Brian Trzupek Podcast Transcript
Brian Trzupek joins host Brian Thomas on The Digital Executive Podcast.
Brian Thomas: Welcome to The Digital Executive. Today’s guest is Brian Trzupek. Brian Trzupek is the senior vice president of product at DigiCert. A crypto and security tech by day and night, Brian brings nearly two decades of expertise on many security subjects to the team. He’s constantly innovating use cases for enterprise PKI.
He previously worked for more than six years as vice president of managed identity and authentication at Trustwave, where he helped fight cybercrime, protect data, and reduce security risk. While at Trustwave, he prepared testimony for a congressional panel on the December 2013 Target breach. Prior to Trustwave, he was founder of Crediware Software, a company that automated credential password and digital certificate renewal and installation, as well as policy-based application monitoring.
Well, good afternoon, Brian. Welcome to the show.
Brian Trzupek: Thank you, Brian. I appreciate you having me.
Brian Thomas: Absolutely. Brian to Brian. Spelled the same way, too, so I always like to get a fellow Brian on. Which is the
Brian Trzupek: right way.
Brian Thomas: Yeah. Yeah. That’s what, that’s what I like to say anyway to all the Brians out there. So Brian, if you don’t mind I know you’re in Austin.
I’m in Kansas City, so we’re in the same time zone luckily today. So I’m gonna jump into your first question. You’ve spent nearly two decades in security, founding Creduware to automate credential and certificate renewal, then years at Trustwave fighting cybercrime, and now leading product at DigiCert.
You even prepared testimony for a congressional panel on the 2013 Target breach. What was it about KPI and digital trust specifically that became your professional obsession, and how did that congressional experience shape how you think about security today?
Brian Trzupek: Yeah. It, it’s funny. I, I was in tech, and I got into PKI with a job actually at a company, Venafi was the competitor now.
I was there early stages with them, and that’s where I learned everything, and I fell in love with the tech and said, “Wow, this is so oddly specific. Nobody else in the world knows how to do it, so it’s probably a good place to have a job.” And that worked out really well. But you know, i- in, in creating that and seeing that, I saw PKI really just as a layer of fabric that is powering the entire internet, and, All of the things we’re doing, whether it was at Trustwave, whether it’s here at Digicert, Creduware all of these places are, you know, were built on that fabric because it’s just so, so critically important to how the whole internet works and data gets protected.
And then I think what’s interesting is the congressional testimony thing at Target. I really learned a lot of skills there at Trustwave with events like that because PKI is so geeky, right? Like, it, it’s just, like, people… It’s just hard to explain. And we had a non-technical audience here. These are policymakers.
And so how do you explain, what these technologies are doing to a group of people who are non-technical? And, how do you understand and explain that sort of risk and, and balance that in a way that they can understand? And I think that’s a place that’s kind of fit for me, is being able to kind of spread that gap kind of personally to talk about deep tech, but also make it applicable to an audience, and in that case pretty different audience.
And that kind of prepared me for today, right? Like at Digicert as an example, just last week, I was interviewed with Bloomberg Law about these AI laws that are being passed. Like, so how do you figure out what AI laws mean to policymakers and things like that up at that level? So it’s kind of just been the skill that has, been useful through the whole career.
Brian Thomas: That’s awesome. Really appreciate that. And I liked– I wanna just highlight some… I love the backstories. W- that’s usually the first question here on the podcast. But, this, this tech space, right? And it does get pretty geeky, PKI especially but I love the cyberspace. But the Target breach, when you had to prepare that testimony, it’s, it’s all about, a lot of people don’t work in the tech space, but they need to understand the criticality of security, and you were able to do that in layman’s terms, which of course, that translated to your success in your career in, in other spaces after that at Creduware.
But now working at DigiCert, you’re doing a lot of that, and I really appreciate you getting that message out there where people can understand it, so thank you. Brian, DigiCert’s AI Trust Manager is built around three layers: DNS enforcement at the network edge, agent identity through passports and policy, and secure execution through confidential computing, with agent passports binding identity, policy lineage, and ownership into a cryptographically signed object.
Walk us through what an agent passport actually is, and why binding all of that into one signed credential is the key to making agentic AI
Brian Trzupek: governable. Yeah. Let’s define the problem space. I think as anybody familiar with AI knows, agents are all over the place, and they take different forms. So you have agents that, like, a company is building and, and is responsible for the execution of, of those things, like their own workloads.
