Episode 600 ·
Preparing a Security Strategy for a Post-Quantum World with Greg Wetmore, Vice President of Product Development at Entrust
Today we’re talking to Greg Wetmore, Vice President of Product Development at Entrust. We discuss the advent of post-quantum cryptography; how to prepare your company’s security strategy for a post-quantum world; and lessons learned from leading through company mergers and acquisitions.
All of this right here, right now, on the Modern CTO Podcast!
Check out more of Greg and Entrust at https://www.entrust.com/

About Entrust:
Entrust keeps the world moving safely by enabling trusted experiences for identities, payments, and digital infrastructure. We offer an unmatched breadth of solutions that are critical to enabling trust for multi-cloud deployments, mobile identities, hybrid work, machine identity, electronic signatures, encryption, and more. With more than 2,800 colleagues, a network of global partners, and customers in over 150 countries, it’s no wonder the world’s most entrusted organizations trust us.
Transcript
(Joel Beasley at 00:00:01) Today, we're talking to Greg from Entrust about post-quantum cryptography. You're listening to Joel Beasley, Modern CTO. Greg.
(Greg at 00:00:14) Hey, Joel. How are you?
(Joel Beasley at 00:00:15) Good. So I am really curious when I saw the opportunity for this conversation. I saw something that I had never seen before, and it was called post-quantum cryptography. Now I understand quantum. I understand cryptography, but I don't understand what the deal is with post-quantum cryptography.
(Greg at 00:00:35) Well, I think the starting point there is quantum computers, first of all. So a quantum computer is a fundamentally different computing mechanism than what we're used to today. Compared to the chip in your laptop or the chips in your phone or the computer chips in almost everything, a quantum computer works on totally different physical principles, quantum mechanics, and it encodes information in a different way called qubits. And a quantum computer, it turns out, is going to be really good at solving certain kinds of problems much faster potentially than classical computers can today.
(Greg at 00:01:07) And so some of the excitement around quantum computers is their ability to advance research in chemical systems, material science, pharma, biopharma, because they're really good at simulating physical systems. Turns out though, one of the things quantum computers can do, and we've proven that they can do, is break the public key cryptography that underlies just about everything you do today online. Secure transactions on the Internet and the security mechanisms built into almost every connected device. And so cryptographers have understood this now for a number of years and have been working on what we call post-quantum cryptography or quantum-safe cryptography. And that's really looking to address this problem that will come from a scaled quantum computer to be able to break today's public key cryptosystems.
(Greg at 00:02:00) Quantum-safe cryptography is going to be safe from attack from a quantum computer, but also from a classical computer. And it's going to require us effectively to transition all of the security mechanisms that are based on public key cryptography today to new cryptosystems, quantum-safe cryptosystems.
(Joel Beasley at 00:02:18) So I actually understand it a little bit better now. Thank you. I've had a conversation with the creator of Ripple, the cryptocurrency, and we touched lightly on this about a year or so ago, so it's a little bit fuzzy for me. But I asked him this exact question about the quantum computers breaking, and he said yes, and that it's really far away, but they're working on quantum-safe algorithms and they can switch it. If they needed to switch it sooner, they could switch it pretty quickly.
(Joel Beasley at 00:02:50) But the reason why they don't switch to it directly right now is because they're slower than the unsafe ones.
(Greg at 00:02:59) So first of all, we need to be careful. You brought up cryptocurrency. So cryptography and cryptocurrency are certainly two different things. Cryptocurrencies are based on some very sophisticated secure cryptographic mechanisms. The cryptography is a much more generally applied security mechanism.
(Greg at 00:03:16) So it's everything you do on the Internet through your browser. All the security mechanisms built into your operating system or your mobile phone for the most part have cryptographic systems in them. And most of that also uses public key crypto, which is the system that we're concerned with here. So touching on a couple of the other things you brought to the discussion, the research in the quantum computers is advancing quickly, but there isn't a quantum computer yet that's scaled to the size and speed required to break today's cryptosystems. So it's a bit of a prediction to say when will this happen. And most experts think it's in the seven to ten year time horizon where a quantum computer is going to be large enough and fast enough to be able to actually affect the cybersecurity of our connected devices and systems today.
