
Loading summary
Sponsor Host - Accenture
This episode is brought to you by Accenture. When your advertising operations fall out of sync, everything else follows. Spotify and Accenture are working together to reinvent the rhythm of ad sales using automation, analytics and smarter workflows to simplify campaign delivery and access better data across the business. The result? Less time spent on operations, more time connecting brands with the moments and fandoms that matter most. Learn more@accenture.com Spotify
Sponsor Host - Google Chrome
this episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block. Or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check responses, setup required compatibility and availability various 18 foreign.
Podcast Host
Welcome to Coruscant Technologies, home of the Digital Executive Podcast. Do you work in emerging tech? Working on something innovative? Maybe an entrepreneur? Apply to be a guest at www.corazon.com brand welcome to the Digital Executive. Today's guest is Brian Trupek. Brian Trupek is the Senior Vice President of Product at Digicert, a crypto and security tech by day and night, Brian brings nearly two decades of expertise on many security subjects to the team. He's constantly innovating use cases for enterprise pki. He previously worked for more than six years as Vice President of Managed Identity and Authentication at Trustwave, where he helped fight cybercrime, protect data and reduce security risk. While at Trustwave, he prepared testimony for a congressional panel on the December 2013 target breach. Prior to Trustwave, he was founder of Creditwear Software, a company that automated credential, password and digital certificate renewal and installation, as well as policy based application monitoring. Well, good afternoon Brian. Welcome to the show.
Brian Trupek
Thank you Brian. I appreciate you having me.
Podcast Host
Absolutely. Brian To Brian spelled the same way too. So I always like to get a
Brian Trupek
fellow Brian, which is the right way.
Podcast Host
Yeah, that's what. That's what I like to say anyway to all the Brian's out there. So Brian, if you don't mind, I know you're in Austin, I'm in Kansas City. So we're in the same time zone. Luckily today. So I'm going to jump into your first question. You've spent nearly two decades in security founding Creditware to automate, credential and certificate renewal, then years at Trustwave, fighting Cybercrime and now leading product at Digicert. You even prepared testimony for a Congressional panel on the 2013 Target breach. What was it about KPI and digital trust specifically that became your professional obsession? And how did that congressional experience shape how you think about security today?
Brian Trupek
Yeah, it's funny, I was in tech and I got into PKI with a job actually a company of NFI was a competitor. Now I was there early stages with them and that's where I learned everything and I fell in love with the tech and said wow, this is so oddly specific. Nobody else in the world knows how to do it, so it's probably a good place to have a job. And that worked out really well. But you know, in creating that and seeing that, I saw PKI really just as a layer of fabric that is powering the entire Internet. And all of the things we're doing, whether it was at trustwave, whether it's here at digisirt Creduare, all of these places are, you know, were built on that fabric because it's just so, so critically important to how the whole Internet works and data gets protected. And then I think what's interesting is the congressional testimony thing in Target. I really learned a lot of skills there at trustwave with events like that because PKI is so geeky.
Podcast Host
Right.
Brian Trupek
Like it's just like people, it's just hard to explain. And we had a non technical audience here. These are policymakers. And so how do you explain what these technologies are doing to a group of people who are non technical? And how do you understand and explain that sort of risk and balance that in a way that they can understand? I think that's a place that's kind of fit for me is being able to kind of spread that gap kind of personally to talk about deep tech but also make it applicable to an audience and in that case pretty different audience. And that kind of prepared me for today. Right. Like at digisirt as an example, just last week I was interviewed with Bloomberg Law about these AI laws that are being passed. Like so how do you figure out what AI laws mean to policymakers and things like that up at that level? So it's kind of just been the skill that has been useful through the whole career.
