Loading summary
A
Welcome to the RSAC Cyberatthetop podcast where security leaders across industries share the strategies, hard lessons and real experiences shaping modern cybersecurity and AI insights are grounded in community and built for every level of profession.
B
Quantum computing has long been viewed as a future breakthrough, but for cybersecurity leaders, its implications are already here. The potential for quantum systems to break today's encryption standards introduces a new kind of risk. One that challenges how we think about data protection, how we think about long term security, and also resilience. In this episode, we'll explore what quantum resilience means for today's enterprises, what's real, what's hype and what actions do CISOs need to take. Now to prepare, I am absolutely thrilled by being joined by the amazing Nooper Davis, Chief Information Security and Product Privacy Officer at Comcast. Together we'll unpack the evolving quantum threat landscape and share practical insights on how organizations can begin building quantum ready security programs today. So Nupur, thank you so much for being here.
A
Thank you so much for having me here. I'm very excited about this conversation.
B
It's a great one, it's a very timely one. People are thinking about it, it's top of mind. And maybe just to start off, can you give us a quick just overview of your role?
A
Yes. So Comcast is a huge and very diversified company. So some of our big brands are Xfinity, which is broadband video mobile home security. About half of the US broadband traffic flows through our infrastructure. And then we have NBC, you know, which is the new studios and all of the entertainment. We have Universal Studios, which is the movie business. We have Universal Parks which is the, you know, they're doing amazingly well. We have sky over in Europe that does huge entertainment and sports company, but also infrastructure. Oh we have things like DreamWorks. So it's a very, very diverse.
B
Just throw it in. Oh, thanks. Like dreamwork. Amazing property.
A
Yeah, it is, it is a very diversified company and so we are the nation's critical infrastructure. And you know, in that role we, we do take that very seriously and, and you know, try to make sure that we are doing the right things wherever possible.
B
And you've got such a diverse estate like you mentioned, critical infrastructure, but you've also got physical things like the theme parks and the movie studios. It'd be great to just get your perspective on how should security leaders think about the timeline for quantum threats being something that's real and material.
A
Yeah, you know that's a really good question because when you think about it, you know, the, the current US government directions is like 2035 time frame, right? All government systems should be quantum ready by then, right? And that seems like a long time, but it's not because, you know, I already feel like we're behind and we started about a year and a half ago on a formal quantum process. Shift to quantum. The time it will take, you know, through every layer of the organizational architecture to, to really get quantum ready. It feels like a long time, but it really isn't.
B
I just remember. I'm sure you do too. The switch from DEs to triple DEs to AES. So many systems, so many that have these standards and protocols just kind of hard coded in. And my question to you is, and this is really just as advice to another CISO, 2035, like you said, feels like it's a ways away, but. And it still feels abstract to I think a bunch of security leaders. Why should CISOs be paying attention to this right now?
A
And you know, your example was really right on our SHA1 to SHA256, that was a decade long shift and we're still not done right. So. And PQC is much, much more complex, right. It's, you know, touching a lot of asymmetric primitives and protocols and hardware and supply chains. And it is because of the complexity that CISOs need to start thinking about this now and really hopefully have already started to think about it. And when you think about, you know, modern cybersecurity, it is underpinned by these cryptographic algorithms, our certificate systems that underpin so much of our security, our token systems that underpin so much of our security. So all of that is impacted by PQC by post quantum computing. And so that is why we need to start thinking about it now.
B
I hear many people talking about quantum resilience like that's the, the, the goal, that's the destination, that's, that's where they want to get. When you talk about quantum resilience, what does that actually mean in practice for an enterprise?
