We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
In this interview from Black Hat 2026, José Rosas-Bustos, chief executive officer of EigenQ, joins theCUBE's Krista Case to discuss why crypto agility, not quantum computing itself, is the real challenge enterprises must solve before looming 2027 compliance deadlines. Rosas-Bustos explains why "harvest now, decrypt later" attacks are accelerating urgency across regulated industries, even as awareness remains uneven. He details how EigenQ applies quantum photonics research to harden compute infrastructure at the hardware level, arguing that fixing a single cip...Read more
exploreKeep Exploring
Why should security leaders begin preparing for post-quantum computing threats and the upcoming compliance mandates (around early 2027), and why is this a pressing issue?add
What should management consider when deciding whether to implement quantum-resistant technologies (now versus in future), and what are the main drivers and obstacles to adopting quantum-resistant compute infrastructure?add
How should an organization prioritize which cryptographic assets to address (or migrate) to protect against future quantum-enabled attacks?add
Given the combined threat of artificial intelligence and quantum computing, is upgrading individual ciphers sufficient to protect systems, or should organizations instead prioritize implementing crypto agility?add
>> Hey, welcome back to theCUBE. We are rolling right through the afternoon here at Black Hat 2026 with our live coverage of the event. I'm Krista Case, and we've got a really interesting session for you right now. We're talking a little bit about quantum computing. We're seeing these kinds of harvest now, decrypt later attacks start to emerge where data is stolen today and is potentially decrypted years from now as quantum capabilities mature. Now, this is certainly an issue that organizations need to start thinking about, but one of the problems is that they can't replace their infrastructure simply to prepare for this post-quantum world. So, they need some ways to strengthen their security while protecting the investments that they've already made. I have the pleasure of sitting down right now with José Rosas-Bustos, CEO of EigenQ. José, thank you so much for joining theCUBE.>> Thank you for having us.
Krista Case
>> Absolutely, really appreciate it. Yeah. So before the cameras were rolling, José, we were talking about, there are some compliance mandates that are just around the corner in early 2027, regarding post-quantum computing. So I'm wondering if you could talk a little bit about, why security leaders need to start preparing for this, the compliance piece of it, but also kind of why is this a pressing threat?>> Yeah. So I think quantum technologies have been kind of underestimated in the sense that when they're gonna become relevant. And at the beginning we were thinking 2050, then the industry moved to 2040, 2035, 2030. And now all of a sudden we have several countries and regions that are preparing for a potential threat as early as 2027. And when we're talking about critical infrastructure that whatever we do may take years to migrate is creating, this urgency that is kind of like asymmetric in the industry. So there are actors in the industry that are very aware of the issue, national security, defense, and intelligence. But then other actors are like, "Why will I have to do anything?" So we are facing this kind of asymmetry of understanding of the information that is available there. I believe that the mandates that different countries are putting together and enforcing actually are helping more on this understanding.
Krista Case
>> Sure>> . But the fact is that this is not a quantum problem. This is a crypto agility problem.>> Yes.>> This is a problem that we have been facing as an industry for a long time. And if we had already implemented countermeasures for crypto agility in the past, we would not be facing the issues that we're facing today.
Krista Case
>> It's a very, very good point, right? And I think that's a great segue into looking at, the problem that EigenQ is designed to solve, which I think it's really kind of around that infrastructure piece of it. And I think that's really, kind of the heart of the problem. But maybe you can talk a little bit more about what you're observing from that perspective.>> Yeah, so, when we are in these cycles that we need to harden our cybersecurity itself, the problem you can solve it in different aspect, but it's a systematic problem. It goes from the hardware, operating system, libraries, and the like, and there are many pieces that an attacker can exploit. So it's not a single thing that you need to fix, it's something that you need to fix in a comprehensive way. One of the things that we identified very early on is that the compute infrastructure will become something very critical that needed to be protected first. And we are an applied quantum technology company and we decided to apply our quantum mechanics knowledge and our quantum photonics knowledge to harden conventional compute infrastructure. And this is what we are already deploying in the market along with some OEM partners.
