Encryption & Key Management,
Next-Generation Technologies & Secure Development,
Security Operations
Cryptography Consultant Matous Vambersky on the Shortcomings of Automated Tools
Organizations frequently harbor the belief that they possess comprehensive visibility into their cryptographic assets. However, upon automating the discovery process, they are often faced with the harsh reality of significant gaps in their inventory. According to Matous Vambersky, a consultant specializing in post-quantum cryptography, the discovery of missing assets can pose substantial risks to cryptographic bill of materials (CBOM) initiatives. Without a complete inventory, organizations are susceptible to misconceptions regarding their level of security coverage, leading to insufficient protection against potential vulnerabilities.
Vambersky points out that many legacy systems, operational technology, and bespoke implementations typically remain outside the scope of automated scanning tools, creating critical blind spots that automated solutions alone cannot resolve. This results in teams construing an incomplete inventory as a comprehensive migration roadmap, ultimately underestimating the challenges they face ahead. A common pitfall occurs when teams realize mid-migration that entire systems have been inadvertently excluded from their assessments. “The biggest risk is this false feeling of safety, this false feeling of visibility,” Vambersky affirms. He emphasizes the importance of a proactive risk management strategy and highlights that by identifying blind spots, organizations can adequately prepare and safeguard their operations.
“The challenge isn’t merely to produce an inventory document. The true challenge is achieving continuous discovery and maintaining an up-to-date cryptographic inventory,” Vambersky elaborates. The consultant acknowledges the value of automation in generating large-scale inventories but insists that expert insights are crucial for determining which elements of the inventory should indeed undergo migration. This is a vital consideration as it combines the efficiency of automation with the strategic reasoning that comes from human expertise.
In a video interview conducted with ISMG, Matous Vambersky delves deeper into several compelling topics. He elucidates on the advantages of adopting standardized formats to facilitate the merging of cryptographic inventories. This standardization is particularly beneficial for organizations aiming to streamline their security protocols across various platforms. Additionally, he addresses the growing pressure from evolving regulations, including the Digital Operational Resilience Act (DORA) and executive orders from the U.S. government, which are progressively mandating the adoption of CBOMs across various sectors.
When discussing which systems should be automated first, Vambersky advises prioritizing external-facing assets and data in transit. These areas typically pose greater risks and are prime candidates for enhanced cryptographic measures. By focusing on these critical components, organizations can bolster their defenses at a foundational level.
With over 15 years of experience in cybersecurity and technology consulting, Matous Vambersky is well-equipped to navigate the complexities of modern security landscapes. His specialization in post-quantum cryptography, crypto-agility, and cybersecurity strategy enables him to provide organizations with insights that prepare them for emerging cryptographic threats. Vambersky’s previous roles at esteemed firms such as Accenture and PwC have further refined his expertise, allowing him to effectively translate intricate technical risks into actionable security strategies tailored for the modern digital environment.
As organizations continue to grapple with the challenges posed by rapid technological advancements and evolving threats, the insights shared by Vambersky serve as crucial guidance for those seeking to strengthen their cryptographic practices. The necessity for a robust understanding of both automated tools and human insight is more vital than ever as organizations strive to achieve a secure, resilient infrastructure.

