Quantum Risk, Readiness, and the Enterprise Boardroom with Richard Entrup

The New Quantum Era - innovation in quantum computing, science and technology

Richard Entrup is unusual in quantum circles: he's not a physicist, and he doesn't pretend to be. He spent decades as a CIO, CTO, CDO, and CISO at organizations including Verizon, Christie's, Disney/ABC, Time Warner, and Tiffany & Company before joining KPMG to lead its Emerging Solutions practice. That background — deep operational experience on the client side — shapes everything about how he thinks about quantum. He's not selling a hardware roadmap; he's thinking about what it actually takes to get a large, complex organization to change its cryptographic infrastructure before a threat materializes.

The conversation matters now because the signals are accelerating. NIST has finalized its first post-quantum cryptography standards, executive orders in the US are pushing federal agencies toward PQC migration, and the algorithmic efficiency gains that reduce the qubit threshold for breaking RSA-2048 keep coming. Listeners who work in enterprise technology, cybersecurity, or quantum strategy — or who advise organizations that do — will find Entrup's practitioner perspective a useful counterweight to the more hardware-focused conversations that dominate the field.

What We Get Into

  • Why Q-Day's exact date is the wrong question — and why the more important issue is how long it will take enterprises to even inventory their cryptographic exposure, let alone remediate it
  • The scale of the cryptographic migration problem, including why a single laptop may contain hundreds of individual cryptographic components and why upstream/downstream API dependencies make this a supply-chain-wide challenge, not just an internal IT project
  • Why "harvest now, decrypt later" creates urgency today, regardless of when fault-tolerant quantum computers arrive — and how compliance and regulatory timelines interact with that threat model
  • What crypto agility actually means in practice — moving from a "set it and forget it" cryptographic posture to a dynamic, continuously monitored framework, including the pressure SSL certificate renewal windows are already creating
  • How KPMG built its PQC practice, incubated it within the firm, and handed it off to the cybersecurity advisory team as a core service offering
  • The "good quantum" side of the ledger — how KPMG's emerging research function is approaching quantum computing as a source of competitive advantage, not just risk, and what sectors are furthest along in exploring it
  • The AI-quantum convergence, including Entrup's observation that AI is already being used to read and crack code — and what that means for the urgency of cryptographic modernization
  • Why the enterprise quantum opportunity still has a long tail, and how the current moment compares to the early infrastructure phase of the internet — when everyone was talking about TCP/IP and DNS, not Uber or Netflix

Resources & Links

Guest & Organization

Reports & Research

Ecosystem & Events

Independent Coverage

Key Quotes & Insights

> "It's not if but when. And it could be five years, could be three years, could be ten years. The fact is organizations are not gonna be ready. And that's the scary part." — Richard Entrup on Q-Day

> "This is not just the CISO. This is gonna be the software engineering app dev guys. This is gonna be all your partners, upstream and downstream, who have to also be compliant — because if you change your crypto and they don't, that stuff's gonna break." — On why PQC migration is an enterprise-wide, supply-chain-wide problem

Insight: Entrup draws a sharp distinction between the "bad quantum" (cryptographic risk requiring urgent defensive action) and the "good quantum" (competitive opportunity with a longer tail) — and argues that most organizations aren't adequately addressing either.

Insight: The analogy to the early internet is deliberate: just as the 1990s were consumed with TCP/IP and DNS rather than the applications those protocols would eventually enable, the current quantum moment is still largely an infrastructure conversation — and that's normal, not a sign of failure.

> "AI is expediting all of this. If AI is doing one thing, the use case is reading code and cracking it. That's pretty scary." — On the intersection of AI capability and cryptographic vulnerability

Related Episodes

More description

Richard Entrup is unusual in quantum circles: he's not a physicist, and he doesn't pretend to be. He spent decades as a CIO, CTO, CDO, and CISO at organizations including Verizon, Christie's, Disney/ABC, Time Warner, and Tiffany & Company before joining KPMG to lead its Emerging Solutions practice. That background — deep operational experience on the client side — shapes everything about how he thinks about quantum. He's not selling a hardware roadmap; he's thinking about what it actually takes to get a large, complex organization to change its cryptographic infrastructure before a threat materializes.

The conversation matters now because the signals are accelerating. NIST has finalized its first post-quantum cryptography standards, executive orders in the US are pushing federal agencies toward PQC migration, and the algorithmic efficiency gains that reduce the qubit threshold for breaking RSA-2048 keep coming. Listeners who work in enterprise technology, cybersecurity, or quantum strategy — or who advise organizations that do — will find Entrup's practitioner perspective a useful counterweight to the more hardware-focused conversations that dominate the field.

What We Get Into

  • Why Q-Day's exact date is the wrong question — and why the more important issue is how long it will take enterprises to even inventory their cryptographic exposure, let alone remediate it
  • The scale of the cryptographic migration problem, including why a single laptop may contain hundreds of individual cryptographic components and why upstream/downstream API dependencies make this a supply-chain-wide challenge, not just an internal IT project
  • Why "harvest now, decrypt later" creates urgency today, regardless of when fault-tolerant quantum computers arrive — and how compliance and regulatory timelines interact with that threat model
  • What crypto agility actually means in practice — moving from a "set it and forget it" cryptographic posture to a dynamic, continuously monitored framework, including the pressure SSL certificate renewal windows are already creating
  • How KPMG built its PQC practice, incubated it within the firm, and handed it off to the cybersecurity advisory team as a core service offering
  • The "good quantum" side of the ledger — how KPMG's emerging research function is approaching quantum computing as a source of competitive advantage, not just risk, and what sectors are furthest along in exploring it
  • The AI-quantum convergence, including Entrup's observation that AI is already being used to read and crack code — and what that means for the urgency of cryptographic modernization
  • Why the enterprise quantum opportunity still has a long tail, and how the current moment compares to the early infrastructure phase of the internet — when everyone was talking about TCP/IP and DNS, not Uber or Netflix

Resources & Links

Guest & Organization

Reports & Research

Ecosystem & Events

Independent Coverage

Key Quotes & Insights

> "It's not if but when. And it could be five years, could be three years, could be ten years. The fact is organizations are not gonna be ready. And that's the scary part." — Richard Entrup on Q-Day

> "This is not just the CISO. This is gonna be the software engineering app dev guys. This is gonna be all your partners, upstream and downstream, who have to also be compliant — because if you change your crypto and they don't, that stuff's gonna break." — On why PQC migration is an enterprise-wide, supply-chain-wide problem

Insight: Entrup draws a sharp distinction between the "bad quantum" (cryptographic risk requiring urgent defensive action) and the "good quantum" (competitive opportunity with a longer tail) — and argues that most organizations aren't adequately addressing either.

Insight: The analogy to the early internet is deliberate: just as the 1990s were consumed with TCP/IP and DNS rather than the applications those protocols would eventually enable, the current quantum moment is still largely an infrastructure conversation — and that's normal, not a sign of failure.

> "AI is expediting all of this. If AI is doing one thing, the use case is reading code and cracking it. That's pretty scary." — On the intersection of AI capability and cryptographic vulnerability

Related Episodes

2026-08-24 35 min Transcript
Listen elsewhere

Available Results

Generated results are saved to your library for reuse and search.

No generated results are available for this episode yet.

Transcript

Open the Transcript tab to load the transcript.

Chapters

No chapters available.