top of page

CBOM - The Real Story

  • Writer: Brian Couzens
    Brian Couzens
  • Jul 8
  • 2 min read

𝐏𝐐𝐂 𝐝𝐢𝐬𝐜𝐨𝐯𝐞𝐫𝐲 𝐚𝐧𝐝 𝐫𝐞𝐦𝐞𝐝𝐢𝐚𝐭𝐢𝐨𝐧 𝐯𝐞𝐧𝐝𝐨𝐫𝐬 𝐥𝐨𝐯𝐞 𝐭𝐞𝐥𝐥𝐢𝐧𝐠 𝐨𝐫𝐠𝐚𝐧𝐢𝐬𝐚𝐭𝐢𝐨𝐧𝐬 𝐭𝐡𝐞𝐲 𝐡𝐚𝐯𝐞 "𝐦𝐢𝐥𝐥𝐢𝐨𝐧𝐬 𝐨𝐟 𝐜𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐚𝐬𝐬𝐞𝐭𝐬."


That sounds impressive.


In reality, it frequently conflates cryptographic #instances with unique cryptographic #dependencies.


There is a fundamental difference.


The same cryptographic library, certificate, key store, or implementation can appear thousands of times across servers, containers, virtual machines, firmware, applications, and cloud workloads. Every deployment is counted separately, even though they may all originate from the same cryptographic implementation.


That is not intelligence.


That is noise.


The real question is far more useful:


𝐇𝐨𝐰 𝐦𝐚𝐧𝐲 𝐮𝐧𝐢𝐪𝐮𝐞 𝐜𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐝𝐞𝐩𝐞𝐧𝐝𝐞𝐧𝐜𝐢𝐞𝐬 𝐝𝐨 𝐰𝐞 𝐚𝐜𝐭𝐮𝐚𝐥𝐥𝐲 𝐡𝐚𝐯𝐞?


That is where a Cryptographic Bill of Materials (CBOM) changes the conversation.


But only if it is done properly.


A CBOM should not measure how much cryptography you have.


It should reveal how little is actually unique.


Its purpose is to deduplicate repeated observations and expose the algorithms, libraries, certificates, key stores, and cryptographic implementations that genuinely require governance and migration decisions.


An organisation may observe five million cryptographic instances.


After deduplication, those five million observations may collapse into only a few hundred unique cryptographic dependencies that actually require engineering decisions.


That distinction changes everything.


Budgets become more accurate.


Migration planning becomes more realistic.


Engineering effort becomes measurable.


Board reporting becomes meaningful.


𝐖𝐢𝐭𝐡𝐨𝐮𝐭 𝐝𝐞𝐝𝐮𝐩𝐥𝐢𝐜𝐚𝐭𝐢𝐨𝐧, 𝐲𝐨𝐮 𝐚𝐫𝐞 𝐧𝐨𝐭 𝐦𝐚𝐧𝐚𝐠𝐢𝐧𝐠 𝐜𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐲.


You are managing vanity metrics.


Boards should stop asking, "How many assets did the tool find?"


They should ask, "How many unique cryptographic dependencies do we actually need to remediate?"


Because you do not migrate five million assets.


You migrate the few hundred unique cryptographic implementations that happen to be deployed five million times.


𝐃𝐢𝐬𝐜𝐨𝐯𝐞𝐫𝐲 𝐟𝐢𝐧𝐝𝐬 𝐞𝐯𝐞𝐫𝐲𝐭𝐡𝐢𝐧𝐠.


Deduplication tells you what actually matters.


Shortly I will be publishing a follow-up explaining how CBOM deduplication works in practice, because this is where many organisations are still measuring volume instead of understanding risk.



 
 
 

Comments


bottom of page