Why Identity Is the New Cybersecurity Perimeter

Presented by Ping Identity & Carahsoft

Post-quantum computing could give government agencies enormous new computing capabilities while weakening many of the protections they currently rely on. Troy Grubs, Vice President of U.S. Public Sector at Ping Identity, says agencies should use the time available now to strengthen their architectures, improve identity security and prepare for the technology’s opportunities and risks.

Speaking at the Billington Cybersecurity Summit 2026, Grubs describes post-quantum cryptography as a rapidly developing field. Agencies are beginning to consider how quantum computing could improve mission speed and efficiency while also preparing for adversaries to use similar capabilities.

Government often receives criticism for adopting emerging technology more slowly than the commercial sector. Grubs believes the post-quantum transition creates an opportunity for government to lead.

Agencies can establish standards for the secure and practical use of the technology rather than waiting for commercial practices to mature. That leadership can extend beyond policy to the way organizations design applications, networks and enterprise architectures.

Quantum Computing as an Asset and a Liability

Screenshot 2026-09-17 at 5.44.53 PMQuantum capabilities could allow government to complete complex computations far more quickly than traditional technology. That speed could improve mission execution, accelerate analysis and support the deployment of new applications.

The same capability could be used against government. Adversaries may apply quantum computing to cyber operations or attempt to defeat cryptographic protections that secure sensitive data.

Post-quantum computing should therefore be considered both an asset and a possible liability. Agencies must prepare to use it effectively while redesigning systems that could become vulnerable.

Grubs compares the situation to agentic AI. Both technologies may deliver major operational benefits, but both also require organizations to build appropriate controls before deployment becomes widespread.

Education and awareness are part of that preparation. Leaders need to understand what the technology can do, which risks are immediate and which require longer-term planning.

Identity Replaces the Traditional Perimeter

Government networks no longer operate within a clearly defined boundary. Employees, contractors, applications, devices and cloud services connect from many locations.

In that environment, Grubs says identity becomes the new security perimeter. Agencies must determine whether they can trust every person, device and nonhuman entity requesting access to data or an application.

That trust cannot be permanent. A user who successfully authenticates in the morning may experience a compromised session later in the day. A device that complied with security requirements yesterday may no longer meet them today.

Agencies therefore need the ability to evaluate trust throughout an interaction. That can include the user’s identity, device security, behavior, requested resource and surrounding context.

Quantum computing raises the stakes because authentication itself depends on cryptography. Agencies must ensure that the systems establishing digital trust can withstand both current attacks and future quantum-enabled threats.

Zero-trust architecture provides a useful model by assuming that no user or system should receive broad access simply because it has entered the network.

Establishing Trust for Agentic AI

The identity challenge increasingly includes AI agents. Autonomous systems can access applications, gather data and complete actions on behalf of users or organizations.

Agencies must know which agent is operating, who authorized it and what resources it needs. An AI system should not receive unlimited access merely because it is acting for an approved employee or mission.

Grubs says agentic AI should be allowed to operate autonomously where appropriate, but people must retain custody and visibility. Agencies need to understand what the agent is doing and maintain the ability to intervene.

That requires strong nonhuman identity management, clearly defined permissions and continuous monitoring. Autonomous agents may operate much faster than people, making it essential to prevent inappropriate access before it can spread.

Government has several years to improve these foundations, but architecture changes can take time. Agencies that begin planning now will be better positioned to use quantum computing and agentic AI without exposing their missions to unnecessary risk.

The underlying question remains consistent across both technologies: Can the organization trust every action, every identity and every moment of access?

Key Takeaways

  • Post-quantum computing gives government an opportunity to establish standards for secure adoption and practical use.
  • Identity is becoming the primary security perimeter as users, devices and autonomous agents access distributed resources.
  • Agentic AI requires strong nonhuman identity controls, continuous visibility and appropriate human oversight.