(Greg at 00:04:09) But I think what we've learned from past crypto transitions, we've done this before. Cryptography evolves over time. Mathematicians and scientists find defects in these algorithms and we have to change them over time. And we have done this before. For instance, we've moved from SHA-1 to SHA-2 hashing algorithms over the last few years. We've changed from RSA public key crypto in some places to Elliptic Curve.
(Greg at 00:04:36) One of the things we've learned from those transitions is they're time-consuming, they're expensive, they're difficult for organizations to manage, and legacy systems often get stuck in these old security mechanisms and it's really difficult to change them. So this transition to quantum-safe, we have to learn from our past here and understand it's going to take some time. Starting now, taking some actions now to prepare an organization is really important. So that's one comment that addresses the time horizon. We know this is going to take a long time. It's going to be difficult for organizations.
(Greg at 00:05:13) We can't predict exactly when it will happen. Is it two years away? Probably not. But it could be. Is it five, seven? That's what the experts are thinking right now. You also talked about performance, and that goes into the impact of this transition as well. Quantum-safe cryptographic algorithms do perform differently. Keys are larger. The algorithms take more time to execute. Message sizes are larger. And that goes to my earlier comment that this transition could be difficult, will impact the systems as they exist today. And understanding, testing, being able to make that migration over time is really important, and it calls for action now, really.
(Joel Beasley at 00:06:01) So I'd like some clarity. So we talked a little bit about the speed and performance and ability to crack on the cryptocurrency side. For the public key, we are there yet. We're not. I thought you said earlier that we've already been able to crack the public key. So we are able to do that aspect. We're just not able to crack a specific currency.
(Greg at 00:06:25) No. That's not quite right. So what mathematicians have done, they've discovered a mathematical algorithm. It's called Shor's algorithm, and it can run on a quantum computer. And so we know mathematically that a quantum computer that's big enough and can run Shor's algorithm will be able to crack public key crypto.
(Greg at 00:06:47) But we're waiting for that, what we call a scaled quantum computer, waiting for that quantum computer to exist, to be discovered and realized, before that's going to happen. And that's what really is that seven to ten year time horizon. We're seeing these advancements in quantum computing almost every month, but the state of the art today are quite small quantum computers that are not powerful enough, not large enough or fast enough to actually break the security mechanisms that we're talking about.
(Joel Beasley at 00:07:18) Are there any computers that are quantum computers that can break any types of encryption? SHA-1, SHA-2, RSA, Elliptic, any of those?
(Greg at 00:07:27) So today's state of the art public key crypto, you talked about hashing algorithms, SHA-1 or SHA-2, or public key crypto or say an Elliptic Curve. When you're using best practice sizes and implementations of that crypto, today is safe. Cannot be broken by today's classical computers, cannot be broken by today's quantum computers because they're small.
(Joel Beasley at 00:07:52) Okay.
(Greg at 00:07:52) Or not large enough.
(Joel Beasley at 00:07:54) So we don't need to freak out.
(Greg at 00:07:55) Yeah.
(Joel Beasley at 00:07:55) It's not working now.
(Greg at 00:07:56) Yeah. But there is a real call to action here because this is coming. It's a, in my opinion, an inevitable consequence that when you look, every month, if you're watching the research, Microsoft or IBM or Google, some of the biggest, most capable technology companies in the world are announcing further advancement in quantum computers. You can bet that some of the largest governments, China, United States, are working on this too. So my point of view is these are well-funded organizations.