There’s agents that you’re using maybe on your desktop or remotely through a SaaS-based ser- based service that you don’t have that execution control of, but still, it, it’s operating on your behalf and doing things. There’s obviously pservers actually in, in that whole chain too as well that are, are participating in this ecosystem.
So you have this really diverse infrastructure, but the goal, as we hear from customers, is they want a kill switch fundamentally. They want to be able to say, “Stop doing something that I don’t accept.” When you unpack that, what they’re really saying is, “I need to find and identify something, so I need identity.”
That’s layer one of our passport. They need policy. That’s layer two of our passport. So if you wanna kill something, it’s probably ’cause it’s violated something, so it has to relate to some sort of policy. And then I need to understand what’s in it to have a policy, so layer three is lineage. Like, what, what can that touch?
What, you know, maybe models is it working with? What’s the supply chain integrity evidence? How did it come to be? And then last for that kind of goal of kill switching is ownership. Like, is this tied to a specific user? Is this tied to some se- sort of machine account? What data handling constraints c- does that thing have?
And, and all four of those layers, identity, policy, lineage, ownership, kind of s- scale up to that passport, and then that passport fundamentally becomes, you know, the thing that can prove that identity, right, for that agent in any of those deployment scenarios. And then you can kinda think of, like, visa stamps.
They show the authorization and policy, and the travel record becomes the audit trail behind that thing. And what’s interesting is it all ladders up in all of those environments where, you know, a lot of people are concerned about the data protection, right? Data sovereignty and, and the laws that are being passed and things like this.
How do I protect my data? I, I can’t tell how many customers, you know, they’re trying to build knowledge bases. They’re doing all this stuff where they’re sending corporate data outside the firewall. I did this session in Au- in Australia, and it was about, 150 CISOs in the room. I said, “Show of hands.
Who’s afraid of sending your data outside of the organization to go train a knowledge base?” Every hand went up in the room. So people want to have these protections. They want to understand what these things are doing and we’re doing interesting things to, you know, kind of pool that together and make sure that, you know, agents can ultimately reach that goal of being kill switched by these organizations
Brian Thomas: Thank you. That’s, that’s so important, and you did highlight that. Agents are now just proliferating through our environments across infrastructure and platforms, and, and how do we build in that security or that kill switch for these things? And you talked about these passports. There’s, there’s four layers you talked about: identity, policy, lineage, and ownership.
And, and I really appreciate you unpacking that for our audience. But that, that is so important, and I, again, love what you talk about, especially around some of your p- your platforms like your AI Trust Manager, so thank you. Brian, you’ve said twenty twenty-five was the year quantum readiness stopped being o- optional, and DigiCert has been experimenting with approaches like Merkle tree certificates for the post-quantum web.
For a security leader who knows quantum is coming but doesn’t know where to start, what’s the practical first move towards crypto agility, and how much runway do organizations realistically have?
Brian Trzupek: Yeah. Let me answer that direct and then unpack it a hair. So I think the first thing that an organization wants to do when we talk with them is get that inventory.
Everywhere you’re using cryptography, certs, keys, algorithms, protocols you can’t protect what you don’t know you have, and so that’s the first part. Now, customers will tell you once they get that inventory, that is a cl- cluttered space. There’s a lot going in there. It becomes almost unmanageable. So you need some intelligence.
You need an intelligence layer to make sense of that inventory so you can start to risk assess, create those plans for how you’re gonna do things. But I’ll tell you, I think there’s a larger kinda macro goal here, and this is why I was saying twenty twenty-five is the year, is as you mentioned with Merkle tree certificates.
Merkle tree certificates is a response from Chrome, Google, you know, Google Chrome team. They’re looking at how to make revocation maybe more scalable through the g- the global internet, and that is their approach. But the, there’s actually a couple more things, right? So quantum is, is one tailwind.
Shortening certificate life cycles of forty-seven day is another tailwind. That Chrome deprecation I just talked about, where they’re saying mutual TLS will go away, and you need to use something else is another tailwind. And then, as we’ve seen over the years, when a CA may have misissued certificates or, or gotten to a compliance, hiccup, there’s these certificates that need to be revoked in mass, right?
I think two years ago, we did about sixty-five thousand certificates. Those are actually all the same thing, Brian, right? Like, all of those things mean you need to be crypto agile. And so the theme is, if you’re crypto– If you have crypto agility, your post-quantum experience is gonna be much easier.
