Key management
Cryptography almost never fails at the mathematics. It fails at the keys.
How a key is created, where it is stored, who can reach it, how it gets replaced and what happens when somebody leaves are the questions that decide whether any of the maths mattered. A perfectly implemented algorithm with the key sitting in a config file next to the data is protecting nothing. This is unglamorous work, which is a large part of why it gets skipped, and why it remains the most reliable place to find a real weakness.
Checked against the primary source.
