Everyone, welcome to Fortinet Quantum Cybersecurity Webinar. Thank you for joining us today. I'm Amol Bhandarkar, and on behalf of Fortinet, it's my privilege to have you all for this conversation. I believe this is one of the most consequential one in cybersecurity right now. Let me start with this number, 2034. That's Gartner's projection when quantum computing is going to break virtually all the cryptographic standards. Gartner has highlighted this post-quantum cryptography as one of the top strategic technology trends, warning that the quantum computers will break all the cryptographic within a decade. That sounds like a future, but threat is already here today. Threat actors, often state-sponsored, are already executing what's known as a harvest now, decrypt later attack. They're exfiltrating your encrypted data and storing it and waiting for quantum capabilities to unlock it. For the organizations who deal with this data, financial record, patient history, intellectual properties, government communication, your data that's encrypted right now may be compromised in somebody else's data store. India's regulatory landscape also is tightening very fast. DPDP Act, which is already operationalized in 2025, mandates a reasonable security safeguards and accountability for data breaches. Regulators like RBI, SEBI, IRDAI impose additional stricter cybersecurity obligations on financial services. Now, as a country's framework are collectively establishing a robust compliance architecture for current threats, they remain largely technologically neutral when it is in case of explicit contemplation of quantum-induced vulnerabilities, which means t here is a gap between a regulatory intent and a quantum readiness that falls on the organization like yours to proactively, closely monitor it. Regulators are already shifting the Q-Day estimates into the mid-2030s window, which is more tighter deadlines for us. At Fortinet, we have been building this for this particular moment, whereas our FortiOS is supporting NIST-approved PQCs, QKDs, integration, FIPS compliances, hybrid mode, and algorithm stacking, w hich will allow the organizations like you to transition into a quantum- safe encryption at your own pace without any overheads or performance compromise. In next one hour, Nitish, who is our Subject Matter Expert for quantum computing, will walk you through a threat landscape, a regulatory imperative specific to your vertical, and the practical roadmap to become quantum-safe, n ot someday, but today itself. Let's get started. I hand it over to Nitish to take you forward. All right. Awesome. Thank you so much, Amol. A warm welcome to everyone to Quantum Cybersecurity Webinar: Securing the Future Beyond AI. Now, we understand that this is one of the major technology booms that has come up from last five years or three years per se, and w e understand this is the problem with a lot of customers as well in understanding the time frame, how and when to start, and how to start as well. Right? That's the reason we are doing this webinar to understand the timelines, what is quantum computing in the first place, right? How the quantum physics, which talks about the electrons, protons, and neutrons, are being translated to the bits, which is zeros and ones, which are computed today, understand it, right? Now, we need to understand that how quantum is getting translated to today's computer language, which is zeros and ones. Right? We'll talk about that as well. To set you the context of the today's webinar, let me walk you through the agenda that we're going to cover today. Right? The first thing is on the quantum computing, like I said. We'll also talk about the harvest now, decrypt later. There are interchangeable names, store now, decrypt later attacks. We'll also talk about the quantum day, right, or t he quantum year, which was previous 2025. We were calling it as quantum year. We'll talk about the impacts on specific industries that is covering most of us, right, w hich is finance, healthcare, utility, e-commerce. Now, as a user, as an administrator, as an organization, you are being impacted, right? We'll talk about the challenges also, the solution landscape, how and when you need to adopt them, and what is the timeline for it, right, and a lso, the flexibility to adopt b ecause the concern is that because you have a legacy data center, firewalls per se, or servers, switches, or routers, which does not understand post-quantum cryptography. Right? Now, your concern is how we do the shift to the post-quantum era b ecause you might need to upgrade it, you need to buy new stuffs, and the procurement or the solution to adopt these will take some time. What is your planning looks like in terms of the adoption for post-quantum? We'll shift our gears on Fortinet's solution, which we are calling it as quantum-s afe portfolio, w herein we talk about the FortiOS, which is our fuel in the product line that we have, right, w hich is the operating system. We have natively integrated the post-quantum cryptography because, like I said, the challenges, the adoption is one of the challenges, right? We are making it easier for customers to adopt it from day zero, right, to your day N. Then, you already are aware of the FortiGates, be it your VM form factor or the on-prem form factor or physical form factor, all have these capabilities. Right? Now, we have taken a step, as in, we know that the customers would be taking certain time to adopt. That's the reason we have natively integrated with the FortiOS, and we understand the simple upgrade to a FortiOS version will make that magic happens in your environment. Right? Now, for certain customers who are looking into highest quality of keys, putting everything in terms of their on-prem data centers, or they are more into the AI sovereignty compliances, r ight, f or them, we also have the integration with the quantum key distribution, which creates the highest quality of keys, which are dependent on the post-quantum cryptographies, again, can be integrated with our FortiGates, which then do your quantum-safe terms like VPN, your remote access VPN, or decrypt those PQCs, or even do the translation from your