Podcast Host
That's awesome. Really appreciate that. And I like, I'm just highlight some. I love the backstories. That's usually the first question here on the podcast. But this, this tech space, right. And it does get pretty geeky, PKI especially but I love the cyberspace. But the target breach, when you had to prepare that testimony, it's. It's all about a Lot of people don't work in the tech space, but they need to understand the criticality of security. And you were able to do that in layman's terms, which of course that translated to your success in your career in other spaces after that at creditware. But now working at Digicert, you're doing a lot of that and I really appreciate you getting that message out there where people can understand it. So thank you, Brian. DigiCert's AI trust manager is built around three layers. DNS enforcement at the network edge, agent identity through passports and policy, and secure execution through confidential computing with agent passports binding identity, policy, lineage and ownership into a cryptographically signed object. Walk us through what an agent passport actually is and why binding all of that into one signed credential is the key to making agent AI governable.
Brian Trupek
Yeah, let's define the problem space. I think, as anybody familiar with AI knows, agents are all over the place and they take different forms. So you have agents that like a company is building and is responsible for the execution of those things, like their own workloads. There's agents that you're using maybe on your desktop or remotely through a SaaS based service that you don't have that execution control of, but still it's operating on your behalf and doing things. There's MCP serves actually in that whole chain too as well that are participating in this ecosystem. So you have this really diverse infrastructure. But the goal, as we hear from customers, is they want a kill switch. Fundamentally they want to be able to say, stop doing something that I don't accept. When you unpack that, what they're really saying is I need to find and identify something. So I need identity. That's layer one of our passport. They need policy, that's layer two of our passport. So if you want to kill something, it's probably because it's violated something. So it has to relate to some sort of policy. And then I need to understand what's in it to have a policy. So layer three is lineage, like what, what can that touch? What, you know, maybe models is it working with? What's the supply chain integrity evidence, how did it come to be? And then last for that kind of goal of kill switching, is ownership like, is this tied to a specific user? Is this tied to some sort of machine account? What data handling constraints does that thing have? And all four of those layers, identity, policy, lineage, ownership, kind of scale up to that passport and then that passport fundamentally becomes, you know, the thing that can prove that identity right for that agent in any of those deployment scenarios. And then you can kind of think of like visa stamps, they show the authorization and policy and the travel record becomes the audit trail behind that thing. And what's interesting is it all ladders up in all of those environments where, you know, a lot of people are concerned about the data protection, right, Data sovereignty and the laws that are being passed and things like this. How do I protect my data? I can't have any customers. You know, they're trying to build knowledge bases. They're doing all this stuff where they're sending corporate data outside the firewall. I did this session in Australia and there's about 150 CISOs in the room. I said show hands. Who's afraid of sending your data outside of the organization? You go train a knowledge base. Every hand went up in the room. So people want to have these protections, they want to understand what these things are doing. And we're doing interesting things to kind of pull that together and make sure that agents can ultimately reach that goal of being kill switched by these organizations.
Podcast Host
Thank you. That's so important. You did highlight that agents are now just proliferating through our environments across infrastructure and platforms. And, and how do we build in that security or that kill switch for these things? And you talked about these passports. There's, there's four layers. You talked about identity, policy, lineage and ownership. And, and I really appreciate you unpacking that for our audience. But that, that is so important. And I again love what you talk about, especially around some of your, your platforms, like your AI trust manager. So thank you. Brian. You've said 2025 was the year quantum readiness stopped being optional. And Digicert has been experimenting with approaches like Merkle tree certificates for the post quantum web. For a security leader who knows quantum is coming but doesn't know where to start, what's the practical first move towards crypto agility? And how much Runway do organizations realistically have?
