What keeps the digital world running safely behind the scenes, and why are so many organizations only now discovering that one of their most important security foundations is becoming increasingly difficult to manage?
In this episode, I sit down with Lakshmi Hanspal, Chief Trust Officer at DigiCert, to demystify Public Key Infrastructure (PKI) and explain why it quietly powers almost every secure digital interaction we rely on each day. From online banking and cloud services to connected devices, APIs and AI systems, PKI is the technology that verifies identities, protects communications and helps ensure the information we exchange can be trusted.

Our conversation is inspired by DigiCert's latest PKI Modernization research, which surveyed senior IT and security leaders to understand how organisations are managing digital trust in an increasingly connected world. The findings reveal a growing gap between awareness and execution. While most leaders recognize the importance of digital trust, only 34% report having full visibility into their digital certificates, leaving many vulnerable to outages, operational disruptions, and unnecessary risk.
Lakshmi explains why certificate management has become so fragmented over the years, how machine identities now outnumber human identities by a significant margin, and why AI is adding another layer of complexity as autonomous systems communicate at unprecedented scale. We discuss why spreadsheets and disconnected management tools are no longer sufficient, and why many
organizations are moving towards centralized PKI management with greater automation and policy enforcement.
We also look ahead to two challenges that are rapidly moving up the boardroom agenda. The first is establishing trust in AI-generated content through stronger verification, digital signatures, and cryptographic provenance. The second is preparing for a future in which quantum computing could eventually undermine today's encryption standards, making cryptographic agility an important business capability rather than simply a technical consideration.
If you've ever wondered what lies behind the secure websites, applications, and digital services you use every day, this conversation offers a practical introduction to one of the internet's most important foundations while explaining why modernizing digital trust has become a business priority rather than simply an IT project.
How prepared is your organization for the next generation of digital trust? I'd love to hear your thoughts and whether PKI modernization is already part of your security strategy.
Useful Links
Connect with Lakshmi Hanspa

[00:00:00] Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest.
[00:00:32] What if one of the most important technologies protecting your business is something that most people have never even heard of? Well, today I want to tackle a topic that quietly sits behind almost every digital interaction that we make. So whether you are logging into your bank account, completing an online purchase, connecting cloud services, or increasingly relying on AI-powered systems, there is an invisible layer of trust that is working in the background.
[00:01:02] And this is what makes all those interactions possible. And my guest today is the Chief Trust Officer at a company called DigiCert. And they help secure the digital world through public key infrastructure, better known as PKI. And if that sounds highly technical, don't worry. One of the reasons I'm excited about this conversation today is demystifying PKI and how it impacts every business, whether you realise it or not.
[00:01:28] So today we will discuss DigiCert's latest PKI modernisation research, which surveyed hundreds of IT and security leaders and uncovered some pretty eye-opening findings. And despite certificates underpinning many business operations, only a small percentage of organisations report having full visibility into them.
[00:01:52] And many more remain concerned about outages, security risks and growing operational complexity. So today I want to examine how machine identities are outnumbering human identities, understand more about why AI is creating entirely new trust challenges, and also why quantum computing is forcing organisations to rethink long-term cryptographic strategies much sooner than many expect.
[00:02:19] So if you've heard terms like digital trust, machine identities, crypto agility or post-quantum security and wondered what does all this mean for me and my business, this conversation today is designed to connect all those dots. So let's get started and discover why digital trust could becoming one of the most important business capabilities of the AI era. That's right, it's time for me to introduce you to my guest right now.
[00:02:46] So thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do? I'm Lakshmi Hanspal. I'm the Chief Trust Officer at DigiSearch. And DigiCert is a critical infrastructure company. We power what we call the underlying cryptography and protection name services layer for the internet.
[00:03:10] In short, we are powering digital trust as intelligent trust for modern businesses. And intelligent trust is becoming critical infrastructure for many companies. And digital trust officer, that's got to be one of the coolest job titles I've heard in a long time. And one of the things I try and do on here every day is demystify some of the complex technologies that they might hear about and put them in a language everyone can understand.
[00:03:39] So I don't want to lose anyone here. So for listeners hearing the term for the first time, what exactly is a public key infrastructure or PKI? And why has it become such a foundational layer of trust for everything from a website to an app or connected devices and AI systems? Public key infrastructure or PKI is the trust layer behind every single transaction that we see today and the years before and the years ahead.