non-PQC to PQC traffic. We'll talk about the performance and interoperability. Whenever you hear about a change in the key size or a newer technology as a whole, which is post-quantum cryptography now, and you understand this is a sophisticated technology, right, y ou know that the performance would be impacted. What if I say you that if you turn on the services or the PQC services on the FortiOS, there is no performance impact at all. Right? If you compare with any other vendors, the story is different at all. Right? We'll cover that in more details when we talk about those slides. On the last but not the least, we'll talk about the real-world use cases. Right? We need to see that where are we implementing these? Why QKD is making sense, right? There are caveats that you must have heard about QKDs as well, that it depends on photon and photons can be translated or transmitted onto the cables, which can be extended only up to 150 km, but t here are vendors in-house in India which are working on 500 km and even 2,000 km for defense customers. Right? We know that the evolution is happening along the line as we speak, and we'll also talk about the OT security. OT with quantum is a very great use case that you need to see. I don't know if you have heard about this, but we'll make sure that you understand these use cases. All right. If that sounds good, I'll straight away go to what is quantum computing. Now, like I mentioned when I started my session, stating that any computer today, be it your any technology you are running, they all talk in the bits, which are zeros and ones. The challenge with the scientists and researchers were, how do we convert the electrons, protons, and neutrons which were there in the quantum physics to zeros and ones, which will actually understand it in the classical computers or the computers or technology that we have today. Right? Scientists and researchers also understand that this is a phase-wise approach, not a big bang approach. You need to take a phase-wise approach wherein you need to adopt fast, react fast, and then turn on the features on the whole infrastructure, and w e'll talk in the planning as well. Right? If you have learned physics in your class 10, 12th, you must have heard about the force called centrifugal force. You also know that in an environment, the electrons, protons, and neutrons travel randomly. When you have a force, when it pulls to itself, a circular motion is formed. Right? Now, when a circular motion is forming, what the scientists and researchers were doing is whenever electrons, protons, and neutrons were going up the cycle, it was denoted as one. Whenever it is going down, it was denoted as zero. The job of translating the electrons, protons, and neutrons were that, zeros and ones. Right? Now, you would say that, "Okay, you just translated to zeros and ones. Now, what is the advantage of using quantum computer?" We talk about it has computational power, it has more speed, it has more resources per se, which can perform, and [Foreign language] any of the classical computers today or supercomputers today. Right? The reason is, if you look at it, when the circular motion is happening, at the mid of the circle, right, there could be two scenarios. It could be a zero or either it could be a one. Right? In the classical bits, wherein it was just zeros and ones, here, you can get the flavor of zero one one zero zero zero one one. If you look at it, the number of bits for the same state is being multiplexed. Right? That's the whole purpose of quantum computing becoming more powerful. Right? Those are called a quantum bits or qubits. That's the reason we call it as quantum bits. As long as you increase the number of qubits, the number of the quantum or the power of the quantum computer also increases. There are two terminology. I will not go in detail, but you can do a Google. That's your homework that you can do it after the session about the superposition and entanglement. Right? These are two interchangeable or terms that we use in quantum computing. There are also algorithms like the Shor's algorithm as well as the Grover's algorithm, which actually came in in 1996. It's a fun fact, right? It came in theory in 1996, the Shor's algorithm, which is targeting your asymmetric classical algorithms, right? Now, f or the symmetric algorithm, there is another theory that came in in 1998 called Grover's algorithm, r ight? These things came in like 20, 30 years ago. Now, the theory is being converted to practical, r ight? It is practically available quantum computer, or you might be hearing about surrogate quantum computers also. Because we know that the adoption or to get the quantum computer or a chip in a computer that we have today will take certain time because there are so many permutation, combination, and a maturity need to be taken place. What they are doing is that in place of the quantum computers, they are actually using surrogate quantum computers. They are using GPUs, or TPUs, or even the NPUs in such a way that it give you a feel like of quantum computer. Right? That's the reason the timeline that you see for 2030, 2034 is actually now coming to 2029, 2028, right, as we speak. You have heard about Google, Microsoft, they came up with a palm-sized quantum computer. Things are happening in the lightning speed in terms of the evolution. We imagine 100 years ago, 50 years ago, that for connecting to one person to another, there used to be a operator in the telephone operating department, which used to actually multiplex the calls from one source to destination. Now, we have a palm-sized mobile phone, tablets, watches that receive calls, right? The technology is evolving. Similarly, it will evolve for quantum computer also. We have seen various advantages of quantum in AI as well. The learning the data set, which is only possible in 3D, 5D, which can be possible in 13D, 12D as well, when the quantum computer servers and learning will come into picture. Right? This is what the quantum computing all about in very brief. Right? Now, what is the quantum challenge? Now, we understood the advantages in the last slide, that the speed is there, it is multiplexing it, and