A
So, you know, you'll hear the term quantum agility a lot. And the, the way that we think about it is, you know, NIST approved the first quantum algorithms in August of 2024. You know, this included key establishment signatures, so, you know, a complete set. However, we do know that between now and whenever relevant, quantum computer is ready, there will be changes. You know, in the past NIST has released things that were then, you know, cryptography was broken. So quantum agility means that we need to get ready so that as this journey starts, we are Ready to accommodate whatever new algorithms are established and approved. So, you know, we're starting with a set that are approved by NIST today. They will likely change. There might be more that come in that are more suitable for certain performance constraints. So as this evolves in the next few years, we've got to have that agility, that capability to change the core cryptographic underpinning on the fly. So that's what agility means to us.
B
That's great. I mean, it's a very different architectural approach to just moving from thing A to thing B. It's more like removing from thing A to thing B. But B could change to C quickly, C could change to D and to
A
E into F. Exactly. There could be multiple, you know, we know we're here today, we know that when we get to the destination that we'll be ready for the quantum computer. How, what is going to happen between now and then? You know, there's, there's just a lot happening in this space and we've got to just be agile. We at Comcast build and run our own public key infrastructure, our pki. We operate at huge scale. So that System has delivered 1.5 billion certificates to date. We run our own token systems and the token systems we do about 800 million a week. Some ridiculously large number. One of the journeys that we've been on is, is full lifecycle management of those certificates. You know, how do we take every certificate in the company, whether it's public or private, and put it, you know, first you have to find it and then onboard it onto our full lifecycle management. So you know, they're auto rotated, auto discovered. So that is in a way that first step, right? Like do you know where just your search start? Forget all the other crypto assets, right? So we have, you know, an approach which has three components. You know, the discovery and onboarding to the right systems is the first of those steps.
B
Makes sense. Like if you, if you don't know what your crypto inventory is, you know, how do you, how do you move forward? How do you even figure out where to progress? And I'm wondering if you had to think about priorities, which part of the enterprise is most at risk in a post quantum world? Is it data, identities, communications? How should folks think about that?
A
For a company like ours, it really is almost at every layer. Because let me give you an example, right? The network protocols today are cryptographically dependent. So the fundamental network protocols that our networks run on. So yeah, that is super important. We have close to 100 million devices in our customer homes. And those devices have full cryptographic chain of trust from a safe boot to tamper resistance. Then if you just move up, you know, our API security and APIs are everywhere, you know, depend on cryptographic tokens. So I think it's really hard to pick where. So, and then, you know, you go to third parties. We are very dependent on third party. You know, there are Broadcom chips in our devices. There are other. So, you know, if you think about it, right, it's certificates, it's code, it's library, it's network protocols. You know, our fundamental protocol that cable systems run on, docsis has a cryptographic component. It is very pervasive the ecosystem. It's hard to isolate one part of the ecosystem and say this is the most important.
B
Gosh, I mean, just the way that you talk about it, the estate is so profound. It's just baked into so many processes.
A
Yes, exactly, exactly.
B
And I'm just curious, I'm thinking about, you know, somebody listening to this. They're a ciso, you're well down the journey, right, and you're, you know, you're, you're doing the inventories, you're kind of understanding where to go and how to bring agility in. But for a CISO that hasn't even started thinking about this yet, right? Ah, 20, 35, right. We've got, we've got password problems right now. How, how should, how should they start? Like, what are the first two to three steps that you think that they should take?
