Back to episodes

What 30 years inside critical infrastructure teaches you about security | Karl Holmqvist, CEO of Lastwall

In this episode of Tank Talks, host Matt Cohen sits down with Karl Holmqvist, co-founder and CEO of Lastwall, a FedRAMP-certified identity security platform built for the highest-risk use cases. Karl has been deep in cybersecurity since the 1990s, with early experience building critical infrastructure, including Canada’s first high-speed mobile data network, and a recent focus on identity security at the forefront of making systems quantum-resilient. In this conversation, they explore the evolution of Lastwall from early behavioral biometrics and cognitive signals to today’s hybrid post-quantum cryptography.

Karl Holmqvist

Karl Holmqvist

Karl Holmqvist background

  • Karl Holmqvist is co-founder and CEO of Lastwall, an identity-as-a-service platform built on Zero Trust principles and public key infrastructure, hardened with post-quantum cryptographic resilience.
  • Lastwall serves the U.S. Department of Defense and a growing number of civilian government agencies and critical infrastructure operators.
  • Karl has been a cybersecurity enthusiast since the 1990s, with a background spanning telecommunications infrastructure (including building one of Canada’s first high-speed mobile data networks), renewable energy infrastructure across the Middle East, North Africa, and Southern Europe, and international investing.
  • He studied at Mount Allison University and is based in Vancouver, BC.

Episode Overview

  • In this episode of Tank Talks, host Matt Cohen sits down with Karl Holmqvist, co-founder and CEO of Lastwall, a FedRAMP-certified identity security platform built for the highest-risk use cases.
  • Karl has been deep in cybersecurity since the 1990s, with early experience building critical infrastructure, including Canada’s first high-speed mobile data network, and a recent focus on identity security at the forefront of making systems quantum-resilient.
  • In this conversation, they explore the evolution of Lastwall from early behavioral biometrics and cognitive signals to today’s hybrid post-quantum cryptography.
  • They also dig into the journey to FedRAMP approval and what it really takes to sell to the hardest customers on the planet, from the DOD’s Innovation Unit to critical infrastructure operators globally.
  • Karl shares his view on why hybrid cryptography is the only responsible path right now, the magnified risk of the AI agent era, and his strongly held belief that when it comes to quantum resiliency, you’re either going to be too early or too late.
  • Whether you’re a founder navigating a path into regulated markets, a security leader thinking about the agentic AI era, or just curious about what it takes to protect critical infrastructure, Karl delivers a grounded, technical, and occasionally unsettling look at where identity security is headed.

Key Topics

  1. Growing Up in Dubai During the Gulf War

    Karl’s childhood in Dubai as an expat during the Gulf War

    Visiting the USS Nimitz and seeing 5,000 people living on an aircraft carrier

    How jets overhead and allied ships shaped his early view of technology and defense

    The BBS era and the thrill of finding information that wasn’t available to everyone

  2. From Mobile Data Skepticism to Building Canada’s First High-Speed Network

    Why people thought mobile internet was “the stupidest thing” in the early 2000s

    Building a data-only carrier when no one believed you’d want internet everywhere

    The Nokia Communicator as his favorite tech gadget and early glimpse of mobile data

    Connecting critical infrastructure and discovering default credentials left wide open

  3. The Wake-Up Call: Wastewater Plants and Unsecured Dams

    Finding a wastewater flow control valve dangling on the internet with admin/admin credentials

    The “air-gapped” power plant where an engineer plugged his BlackBerry in to charge

    How Shodan and friends revealed dams and power facilities publicly accessible

    The founding of Lastwall: “Hackers will be everywhere. We’ve got to do something.”

  4. From Behavioral Biometrics to Quantum Resilience

    Why 85% of hacks still use valid stolen credentials, the same as the 1990s

    Early experiments with keyboard dynamics, mouse movements, and cognitive biometrics

    Tracking Peter Shor’s algorithm since university and the IBM factorization of 15 in 2001

    The 2017 to 2018 decision to embed quantum resiliency natively into Lastwall

  5. Selling to the Pentagon: DIU and the “Hard Mode First” Strategy

    Landing the first major deployment with the U.S. Department of Defense Innovation Unit

    How DIU pioneered procurement that matches innovation cycles, months instead of years

    The advice from Carbon Black founders: build the regulated stack first

    Why defense tech used to shut VC doors and how times have changed

  6. FedRAMP, Canada, and the Case for Harmonization

    FedRAMP as the gold standard: do compliance once, reuse everywhere

    The Canadian challenge: every agency doing its own security review

    Why Canada should base its program on NIST 800 and harmonize with the U.S.

    The reality of the integrated North American power grid and shared defense

  7. AI Agents and the Blast Radius of Credential Theft

    Why 50 to 100 agents per human in 2 to 3 years will magnify damage exponentially

    The OpenClaw lesson: agents do what agents do, not what you expect

    The “YOLO” approach to AI deployment and why enterprises aren’t calling enough

    Advice for founders: sandbox first, don’t connect your whole drive, go slowly

  8. The $60M Series A Extension and the Path Forward

    Raising BDC Capital’s Strong North Fund led by Major General (Ret.) Peter Dawe

    The milestone of FedRAMP certification and opening the floodgates to U.S. agencies

    Deploying in disconnected environments: field containers for critical infrastructure

    Why defense is ultimately about protecting the economy