we can do lot of processing with quantum computers. If you put the adversaries or the actors who might take advantages of these technology as well, which means that they can use sophisticated attack using quantum computers, or even they can use post-quantum cryptographies by encapsulating a malware, meaning that they have a malware, they encapsulate a malware with a post-quantum cryptography. Now, because your firewall, edge/core firewall, does not have a visibility on the post-quantum cryptography, they will take it as a standard TLS and SSL connection, and it will pass through because it will just see the five tuples or maybe threat inspection and all. Threat inspection is not able to understand your PQC-based traffic. It is taking or treating it as HTTPS. Right? That's when the attackers are one step ahead. Right? We need to have solutions which can decrypt it, which can have visibility, because, in short, in cybersecurity, if you don't have visibility, you cannot apply security. As simple as that. Right? Coming to another theory that you must be hearing or you haven't heard about it, but it's called Mosca. What is it, right? It's X plus Y greater than Z. X is your data that you want to store. For how many years you want to store is the Y terminology, and Z is the D- date, which is 2030 or 2034, if you have adopted any of the compliance from NIST or Quantum National Mission and all those stuff. Right? Z is the number when the Q- date will happen. X is your data duration that you want to save those data, and Y is the number of years that you want to save those data. If X plus Y is less than Z, then you don't have a problem, right? If X plus Y is greater than Z, meaning that you would take 2038 to safeguard your data and you need this data up to 2034, then you are already done with the quantum attacks. We'll talk about it. The threats are harvest or decrypt later, which Amol also touch upon it. Right? As the name suggests, we are harvesting, the adversaries or the attackers are harvesting. Now, the best part for an adversaries or an attacker is they don't need a quantum computer. I am just capturing data, intercepting as a man-in-the-middle over the internet, maybe, from your banking website to the bank's web, the servers. I'm just doing a man-in-the-middle and capturing just encrypted data. The best part, again, for the attacker is there's no way that the bank and the user would know that somebody is intercepting my data. Now, you would say that it's an encrypted data, w hat is the problem with that, right? That's when the quantum computer and surrogate quantum computers into the play. They can actually do permutation, combination, looking at your public key and understanding based on the public key, they can get your private keys, meaning that they will be in clear text. As I was mentioning, the data that you have identified, what is the number of duration of years that you want to keep this data isolated, nobody should see it. For example, your roadmap of next five years or 10 years, per se, which nobody or no other vendors or no other country should look at it. There would be a reputational concern, right, or t here would be a problem if it comes out. That's the reason, this Mosca's theorem and harvest now, decrypt later is one of the dangerous attacks. I talked about the encapsulation, that's another attack that's happening, right? There are experimental post-quantum cryptographies, right, which are being used in the environment or in the infrastructure. The fun part is, the HTTPS traffic that you see on the internet, 52% and more as of December 2025, you've seen 52% of the HTTPS traffic is based on the post-quantum cryptography. So, ask question to yourself. You were imagining that, is it being used entirely or nobody's using post-quantum cryptography? It is already being used and it's 52% and more, right, and t he total number of HTTPS traffic over the internet would be 95%. It is already 52%, reaching 60% in next couple of months. We know that the post-quantum cryptographies are being adopted by browsers, by SaaS applications, by vendors like Amazon, Flipkart, and what other companies, right? We understand the important, and that's the reason the adoption is also booming, right? Now, everything that you're using, now, let me take a step back. Everything that you're using today are all based on some encryption. Those encryptions are based on your classical algorithm, be it asymmetric, be it symmetric. Now, what we are saying is that they are all at risk. Now, you imagine from a person logging in with his card to authenticating it to their critical websites, to their critical databases, everything at stake. Accessing emails, accessing cloud database, wherein you are creating a line zone or landing zone per se, and t hen you are creating or onboarding users in the MSSP format, maybe, e verything, it at stake. Your VPNs, your remote access VPN, everything is at stake. Code signing. You are delivering certain patches to your users. Now, I'm sitting in man-in-the-middle, get hold of these with my surrogate quantum computer, quantum computer, I induce a malware, t he user is understanding that it is coming from a legitimate source, I will simply download it. What is happening is, a fileless malware is being introduced, or certain commands have been on your laptop or desktop or your services, and a backdoor has opened up, which you have no idea about. Right? And when you understand there is a backdoor, it's already too late, right? And t here would be dynamic DNS kind of attacks that could happen with the bots that would be created in your environment, right? This slide talks about the users' infrastructure, application or data. Everything is at stake if you're using the classical algorithm. With the power, with the computational speed, the quantum computers will be able to break those, right? The best part is, we are here, Fortinet is here to help you to secure your entire estate. Right? We'll talk about it. Now, like I said, we have verticals. As a user, you are using some bank website. As an administrator, you are managing certain data centers or databases, right, or websites. As an organization, you're maintaining