(Greg at 00:08:26) They're motivated to build these quantum computers because of the opportunity to do amazing things. The cybersecurity consequence just kind of tags along with that. So this is going to happen. Organizations have to start thinking about the transition. But you're right to say this isn't a tomorrow, but it is, the time is now to start thinking about, planning for, understanding the journey from where we are today to where we need to get to.
(Joel Beasley at 00:08:56) So quick background about me. So I was a software engineer for 17 years, and I started the show. Then the show became my full-time job, so I haven't been actively writing code the past three years. A year and a half to two years ago, I did a special series, three or four episodes on trying to understand quantum. So I went onto YouTube. I found red versus blue or something like that, learned some of the basics about it, had the head of quantum at Honeywell come on, had Robert Sutor, who wrote Dancing with Qubits, he's the head over at IBM, come on, and talked about the state of this quantum computing. Because when you see an emergent technology and everyone's talking about it and there's tons of money, you can't not go pay attention to it. Everything in this environment has the ability to knock an industry out overnight. So I'm curious. You don't manufacture the computers. Right? Are you writing books on them?
(Greg at 00:09:57) No. No. We're a cybersecurity company, and we are building the security infrastructure that's going to allow our customers and organizations all over the world to remain safe, to be able to make this transition from today's classic public key cryptosystems to tomorrow's quantum-safe cryptosystem.
(Joel Beasley at 00:10:16) So companies are budgeting for that in 2023?
(Greg at 00:10:19) They are starting. There's some regulatory and compliance signals to tell customers that the time is now to start. The NSA released security guidelines in September 2022. The US passed the Cybersecurity Preparedness Act in December 2022 that called for all US federal agencies to start preparing. ETSI and BSI, standards organizations in Europe, are talking about organizations needing to make this transition.
(Greg at 00:10:53) So there's starting to be real discussion in the industry. Analysts are starting to follow this and publish guidelines. The call to action is the right way to think about this. This discontinuity, so to speak, is coming as quantum computers get larger and faster, and organizations need to prepare their security mechanisms as a result of that.
(Joel Beasley at 00:11:17) It's funny because you don't usually see the government lead on topics. So if you see the government leading on the security topic, I'm curious if maybe in their own private programs, they're starting to get really, really close or they've already done it.
(Greg at 00:11:31) Well, it's such a tantalizing capability if you're an intelligence organization or a national level entity to be able to watch and listen to the world's secure communications. And so, yeah, you can bet the United States and China and many governments around the world are investing heavily to obtain that capability.
(Joel Beasley at 00:11:53) And so walk me through this process. Right? Let's say I'm sufficiently concerned, and it's on my radar for 2023, 2024. As a business, how is this impacting me? Is it in my development teams? Is it in my internal IT infrastructure? I mean, cryptography touches everything. So where do you even start?
(Greg at 00:12:15) You're certainly right about that. Organizations find that public key crypto literally is everywhere in their infrastructure. It's in the applications they build. It's in the systems they deploy. And so really that is the starting point. We talk about the journey from where you are today to where you need to be, and it's pretty straightforward. I think the first step for organizations is to create a team. We call it a cryptographic center of excellence. You could call it whatever you want. You need to create a group who's responsible for managing the cryptographic assets of an organization.
(Greg at 00:12:49) And once you've got some people who are responsible, then they can start down this path. The next step we talk about to our customers is understand the data that's in your organization. And it's really the most secure, most sensitive, most important data gives you that map on where to start. And the next step after that is really understand your cryptographic assets, inventory your keys and certificates and secrets and crypto algorithms that are being used in your organization. There are some great tools and capabilities in the market. We build some of those that can go out and inventory all of that, really give you visibility to the scope of this issue. Then we talk to our customers about, you know, build a strategy, build maturity in how you manage those cryptographic assets. Really what you want to build in your organization is what we call cryptographic agility, the ability to change the algorithms and keys and certificates that are being used underneath all of these systems in a way that's automated and orchestrated and policy-driven and not require a whole bunch of people to go out and make error-prone changes. And then ultimately, once you have built that level of maturity to manage your cryptographic assets, you need to test and migrate and operationalize this transition to quantum-safe.