Krista Case
>> Mm-hmm. Absolutely. And I know you had an announcement with Intel, which we'll get to. >> Yes
Krista Case
>> . In just a second. But maybe, so, understanding why that server infrastructure is an important piece of this metaphorical puzzle. At the same time, as we've been talking about, enterprises can't simply rip and replace their server infrastructure. So how should security leaders think about, if they're bought in, which they should be, that this is a problem that they need to address, how should they think about, approaching it given the fact that they can't rip and replace their entire server infrastructure?>> Yeah, so you're touching on 3 different points. You have the infrastructure is already deployed. And then you have your decisions about purchasing the new devices or the new cycle. And then you have what is gonna happen in 3 or 4 or 5 years with the offering that these providers will have to offer. So the natural thing to do from the management perspective is that if there is a technology there that can protect me better against conventional attacks, and against potential quantum attacks, the question is why I will not implement that today. So then it's a matter of a budget. If this is within your budget, so what justification are you gonna have to your board or to your management in 3 or 4 years about why you didn't make this decision today? So that is one of the drivers.
Krista Case
>> So driver one is sort of getting the budget.>> Yes, correct. And then there is, you have this dichotomy of solutions because To become quantum resistant, you can do it in many ways, but usually if you are targeting your current install base first, that becomes very lengthy projects that, as you were saying, you will not be able to rip and replace immediately. The low-hanging fruit is to buy your new servers or your new compute infrastructure with technology that is already compatible, that is already being certified by the manufacturer, that has integrated this technology. What is the problem there is there is no offering. So we launch on June 17th, the first compute infrastructure server that has quantum-resistant technology integrated by the manufacturer along with HPE and Intel. But there is not a wide offering.
Krista Case
>> Yeah.>> So then even if you want to try to do the low-hanging fruit, actually you don't have so many options.
Krista Case
>> Yeah, no, that makes sense. And maybe you can talk a little bit about the announcement and the partnership. I know you mentioned Intel and HPE.>> Yes.
Krista Case
>> Can you give a little bit more context around that announcement? >> Yes
Krista Case
>> . And then also, what strikes me is this is going to be, vendors that are already widely deployed in customers' environments. So I'm sure that was an important part of that decision to partner with those companies.>> Yeah, so the compute infrastructure actually has very few actors. But they are brands that are being consolidated over the years and the end customers trust those brands and they have already a full support and SLAs that create this trust. So for a company like ours, it will be very difficult to create that level of trust in the very short term that we need to deploy this technology. So we make a decision to be an OEM component, to be a component that actually is integrated in a platform that already has the customers and the trust itself. And on the other hand, these brands are having the problem that even though they may have a solution down the road, they were not able to provide a solution in the short term. And that creates this opportunity for us. Very important partner for us is HPE. We have been working with them for kind of a good year, year and a half. And we ended up integrating a solution that allows us to provide these quantum-resistant services natively in their platform. And we also got the support of Intel on that particular platform as well. So it's a triangle that is Intel, HPE, and us providing these kind of solutions. What is the big announcement of that? That is a product that is already in the market. It's a product that you can buy today. That is a product that nowadays we have around 47 proof of concept running in different environments. So the expectation is that the full commercialization will start in Q4, Q1.
Krista Case
>> Mm-hmm.>> Yeah.
Krista Case
>> And so José R. Rosas-Bustos José, on the concept of proof of concepts, I understand that EigenQ is also doing some sort of quantum-ready assessments. >> Yes
Krista Case
>> . For the practitioners that are maybe here at Black Hat and they're interested in sort of understanding their organization's readiness for this post-quantum world. What are maybe one or two of the first steps that they should think about taking?>> So I will say that there are many things that are being written about this, if we go by the standard recommendations, you should start with inventory and identifying what will be the vulnerable potential ciphers that you may have over there. But in practice, in the practicality of it, actually it's a bit different because inventory only gives you information, but it doesn't allow you to make decisions.
Krista Case
>> Correct.>> So the main driver that you can have nowadays though is how long you need to store information that is critical for your organization and what will happen if that information got compromised 5 or 10 years from now. So then you have many organizations that they need to store information, and if that information is not encrypted in the right way, it doesn't matter if the attack happens today, but you need to start thinking what happens if an attack will happen in 5 years, 10 years, when these quantum capabilities are more likely to be deployed. So it's not only inventory. The inventory will give you where the weaknesses are, then the next step is how do you make the priorities, right?