the bunch of users or bunch of administrators or bunch of customers per se. All are impacted in any of the verticals that you look at. PII information in the medical records, right? Yo u are putting your credit card information in the e-commerce because you want to buy some refrigerators, right, in the sale that's going to happen. Utilities, the grid that you have, t here is a power outage, uncertainty, n obody was planning for it, right? All have been encrypted today with classical algorithms. Innovations, the IP that is working or the patents that you are doing, right, w hich is, which should not be shared to anybody because it's a patent idea, per se, right? You are securing it in some way. A company's patents, per se. Everything, it at stake. If you imagine any of the verticals, if you imagine any of the classical algorithms that they're using or you are using, are all at stake. Right? Now, quantum challenges or implementation challenges, we've talked about it when I was initially pitching it, the idea. We know that the people needs to be trained, right? There would be certain budget or budget planning that you need to do, and y ou don't know how to educate your procurement team also. Right? That whenever a BOQ or a bill of material or bill of quantity is created, it should have a vertical or a terminology, which talks about the quantum cryptographies, right? So, w e understand the challenges and quantum expertise. Now, you've already taken us two steps ahead, right, but h ow would you know that you are at the right path? You would need or want to hire certain quantum expertise that will actually tell you that you are at the right speed and the right path to take the quantum- safe journey, right? Now, t he last challenge that most of you are facing, and you are not realizing it also, which is the legacy infrastructure. Like I said, your routers, switches, your F5 load balancer or any load balancers per se, right, are all based on classical algorithm. Now, to upgrade them, you have to upgrade the box completely because t here is no way that you can upgrade on the software and then get the flexibility to adopt, because you know that quantum cryptographies are heavier on the side. Right? You would need different technologies. You would need quantum- aware chipsets. You would need quantum- aware servers, right? Then, only you will do that upgradation. So, you need to buy those items and then do the cryptography migration from classical to post-quantum, which we understand would be long, long years ahead, right? Now, if we go back to the Mosca's theorem, you have data that you need for five years, but to do the migration, you need 10 years, which is 15 years. You're putting Z or the zed as the 2034, you're already late, right? That's when Palo Alto Networks, and when there's like Fortinet comes into picture or any other vendors are coming into the picture. We'll talk about the advantages that we have with any other vendors out there. The solution that we are providing you is the quantum key distribution, right? Now, t here are vendors who only support a few of the vendors. We have four and plus QKD providers that you can integrate with the FortiGate services and FortiGate firewalls, right, w hich you can then leverage to create the site-to-site VPN, which is based on the highest quality of quantum keys. PQCs, now, i f you are saying that, "I don't want to buy or purchase additional hardware called as quantum key distribution. I want to use the FortiGate's natively integrated post-quantum cryptography," the answer is yes, you can utilize that as well. Meaning that you can leverage the post-quantum cryptography's base quantum- safe VPNs to create site-to-site VPN from one pair to the other pair. You can also onboard your remote users, which are using FortiClient, to connect to the FortiGate using the post-quantum cryptography. If somebody is doing man-in-the-middle attack and they have the surrogate quantum computers or quantum computers, they will not be able to break it because there is no characters or no prime numbers dependent on the post-quantum cryptographies. That's the beauty of PQCs, right? Now, the AES and symmetric encryption, like I said, you can do the translation from non-PQC to PQC and vice versa also. We'll talk about it. You can also decrypt the post-quantum because I talked about that 52% and more HTTPS-based traffic are being used over the post-quantum cryptography. We already know that the quantum-based traffic is coming in your environment. To inspect those, you need decryption capabilities, right? That's when the FortiGate solutions comes into the picture. Right? We talk about this timeline. We have actually started our journey with quantum or post-quantum practices back in 2018. We have done evolutions, we have done the patents on the post-quantum cryptographies and started, and now we are sitting at March 2026, wherein we have the capabilities such as the decryption over the post-quantum cryptography. You can create site-to-site VPN, you can create remote access VPN based on post-quantum cryptography. You can access Fortinet's firewalls over the post-quantum cryptographies because the SSH is also, if you're using classical, they can be hampered with quantum speed. If the attacker have attacked the firewall, then you are done and dusted, right? To counter that or to prevent those kind of attack, you can actually use, if your browser is ready with post-quantum cryptography, you can access the GUI or the graphical user interface using the post-quantum cryptographies. Even if you have PuTTY or SSH terminal that supports the post-quantum cryptographic, you can do the SSH based on PQC as well, right? These are all natively integrated with our FortiOS, which means that the performance impact is minimal that I will talk in this slide anyways, but t his give you an advantages, right? Imagine that you don't have to upgrade any of the routers, which is the legacy infrastructure. You just upgrade your firewalls with a FortiOS that supports the post-quantum cryptography, and you can actually take your own time to do the migration from classical to post-quantum because all the threats have been eliminated on the