Bombellii Ventures

By Odilo Schwade Junior , For Bombellii Ventures

From Securing People to Securing Everything

For most of the internet’s life, security was built around people. A human logs into a bank, sends a message, approves a purchase, and cryptography wraps that transaction so no one who intercepts it can read it. Two things sit underneath every one of those moments: the cryptography that protects the data, and the identity of whoever initiated it. For decades, that model held because the assumptions behind it held. The math was hard to break, and the identities were mostly human.

Both assumptions are now expiring at once, and the energy sector is where the consequences land hardest.

The cryptography that secures nearly everything online, RSA and the elliptic-curve math beside it, has a deadline. Quantum computing will eventually break it, which is why the U.S. has set a schedule to deprecate these algorithms by 2030 and disallow them by 2035. At the same time, identity has stopped being mostly human. Machines, services, and now autonomous AI agents authenticate constantly, holding their own keys and tokens, taking action with no person in the loop. The result is a system being asked to migrate its cryptographic foundation and absorb an explosion of non-human identity simultaneously, while continuing to run. How this transition is managed will determine whether the infrastructure we are electrifying can be trusted at scale, or whether we spend the 2030s re-securing everything we are building right now.

That transition is already underway. The question is no longer whether the foundations of digital trust will have to change. It’s whether we shape that change deliberately, or retrofit it later at far greater cost.

The Cost of Building on Expiring Foundations

The market is beginning to price this, Cybersecurity venture funding approached $150 billion in 2025, and the capital is concentrating, not spreading. A disproportionate share flowed into fewer than 100 deals, with AI security and identity as the clearest magnets. The federal government’s own civilian post-quantum migration has been estimated, roughly, at $7 billion and that figure covers only replacing the locks on systems that already exist.

More revealing than the scale is where the risk concentrates. The usual framing of the quantum threat is decryption: someone records encrypted traffic today and reads it once they have the machine to break it. But cryptography doesn’t only hide information: it proves identity. Signatures, certificates, and tokens are how a system knows a message is genuine. Break those, and an attacker doesn’t just read; they forge. They mint credentials indistinguishable from the real thing.

This matters because of how identity is structured. Recent peer-reviewed work on migrating agentic AI systems (Campbell, Computers, 2026) makes the point sharply: every identity splits into two layers that scale in opposite directions:

  • The credential layer: the keys and tokens each agent holds, numerous but cheap to replace.
  • The trust-anchor layer:the handful of signing roots that underwrite the entire fleet. Few in number, but each one carries a forgery blast radius equal to every identity beneath it.

Migrate millions of endpoints while leaving one issuing key vulnerable, and you’ve done nothing. The work that matters is concentrated in a small set of anchors, and most of them are owned not by you but by your cloud provider or certificate authority.

We are already seeing what happens when capable agents are pointed at these foundations. Anthropic reported that its Claude Mythos model, running on ordinary hardware rather than a quantum computer, found a genuinely novel weakness in a candidate post-quantum scheme that human experts had missed. It affected no production system, and the scheme was only a NIST candidate, but the direction is the signal. When the discovery of cryptographic weakness is itself accelerating, the comfortable distance to the deadline shrinks in ways a calendar can’t capture.

Where the Risk Concentrates

The exposure is not evenly distributed. It gathers wherever identities are embedded, long-lived, and rooted in shared anchors, which describes the digitized energy grid almost perfectly. Our research points to four places where this becomes acute, and investable:

