Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

πŸ‘€ Speaker
414 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And my vote is you have to put a point where, to your point, they prove something out and then it gets prioritized and traditionally scaled, developed, etc.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Right.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And somebody else takes it over.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Exactly.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I don't think it's going to replace the developers right away.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I've seen some cases where companies try to do that, but it's definitely an accelerator, right, of the, you know, I did 10 plus years of development back in the day and I use it right now and it definitely accelerates the basic work I do.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I think the interesting thing is like people hear AI and they automatically think it's special, but when you ask how are security leaders supposed to think about AI generated code, there's a lot of basic controls that should be applied, whether it's AI or human generated, right?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So like AI generated code could have the same weaknesses as human code.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So the middle ground may be the same CICD pipeline as human generated code.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

It should have code scanning, secret detection, software composition analysis,

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

like all this stuff that we should have anyhow.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But we do, and I love your point, Andy, need to consider where it's different.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So if you're considering fully agentic development, we should consider human in the loop, if it makes sense, when those risks necessitates it.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

AI generated meta tagging may be a thing.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So if someone's going back and looking at code later, they know who has the accountability for it, or AI had the accountability for it, or tie it back to the product.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

If a product owner is gonna be using AI,

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

make them be accountable for that code regardless of whether it's AR or not.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

The thing that I find interesting, though, in the AppSec or the ProductSec world is SBOM analysis and SCA and all that stuff becomes very important because we don't know where this code is being taken from or where it's being motivated and inspired from.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So, like, that can be very important.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But at the end of the day, the company's got to decide –