Your forty-seven day, your Chrome deprecation, and those mass revocations become all manageable events. So really, when I answer this question for customers, it’s inventory to start, but what you’re trying to do is de-risk by leading towards a plan that gets you to be crypto agile
Brian Thomas: Thank you. Really appreciate that.
And I’d love to get into quantum a little bit cryptography, et cetera. We know that this technology is here now. A lot of governments are investing in quantum, and if we don’t get our act together around security we could be having some other problems. But luckily, Brian, you and, and folks at DigiCert are, are helping pave the way.
I like what you said, you can’t protect what you don’t know you have, and so you need to build in that intelligence layer and inventory to determine what you have and determine that risk. I, I just think it’s awesome, and I appreciate you unpacking all that for us here today. And Brian, the last question of the day as we look ahead to the future, you’ve argued that digital trust have moved from an abstract value to a quantifiable driver of engagement, compliance, and revenue, and that organizations treating it as a strategic asset will be better positioned than those that don’t.
As machine identities explode, certificate lifespans shrink, and AI agents proliferate, where do you see digital trust infrastructure heading over the next five years, and what does the winning enterprise get right today?
Brian Trzupek: Yeah. I, it’s, it’s such a, a good question, right? I think it, it maybe even points back to the, the answer to question three there.
I think the closer your organization can get to being crypto agile, you’re gonna solve a lot of the underpinning problems here. But that’s not enough, right? Because you need identity, like I just talked about with agents and the passports. You need to know what these things are so you can attach policy and ownership, and that needs to go across users, device, agents, models, content.
These are all things that need to be managed at that level, and so that means you need certificates to be able to, to, to deal with these, right? And those lifespans are, are, are shrinking, right? And machine identities are exploding like we talked about. When you look at the AI layer, which I’m deeply involved in with our AI trust manager and our technologies here and then personally and what I hear from customers is they’re deploying these things at breakneck speeds.
We have customers who are deploying about four hundred agents per week as one customer cites. We have another customer that has several hundred MCP servers going up a quarter. And this– it’s just exploding, right? And so what’s the identity of these things? What is the trust factor for these things and, and how are people working with them and managing them across that stratified kinda deployment infrastructure I talked about earlier?
And I think, Brian, it’s only gonna get more complex, right? We see, I spoke at the Confidential Computing Consortium in San Francisco. Anthropic was there speaking. I got to talk with them. They actually said everybody’s creating too many agents. And they said, “Look, you need to shift to MCP servers organizations.”
They’re viewing Anthropic and, and Claude as kind of the orchestrator of AI that will interact with more MCP servers that will interact with local models and, kind of move that data burden into the customer’s environment for a lot of tasks. Well, if you do that, can you think of how many identities are gonna explode with that?
H- you know, how do you keep track of those things? How do you manage it and how do you, how do you put policy around it? I think that’s where things are going. That’s not gonna happen tomorrow, but it’ll happen pretty quick. AI seems to change every twenty-four hours. But that is kind of where, where things are going, and I think winning enterprises will treat identity and trust as one automated system across humans, devices, workloads, and agents, really not as like a bolt-on layer for, kinda every new technology wave, rather a foundational layer that p-powers it all.
Brian Thomas: Thank you. Really appreciate that. Yeah, just to highlight a few things, Brian, the closer you can get your organization to crypto agile, the better off you’ll be. You talked about that. Obviously there’s a lot of things to manage here. You talked about the platforms, models, devices, agents, content, everything that’s, that’s there.
And then of course, people. Some companies are just these, this agent deployment is exploding as you talked about raising that complexity and risk. And again, with your background and, and going to some of these conferences and, and talking to some of these experts in this area, especially AI I think you’re, you’re really working to provide a better really some better guidelines around how we manage our environments and deploy agents.
Like I said, everybody wants to be ahead of everybody else in this world of AI, but there’s a lot of risk here, so I appreciate your insights today.
Brian Trzupek: Yeah.
Brian Thomas: And Brian, it was such a pleasure having you on today, and I look forward to speaking with you real soon.
Brian Trzupek: Yeah, thanks, Brian. Great, great. I appreciate being here.
Brian Thomas: Bye for now.
Brian Trzupek Podcast Transcript. Listen to the audio on the guest’s Podcast Page.











