A Leader’s Insights on Post-Quantum, AI and Resilience

Discover how leaders can stay ahead in the evolving cybersecurity landscape with insights on post-quantum, AI, and resilient strategies for the future.

tl;dr: Cybersecurity is entering a transformative era shaped by emerging technologies. Dell’s Bobbie Stempfley shares the challenges and opportunities that will define the future of cybersecurity, from the immense task of transitioning to post-quantum cryptography to the evolving roles of AI and global regulation.


As part of Cybersecurity Awareness Month, I had the privilege of sitting down with Bobbie Stempfley, vice president of cybersecurity and business unit security officer at Dell, to discuss what’s on the horizon for our industry. Technology drives human progress, and staying ahead of emerging threats helps ensure that progress is secure.

In our conversation, we explored the critical challenges and opportunities that will define the future of cybersecurity, from the immense task of transitioning to post-quantum cryptography to the evolving roles of AI and global regulation.

Success tomorrow requires planning today, and we’re excited to share insights that can help every organization prepare for what’s next.

The following has been edited for length and readability.


I know that most people in the security space and IT decision makers are thinking about post-quantum cryptography (PQC). Can you start by defining the scope of this problem?

Stempfley: Post-quantum crypto is quite a place to start. Think about encryption: it’s at the foundation of everything. A friend of mine has a phrase that says “cryptography is like water. It gets everywhere.” The scope of a wholesale transition of our cryptographic foundations is immense, and it should be top of mind for IT professionals today, even though the timeline for when we must make this transition isn’t immediate. We have a few years, but because cryptography gets everywhere, it’s something you really must start paying a great deal of attention to right now.

What is a good place for organizations to start if they’re just catching up to this problem?

Stempfley: If I were in the shoes of an IT decision maker, I would start with two key questions. The first one is where? Where are all my cryptographic modules? Where do I use it in my enterprise? You need to think about this not just in terms of encrypting data at rest, but what libraries are they in? How do I handle data in flight, key management, code signing regimes, device identifications, and secure access? Once you’ve got an inventory, the second question is to your suppliers: where are they in their journey to understand their cryptographic uses and migrate into a post-quantum world?

When we think about supply chain, are we only as strong as the weakest link? Is that fair?

Stempfley: Yeah, that is always asserted as a true statement in security. There are many controls that you can put around your weakest links to help them be less impactful. The same is largely true in a cryptographic sense. You do have to get most of the space transformed. You can’t just move the living room; you must move the whole house. It’s a complex orchestration for an enterprise.

When we do approach a solution, do you think there will be an industry that springs up around this? Do you think there will be a spate of companies that are focused on creating turnkey solutions?

Stempfley: Post-quantum cryptography is another example where there isn’t going to be a single solution. The kind of transformation that’s necessary requires us to have solutions in all places that we leverage cryptography. For encryption, for code signing, for digital device identification. This precludes a single organization from coming in and saying, “I am PQC ready.” Unfortunately, it’s a transformation for the entire enterprise.

Let’s talk about regulations. What trends are you seeing in regulations around the world relative to cybersecurity? 

Stempfley: You’re seeing everything from rules and guidance around data, and data sovereignty to infrastructure and product. We’re seeing what nations like the US are doing in terms of attestations around security capabilities, and the industry is working through what the EU has put forward in several areas. I don’t think this trend is going to change. When you think about the dependency that almost every industry has on a digital infrastructure, the ability to ensure that it’s supportive of our customers and enables strong, secure connectivity is an important part of this.  Of course, while regulatory frameworks are important for security, it’s vital they enable rather than hinder innovation that can scale in line with the needs of nascent technologies, and this fast-paced AI evolution we are in the midst of.

We have seen some incidents where security executives and board members have faced additional pressure over past actions if an attack has occurred. What tips can you give to organizational leaders to help them navigate this dynamic?

Stempfley: In security, we spend a lot of time speaking in jargon. It’s important that we take the obligation to make sure we are understood and move beyond the jargon. We must communicate with business leaders, technology leaders, and our boards in ways that they understand what we’re saying and what risks exist in the enterprise, so they can be informed as they accept those risks.

How do you see the threat landscape continuing to evolve? Recently we have seen AI facilitate attacks in new ways.

Stempfley: It’s impossible to have any conversation today about security without talking about AI. The opportunity that AI presents for adversaries and for defenders are both very real. We’re seeing AI enhance adversaries’ ability to target. It’s also helping us move beyond the security of containers to really understand the data that’s necessary for the enterprise. The opportunity to connect those two together, I think, is particularly transformative for us as an industry.

As we implement more AI in our security programs, it will also generate a lot of data. Is it now creating an attack surface that also needs to be defended?

Stempfley: AI is absolutely changing the nature of the attack surface. It’s moving from a very deterministic world to a non-deterministic world. Our inability to predict creates a new attack surface that we need to really understand. I think that attack surface is very similar to the human one we have today. Time will tell whether I’m right, but our ability to really monitor and understand that over time is the key challenge right now.

I want to come back to one thing we mentioned earlier, which was ‘passwordless.’ Why is it beneficial to go in that direction?

Stempfley: Passwords and access control are one of the most widely used attack vectors today. There are much more resilient and higher-fidelity ways to do identity and access control that are passwordless. The movement to passwordless solutions can remove entire classes of attacks and change your attack surface. Everything from certificates and other credentialing mechanisms are an important part of that. It’s an important transformation the industry needs to make.

Is there anything before we close that you’d like to leave readers with?

Stempfley: I would say two things. It’s 2025. Do you know where your encryption lives in your organization?

  1. Do your inventory of your cryptographic modules and usage throughout your enterprise.
  2. Understand your data.

Those two things together are simply said and incredibly complex actions, but they’re pivotal to an organization’s success in 2025 and the future.


Explore more cybersecurity and resilience insights and resources at https://www.dell.com/en-us/lp/dt/cyber-awareness-month.

Sameer Shah

About the Author: Sameer Shah

Sameer is a cybersecurity subject matter expert focused on developing content and messaging to tell Dell’s holistic cybersecurity story. He has over 15 years of experience in marketing and sales support, ranging across large companies and startups. In prior roles he has served as V.P. of Marketing at a growing food company and founded a marketing consultancy. Sameer holds a Master of Science in Finance from Texas A&M University and is a veteran of the United States Marine Corps Reserve.