very capable of operating in that environment you know, where they know how to research. They know how to hypothesize. They know and then they know how to apply that to to the real world.

So because, again, you know, we are resource constrained. Right? I don't have a big budget for for this. And so, you know, that is the decision that the person who's leading this for me, amazing guy called, known as VG, that is the sort of approach he took. You know, he's very connected in that community, and, you know, he's picked and, you know, because we have constraints on our budgets and everything else, you know, we've picked people who can come in, and I think it is it's sometimes great to have constraints because they force you to be creative, and that team is, like, kicking it out of the park. It's just awesome.

I love it. It's like well credentialed experts in this space. Yes. But still with the plasticity.

Yes.

Go in and think differently and also prove it. That's the word. Try it. Yeah.

That's the word. And, you know, we bring in the experts all the time from academia, from corporations like IBM who think about this deeply. And our team, though, is very they are experts now.

Example, our third pillar, the PQ bench, the post quantum bench, again, something that we have open sourced.

You know, that was built by one of these amazing young lady who, you know, figured all this out and then built this kind of lab in a box that, you know, you can just deploy and bring in your applications and go, okay. I've, you know, just and how do I simulate it, and what tests do I run? And And, you know, so those kind of, you know, like latency budgets and fragmentation issues and memory constraints and all of that kind of stuff is like a lab in a box now that, you know, people can just come and experiment with. So I love that practicality of the team.

That's great. And it's enabling others, right? Lab in a box.

Absolutely. We do open source a lot of what we build in this space.

So PQBench and then CARAF. CARAF is the risk framework, and then PQBench is this analysis framework.

Those are both available.

Well, thank you so much for giving back to this community in that way. I mean, that's phenomenal.

Absolutely. It's a give and take. We take a lot, too. Absolutely. Yeah.

And one last question for you, which is, you know, somebody's sitting, they're they're listening to this discussion, and if there's one thing that you'd want every cyber leader that's listening to this to do differently starting tomorrow based on your experience, what would it be?

I think you have to start.

That is the hardest thing is, you know, sometimes you just get paralyzed by the size of the task ahead of you. Right? And it doesn't matter if you're not as big and complex as Comcast because, you know, a smaller org will have even more constraints, right, in a lot of ways.

So but you have to get started. You know, if the the thought of, you know, even getting a crypto asset inventory is scary, and you just start with the ones that are easy to get.

You know, I'm a true believer in incrementality and that, you know, you start where you are and then you make small steps of progress. But if you don't start, then I think it'll be hard to catch up.

I love it. Just get started. And, Noopur, thank you so much for being here and just being part of this discussion and being so open and just sharing your expertise. I know so many will benefit from that.

And I wanted to thank our listeners. Thank you for tuning in. And please keep the conversation going on our RSAC membership platform by visiting OneRSAC.com/Membership, and be sure to check OneRSAC.com for new content posted year round. Noopur, thank you so much again.

This was fantastic.


Participants
Noopur Davis

Executive Vice President, Global Chief Information Security Officer, Comcast


Share With Your Community