Brian Trupek
Yeah, let me answer that direct and then unpack it a hair. So I think the first thing that an organization wants to do when we talk with them is get that inventory everywhere. You're using cryptography, search keys, algorithms, protocols. You can't protect what you don't know you have. And so that's the first part. Now customers will tell you once they get that inventory that is a cluttered space, there's a lot going in there, it becomes almost unmanageable. So you need some intelligence. You need an intelligence layer to make sense of that inventory so you can start to risk Assess create those plans for how you're going to do things. But I'll tell you, I think there's a larger kind of macro goal here. And this is why I was saying 2025 is the year is as you mentioned, with Merkle tree certificates. Merkle tree certificates is a response from Chrome Google, you know, Google Chrome team, they're looking at how to make revocation maybe more scalable through the global Internet. And that is their approach. But there's actually a couple more things. Right. So Quantum is, is one tailwind. Shortening certificate life cycles of 47 day is another tailwind. That Chrome deprecation I just talked about where they're saying mutual TLS will go away and you need to use something else as another tailwind. And then as we've seen over the years when ACA may have MIS issued certificates or gotten to a compliance hiccup, there's these certificates that need to be revoked in mass. Right. I think two years ago we did about 65,000 certificates. Those are actually all the same thing, Brian.
Podcast Host
Right.
Brian Trupek
Like all of those things mean you need to be crypto agile. And so the theme is if you're crypto, if you have crypto agility, your post quantum experience is gonna be much easier. Your 47 day, your Chrome deprecation and those mass revocations become all manageable events. So really when I answer this question for customers, it's inventory to start, but what you're trying to do is de risk by leading towards a plan that gets you to be crypto agile.
Podcast Host
Thank you, really appreciate that. And I love to get into quantum a little bit, cryptography, etc. We know that this technology is here now. A lot of governments are investing in Quantum and if we don't get our act together around security, we could be having some other problems. But luckily Brian, you and folks at Digicert are helping pave the way. I like what you said. You can't protect what you don't know you have. And so you need to build in that intelligence layer an inventory, determine what you have and determine that risk. I just think it's awesome and I appreciate you unpacking all that for us here today. And Brian, the last question of the day as we look ahead to the future. You've argued that digital trusts have moved from an abstract value to a quantifiable driver of engagement, compliance and revenue. And that organizations treating it as a strategic asset will be better positioned than those that don't. As machine identities explode, certificate lifespans shrink and AI agents Proliferate. Where do you see digital trust infrastructure heading over the next five years? And what does the winning enterprise get right today?
Brian Trupek
Yeah, it's such a good question, right? I think it maybe even points back to the answer to question three there. I think the closer your organization can get to being crypto agile, you're going to solve a lot of the underpinning problems here. But that's not enough, right, because you need identity. Like I just talked about with agents in the passports, you need to know what these things are so you can attach policy and ownership. And that needs to go across users, device, agents, models, content. These are all things that need to be managed at that level. And so that means you need certificates to be able to deal with these. Right. And those lifespans are shrinking.
Sponsor Host - Google Chrome
Right.
Brian Trupek
And machine identities are exploding. Like we talked about, when you look at the AI layer, which I'm deeply involved in with our AI trust manager and our technologies here, and then personally, and what I hear from customers is they're deploying these things at breakneck speeds. We have customers who are deploying about 400 agents per week. As one customer sites, we have another customer that has several hundred MCP servers going up quarter and this, it's just exploding. Right. And so what's the identity of these things? What is the trust factor for these things and how are people working with them and managing them across that stratified kind of deployment infrastructure I've talked about earlier? I think, Brian, it's only going to get more complex. Right? We see. I spoke at the Confidential Computing Consortium in San Francisco. Anthropic was there speaking. I got to talk with them. They actually said, everybody's creating too many agents. And they said, look, you need to shift to MCP servers, organizations. They're viewing Anthropic and cloud as kind of the orchestrator of AI that will interact with more MCP servers, that will interact with local models and kind of move that data burden into the customer's environment for a lot of tasks. Well, if you do that, can you think of how many identities are going to explode with that? You know, how do you keep track of those things? How do you manage it and how do you put policy around it? I think that's where things are going. It's not going to happen tomorrow, but it'll happen pretty quick. AI seems to change every 24 hours, but that is kind of where where things are going. And I think winning enterprises will treat identity and trust as one automated system across humans, devices, workloads and agents. Really not as like a bolt on layer for kind of every new technology wage, rather a foundational layer that powers it all.