(Joel Beasley at 00:14:08) What does that migration actually look like in execution?
(Greg at 00:14:11) So it really depends on how much your...
(Joel Beasley at 00:14:15) We can pick one. Yeah. We can pick one. Alright. Let's say a GitHub repo type deal. Maybe my code repository situation. What would the transition actually look like if I wanted to move from one to another?
(Greg at 00:14:28) So we talk about cryptographic agility, and that's really the end state we're looking for. And so if I was talking to a development team or development organization, I'd be talking to them about you need to externalize the implementation of your crypto, make it policy or configuration-driven. So it's not hard-coded in your code that I am creating an RSA key and I'm using it to open a TLS connection, that those mechanisms are driven by configuration. And basically allowing you once that application is deployed to change your configuration to say, I want quantum-safe keys in this TLS connection. That's the nuts and bolts details of it.
(Greg at 00:15:13) And so that ultimately probably requires applications to change, operating systems and infrastructure to change, because a lot of that today is hard-coded and isn't crypto-agile as we call it. So there's real meaningful amounts of work to do. And that's again, we go back to this call to action that even though this event where a scaled quantum computer is suddenly available, the preparedness, the transition is long and we need to start working on this now.
(Joel Beasley at 00:15:46) Yes. Especially at the larger companies. Right? Because they do initiatives way far in advance and moving a giant ship is really tough, especially when you think of the scale of, you know, Walmart. You're talking about tens of thousands of developers and all of the big companies.
(Joel Beasley at 00:16:07) I've got a couple more specific questions I want to dive into. Also, I'm not an expert here. You can help correct me in my understandings and things like that. I'd be appreciative of that. Do you have audit tools that you can unleash into my environments and you can tell me where this is happening, static code analysis type tools?
(Greg at 00:16:25) Yeah, that's exactly what we're part of the capability that we have as a company and others do too. It's really inventorying your cryptographic assets, tools that can go out, scan your network, so, you know, open ports, make TLS handshakes, figure out what keys and algorithms are being used on all the network services. You know, look on your disks, look for keystores, look for cryptographic libraries deployed in all the different systems that are in your organization, and basically give you that inventory of your cryptographic assets, your certificates, your keys, your secrets, your cryptographic libraries or algorithms like OpenSSL or commercial cryptographic libraries or crypto libraries that are part of operating systems. That really gives you the visibility to what do I have, what's being used in my organization.
(Greg at 00:17:18) There are great tools that do that, and then that sort of first step then lets you, okay, let's build policy around this. Let's build automation and orchestration so that, you know, starting with the very most important places in my organization that's touching the most valuable data that needs to be secure, that's where you go first. But it gives you this roadmap, basically, to visualize the scope of the problem and start implementing policy and orchestration to be able to transition that to post-quantum.
(Joel Beasley at 00:17:49) And where are we at in ease of ability to do this? The system to manage these keys, so you'll do an audit and then the system to manage them and permission them, that's what Entrust builds?
(Greg at 00:18:04) That is part of what Entrust builds. We're also building cryptographic implementations and our security infrastructure. PKI, for instance, our hardware security modules can issue quantum-safe certificates, can create and manage quantum-safe keys. So a lot of the security infrastructure required today when you're operating using public key crypto, that's our stuff. And tomorrow, as you're making that transition to post-quantum, our infrastructure can help you do that too. But sort of going back to the first part of your question, how easy is this?
(Greg at 00:18:38) It's really a spectrum, and it's typical in an IT transition, any kind of technology transition. The more modern, the newer applications and systems have easier and better capability to automate and be cryptographically agile. The older legacy systems, you know, we are going to have this tail of legacy systems that are really hard to upgrade, hard to change. We've seen this before, and that long tail is going to be a work effort to make this transition.