FortiGate firewall altogether right? Why Fortinet? Like I mentioned multiple times, that we want our customer to act first and act fast, right? We have integrated them in the FortiOS natively, which means that in a click of a button, you just enable the post-quantum cryptographies and nothing is needed from the customer end. Right? Standard offering, meaning that there is no charge from Fortinet if you utilize the post-quantum cryptography. You just need to upgrade the FortiOS to a certain version. Right? If you're using a legacy or a E version or D version of the FortiGate firewall, we would recommend you connect to the sales engineers that will help you size the box accordingly because we want our customer to have the highest return on investment, not only quantum, but also AI. We are seeing in the terminologies like quantum AI or the AI optimization for quantum, right? Those sort of things. I don't want customers in next two years to sit in a position that you would be replacing or refreshing the boxes again. Connect to FortiGate's SE or the sales engineers to learn more and get insights on what the sizing or what the box should look like in your environment. Right? We have taken the step in the hybrid migration, now, w hat is hybrid migration or deployment per se? Now, because your administrators are ready and understanding the classical based site-to-site VPNs, right, y ou can leverage the same site-to-site VPN, just turning on the post-quantum cryptography. We are not creating quantum or VPNs based on certain or a different algorithm or different ways to configure it, for which you would need a separate training. That would again put you in a step back, meaning that it will take certain time to train those administrators to learn the post-quantum based site-to-site VPN and then perform those migrations. Right? We don't want that to happen for customers. We want you to leverage the classical site-to-site VPN, just turn on the PQC or the post-quantum cryptography on top of it, giving you the hybrid migration efforts. Right? Now, your concern would be that I've turned on the highest level of classical algorithm. I'm putting a post-quantum cryptography on top of it. My performance is bound to go down and going to degrade. The answer is no. I will talk about the performance testing that we have done, and we'll show you the result as well, right, so that you understand that this is natively integrated. I'm talking about natively integrated performance became minimal to zero that I will show you in a bit. Right? Like I mentioned that they are natively easy to configure. You just go to your site-to-site VPN, you enable it. You'll start seeing that there are options to enable post-quantum by a click of a button. You choose any of the NIST-approved post-quantum cryptographies, be it FIPS 203, FIPS 204, or FIPS 205, w e have all the cryptographies, r ight? Now, you have standardized Frodo as one of your internal PQC per se, so y ou have that flexibility as well. If you have standardized ML-KEM or ML- Dilithium, those are also possible. Right, so all of those as per the NIST, the governance and the standardization body, we need to have those set of PQCs. Now, your answer would be or your question would be that, why don't we allow the experimental PQCs or PQC that I can create and bring onto the table and integrate it with Fortinet or FortiOS? The answer, that is one of the biggest risk because the maturity with post-quantum cryptography is not yet reached, meaning that there are not enough users to call these or the experimental PQCs as standardized, or they are mature enough to not have any vulnerabilities. If there are no governing bodies, then you are at a higher risk of calling attacker to attack you because there would be vulnerabilities that you would not be aware of, right, or any governing body would be aware of because it's an open standard, then that will create a problem. With Mythos and with the GPT Cyber coming into the picture, the ball game going to change for cybersecurity, right? Like I said, interoperability with the NIST, our standard offering, if you want to be as per the NIST standards governing body for all of these, you have these many options that you can choose from, right? You can interchange it accordingly during your years of adoption as well. For example, you want to use BIKE L1 for few years, and now you are upgrading, or you want to use the ML-KEM-512 well, you can choose that by changing the keys altogether. It's simple as that. Right? When I was mentioning the crypto-agility piece, the hybrid mode, which was nothing but you can mix your, the Diffie-Hellman's that you are aware of and you are being trained of from N number of times, right, or N numbers of years, you can just turn on over these with the post-quantum cryptography, right? There are also another challenge that customer face, and I don't know if you are also facing it, but I want to put that challenge as well. Meaning that if you want to do a upgrade from your legacy TLS 1.1 to TLS 1.2, you have to upgrade the whole infrastructure to have the end-to-end TLS 1.2 encryption, right? You must have done that already wherein you had to upgrade all the switches, routers, load balancers, your firewalls, your application servers, databases and everything, which must have taken you a longer time, right? With post-quantum cryptography, with crypto-agility functionality, you can actually mix and match any of the PQCs, meaning that if one of the end is the ML-KEM and the other end is Frodo, for an example, they will still be able to create the post-quantum cryptography. Right? That's the beauty of PQCs, the crypto-agility. Right? Like I mentioned, you have both the options. You can utilize the post-quantum cryptography, which is natively included on the FortiGate or the FortiOS, or you can bring any of the vendors such as Toshiba, IDQ, and whatnot, which we have integration with. We have the tech docs available, which all QKDs we support. You can buy those QKDs and integrate it with our firewalls to use those keys that have been generated from QKD to set up your site-to-site VPN based on post-quantum cryptography. Right? All of these options are