Podcast Host
Thank you, really appreciate that. Yeah, you just to highlight a few things, Brian, the closer we can get your organization to crypto agile, the better off you'll be. You talked about that obviously there's a lot of things to manage here. You talked about the platforms, models, devices, agents, content, everything that's, that's there. And then of course people, some companies are just these, this agent deployment is exploding as you talked about raising that complexity and risk. And again with your background and going to some of these conferences and talking to some of these experts in this area, especially AI, I think you're really working to provide really some better guidelines around how we manage our environments and deploy agents. Like I said, everybody wants to be ahead of everybody else in this world of AI, but there's a lot of risk here. So I appreciate your insights today. And Brian, it was such a pleasure having you on today and I look forward to speaking with you real soon.
Brian Trupek
No, thanks Brian. Great, great. I appreciate being here.
Podcast Host
Bye for now.
The Digital Executive – Ep 1289: Brian Trzupek on The Race to Secure the AI-Driven Enterprise
Date: July 21, 2026
Host: Coruzant Technologies
Guest: Brian Trzupek, SVP of Product at DigiCert
In this episode, Brian Trzupek, Senior Vice President of Product at DigiCert, delves into the critical challenges and innovations at the intersection of cybersecurity, AI proliferation, and digital trust. Brian unpacks how enterprises must adapt to a rapidly evolving threat landscape shaped by quantum computing, shrinking certificate lifespans, and an explosion of AI agents, emphasizing a strategy of crypto agility and foundational trust infrastructure.
(01:04 – 04:40)
Brian’s Unusual Path into PKI:
"I fell in love with the tech and said wow, this is so oddly specific. Nobody else in the world knows how to do it, so it’s probably a good place to have a job."
— Brian Trzupek [02:59]
Communicating Complex Security Issues:
"PKI is so geeky ... How do you explain what these technologies are doing to a group of people who are non-technical?"
— Brian Trzupek [03:54]
(04:40 – 08:19)
AI Agents Create New Governance Challenges:
The "Kill Switch" Requirement:
Agent “Passports”: A Layered Approach
“All four of those layers, identity, policy, lineage, ownership, kind of scale up to that passport... that can prove that identity right for that agent in any of those deployment scenarios.”
— Brian Trzupek [05:51]
Data Sovereignty Remains Top of Mind:
(08:19 – 11:04)
Why 2025 is the "No-Excuses" Year:
"You can't protect what you don't know you have."
— Brian Trzupek [09:14]
Practical Steps for Security Leaders:
"All of those things mean you need to be crypto agile."
— Brian Trzupek [10:40]
Merkle Tree Certificates & Other Industry Moves:
(11:04 – 14:30)
From Abstract to Strategic:
“Winning enterprises will treat identity and trust as one automated system across humans, devices, workloads and agents ... a foundational layer that powers it all.”
— Brian Trzupek [13:52]
Key Trends Over the Next Five Years:
Industry Reality Check:
On Making Security Understandable
"PKI is so geeky...how do you explain what these technologies are doing to a group of people who are non technical?"
— Brian Trzupek [03:54]
On the Power of Inventory
“You can't protect what you don't know you have.”
— Brian Trzupek [09:14]
On Agent Passports
“All four of those layers, identity, policy, lineage, ownership, kind of scale up to that passport...”
— Brian Trzupek [05:51]
On Digital Trust’s Strategic Value
“Winning enterprises will treat identity and trust as one automated system across humans, devices, workloads and agents ... a foundational layer that powers it all.”
— Brian Trzupek [13:52]
Brian Trzupek provides a clear roadmap for today’s enterprises: get visibility and control over digital identities, plan for quantum and algorithm changes through crypto agility, and start treating trust as an essential, integrated layer of the business. With AI and machine identities multiplying at breakneck speeds, those who master digital trust will have a decisive competitive and security advantage.