A
Yeah, I think, I think the three steps that, that we have in our program, you know, three pillars apply to everybody. It's just, you know, our scale is bigger and more complex. Right. So our three steps are, you know, the first is crypto discovery. It's, you know, where are your cryptographic assets? And you've got to find that because again, you can't protect what you don't know or change what you don't know. The second is, you know, okay, you have a list. Now first of all, do you wait till the list is complete? No, that can take forever. If you have a list, what do you do? Let's say you've just started a list and you've got your first thousand crypto assets. Well, the next thing you've got to do is do some kind of risk assessment because you can't do all of it at once, right? And so every one of us is going to have to prioritize. So that's our second pillar, is how do you do risk assessment? And then our third is around enablement as we change to quantum PQC stature. Every algorithm doesn't fit every problem. So you've got to create a framework where you can do a quantified evaluation of PQC algorithm A against my problem B. So for example, there are some solutions that are very sensitive to latency. There are others that may be sensitive to other architectural constraints. And so you have to build that capability to test your deployment. So that is what we are doing. We have a crypto discovery program, we have a risk assessment framework that we've built and open sourced and it's actually available on the NIST website, it's called Carafe C A R A F. And then we are building and will open source if it's not already open sourced, a program called Quant which is going to be able to help you do that quantified testing of your solution that you pick. Now some of the solutions, you're not going to have a choice, right? Your vendors and suppliers will pick. Regardless of what you know, a supplier or vendor does, you're still going to have to do that assessment of, you know, how does this impact my performance, my, you know, my just like the size of the certificate, my memory consumption and all of that kind of tests that you'll have to do to make sure that it works in your context.
B
That's such a great point because it's something that I think people may gloss over and feel like here's a set of algorithms that we're going to move to. But as you say, you've got latency issues, things that really can't afford to even have a multi millisecond delay, for example. I'm just winding the clock back to maybe when you started this project, what other folks inside of the organization did you need to bring in to make this successful? Like legal for example, or engineering or product or maybe even procurement because you're talking about third parties and suppliers.
A
Before we even started I had this question is what is the cyber functions role in this whole post quantum journey? And so I actually sat down with our CTO and our Chief Network Officer and our Chief Product Officer. Chief Product Officer builds our products like our devices. For example. CTO of course is the classic technology officer role and our CIO reports to our cto and then of course our Network officer has an amazing, amazingly complex and challenging job. And so you know, we talked about this and, and we said look, you know, as quantum computers become real, you know, there will be product implications and network implications and our Chief Technology Officer would have to think about, you know, how do I train people and you know, what are the use cases for quantum compute and so on. But as far as, you know, post quantum cryptography is concerned, at Comcast, my team runs most of our, you know, authentication, authorization, crypto, cryptographical solutions already. So at that point we decided that yes, you know, we're going to PQC will be led from my org. So the very first group we formed was a post quantum center of Excellence and that has representation from all parts of the organization. And you know, I sometimes struggle with the word, you know, center of Excellence. You know, it's more like maybe a community of practice, but we're calling it right now COE center of Excellence. And we do have, you know, representation from those different groups that you just mentioned. And you know, part of our team's role is, you know, education. We have a cybersecurity guild at the company and the guild is really a getting together of people who have shared interest. So these are not just members of my team, these are members of all kinds of functions in the org. Just this week, you know, our center of Excellence ran a PQC workshop and I think there were 200 plus attendees. We also collaborate with outside, we've had speakers from IBM, we have professors from universities who come and speak with us. Then when the NSTAC was active, the National Security Telecommunications Advisory Committee, we were leading a post quantum work stream. Sorry, a PQC work stream in that. So, you know, long way to answer your question, saying that it is not just internal collaboration across multiple groups, but a lot of external collaboration. We also work very closely with like NIST workshops and so very engaged in the technology, the standards, the emerging knowledge policy. So we look at it from a very 360 degree view. Very long answer to your question, Hugh.
B
No, it's a great one because it really gives people a sense of the dimensionality and the scope and the constituents involved in this thing. And it just naturally leads me to another question given how expansive that is, this is a huge project that's likely to go on for years. How do you convince executive leadership in a firm that this is something we've got to do now, we've got to invest in. It's going to take time, it's going to take all of these parties coming together even though there's no certainty, let's say, of when there is a cryptographically relevant quantum computer. How do you, how do you broach that conversation?
