MENGENAI EPISOD INI
What happens when a cybersecurity CEO spends 10 hours vibe coding a fully functional SaaS app…using company IP?
He crashes a meeting to find out.
In this special edition of Simplifying Cyber, Reveal Risk CEO Aaron Pritz gatecrashes a scheduled session with Chris Adickes, Todd Wilkinson, and Michael Milroy to demo a third-party risk management platform he built using AI tools like Claude Code.
The twist? He did it the same way many executives and employees are doing it right now — fast, iterative, and dangerously close to sensitive data.
The team dives into the real question companies are facing:
How do you enable innovation without undermining your cybersecurity posture?
They unpack:
- Why blocking AI tools outright doesn’t work (remember Dropbox?)
- The identity and credential risks most teams aren’t thinking about
- What “reasonable controls” actually look like in the age of vibe coding
- Why security teams need to support experimentation — not just police it
- And how life (and AI) will “find a way” whether you’re ready or not
If your CEO is experimenting with AI… or your finance team just connected a database to a chatbot… this episode is your playbook for getting ahead of the freight train.
Innovation is fun. FOMO is real. Risk is optional — if you’re intentional.
Listen in and learn how to keep vibe coding from becoming breach coding.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Tunjukkan NOTA 🔗
TRANSKRIP 🔗
00:00:09.439 --> 00:00:11.759
Thanks for tuning in to Simplifying Cyber.
00:00:11.839 --> 00:00:14.560
I'm Aaron Pritz and Cody Rivers is not here today.
00:00:14.640 --> 00:00:21.280
He's visiting the mouse and emptying his wallet to the Disney Lords for the week and PTO and much deserved.
00:00:21.359 --> 00:00:26.879
I pulled in Bronwyn here, who's on the screen and listening to you online, for a little special challenge.
00:00:27.039 --> 00:00:41.840
I ended up vibe coding a application that does a pretty good swath of one of our full services and very strategically used some intellectual property that was safe, ours, not any of our customers or whatnot, and uh built out this entire application.
00:00:41.920 --> 00:01:03.840
And I'm about to drop into a meeting with Chris Addicts, our CISO and a managing director, Todd Wilkinson, who leads a lot of our technical services and a lot of our AI projects, and Michael Milroy, who was the first reveal risk vibe coder, and uh I caught the FOMO seeing what he was doing, and that one thing led to another, and that led to my little special project here.
00:01:04.000 --> 00:01:06.640
So the goal, they don't know what is about to happen.
00:01:06.719 --> 00:01:11.920
I've pounded their calendar in one of their standing one-on-ones between two of them and added in two more people.
00:01:12.079 --> 00:01:15.519
They saw the Riverside recording link and now they're fully freaking out.
00:01:15.680 --> 00:01:17.040
But we'll see how we manage that.
00:01:17.120 --> 00:01:23.439
And I'm gonna do a quick demo of the application that we built, or I built, really Claude, Cloud Code built.
00:01:23.519 --> 00:01:26.560
Uh, and I I'll take all the credit, but I actually tried that.
00:01:26.719 --> 00:01:29.840
I said, What code, what language did we develop this in?
00:01:29.920 --> 00:01:34.959
And Cloud Code was like, you d uh to be clear, you didn't develop any of this code.
00:01:35.120 --> 00:01:36.159
I did it all.
00:01:36.319 --> 00:01:38.239
But here's the languages that I used.
00:01:38.319 --> 00:01:40.480
It was very, it was very pompous.
00:01:40.799 --> 00:01:44.239
Oh, anyway, that aside, we're gonna drop into this meeting.
00:01:44.480 --> 00:01:46.799
It's gonna be maybe a little awkward at fat at first.
00:01:47.040 --> 00:02:11.360
We're gonna talk about this and then we're gonna shift the conversation to how CISOs, cyber leaders, IT leaders could and should be handling this, whether they want to acknowledge that the stuff is happening or they blocked it and they think that it's not happening, it is, um, or they're really leaning in to try to figure out how to enable innovation and put the right controls in place to make sure that the progress doesn't get shoots and laddered back to the beginning of the board.
00:02:11.520 --> 00:02:13.840
Without further ado, here we go.
00:02:16.240 --> 00:02:16.800
All right.
00:02:16.960 --> 00:02:19.360
So this is a little bit of a simulation.
00:02:19.599 --> 00:02:26.879
You guys, so Chris, you are in the simulation as well as are in for real life, the CISO of our company.
00:02:27.120 --> 00:02:30.960
Michael, you're doing a lot of tech development, have played played with AI.
00:02:31.199 --> 00:02:40.479
Todd, you're AI product advisor, and you're getting a lot of client questions about AI, which all of that is absolutely true.