Krista Case
>> And I imagine that's kind of a collaborative process to a degree, at least with the business, to sort of, to your point, understand the value of the data.>> Correct. And this is kind of— CISOs already know this, that they already have identified what are the critical processes of their business. What is not so much well understood is that is what is the timeframe? And this is the discussion that we have with many of the actors because it's like changes of planning for 2035 versus planning for 2027 in everything is a huge difference. It impacts your budget, impacts the projection that you have. It's a totally different animal. So I believe that the industry was kind of prepared to start with this deployment by 2032, 2033. And that was the common understanding on what we needed to do. 2029 is just around the corner, and for certain critical areas, 2027 becomes the deadline.
Krista Case
>> Yes.>> So then priorities also change with the time frame that you have.
Krista Case
>> And on that note, José R. Rosas-Bustos José, can you talk about where security practitioners might think about prioritizing post-quantum cryptography and upgrading their infrastructure. Given everything we're hearing here at the show at Black Hat, they have a lot of competing priorities.>> Oh, totally, totally. And the conjunction of artificial intelligence and the quantum threat is creating a sense of urgency that we have not seen before in the industry. And this goes back to the point that at the end, one of the main components to solve the quantum and AI problem is crypto agility. And that is a common factor there. So when you are making these decisions as a practitioner, if you are recommending a solution that is only upgrading a cipher, you are just putting a Band-Aid on an underlying issue, is that the ciphers may change, especially the post-quantum cryptography ciphers. We may have new recommendations very shortly as the quantum technology evolves. So Upgrading a cipher is not enough. Implementing crypto agility, on the other hand, creates a skill that provides the organization a strength that is long-lasting.
Krista Case
>> That crypto agility, I certainly agree that's very critical. And for practitioners, what might they expect in terms of that operational roadmap to getting there? I know we've talked a lot about your integration with these OEM partners, but I guess taking a step back, what are, maybe some of the operational steps that practitioners can take?>> Yeah, so then as we were talking about, it's the inventory, then you have the business priorities and then the component on the tactical implementation is Crypto Agility. So then you will have to make those decisions about I will implement the solution as a one-time solution or I will recommend this organization to actually go through an effort that is maybe an extra effort to implement a solution that is more dynamic. And in that sense, we are— facing now concepts that we know them since long time, but nowadays are becoming more important, like hardware dynamic reconfiguration, for example, for cryptographic modules and the ability to upgrade things like the operating system, the firmware over the air and others that we have the technologies, just that it's not been used in a comprehensive way to achieve a full-stack crypto agility deployment.
Krista Case
>> Excuse me. That makes sense, José. And I'm aware that some of these previous kind of past cryptographic transitions, they've taken years, perhaps. >> Yes, exactly. Exactly
Krista Case
>> . And unfortunately, we don't have the luxury of that time right now, but maybe we could leave the audience with what are some of the key learnings that we've learned from some of these previous cryptographic transitions?>> So I think that an interesting example is the process that we started as an industry in 2001 and how national security, defense, and intelligence implemented new cryptographic standards. And then the private sector or other regulated industries, they were like, well, we're not going to implement this now. It's always the economic factor that take place. Nevertheless, every CISO, when there is a new standard, they will want to have the best for their company. And now in that sense, this post-quantum cryptography or quantum-resistant movement actually is creating the same halo. And so in that sense, it's similar. What is very different is the timeframe. Before we ended up having 10 years, now we may have 2, 3 years. And then after those 2, 3 years, we may have to renew the certificates and the ciphers again because something new will come up. So the speed is a huge, huge difference. We have not faced this before.
Krista Case
>> And I'm sure the Crypto Agility will help with that speed as well.>> Hopefully.
Krista Case
>> Yes. Yes, absolutely. Well, José R. Rosas-Bustos José, thank you so much for joining theCUBE. You and your team are certainly doing some very important work in this space, so we really appreciate it. We appreciate the time and the insights.>> Thank you very much for the opportunity.
Krista Case
>> Thank you. Thank you so much for tuning in. As always, don't go anywhere. We're going to be back in just a couple minutes with more of our ongoing coverage here at Black Hat 2026.