  • Cryptographic Agility: The ability to change algorithms by configuration rather than re-architecture. Without it, every migration is a rebuild; with it, the next transition is routine. This is the foundation the other three depend on. This opportunity is worth almost $2B today and is expected to reach $12.4B by 2035 (~21% CAGR). Several startups and later-stage companies are already working in this field, including QIZ Security and QuSecure at the early stage, with PQShield and SandboxAQ scaled ahead.
  • Machine & Agent Identity: Issuing, rotating, and governing the non-human identities (services, devices, AI agents) that now vastly outnumber human users, and doing it at machine speed rather than human review speed. This is the largest and most crowded of the four, worth around $9.5B today and expected to reach $18.7B by 2030 (~12% CAGR). The field is well populated, from incumbents like CyberArk, SailPoint and the hyperscalers, to scaling players like Oasis, Aembit and Astrix, with agentic identity now the hottest seed category in security. The opening here is architectural, not greenfield.
  • Trust-Anchor Management: Discovering and migrating the small set of high-blast-radius signing roots first, including the vendor-owned ones an operator can influence but not command. The highest-leverage work in the entire transition. The broader enterprise-PKI market is worth around $9.5B and growing ~22% CAGR, served by incumbents like DigiCert, Keyfactor and Sectigo. But the industrial and OT slice is barely $340M and has almost no dedicated startups working on it. The absence is the opportunity.
  • Data & Identity Integrity for Critical Infrastructure: Proving that a grid controller’s commands or a meter’s telemetry are genuine and untampered, across an asset lifespan measured in decades rather than product cycles. There is no clean market category for this yet; it lives inside OT security, worth ~$15.4B today and expected to reach $33B by 2030 (~16.5% CAGR). A few companies come close, including Xage and Saiflow, but almost nothing at the seed stage frames data integrity as its own problem. This is the whitest space of the four.

Viewed separately, these look like distinct security markets, together they reveal one pattern: as infrastructure becomes more distributed and longer-lived, value shifts toward whatever lets independent, embedded, decades-old systems keep proving they can be trusted. Their simultaneous emergence is the signal.

Consider the smart meter going into a wall today, you do not replace it the way you replace a laptop every few years, it runs for decades, and it is being deployed right now on cryptography we already know will break. Multiply that by every inverter, substation controller, and grid endpoint across a continent, and the question becomes unavoidable: when the clock hits 2035, or whenever RSA actually falls, how do we re-secure critical infrastructure that is physically embedded, largely unreachable, and already in the ground? For a data center, you re-key a server. For the grid, you’re re-keying the physical world.

Conclusion

These markets favor focused, venture-backed companies for a specific reason: the problem is horizontal but the incumbents are vertical. Cloud providers, energy OEMs, and standards bodies each own a piece, but none is positioned to build the neutral trust layer that has to work across all of them. The companies that define this category won’t own the grid assets, they’ll build the trust infrastructure every asset depends on.

One of the clearest lessons from the energy transition is that the greatest leverage rarely comes from retrofitting mature systems. It comes from shaping the foundations of emerging ones before they harden into place. The migration of digital trust is exactly that kind of opening: a rare moment to build security into critical infrastructure from first principles, rather than bolting it on after the anchors have already broken.

At Bombellii Ventures, we invest at the intersection of AI and climate, and this is the convergence we look for: a hard deadline, an exploding population of machine and agent identities, and the digitized grid, all colliding at once. We’re backing the founders building the trust layer the energy transition will run on.

This article reflects a synthesis of academic literature, industry research, and original analysis. The sources below represent the primary materials informing the thesis.

Selected Sources

Post-Quantum Cryptography & Standards

  • Campbell, R. (2026). Post-Quantum Cryptography Migration for Agentic AI Systems. Computers, 15(7), 434.
  • NIST (2024). FIPS 203 / 204 / 205 — Post-Quantum Cryptography Standards.
  • NIST (2024). IR 8547 — Transition to Post-Quantum Cryptography Standards.
  • Mosca, M. (2018). Cybersecurity in an Era with Quantum Computers: Will We Be Ready? IEEE Security & Privacy.

AI Agents, Identity & Threat Landscape

  • Anthropic (2026). Discovering cryptographic weaknesses (Claude Mythos / HAWK research).
  • Cloud Security Alliance (2026). State of AI Agents and Agentic Identity.
  • NIST NCCoE (2025). Software and AI Agent Identity and Authorization (Concept Paper).

Critical Infrastructure & Energy

  • Zografopoulos, I., Hatziargyriou, N. D. & Konstantinou, C. (2023). Distributed Energy Resources Cybersecurity Outlook. IEEE Systems Journal.
  • U.S. DOE CESER. Post-Quantum Considerations for Energy Systems.

Leave a Reply

Your email address will not be published. Required fields are marked *