The world of coding is undergoing a fascinating transformation, and it's not just the domain of tech experts anymore. With the rise of AI, code-writing capabilities are now within everyone's reach, and this has security leaders in a tizzy. In this article, we'll delve into the challenges and strategies employed by these leaders as they navigate the new reality of 'vibe coding.'
The Rise of Vibe Coding
'Vibe coding' is a term that has emerged to describe the phenomenon of employees using AI to build applications and automations without formal security reviews. It's a trend that's gaining momentum, with even Fortune 500 companies actively encouraging it in their job specs. The result? A potential code sprawl crisis, with 380,000 publicly accessible assets found on various platforms, many containing sensitive corporate information.
The Challenge for Security Leaders
Security and IT teams are facing a unique challenge. They must maintain visibility and control over code development, but with AI, the traditional governance playbook no longer suffices. As one leader put it, "Employees who want to get their job done are the most persistent and successful APTs." They'll find a way to use the latest tools, even if it means taking screenshots and transferring data to personal accounts.
Strategies for Taming the Wild Code
Starting with Data Classification
The foundation for any sophisticated control is accurate data categorization. As Mario Villatoro, CISO at Jamf, explains, "Having the data correctly tagged is critical." Without this, any downstream controls are built on shaky ground.
Becoming the Hub, Not the Gatekeeper
Matt Muller, Director of Security Operations at Datadog, takes an interesting approach. His team provides the tools and encourages feedback, positioning themselves as enablers rather than police. "Make Claude skills available in an internal marketplace, and ask for feedback to improve," he suggests. This way, the governed path is more appealing, and visibility is maintained.
Building a Use-Case Registry
Indu Sajeev, former CISO at ASOS, treats AI agents like infrastructure assets. By creating a use-case registry, accountability is traceable, and the underlying data problems are surfaced. "You need a mature data infrastructure for any AI function to work," Sajeev emphasizes.
Investing in Enablement
Villatoro's approach at Jamf is centered on enablement. By providing employees with the right tools, training, and policies, they're less likely to seek out their own solutions, which often lead to problems.
The Future of Code Sprawl
The security leaders who succeed in taming code sprawl won't be the ones who tried to stop employees from building. They'll be the ones who made the governed path the most appealing and visible. Wild code is here to stay, and the focus should be on tracking, securing, and monitoring it effectively.
What makes this particularly fascinating is the shift in mindset required. Security leaders must embrace a new role as enablers and facilitators, rather than gatekeepers. It's a delicate balance, and one that will shape the future of coding and security practices.