available, be it defense, be it vertical, any vertical, you can utilize them. Right? Save, web browsing that I was mentioning that your browser is already ready. There are two scenarios. Your web browser is already ready with post-quantum cryptography. You are encapsulating the encryption with PQCs. Like I mentioned in earlier also, that if your firewall is not aware, then it will understand it is a normal TLS and SSL connection, which will be a problem for the administrator or the organization, right? Because there might be a malware induced inside a PQC. You need a visibility or deep inspection that can see inside the post-quantum based traffic. Right? That is what is available. The second scenario is, let's suppose a user is trying to access from a web browser, which is already ready with post-quantum, trying to access a database or an application server, which is still based on classical algorithm. Directly from the post-quantum to the classical based server, the encapsulation will not happen. Right? What will happen is that the application server will tell the initiator or ask the initiator to downgrade it to the version that he is supporting or the server is supporting. Right? That you don't want to happen. You want to adopt the post-quantum cryptography phase by phase, wherein whatever the easier way and the fastest way to adopt can be turned on faster, can be turned on quickly. Browser, you have turned on the PQC specific for the users, which can access N number of things and can also access the classical based. You can actually translate the PQC traffic to non-PQC traffic and vice versa as well. If a browser or if a user is sitting inside using a classical algorithm and trying to access a SaaS application which is based on post-quantum cryptography, our firewall, FortiGate's firewall, will do the translation for you from the classical to PQC or PQC to classical. Again, giving you another advantage is that you will take sweet time to migrate to post-quantum cryptographies by buying and upgrading it and then doing the migration. We understand that it's going to take a lot of time. But at the edge or at the core, you can put a FortiGate firewall, can do that magic for you. Right? Now, the use cases part, quantum for OT. You know that OT comes up with N number of visibilities issue, right? Like I mentioned earlier also that if you don't have visibility, you cannot provide security. As simple as that. Right? Any of the monitoring equipment, any of the OT devices, be it your medical, enterprise, or any of the devices, IT, OT environment, connecting to a application that is already based on post-quantum cryptography, r ight, o ur FortiGate, like I mentioned, can translate any of the non-PQC to PQC and vice versa as well. It only not helps you with the safe browsing practices, but also technologies like OT, which will take ages to upgrade, r ight, b ecause they are using certain legacy operating system, and you cannot upgrade them because you know that if you turn off an OT device, there will be a disruption in the environment. How would you turn off the power grids, right? That's one of the challenges with the customers. To cater that and use the FortiGate to the advantages, you can use FortiGate firewall to translate it to the post-quantum based traffics, right, and vice versa. Now, let's come to the performance. We talked about it, how to configure it, what were the challenges with post-quantum, what the attacker is going to use it up against their advantages, like the harvest or decrypt-later attacks. We talked about the translation. We talked about the decryption capabilities. We also talked about that you can use them to access the firewalls in SSH or GUI access based on post-quantum cryptographies, right? We have seen lot of them. Right? Now, the concern is that if I turn on everything, will my performance be impacted? Right? That's the beauty of our NP7, the network processor seventh version. Right? The NP7 ensures that there is no impact on the throughput by offloading them on the NP7. Right? If you have already purchased, if you're planning to purchase, make sure that you talk to your SEs or the sales engineers about the NP7 functionalities because you have to onboard post-quantum cryptography and AI in the future, or you are already onboarding it, or you have already purchased GPUs, or you have certain interference wherein you have already have the pre-trained data that you are utilizing it to train your LLMs or any private LLMs. You need to have these in your environment, right, which will have minimal impact when you are adopting a newer technology. Right? The results, simple as that, we turn on the legacy Diffie-Hellman group 19, 20, 21. We also enabled the 520, the third version and the fifth versions of the ML-KEM. We turned on all the PQCs, which is HQC by Frodo, which are based on lattice, some are based on hash, some are based on Dilithium and all those stuff. What we saw was when we enabled the ML-KEM, which is our recommendation from Fortinet as well, that when you turn on the ML-KEM, we see the similar impact of what the Diffie-Hellman or the classical algorithm used to give. Right? Which means that the recommendation, the NP7, another recommendation, if you're turning on your site-to-site VPN, we recommend you to use ML-KEM. Not just that you cannot enable the other ones. You can enable it, i t's just that when you are turning on the Phase 1 tunnel of the site-to-site VPN, you'll see a few impact, a minimal impact on the CPU utilization of the firewall, but it will come down once the tunnel established, right? The second scenario which I talked about is applying to all the vendors that are out there. Any vendor that talk about quantum-safe VPN has this problem. But because we use our ASIC or the NP7 to our advantages, we have seen this with ML-KEM. With any other vendor, with ML-KEM also, they see a huge impact when they enable a single site-to-site VPN, and they see 30%, 40% of the increment in the CPU utilization. When you are talking about thousands of CPU, your firewall will go down again. You have to be aware of the performance impact and the advantages that FortiGate or the Fortinet product