[00:04:09] So PKI is the technology that establishes trust for everybody today. So when you open up your bank application, your mobile bank app, you want to be guaranteed that you are talking with your bank. You want to make sure that your communication and transactions with the bank are secure. And without that trust layer, banking, online shopping, or just e-commerce or any transaction, business-to-business included,
[00:04:38] on the internet that we see today simply wouldn't have scaled. PKI actually simplifies. It's a complex technology, but it actually simplifies everything organizations need to do to verifying identities. Protecting their communications and ensuring that their information is not altered.
[00:05:01] And so every single website, software update, connected device, cloud service, go through the same trust principles, which is securing all the APIs, securing all the connected devices, the cloud workloads. And that is what PKI enables. It provides the foundation that enables all of these apps to function securely and reliably.
[00:05:28] And with that scene perfectly set, one of the reasons I wanted to almost introduce the concept is DigiCert recently released its PKI modernization research. So tell me a bit more about this research, who it was aimed at and any key insights from that. Oh, we are very excited about this research and even more excited about the insight that the results have offered. Yeah.
[00:05:54] What we, it was aimed at about 400 or so IT and security leaders. These were senior leaders, executive leaders at the C-suite. And what we wanted to understand is how organizations are managing digital trust at scale in a complex global environment. And the results were, you know, really astounding.
[00:06:24] It sort of confirmed many of our beliefs in how organizations need to function today. We explored automation. We explored resiliency, machine identities, human identities, AI adoption, and also readiness towards post-quantum cryptography. So quantum is the ability for faster compute in the world.
[00:06:50] Post-quantum is when we have quantum-ready computers practically available. And one of the areas we are concerned about is the ability for these fast compute mechanisms to challenge existing cryptography algorithms that we have and maybe challenge them in a way that they could break these algorithms. So that means many of what we rely today for secure transactions may be at risk. So that was important for us.
[00:07:20] Now, what we realized with this research is that the challenge isn't awareness anymore. It is leaders are struggling to operate trust at scale. And when looking at the report there, one of the stats that stood out to me really jumped off the page there was, I think it was 34% of organizations say they have full visibility of their certificates, which is shockingly low stats.
[00:07:47] Why are so many businesses still struggling to see and manage what is effectively the digital trust layer of their organization? It's quite a shocking stat, isn't it? It is. It is. It is. And you would think, why is it that 66% are not able to see something that has existed in the environment for decades? Because they have been operating for decades. And this PKI and what we call domain name service, DNS, powers their operations.
[00:08:13] Now, there are a number of reasons, but mainly most organizations have built these technologies over many years across different teams, platforms, acquisitions.
[00:08:28] These technologies of certificates and public key cryptography often exist across many domains, applications, devices, infrastructure, cloud layers, and at the same time, non-human identities.
[00:08:46] So these are cloud identities, machine identities, device identities, workload identities, and now AI identities have grown rapidly and are increasingly so and have complicated some of the management of this critical infrastructure. Now, we truly believe you can't secure what you can't see and you can't automate or modernize that either.
[00:09:10] And so without visibility, these organizations are struggling to automate, to maintain resilience, and reduce risk. So in one hand here, we've got only 34% of organizations saying they have full visibility of their certificates. But there was another stat that stood out, and that was nearly three quarters of organizations are currently worried about outages caused by expired certificates.
[00:09:37] And I think anybody working in corporate America or a big enterprise there would have known what happens when those certificates expire, when you least want them to or least expect them to. So how big of a business risk is this becoming? And are leaders underestimating maybe the operational impact of certificate failures?
[00:09:57] And I think the overwhelming concern that we see with three quarters of the organizations we had surveyed is the realization that certificate outages aren't just security events anymore. They are business-impacting events. Your customers do not see certificate failures. They experience service disruptions. And that is what organizations are quickly realizing.
[00:10:25] Whether it's a banking app, employee portal, customer portal, trust failures are quickly becoming business failures. And organizations that are modernizing PKI with automation, resiliency, policy enforcement are already seeing the benefit, with 60% or more reporting fewer outages and hence fewer service disruptions.
[00:10:52] And for many people listening, they do hear a lot about human identities in cybersecurity. But your research points towards an explosion of machine identities. You mentioned it there. What is driving this growth? And how are AI systems, APIs, cloud services and all these connected applications, how are they changing the scale of this challenge? What are you seeing here?
[00:11:14] We have already entered an era where machine identities have outnumbered human identities by a significant margin. And the correlation is that managing machine trust is just as important as managing human trust. Everything today is connected, automated and increasingly driven by software layers such as AI.