A
It is exactly that is, you know, getting you know, like minded people together so the leaders of, of, of the company and I'm, I'm, I'm very lucky that my boss has all of product and technology for, for Comcast, including the network, all of it. But you're absolutely right. We are competing for resources. Every organization in the world is and we are no different. We always start small and that's what we did. And we're still small. It's a small team. The good news is that because my team also runs those cryptographic systems. So for example, the first adopters of the work that the PQC CoE is doing is our PKI team. Right. Because if I can get my PKI system quantum ready then, and I have a parallel work stream going on, you know, nothing really to do with Quantum but you know, of, of getting all of my certificates under life cycle management then you know, I've solved a HU problem if I can do that. Right. So you have to think about it. You know, how do you do something like this with a small team and in a way that you will get the biggest bang for the buck for your first foray into this very complex ecosystem.
B
I think that's such a great roadmap for internal, like how do you, how do you rally, how do you get people involved and how do you get them caring about it and taking action? And this is going back to something you mentioned earlier in the discussion. The third parties are such a big part of this too. How important is it to start engaging vendors basically now on post Quantum readiness?
A
Oh my gosh, I can't even tell you how important that is. Now the good news is that you know, our hyperscalers, Google aws, Microsoft are already on that journey and have started releasing Quantum Ready. You know, Google has Chrome versions that are using the, you know, PQC compliant algorithms. AWS is I think like 27, like, like literally a year or two away from and they have parts of their stack that is already supporting. So you know, if you're working with you know, the well known hyperscalers, big companies, you know, they're not waiting for us to ask, right? They're already on the journey. The harder bit is the hardware and chip vendors. And the reason that is harder is because it is harder to be crypto agile when you have that. And those cycles are long, those chip cycles and hardware cycles. So that is where if you're a company that is building hardware and you have chip vendors that you're working with, then that cycle really should have started already. That engagement and the you know, if you're doing custom Asics and custom, you know, FPGAs and so all of that and then the other area where there is more worry is the smaller vendors. Right? Is that's what I worry about more than our big vendors are, you know, way down the path. Not worried about that. You know, for there. Our biggest thing is how do we use our risk model? Our risk model basically does two things. You know, it looks at, it's called Carafe Crypto Agility Risk Assessment Framework. Again, it is open source and what it does is it takes an inventory and it comes out with actionable priorities. So we have two axes. One of them is crypto agility. How easily can this asset adopt pqc? So there we consider things like what libraries is it using, what protocols does it need to support, what are the vendor dependencies, what is the performance headroom, you know, what are the hardware constraints? So we sort of go, that's one axis and then the other axis is the risk. You know, how critical is this asset? What kind of data is supported by it? What is the asset lifespan? Because if it's an asset that's about to be retired, has a four year lifespan, then we shouldn't worry about it. Then coming out of it is three actions that we either have to figure out how do we migrate to pqc, or we phase it out, or we just say we accept the risk and we can't. Right. So, and that vendor part that you just talked about is a, is an inherent part of that risk assessment framework.
B
I can, I can imagine. I mean just, I said just the weight of Comcast is probably helpful in those discussions, even with the smaller vendors. And the fact that the demand is coming from multiple places is, is great. And it's very, very useful to understand that this is where potentially the long tail is. And I'm curious, have you had to bring any additional skill sets into the organization as you've gone through this process and as you've done this discovery to be able to make this shift successful?
A
Yes. And can I tell you what the most amazing part of it has been? So my team that is leading this for me is a small team. I think everybody on that team has a PhD and a lot of them are very young. And why am I bringing that up is we need people who have that capacity to, you know, they can do research, they can look at a lot of information, they can, you know, translate it to like working code. I think that has really helped us. So we have not gone and Hired like, like, you know, amazing quantum luminaries. We consult with them and invite them and you know, read their papers and, and, and, and look at their work. Instead. What we have are super smart people who are very capable of operating in that environment where they know how to research, they know how to hypothesize, and then they know how to apply that to the real world. Because again, we are resource constrained. I don't have a big budget for this. So, you know, that is the decision that the person who's leading this for me, amazing guy called Vaibhav Garg, known as vg. That is the sort of approach he took. He's very connected in that community and he's picked and because we have constraints on our budgets and everything else, we've picked up people who can come in and I think it's sometimes great to have constraints because they force you to be creative. And that team is like kicking it out of the park. It's just awesome.
