Opens in a new tab
vmblog logo 2024 wht (updated)

SecureW2’s Kalyan Arety on Identity Security, Agentic AI Risk, and the Post-Quantum PKI Race

Share: 

David Marshall | Published: August 24, 2026
interview securew2 kalyan arety

Coming out of Black Hat 2026, one theme dominated hallway conversations more than any other: identity is now the primary battleground in cybersecurity. Attackers have largely moved away from detectable malware in favor of logging in through trusted identity flows with stolen or misused credentials, a shift that recent industry reports have quantified in stark terms. To unpack what that means for enterprises, VMblog sat down with Kalyan Arety, Director of Product Development at SecureW2, whose platform replaces traditional passwords with certificate-based authentication built on managed Cloud PKI and RADIUS services.

In this Q&A, Arety walks through how hardware-bound, non-exportable certificates are being used to establish Device Trust across Wi-Fi, VPN, and application access, and why credential theft, phishing, and untrusted devices remain such persistent entry points for attackers. The conversation also looks ahead to two of the industry’s thorniest challenges: securing the growing population of AI agents and non-human identities operating inside enterprise environments, and preparing for the post-quantum cryptography migration that Arety warns will require far more infrastructure investment than most organizations currently anticipate. Along the way, he offers a candid take on what “AI-native security” should actually mean and what belongs at the top of every security leader’s priority list for the remainder of 2026.

++

VMblog: For readers who may not be familiar, give us the elevator pitch – who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.

Kalyan Arety: SecureW2 replaces passwords with certificate-based authentication that’s easy to use and manage. Passwords have sucked forever (annoying and easy to exploit), but back in the day, PKI was really difficult to set up and manage. The SecureW2 platform combines managed Cloud PKI and RADIUS services that automate certificate issuance and management in a secure but highly efficient way. It enables customers to control access based on Device Trust for things like Wi-Fi, VPN, and app access, because our certificates are hardware-bound and non-exportable. 

What’s different about SecureW2 is that we take certificate security very seriously. The team is super passionate about it, and it allows us to both be innovative and provide a high level of guidance for our customers. For example, we are able to talk in real-time with security and MDM vendors so customers can automate policies like “this device is managed and currently low risk, so it should get access to sensitive apps in Okta”. There are a lot of cool features that make our certificates different (anomaly detection, API security..etc), but it really comes down to our culture and commitment to certificate security. 

VMblog: The threat landscape today looks very different from even 18 months ago. Which specific threat vectors – whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else – is your solution most directly built to address?

Arety: Identity-based intrusion remains the front door for attackers. Palo Alto’s 2026 Report found identity weaknesses factored into nearly 90% of investigations. CrowdStrike’s 2026 Report notes 82% of intrusions were malware-free. We see the same trends; Attackers increasingly log in with valid credentials through trusted identity flows instead of deploying detectable malware.

The main threat vectors that SecureW2’s product addresses are ones related to credential theft and a lack of Device Trust. Examples of that are phishing, over-the-air credential theft, and the risks that come with giving access to untrusted devices (BYOD, Guest, NHIs), like ransomware spreading, IP theft, identity impersonation, etc.

It’s hard to say the problems that our upcoming AI security solution will address, since AI is evolving so fast, but API Token abuse is definitely something we’re aiming to prevent. It’s been a common entry point in some of the recent events in the news, like the Hugging Face incident.

VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for and with autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?

Arety: The current state of AI Security is really bad! Throughout the history of Cybersecurity, the amount of defensive code required to protect against threats has always been much higher than the amount of code in things like malware/viruses. Since organizations are racing to gain a business advantage using AI, the only way they could actually stay safe is if they spent even more time trying to protect their AI systems… and as you might imagine, reality is the exact opposite. 

There are so many threats today. Easy access to the prompt, shadow IT, agent visibility, lack of review process, exposed data… It’s almost impossible to say what risks enterprises are underestimating right now. I think the best thing organizations can do is continue investing in building strong security teams and getting organization-wide buy-in to staying safe. With a solid foundation like that, then it’s about being plugged into the latest trends in AI security and continuously testing new solutions. 

What we are building as a company can be summarized into three key pillars. Gaining visibility into agents, using SVIDs (very similar to certs) to identify agents, and then controlling what they can/can’t access.

The moment an AI agent or workload receives permission to query data or execute API calls, it becomes a privileged non-human identity. Securing those identities with managed, hardware-bound certificates rather than static tokens is foundational to safely keeping up with agentic automation.

VMblog: The post-quantum cryptography migration is well underway for some organizations and barely started for others. Where should companies realistically be in that transition today, and what’s your honest assessment of how complex the road ahead still is?

Arety: Realistically, organizations should already be establishing a crypto-agile PKI foundation, one capable of preparing for post-quantum cryptography (PQC) standards across both greenfield and brownfield components in their infrastructure.

PKI was always hard to understand, and PQC builds on that. I think something that we’ve seen consistently take our customers by surprise is the fact that it’s going to force a hardware refresh on almost everything. The computing inside devices needs to support PQC algorithms to actually use PQC certificates. Laptops, phones, servers, network infrastructure… You have to buy new devices for almost everything! So definitely start budgeting for that.

We recommend organizations start by securing their Root of Trust (signing their Root CA with a PQC algorithm) as early as possible and prioritize use cases where certs can have a long lifecycle, such as code signing. It goes without saying that organizations need a modern PKI if they don’t have one. SecureW2’s PKI services already support PQC algorithms, and so do many others. We also plan to have the world’s first PQC-compliant Cloud RADIUS service later this year, so networking certificate use cases are able to support PQC.

VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?

Arety: So annoying how this happens every few years… Zero Trust gets such a bad rep because it was beaten to death by marketers!

Feels like “AI-native” can range from a chatbot bolted onto a dashboard, something vibe-coded, to genuine product architecture. I think it’s just the intention behind the message. If a company builds a product that was genuinely designed to help secure AI, it should probably earn that label.

While our upcoming product was designed specifically for AI Security, it also leverages a lot of the engineering we’ve built over the years. But nearly every industry veteran agrees that PKI was always going to be involved in AI Security, since it’s been used to identify non-human identities for decades. So designing a product that allows organizations to use cryptography to better identify and control AI Agents felt like a no-brainer.

VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?

Arety: There have been a lot of changes to the threat landscape for our customers, but something that stands out is visibility into non-human identities. Historically, it was more around servers and IoT devices, but now it’s AI Agents and MCP servers.

We really want to help provide more visibility and control for all NHIs. Shadow IT, lack of process, agents going rogue… customers are concerned about it all. Our solution is designed to help bring better visibility and control over what’s going on, without preventing teams from embracing AI to move their business forward. 

VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?

Arety: A real inventory of every non-human identity (Servers, IoT devices, AI agents, etc.) in the environment, and what they are doing. Most organizations have a decent sense (aside from what’s going on with AI), but it’s usually decentralized, unorganized, and lacks sufficient processes.

VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?

Arety: AI Security. Even though it feels like we are talking about it every day in the news, organizations simply don’t spend enough money and time on it. Whether they are waiting for the dust to settle on industry-accepted security solutions, or they simply feel the need to cut corners as a business. It’s shocking how large the security gaps organizations have, and they are just crossing their fingers, hoping to survive.

##