brings onto the table. Talk to your sales guys and talk about these functionalities and see how you can start the next step as well. Now, the QKD use case. We had done the testing with the IDQ where we integrated the IDQ QKD with the FortiGate, right? There were data centers from one end to the other end, which was 46 km apart and we have chosen Singapore, which makes a lot of sense because everything is closer to them, and it has the perfect use case for QKD usage, right? We used our FortiTester to do the testing on the PQC-based traffic, right? Then, w e did the end-to-end PQC. Now, we are the only vendor who does the combination. Other vendors can choose only PQC or only QKD. You can actually combine to have a military-grade encryption in your environment, meaning that just by turning the PQC plus the QKD, meaning that the quantum key that you have received from QKD, on top of it, you have a PQC on the ML-KEM, w ithout any impact, you can create a military-grade site-to-site VPNs. If you have a super critical environments or databases, data centers, or DC-DR setup wherein you have that concern, you can create these set of quantum- safe VPNs, right? Even you have on-prem to cloud connectivity, y ou put a FortiGate VM, you put a on-prem firewall and create a site-to-site VPN. Done in that state. Any user who is trying to reach your on-prem and then trying to access the cloud workloads can be done through those quantum-safe VPN as well, right? I think you must have heard about this, or you have already had this thought, or you had the thought while I was giving this session, right, that what is the risk? We talked about that the verticals were all impacted because the quantum power and speed, what it can bring onto the table. If your data need to stay confidential, you need to act now. You are already late in the game. You have to talk to your leadership, you talk to your procurement team, or if you are leaders, you talk to your IT team to fastly adopt it with FortiGate firewalls and Fortinet product lines. The SD-WAN. Our SD-WAN solution also supports post-quantum cryptographies. If you have these SD-WAN tunnels or you are planning to adopt or planning to have SD-WAN in your environment, give a thought to FortiGate as well. We set up the SD-WAN based on the PQC as well, right? The other questions or the thoughts that can ponder, is the too early? Is the harvest now, decrypt later is actually happening now, right? Just put a Google search or a Gemini search or any of the gen AI or LLM search for that, is there any HNDL attack that is happening, or are there any articles around it? You'll see 1,000+ of articles that the customers, organization have seen. By changing just the BGP routes, they can actually redirect it to their own databases where they will capture the encrypted data, right, without the customer knowing it. They might know after some time that the latency has come in, but i f you have a edge location which is in your region, you will not have that concern also. You will never have that visibility. If you have app accelerators, which is actually buffering some data, you will never know that there is some capturing happening within the environment. It is a dangerous attack wherein you need to act now. There are complaints that are coming that I will also show in the next slide. Future-proofing. Is your infrastructure being evaluated for post-quantum readiness? Now, you are doing the evaluation to adopt the post-quantum cryptography, but the attacks are happening now. Harvest now, decrypt later, encapsulation, malwares, remote access VPNs are being intercepted, your site-to-site VPN being intercepted. What is the solution? The solution is FortiGate. Fortinet's product line. You enable the PQCs without any cost, without any performance impact, turn on the site-to-site VPN based on PQCs, remote access VPNs on PQCs, decryption on PQCs, your SSH, SSL connections, PQCs, translating the non-PQC to PQC or vice versa, all are possible in the same firewall. The best part, is it too costly? Like I said, no costing, but there are vendors who are charging for quantum subscriptions. We want our customer to stay ahead, not having any caveat or a back problem such as the costing. You have the firewalls, latest firewalls, give it a thought to enable it or do the testing POCs or buy the other, which has the NP7 capabilities, if you are looking for a tech refresh. Call to action for all of you, schedule a quantum risk assessment with Fortinet sales guys. Let them know that you are interested onto it, have your questions to them, then we can prepare POCs with you and then take it forward, or you can just turn it on, do the POC because it's simple as it is. Right? It is natively integrated onto the FortiOS. You can test it out with few site-to-sites and just see the power of the FortiGate. Right? Now this is the sector comparison at a glance. Right? How ready the quantum in India is today. Right? Be it your BFSI, the banking and finance, public sector or large enterprises, how are you placed in, and what all compliances you should look at. Right? Top threats for the BFSI, harvest now, decrypt later, as you're aware. NEFT, UPIs or CBS payment set flows, if somebody's intercepting it, somebody is just doing the capturing of those encrypt data, that is one of the biggest threat. Key regulators, RBI, SEBI, DPDP Act, that is famous, it's a buzzword happening. Phase 1 action is crypto inventory, which means that the crypto bill of material, meaning that you should know that what all cryptographies that is going inside your environment. Right? Which all cryptographies needs to be migrated to post-quantum first. Right? Our Fortinet fit, you need to talk about the hybrid PQC VPN with our FortiManager readiness view. Right? The full PQC target for the BFSI customers is the 2029 and 2030 because the data is everything for the BFSI. Right? It's true for all, but it is more critical for the BFSI. Public sector, the nationwide intercept of the sovereign comms and Aadhaar card, the top threat. There are nation-led attacks that is happening from other countries to our country, which will lose our reputations globally as well. Those are the