B
I love it. It's like, well, credentialed experts in the space, but still with the plasticity. Yes, go in and think differently. And also proof of concept. Try it.
A
Yeah, that's the word. And you know, we bring in the experts, you know, all the time from academia, from corporations, you know, like IBM who are, you know, think about this deeply. And our team though is very, they are experts. Now they, you know, for example, you know, our third pillar, the PQ bench, the post quantum bench, again, something that we have open sourced, you know, that was built by one of these amazing young lady who, you know, figured all this out and then built this kind of lab in a box that, you know, you can just deploy and bring in your applications and go, okay, I've, you know, just, and how do I simulate it and what tasks do I run and, and you know, so those kind of, you know, like latency budgets and fragmentation issues and memory constraints and all of that kind of stuff is like a lab in a box now that, you know, people can just come and experiment with. So it's, I love that practicality of the team.
B
That's, that's great. And it's enabling others. Right, lab in the box.
A
Absolutely. We do open source. A lot of what we build in this space. So PQ bench and then carafe, carafe is the risk framework and then PQ bench is this analysis framework. You know, those are both available.
B
Well, thank you so much for giving back to this community in that way. I mean, that's, that's phenomenal.
A
Absolutely. It's It's a give and take. We take a lot too, so. Absolutely. Yeah.
B
And one last question for you, which is somebody sitting, they're listening to this discussion and if there's one thing that you'd want every cyber leader that's listening to this to do differently, starting tomorrow, based on your experience, what would it be?
A
I think you have to start. That is the hardest thing is sometimes you just get paralyzed by the size of the task ahead of you. Right. And it doesn't matter if you're not as big and complex as Comcast because, you know, a smaller org will have even more constraints. Right. In a lot of ways. So. But you have to get started. You know, if the thought of, you know, even getting a crypto asset inventory is scary, you just start with the ones that are easy to get. You know, I'm a true believer in incrementality and that, you know, you start where you are and then you make small steps of progress. But if you don't start, then I think we'll be in. It's hard. It'll be hard to catch up.
B
I love it. And just, just get started. And Newport, thank you so much for being here and just being part of this discussion and being so open and just sharing your expertise. I know so many will benefit from that and I wanted to thank our listeners. Thank you for tuning in and please keep the conversation going on our RSAC membership platform by visiting onersac.commembership and be sure to check onersac.com for new content posted year round. Nuper, thank you so much again. This was fantastic.
Episode: Preparing for Quantum: A CISO's Roadmap to Resilience
Date: July 16, 2026
Host: RSAC
Guest: Nupur Davis, Chief Information Security and Product Privacy Officer, Comcast
This episode centers on how CISOs and cybersecurity leaders should prepare for the coming disruption of quantum computing, particularly its profound impacts on encryption, data protection, and organizational resilience. Nupur Davis, CISO of Comcast—a company with vast and diverse digital infrastructure—shares practical steps, lessons learned, and real-world strategies for achieving “quantum resilience.” The conversation addresses both the hype and the reality around quantum threats, providing an actionable roadmap for enterprises at any stage of readiness.
Quantum’s Arrival: Quantum computing’s ability to compromise current encryption is no longer a distant threat (03:27). U.S. government directives require all systems to be “quantum-ready” by 2035, but transitioning large organizations will take years—perhaps a decade or more—mirroring or exceeding past encryption shifts like SHA1 to SHA256.
“The time it will take, you know, through every layer of the organizational architecture to really get quantum ready. It feels like a long time, but it really isn't.”
(A, 03:27)
Preparation Must Start Now: The complexity and pervasiveness of cryptography forces immediate action for CISOs, not just abstract planning. Delaying creates risk and an unmanageable migration later.
“PQC is much, much more complex... touching a lot of asymmetric primitives and protocols and hardware and supply chains. And it is because of the complexity that CISOs need to start thinking about this now...”