[00:11:39] And organizations managing identities across various layers, containers, cloud services, devices, AI systems, APIs, are seeing the complexity that the explosion of machine identity has added. And they need to simplify it. AI is accelerating this trend because every AI system depends on interactions.
[00:12:03] And so the scale and speed of business growth here makes automation essential. You work right in the heart of this space. You probably think very often that you've been there and seen it all before and seen so many different reports throughout your career. I'm curious. Was there anything that surprised you when analyzing the findings? Anything stand out there? I think it is. You know, if you would ask me this question of a few years ago,
[00:12:34] I would say if you draw the graph off, you know, what we call the acceptance graph, you know, first in denial and then you're in depression and then you're angry. And then somewhere along the journey, you come to acceptance. So here we are today in 2026. And so what we're seeing more and more is that organizations accepting that AI is a reality, post-quantum crypto readiness is a reality,
[00:13:03] critical infrastructure protection and modernization PKI is a reality. So no surprises there. But what surprised me is the gaping jaw or the gap between where leaders know what needs to be done, but are having challenges executing that at scale. So it's the gap between awareness and readiness. And in this report, that stood out very clearly.
[00:13:34] Now, organizations understand the importance of resilience, right? We and post-quantum preparation. I just mentioned that they've reached the acceptance stage, at least most of them have. But many of them still lack the visibility. You can't protect what you can't see. They rely on fragmented tools, many manual processes. Many organizations are working all of this with a spreadsheet and a prayer.
[00:13:59] And so what organizations, when they do modernize, they suffer these fewer outages and lower risk. And there will be people listening in organizations that will admit that they do still rely on fragmented PKI tools and manual processes. But I've got to ask on behalf of those people, why has certificate management historically become so siloed?
[00:14:25] And what are the real world consequences when companies fail to modernize and take this stuff seriously? Certificate management has existed over decades. And so in many cases, it is the result of different teams implementing different solutions, not really solving it separately, not working together, acquisitions, cloud migrations. We saw quite a bit of that in the last 10 years.
[00:14:53] And then over time, these environments do become fragmented. They become complex to manage. And what we're seeing more and more is that organizations have operated what I would call with learned helplessness, relying on spreadsheets and disconnected tools to track these critical trust assets.
[00:15:17] But what's important to understand is technical debt is now trust debt. And so the result of a trust debt can be outages, operational disruption, compliance and regulatory challenges and security blind spots. Technical debt is trust debt. Absolutely love that line. And there does, thankfully, seem to be a broader shift towards centralized PKI management and automation.
[00:15:46] So what does a modern PKI strategy actually look like this year? A good one, a good example. And how can organizations move towards automation without running the risk of creating even more complexity? I would imagine a few people listening want to improve, want to change, but are also quite nervous that they just end up making things more complicated. Yes. And, you know, that's a valid concern.
[00:16:09] Now, across thousands of customers whom we engage with, we're seeing a pattern. And that is that the most successful organizations are simplifying trust operations. They're not adding to the complexity. A modern strategy starts with visibility. It starts with centralized management. And then from there, so once you establish visibility, you can see what you need to protect.
[00:16:38] And then organizations automate life cycles because they don't want to rely on manual processes and spreadsheets and defragmented tools. And then they move to policy enforcement as in sustaining that automation and then becoming more and more compliant in these processes. Now, the goal here is in managing more certificates. It is managing trust more intelligently.
[00:17:08] And automation becomes a key part of that equation. And as we look to the future, there are two major themes that are emerging now. Securing AI systems and also preparing for quantum era cryptography. We're already hearing harvest now, decrypt later. But how concerned should businesses be right now about those future quantum risks?
[00:17:32] And what role do you see PKI playing in protecting AI-driven infrastructure over the next few years? PKI modernization and quantum readiness require action today. And securing AI, which is AI trust, has even bigger impacts in the months and years to come. So this is an action for today. This is not a next-gen problem. This is not for our children to solve. This is for us to solve.
[00:18:02] Because AI creates new challenges around authenticity, provenance, and verifying what can be trusted. Now, at the same time, only 22% of the organizations we surveyed said they fully understand what it means to be quantum-ready in terms of cryptographic risks.
[00:18:24] So being quantum-ready means the ability to be agile with the selection of the cryptographic algorithms that you select. So that if at any point, A or A or more, one or more algorithms become compromised in some way, then it's the simplicity that you operate with in terms of removing the trust in that algorithm within your operations.
