Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

๐Ÿ‘ค Speaker
182 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So if you're considering fully agentic development, we should consider human in the loop, if it makes sense, when those risks necessitates it.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

AI generated meta tagging may be a thing.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So if someone's going back and looking at code later, they know who has the accountability for it, or AI had the accountability for it, or tie it back to the product.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

If a product owner is gonna be using AI,

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

make them be accountable for that code regardless of whether it's AR or not.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

The thing that I find interesting, though, in the AppSec or the ProductSec world is SBOM analysis and SCA and all that stuff becomes very important because we don't know where this code is being taken from or where it's being motivated and inspired from.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So, like, that can be very important.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But at the end of the day, the company's got to decide โ€“

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

what the risk tolerance is.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Some companies may choose to ban AI code from specific databases and specific intellectual property, or some companies may open it wide open because they see the business value in it.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But I think only the last thing to think about, and Mike Johnson and I talked about this last time on the show, is if it's code, the cool thing about it is you can also do security as code.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

We can do quality, risk, compliance, all that.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You can use AI against AI.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So why not have a trained AI security bot that's going to check all the AI work and use it against itself, right?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

There's a lot of potential value here.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Excellent.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Great job on today's show.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

This is always fun.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Andy, I appreciate the banter.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And let's do more of these fun what's worse.