concerns that are coming up as top threats. Key regulators, like [audio distortion], DRDO, National Quantum Mission, which has just planned to spending around INR 6,000+ crore on the quantum initiative. Right? That's the reason you must have heard about Andhra Pradesh, Karnataka becoming the quantum states. Right? The Phase 1 action for these guys are discovery across the NIC, which is the governing body for the connectivity part and the governance part, the DigiLocker, OT, and ICS. Right? Your OT environment, the control systems that you have, or the SCADA system that you have. The fit from Fortinet is the QKD integration with FortiGate and create the site-to-site VPN. You also saw the OT PQC translation from non-PQC or the classical to PQC and vice versa. Right? The full target is around 2030, 2031. We are already late, we are sitting at 2026. For the large enterprise, the top threats are DC interconnects or the connectivity from on-prem to data centers or your on-prem to cloud environment. Even now, the third threat is coming in. Right? From your on-prem or legacy data center or cloud to AI factories or AI data centers. Right? For that also, you need to have this security. Because if you are training your LLM with the data sets, right? If the attackers are poisoning those LLM models, then you will never be able to do or achieve what you are trying to achieve with that LLM. The fine-tuning will take N numbers of years. The data that you have been putting on the LLMs will be at stake, right? The data poisoning, the data theft, the data leakage kind of attacks will be on the rise. Right? Key regulators for it, DPDP, that you're already aware, SEBI, NIST, EUs. If you are the GCCs, you have companies or branches here in India, you are all at stake because you would be connecting anyway, which ways to your NAM, to EMEA, DCs or the services. Phase 1 action is DC interconnects, cloud gateway, crypto scan, and now the AI factory and AI data centers. Fortinet's fit is, you use our intelligent FortiGate SD-WAN with PQC and quantum readiness view, which is available on the FortiManagers and the QKD integrations. Right? The full PQC target for the large enterprise is looking at 2028 and 2030. Right? The last slide that I have for today is that Fortinet is quantum- ready. We are aware of the challenges that customers are facing. That's the reason we have N number of features so that you can adopt first and adopt fast. Right? You can protect your data today with the harvest now, decrypt later, or store now, decrypt later kind of attacks. You have interoperability, meaning that you can enable your classical VPNs and have the PQCs on top of it without any performance impact. You can do the translation from the non-PQC to PQC and vice versa. You can secure your firewall using post-quantum cryptographies. You can do the decryption on the post-quantum based traffics, giving you the end-to-end in-depth protection against quantum threats. This is not just looking at the current threats that we're talking about. It is also talking about the futuristic threats that we have not anticipated at all. Right? The encapsulation of the PQCs with malware or fileless malware. Right? The transition is easy. Talk to us, talk to the sales engineers, the sales managers, and let us do the job for you. What is the best that we can do it for you? Please connect to our sales guys. Right? That's all I had. I will now go to the chats if there are any. Stop sharing it. Let me see the chats. Okay, I see a lot of questions here. Okay, how can we get a Fortinet certificate? Where can we learn? Right? The learning is that we have a number of YouTube videos on our FortiGate channel. Please leverage that. We have the documentation that are available that you can actually summarize it with any of the gen AI application that if you are using it, any, to ask and learn more about the quantum offering from Fortinet. Right? Then you can learn in that way as well, and you can educate others as well, right? Because this is not a single or an isolated effort to go to quantum era. It's a team effort that you need to put in. Right? Why is government policy important in quantum cryptography? Like I mentioned, I talked about it, right? There should be a governing body, right, that should help you with the right path. If you have adopt anything or everything, you don't know where you're going with, right? If there are any vulnerabilities or unseen or unknown vulnerabilities that you have not anticipated, then that would be a problem, right? That's the reason the government policies are important as well as the governing bodies or the compliance bodies like NIST is possible and it's mandatory. We talked about the QKD use cases, right? Say, quantum key distribution, if you don't want to use the PQCs which are on your FortiGate firewalls and you want to have the highest quality of keys from a third-party source, right, which is QKD, you can integrate them with the firewalls, and we can leverage the same keys to create the site-to-site VPN. Now, the problem with that is the keys that you have created, it needs to be delivered to FortiGate, right? The FortiGate will use that keys to the other pair. The same key has to be transferred to the second pair as well, right? You need to have the same set of pair. Maintaining those keys would be a challenge for customers in the long run. If you have 10,000 VPNs, you would not be creating 10,000 of keys. That's the reason Fortinet has the PQC integration, right? I think in the interest of time, we are already two minutes ahead. What I will do is I will gather these questions, I will answer them on the Excel sheet, and maybe I'll share with you guys, right? Like I said, thank you so much for your time today, and really appreciate your time today and hope to have more conversation around post-quantum cryptography. Do reach out to your sales engineers and sales managers and talk about how to start with post-quantum cryptographies. In that note, thank you so much. I hope to see you on the field, and please reach out to us, like I said, and we'll see how we can help you with quantum era. Well, thank you so much, guys. Have a good one
Loading workspace