(A, 04:49)
Quantum Agility Defined: The focus isn’t just on swapping in new algorithms, but on building systems capable of swapping algorithms multiple times as quantum standards change.
“Quantum agility means... we are ready to accommodate whatever new algorithms are established and approved... as this evolves... we've got to have that agility, that capability to change the core cryptographic underpinning on the fly.”
(A, 06:07)
Architectural Mindset Shift: It’s not a simple ‘A to B’ replacement; protocols must flexibly accommodate evolving standards (07:29).
“First, you have to find it and then onboard it onto our full lifecycle management... That is in a way that first step, right? Like do you know where just your certs start?”
(A, 07:46)
“It's certificates, it's code, it's library, it's network protocols... It's hard to isolate one part of the ecosystem and say this is the most important.”
(A, 09:50)
Cross-Departmental Buy-In: Legal, engineering, product, procurement—all must engage early. Comcast began with a Post Quantum Center of Excellence (COE) but considers it more a “community of practice” that includes education, academic experts, and third parties.
“We do have, you know, representation from those different groups that you just mentioned. And... our team's role is, you know, education... these are members of all kinds of functions in the org.”
(A, 15:52)
External Partnerships: Close collaboration occurs with NIST, IBM, universities, and broader industry working groups.
“We always start small and that's what we did... you have to think about it... how do you do something like this with a small team and in a way that you will get the biggest bang for the buck...”
(A, 20:10)
Vendors Are Key (And Not Equal): Engage hyperscalers (e.g., Google, AWS, Microsoft) and large vendors early—they're already progressing. But pay special attention to hardware/chip vendors and smaller suppliers where delays and inflexibility are higher.
“The harder bit is the hardware and chip vendors... And those cycles are long... The engagement... really should have started already.”
(A, 22:13)
Integrated Risk Framework: Comcast’s CARAF accounts for “crypto agility” and classic risk, prioritizing migration, acceptance, or decommission actions for each asset, with vendor dependencies baked in.
Leverage Research-Driven, Adaptive Teams: Comcast’s team is small but highly technical, with researchers skilled at bridging theory and practical implementation. Big names are consulted, but internal innovation, experimentation, and adaptability are prized.
“What we have are super smart people who are very capable of operating in that environment where they know how to research, they know how to hypothesize, and then they know how to apply that to the real world.”
(A, 26:21)
Open Source for the Community: Tools like PQ Bench (for algorithm evaluation) and CARAF (risk assessment) are shared for broader industry benefit.
Memorable Closing Quote:
“You have to start. That is the hardest thing is sometimes you just get paralyzed by the size of the task ahead of you.”
(A, 30:49)
“I’m a true believer in incrementality and that, you know, you start where you are and then you make small steps of progress. But if you don’t start, then I think we’ll be in ...it’ll be hard to catch up.”
(A, 30:49)
On urgency:
“If you don’t know what your crypto inventory is, how do you... figure out where to progress?” (B, 09:20)
On the pervasive impact:
“It's hard to isolate one part of the ecosystem and say this is the most important.” (A, 09:50)
On execution at scale:
“That team is like kicking it out of the park. It’s just awesome.” (A, 28:23)
On open sourcing for the community:
“PQ bench and then carafe, carafe is the risk framework and then PQ bench is this analysis framework. You know, those are both available.” (A, 29:56)
Nupur Davis distills a daunting challenge into three clear steps: inventory your cryptography, assess and prioritize risk, and incrementally enable quantum-safe solutions—while fostering agility for algorithmic shifts ahead. She stresses collaboration, both within organizations and across the industry, and advocates immediate, incremental action over hesitation.
Essential Takeaway:
No matter your company’s size or complexity, the path to quantum resilience begins with a single step: Get started—now.
Resources Mentioned:
For further discussion and resources, participants are encouraged to join the RSAC membership platform and access content at onersac.com.