(Joel Beasley at 00:19:15) Behavior change is hard. It's one of the hardest things in business and in engineering. There are still companies out there that don't test their code, right? Explain to me how you work with a company that wants to do this. You said the steps. I'm good with the steps. You create a team, you secure, map data, you figure out where to start, you do inventory, get to level of maturity, you test and migrate. So I'm good with that. But from a human standpoint, are you putting someone in their office? Is it a situation where they have to have the drive and desire to push it forward and you're not completely hand-holding as consultants every step of the way? Describe how that works.
(Greg at 00:19:54) Well, I think part of change in an organization has to be driven at the leadership level, and we're starting to see post-quantum or quantum readiness being at board level and C-level discussion. We're just at the beginning of the education and the awareness is starting to build. You know, the big analyst companies are talking about it. We talked about organizations like the US government, you know, publishing and making laws. That's sort of the beginning of this. And when you have that leadership backing, when you have a board member asking a CISO the question of what are you going to do about quantum? Are you ready? Do you have a preparedness program in place? That's the start of this organizational change that you're talking about. And I think that's a really important piece to seeing this call to action start to be adopted in organizations.
(Greg at 00:20:51) And then you talked about sort of the person who has their fingers on the keyboards. How, you know, how do we help them? So I believe we're building some great technology that does make that person's job easier, makes it more about automating and setting policy and orchestrating and less about digging in manually making changes in all of these systems. There's a big ecosystem piece to this as well. No IT system today really exists on its own. The operating system vendors and the networking equipment vendors and the application and the cloud services, and all of this stuff has to work together. And the security infrastructure tends to be interoperable and standards-based. And we're still pre-standards in a lot of places for quantum, but that stuff is rapidly coming. We're working with the IETF on standards. NIST just published the finalist algorithms, and that should be standardized over the next year. So we're right at the right time where technology companies are going to start adopting these new standards. And an IT analyst or a person whose job it is to manage these systems is going to start to have availability from their vendors capability that will allow them to make this transition.
(Joel Beasley at 00:22:03) And how long has Entrust been around?
(Greg at 00:22:06) Entrust as a company has been around for decades, since the sixties, to be quite honest. So many decades. As a cybersecurity company, we're 30 years old. So we've been doing public key crypto, for instance, since the nineties. We're one of the leaders in this industry and have a track record of innovating and really keeping our customers safe for years and years.
(Joel Beasley at 00:22:33) Now, obviously, we're here to talk about quantum readiness and post-quantum cryptography, but do you want to give a quick shout-out for maybe some of the other lines of business that Entrust has? I don't know if we're prepared for that, but if you are, rock and roll.
(Greg at 00:22:47) Sure. So I mean, Entrust is a global technology company. We really help our customers secure their identities, their payments, and their digital infrastructure. So we spent sort of the bulk of this discussion talking about our customers' digital infrastructure, their systems and communication mechanisms and data security that underlies their IT estate. But, yeah, we have some great solution capabilities that, whether it's digital identity or physical identity, whether it's the credit card or driver's license or passports you have in your wallet or the digital identity that you use to log in to your bank or your business or your VPN, we have great technology that customers deploy all over the world to secure digital identities and payments. We're the largest provider of technology that allows companies to create credit cards, payment cards, debit cards, whether those are physical or digital. So whether it's, you know, tap and pay with your phone or tap and pay with your card, we're one of the largest providers of all of that technology in the world.
(Joel Beasley at 00:23:52) That is pretty cool. I saw on my notes that you guys have a lot of employees, and I thought they clearly aren't just a startup that's trying to solve this quantum problem. And it's great to hear that you guys have been in the industry for that long. Why did you get into quantum readiness? Were you the one that spun it out and started this endeavor for the company? Or how did that work?
