Automated Cryptographic Inventory Tools Fall Short, Consultant Warns
Automated tools for generating cryptographic bills of materials (CBOMs) can create a false sense of security, as legacy and operational systems often remain hidden from automated scans, according to consultant Matous Vambersky.

Organizations pursuing cryptographic resilience, particularly in the context of post-quantum migration, may be misled by automated tools designed to generate cryptographic bills of materials (CBOMs). Matous Vambersky, a consultant specializing in post-quantum cryptography, warns that these automated solutions often create a "false feeling of safety" by providing an incomplete picture of an organization's cryptographic assets.
The primary challenge lies in the inherent limitations of automated scanning technologies. Legacy systems, operational technology (OT) environments, and custom-built software implementations frequently operate outside the scope of typical automated discovery tools. This creates significant blind spots, meaning that even a comprehensive automated scan may fail to identify all cryptographic components within an organization's infrastructure.
When organizations rely solely on these incomplete inventories to build migration road maps, they risk underestimating the scope and complexity of their transition efforts. Vambersky highlights that teams may discover mid-migration that entire critical systems were overlooked, leading to delays, increased costs, and potential security gaps. A proactive risk management approach is therefore essential, acknowledging and preparing for these known blind spots.
"The challenge isn't generating some inventory document. The challenge is the continuous discovery, the ability to maintain the cryptographic inventory up to date," Vambersky stated. He emphasizes that while automation provides the necessary scale for inventory management, it must be augmented with expert human insight to accurately assess migration priorities and risks.
Regulations such as the EU's Digital Operational Resilience Act (DORA) and various U.S. executive orders are increasingly driving the adoption of CBOMs. These mandates underscore the growing importance of understanding and managing cryptographic dependencies, especially as the threat landscape evolves with the advent of quantum computing.
Vambersky also touched upon practical aspects of CBOM implementation, including the benefits of standardized formats for merging disparate inventories and prioritizing which systems to automate first. External-facing assets and data in transit are often recommended starting points due to their higher exposure and criticality.
With over 15 years of experience in cybersecurity and technology consulting, Vambersky's work focuses on preparing organizations for emerging cryptographic risks and facilitating transitions to quantum-resistant security. His advisory roles have involved translating complex technical risks into actionable security strategies, drawing on his experience at firms like Accenture and PwC.
The core message is clear: organizations must move beyond a reliance on purely automated solutions for cryptographic inventory. Achieving true cryptographic resilience requires a hybrid approach that combines the scalability of automation with the critical judgment and deep understanding of human experts to ensure all cryptographic assets are identified, managed, and secured.