[00:18:52] And that is where PKI remains foundational, enabling trusted identities, secure communication, digital signatures, and also verification of AI-generated content. What we are seeing is that the future belongs to organizations that can adapt quickly. We talked about agility and the agility that can adapt their trust quickly as these technologies change. I completely agree with you.
[00:19:21] I think we're already seeing AI-generated content becoming harder to distinguish from what's real and what isn't. How do you see organizations approaching trust differently over the next few years? Are you hearing about different approaches? Are you seeing people get it wrong or get it right? How are you seeing different approaches to this problem? Well, we're all learning through this journey. So I think there are things we're going to get right and there are things that we may not get right in the beginning itself.
[00:19:50] But that's part of the learning mechanism. So I think organizations are increasingly focused nowadays on proving authenticity, not simply assuming it. So when we think about deepfakes, synthetic content that can be AI-generated, now whether that's content, software, documents, communications, all of those need to be protected with stronger verification mechanisms.
[00:20:18] And technologies such as digital signatures, cryptographic provenance, provenance proves both authenticity as well as source. They are becoming increasingly important. What we're seeing is in an AI-first era, trust must be verified, not assumed.
[00:20:39] And what I continue to impress upon my teams, my own teams in operations as well as customers is that proof beats promise. And finally, before I let you go, for any CIOs or CISOs listening to our conversation today, any advice on what they should be prioritizing over the next year when it comes to digital trust and crypto readiness, etc.?
[00:21:06] For C-suite leaders thinking about how can they modernize their operations, how can they make digital trust increasingly a competitive advantage, not just a compliance or security requirement? I would say that trust isn't something you can bolt on later. It is something that you need to build in from today. And the way to do that is establish visibility.
[00:21:35] You can now secure what you can see. Think highly automize your manual operations because those won't scale with the machine identity growth or AI identity growth. And third, agility within cryptography and preparation to post-quantum readiness is key.
[00:21:56] And leaders should view digital trust as that empowerment, as that business capability that supports innovation, that supports resilience and ultimately the trust that your customers have in you. Well, we've covered so much in a 30-minute podcast today. A lot of information to digest, take away and marinate on.
[00:22:20] And for anyone listening that would like to carry on that conversation with you or your team, find out more information about DigiCert or indeed check out that report that we've referenced a few times today. Where would you like me to point everyone listening? We're always available at DigiCert.com. It's the best place to explore research, learn about the report, the results, digital trust as a competitive advantage, and also post-quantum readiness.
[00:22:46] We also regularly share insights and thought leaderships through LinkedIn and the broader community. My advice would be is to look us up, start the conversation now, think about machine identities, AI trust, crypto agility. Early preparation pays dividends. Fantastic. I will have links to everything that you mentioned there. We talked about a very complicated topic today in a language everyone can understand.
[00:23:15] And I hope that anybody listening, regardless of your technical level, will be able to take something away here and talk about it inside your organization. I'd love to hear anybody listening from your experiences on anything we talked about today. But more than anything, thank you for bringing this to life today and giving it the attention it deserves. Really appreciate your time. Thank you, Neil. Having listened to my guest today, I think it's clear digital trust has moved far beyond being a purely technical discussion.
[00:23:44] Because for years, certificate management, PKI and cryptography often sat quietly in the background, largely unnoticed until something went wrong. But my guest highlighted today that some technologies are now, that these same technologies are now directly tied to business resilience, customer confidence, AI adoption and future readiness. And organizations understand the importance of AI, machine identities, automation and quantum readiness.
[00:24:13] But despite this, many are still struggling with the visibility, fragmented tools and manual processes. And as my guest said today, you can't secure what you cannot see. And her observation that technical debt has evolved into trust debt feels especially relevant, I think.
[00:24:33] And as businesses become increasingly dependent on connected applications, APIs, AI systems and automated workflows, trust becomes something that must be actively managed rather than just assumed. So let's look ahead. The combination of AI generated content, machine identities and future quantum risks. All these things collectively mean that this conversation is only going to get more important.
[00:25:01] And the organizations that build trust into their very foundations, they're the ones that are likely to be in a much stronger position tomorrow. But as always, love to hear your thoughts on this one. How prepared do you think organizations really are for the explosion of machine identities, AI trust challenges and post-quantum security requirements? And is digital trust receiving the attention it deserves in your organization today?
[00:25:29] If it isn't, please send them this conversation. Hopefully this may wake a few people up. And as always, let me know any thoughts, any comments, techtalksnetwork.com. Send me a message from there. But that's it for today. So thanks for listening as always. Bye for now.