(Greg at 00:24:15) Yeah, I don't, we're like you said, a big enough company, I don't think I can take sole credit for that. We've been in the PKI, public key infrastructure business, for decades. And the threat from quantum computers is sort of very much, affects public key cryptography. So it sort of very much affects one of the core security products that we provide to our customers. So from sort of the beginning of the discussion about the impact of quantum computers on public key crypto, we've been involved in thinking about, well, how does this affect our products? How does this affect our customers? So we've been following this as a company for a number of years and investing in research ahead of that and are sort of, you know, quite proud of the fact that we have a program in place today that has capabilities available to our customers today, even pre-standards, even sort of at the beginning of this journey. We're starting to help our customers with this transition.
(Joel Beasley at 00:25:10) How long until we should expect standards to emerge?
(Greg at 00:25:14) Well, the four finalist algorithms were announced in June 2022 by NIST, and they're talking about that standardization effort to take about a year from June. So, you know, I'm expecting in the next few months to see sort of standard official implementations of quantum-safe algorithms for digital signature and for encryption. We're working with the IETF. That's a body that standardizes a lot of the protocols and messaging formats that we use on the internet. And so they're the body that holds a lot of the standards around PKI and other things. We're working with them, so that standards initiative is ongoing. I suspect that will be advancing over the next few months. So, like, you know, my suspicion is, or my prediction is, that over the next year, we are going to see real, adoptable, interoperable standards published in this space.
(Joel Beasley at 00:26:06) And so the idea is we get ready, then the standards come out, but we already have some benefit just from the act of taking something that was fixed and essentially making it somewhat dynamic, right?
(Greg at 00:26:19) Yeah. Building that maturity so that you can make this transition, that work we can start now. We have pre-standards implementations of a lot of the stuff, so organizations can take that, test, try, adopt, put them in their labs, proof of concept, prototype, whatever you want to talk about, we can do that. And then there are some very specific use cases where people like the NSA have said, hey, you might want to think about doing this now even before standardization. A couple of places that we talk to our customers about: one is if you're a device manufacturer and the in-service life of that device is more than ten years, think about connected IoT devices or manufacturing or industrial controls or even your car. Thinking about quantum-safe now, if the in-service lifetime of that connected device is, you know, ten years, you might want to be putting PQ in it today. The other use case we talk about is a threat we call "harvest now, decrypt later." Think about all of the secure information that's traveling over networks today, over the internet or wide area networks. That stuff's probably encrypted, hopefully. But a sophisticated adversary could be scooping that up and saving it and waiting. You know, ten years from now that information may still have a heck of a lot of value to the bad actor who can then decrypt that with their quantum computer and access that confidential information. So there are some use cases today where customers are thinking about, okay, I need PQ now, even though we're ahead of standards. And, you know, we're supporting our customers thinking about that too.
(Joel Beasley at 00:28:02) And how did you get involved with Entrust?
(Greg at 00:28:04) I started at Entrust as a young software developer. I've had a long career. I've been at Entrust now for over 20 years. And, you know, we're talking about crypto. That was one of the draws I had to Entrust as a young software developer. I was interested in cybersecurity. I was interested in cryptography, and this was a company with a big engineering footprint in my neck of the woods. I'm Canadian, where I lived and where I was educated. And, yeah, I was interested in it then and still interested 20 years later.
(Joel Beasley at 00:28:37) I want to talk a little bit about leadership and your journey, but first, what's the website?
(Greg at 00:28:42) Entrust.com.
(Joel Beasley at 00:28:43) That's easy. I like it. Okay. So you've been at this company with them on this journey for 20 years. You started out early on your career. Now you're clearly leading teams and have an incredible amount of responsibility in the security space. How did you do it?
