top of page


What Is an Endpoint, and Why Does It Matter for PQC Migration?
You likely interacted with several cryptographic endpoints before finishing your morning coffee. Your smartphone authenticated to Wi-Fi. Your laptop established a corporate VPN session. Your browser negotiated secure connections to email, cloud software, or online banking. Every single interaction relied on asymmetric cryptography to authenticate entities, perform key exchanges, verify digital signatures, or establish encrypted channels. Understanding where those cryptographi
Brian Couzens
Aug 233 min read
ย
ย
ย


Why 47-Day SSL Certificates Will Break Legacy Discovery Tools
The 47-day certificate era is coming - and your #discovery tools are about to break. โณ๐ Nearly all security and infrastructure teams know about Ballot SC-081v3 passed by the CA/Browser Forum: โข March 15, 2026: Validity capped at 200 days โข March 15, 2027: Ceiling drops to 100 days โข March 15, 2029: Mandatory 47-day max lifespan We talk often about auto-renewals, but we aren't talking enough about discovery. If your discovery strategy relies on active network port scans run m
Brian Couzens
Aug 182 min read
ย
ย
ย


CRYPTOANALYSIS: LET ME EXPLAIN THIS FFS
The sensational headlines surrounding Anthropicโs AI work on HAWK reveal a fundamental misunderstanding of how global cybersecurity actually operates: cryptanalysis is not a panic event; it is the continuous quality-control engine of the digital world. The framing that "AI broke post-quantum security and everything is collapsing" is pure noise. Here is the reality. 1. This Is an Ongoing Discipline Run by Dedicated Teams Cryptanalysis isn't something that happens once in a blu
Brian Couzens
Aug 12 min read
ย
ย
ย


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
Jul 124 min read
ย
ย
ย


CBOM: The Difference Between Discovery and Intelligence
The Missing Discipline The post-quantum conversation has a numbers problem. Vendors love to say they have found millions of cryptographic assets. That sounds serious. It sounds comprehensive. It sounds like the sort of number a board should pay attention to. But in most environments, that number is doing a lot of rhetorical work. What organisations usually have are millions of cryptographic instances. The same library. The same certificate. The same key store. The same implem
Brian Couzens
Jul 85 min read
ย
ย
ย


CBOM - The Real Story
๐๐๐ ๐๐ข๐ฌ๐๐จ๐ฏ๐๐ซ๐ฒ ๐๐ง๐ ๐ซ๐๐ฆ๐๐๐ข๐๐ญ๐ข๐จ๐ง ๐ฏ๐๐ง๐๐จ๐ซ๐ฌ ๐ฅ๐จ๐ฏ๐ ๐ญ๐๐ฅ๐ฅ๐ข๐ง๐ ๐จ๐ซ๐ ๐๐ง๐ข๐ฌ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ญ๐ก๐๐ฒ ๐ก๐๐ฏ๐ "๐ฆ๐ข๐ฅ๐ฅ๐ข๐จ๐ง๐ฌ ๐จ๐ ๐๐ซ๐ฒ๐ฉ๐ญ๐จ๐ ๐ซ๐๐ฉ๐ก๐ข๐ ๐๐ฌ๐ฌ๐๐ญ๐ฌ." That sounds impressive. In reality, it frequently conflates cryptographic #instances with unique cryptographic #dependencies. There is a fundamental difference. The same cryptographic library, certificate, key store, or implementation can appear thousands of times across ser
Brian Couzens
Jul 82 min read
ย
ย
ย


๐๐๐ฉ๐ฅ๐จ๐ฒ๐ฆ๐๐ง๐ญ ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐๐๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ. ๐๐ฅ๐ข๐ฆ๐ข๐ง๐๐ญ๐ข๐จ๐ง ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ ๐ฉ๐ซ๐จ๐ ๐ซ๐๐ฌ๐ฌ.
This week I read the best description of how to measure success against quantum risk. It comes from a recent Department of War (DoW) strategy document, and it is a breath of fresh air. ๐ ๐ช๐ฎ๐จ๐ญ๐: "Quantum resistance is not achieved when PQC is rolled out, but when quantum-vulnerable solutions are deprecated." Let's dissect what that means because it cuts straight through the marketing theatre dominating cybersecurity right now. ๐๐๐๐ข๐ง๐:"Quantum-Vulnerable" Any algor
Brian Couzens
Jun 252 min read
ย
ย
ย
bottom of page