(Greg at 00:29:03) Great question. And part of how I'll answer that is slightly different. You know, why are you still here doing this? That's maybe a starting point. I'm still here doing this because I'm working with some of the smartest people I've ever met, and we're building things that matter. As an engineer, I think one of the things that really drives me at my core is building things that deliver meaningful value to our customers. Our customers are some of the biggest companies, banks, governments around the world, and they use our infrastructure to really make our lives better, make our financial transactions secure, make crossing borders secure, very meaningful contribution that Entrust makes to society. So that's what drives me as an engineer, and that's why I'm still here doing this. And that's sort of a roundabout way to say, well, how did I get here? It was, you know, starting with something I was really interested in. We talked about as a young engineer being interested in cybersecurity and crypto and getting a chance to do that and learn that as a software developer in a tech company. But really, I just, it became my passion, became my interest to learn more and more, learn more about my customers, learn more about our technology to the point where I was able to have more influence and accomplish more strategic things as my career progressed. Interesting working at Entrust, we were, you know, pretty small company when I started. We were public at the time. We ended up being private. We ended up being acquired. So it's kind of like I've worked for three or four different companies over time, and those changes, you know, some people change the company they work for to get the next opportunity. But those ownership changes in the company was one of the things that really allowed me to extend my career experience, get new opportunities, work with different people, work on different product lines, work with more customers. And I think it's that varied experience, even though I've been at the same company for 20 years, I think it's those changes that really allowed me to step into the next role, gain the next amount of experience, and build my career.
(Joel Beasley at 00:31:07) And there might be somebody out there that's leading a team that's going through a merger right now, and you've done it a couple times. How do you lead a team through a merger? What's the important thing to think about?
(Greg at 00:31:21) It's a great, first of all, that transition is a great opportunity for a leader to build their skills, learn something new, but also, you know, show off their profile to the people who work for them and the people around them, the leaders around them and their managers and the strategic leaders in the company. It is a difficult thing to take a team or a company through an acquisition. There's always going to be differences in culture. There's going to be differences in strategy. There's a lot of change management. You know, change is hard. Engineers in particular are pretty change-averse. You know, they like their comfort zone. And so as a leader, you can help take your team through those changes, manage through those changes. And I think you've got to go in with an open mind. Most companies, when they acquire someone, they're trying to get the best out of that organization and that company. They want you to bring to the table, you know, the things that you do really well, the aspects of your culture that you think are incredible or excellent. And so I took that approach of not sort of thinking that the company acquiring us was going to just kind of change us to their, you know, to their mold, so to speak, but that they were bringing their best intention, and they wanted to hear from us or from me the best parts of what we brought to the table. And so that kind of mixing or melding of two company cultures, I think, is what really results in a stronger, better, faster organization at the end or as you get through a merger.
(Greg at 00:32:57) And I really took that to heart, adopted that mindset in my leadership style, and brought my teams through that transition point with that in mind that, hey, this organization wants us to be the best we can be. They want us to bring to them all of the things we do incredibly well and learn from them all the things they do well and build this kind of meld, meld these two cultures together.
(Joel Beasley at 00:33:21) I always thought it was interesting. So I've never worked at a large company with thousands of employees that got acquired or anything of that nature. But I have found it interesting doing all of these interviews and talking to people outside of the interviews, how there's a lot of fear when they're getting acquired. And I thought it was somewhat counterintuitive or at least interesting for me because as an entrepreneur, you know, the most important thing when merging these companies is culture because you need everybody to get along, have similar styles, and be compatible. But also, the acquirer typically is gonna do everything they can to get the people to stay because the last thing you wanna do is acquire a company and have all the talent leave.
(Greg at 00:34:09) Yeah. You're definitely right. And we've done the opposite too. I've been the target of an acquisition, and since Entrust was acquired in 2014, we've probably acquired four or five different companies. And as a technology leader working on an acquisition from the acquirer side, you know, we're evaluating, we're doing our due diligence, evaluating the technology and the products and the customers and how good is this stuff and how does it fit with our stuff.
(Greg at 00:34:38) But, you know, one of the largest conversations we have as an acquirer is how do we keep these people effective and happy and, you know, how do we take them to the next level? How do we grow this? And that really starts with the people. You can't grow and be successful unless your colleagues, your people, are feeling empowered and included and part of the organization. And so we work really hard when we acquire a company to share that, to share our vision, and to bring that team in and make sure they are empowered to be successful.
(Joel Beasley at 00:35:17) Your acquisition strategy, is it just as deals come about, or do you actually have a team that's continuously looking for possible deals? How does that work?
(Greg at 00:35:27) Yeah. The latter. We have, right at the C-level of our company, a person responsible for our corporate strategy, and acquisition is part of that.
(Joel Beasley at 00:35:37) Oh, very cool. So that's a title. I didn't know. That's something new I'm learning. So corporate strategy can be a title for people who are looking for potential acquisitions.
(Joel Beasley at 00:35:47) Are there any titles? Do we see head of quantum security readiness? Have you seen any of those yet, or is it a little bit too early?
(Greg at 00:35:56) Yeah. I haven't. I think it's gonna fall in the CISO part of the organization, or CIO, you know, CTO. Those, the technology part of an organization, is where this initiative is gonna sit. I do think quantum preparedness will be a board level. There will be board level visibility. It will be part of the discussion that happens at that level of a company and at the C-level of a company. It's that important and it's that impactful or comprehensive, this journey from where we are today to where we need to get. So this is an important strategic item for all organizations to start thinking about.
(Joel Beasley at 00:36:36) If you're advising a company that's, let's say, mid-market engineering type company, and their first question in the boardroom is, okay, we understand that we need to be quantum ready. How do we think about budget? Is it a percent of existing spend? How do you start to figure out what numbers would look like to do one of these endeavors?
(Greg at 00:37:01) Yeah. So I think practically companies aren't quite there. Like, we're right at the start of this. Most organizations today haven't allocated budget to this, and so there isn't a formula yet. But, you know, we foresee that this is going to be at that level of discussion where companies are setting their IT and technology strategies, that quantum preparedness will be part of the spend profile for those companies.
(Joel Beasley at 00:37:26) Well, it's the equivalent of removing every single lock in your city. Walk around and grab whatever you want if you're not ready for it.
(Greg at 00:37:34) That's a good analogy. You know, public key crypto is under almost every security mechanism in an organization today. It's everywhere.
(Joel Beasley at 00:37:44) I can flush that out with your marketing team if you want. This is fun, man. I've got one last final leadership question. I want you to think about one piece of leadership advice that you've heard. It can be unique or cliche. It doesn't matter. But the important part is that you took this leadership advice, you put it into action, and you remember it. Like, it continuously comes up in your brain from time to time, like a lesson or a principle that you've learned as a leader.
(Greg at 00:38:14) Yeah. So the one that comes to my mind is be obsessed with delivering value to your customers. And what I mean by that is when you're faced with a decision, choose the path that's best aligned with the interest of your customers. You know, I've, it's amazing how the alignment with your customer's interest results in the best outcomes for the company, the best outcomes for its employees, the best outcomes for its shareholders. And for me, it's almost easier to apply this dated on those day-to-day decisions than maybe the big strategic ones. It's do we take this, you know, more difficult path because I can deliver something better to my customers? Do we fix this last problem or defect rather than release the software because of the impact it will have on my customers? You know, should we extend ourselves outside of our norm or our policy to help this customer? It's those day-to-day decisions that drive this obsessive alignment with customer value.
(Greg at 00:39:18) And I go back to, you know, I've very rarely taken that path and then regretted it after thinking, well, that actually didn't deliver the best outcome for the company or the employees or the shareholders or some other stakeholder.
(Joel Beasley at 00:39:31) How did you learn that lesson?
(Greg at 00:39:33) Oh, it was, you know, a mentor, a manager that I worked for for a while, a great leader, and that was one of his principles.
(Joel Beasley at 00:39:42) Fantastic. Dude, we did it. We made a podcast. How do you feel?
(Greg at 00:39:47) Feels great.
(Joel Beasley at 00:39:47) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn, or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.