00:02:40.879 --> 00:03:00.000
So, what I want to do is um Todd and I were in a conversation with a customer last week, and he was talking about um the CEO is just like hardcore into vibe coding, and he's having to give data access to them to kind of try to contain it, try to enable him to do what he's doing.
00:03:00.080 --> 00:03:01.280
What he's doing is really cool.
00:03:01.520 --> 00:03:14.879
But he's trying to kind of figure out how do you enable the innovation, but also control the just the out-of-control, like what if he uses client data, what if he pinholes access to things that he shouldn't.
00:03:15.039 --> 00:03:17.360
So it's a new landscape, new control stuff.
00:03:17.439 --> 00:03:23.520
So, what I'm gonna do here is I I emulated what he's doing in our own environment.
00:03:23.759 --> 00:03:50.639
And I'm gonna show, I'm gonna do a quick demo of what I did because it's interesting, it's cool, but I also want to have a little bit of an impromptu discussion on what our clients should be doing to not necessarily prevent this, but get our arms around the fact that AI is leapfrogging on a weekly or monthly basis, and executives and employees are all out there trying stuff, and cyber many in many cases is not at the table.
00:03:50.960 --> 00:03:51.520
All right.
00:03:51.840 --> 00:04:02.560
So, and I'm gonna be a little provocative here for I I did do this in a very controlled fashion, but I'm gonna I'm gonna I'm gonna I'm gonna over overplay what I did just for effect.
00:04:03.599 --> 00:04:11.520
So I took all of our third-party risk management intellectual property and I uploaded it into Claude Code.
00:04:12.080 --> 00:04:17.839
From Claude Code, I third-party risk is a tough topic.
00:04:18.000 --> 00:04:21.279
There's GRC tools that we've tried and had really painful.
00:04:22.000 --> 00:04:48.959
So within the the confines of a few hours over the weekend and then a couple nights this weekend, I iterated probably total cumulative of 10 hours to take all of our IP and develop our entire process in a fully functioning SaaS app that's running locally right now, but could easily be re-platformed and deployed in the cloud or on Azure or whatnot.
00:04:49.199 --> 00:04:54.560
So just to kind of talk about the tool for a little bit and kind of show how it aligns to our process.
00:04:54.800 --> 00:04:58.639
Right now we're looking at the analyst queue, kind of showing the actions.
00:04:58.800 --> 00:05:13.600
We've got the overall platform, some really cool metrics of high-tier, open findings, average daily cycle time, all coming from Michael's metrics packages that he's put in place before.
00:05:13.839 --> 00:05:17.439
Some really cool summary, like risk by domains.
00:05:17.600 --> 00:05:23.279
You know, general, obviously, that's uh bundling things together, but data protection, access control.
00:05:24.079 --> 00:05:29.120
From a risk summary standpoint, I can drill a little bit more detail.
00:05:29.279 --> 00:05:33.519
I can see that we're only remediating 12% of our findings.
00:05:33.759 --> 00:05:50.800
Um, and I can see more specific things on risk domain and get into details with reveal risk recommendations, which we could tune on the bigger themes so we could actually action enterprise level decisions based upon the themes we're getting out of third party.
00:05:51.680 --> 00:05:56.639
With our process, obviously, tiering things by t-shirt size is important.
00:05:57.759 --> 00:06:18.240
And also we were able to add AI risk analysis on the vendors itself, so you could kind of get an early look before you even get into the assessment itself, and then confirm from an analyst standpoint, you know, do we believe that that would change, you know, that individual risk and override, describe things like that.
00:06:19.199 --> 00:06:22.480
And obviously, we can we can see the the list of vendors.
00:06:22.560 --> 00:06:24.959
This is all hypothetical data.
00:06:25.279 --> 00:06:29.040
You can see here we have the addicts art bar and grill.
00:06:30.240 --> 00:06:33.519
And I only chose art because there's an addicts art out there.
00:06:33.600 --> 00:06:36.160
I wanted a real URL that I could I could see in.
00:06:36.639 --> 00:06:37.839
Yeah, exactly.
00:06:38.079 --> 00:06:55.360
Um, and then we can see we've sent a you know an assessment to them, a rapid triage, uh, so we can get back to that back and then be able to have analyst analyst analysis on the back end, as well as the risk scores and then specific contacts that would come up.
00:06:55.680 --> 00:06:59.120
This is where I onboarded that vendor before this call.
00:06:59.360 --> 00:07:01.600
And then questionnaires, obviously, we can load in.
00:07:01.680 --> 00:07:12.800
I loaded in a few samples of questionnaires we have from our frameworks library, you know, the pharma assessment, the rapid triage, and then this was an evidence checklist.
00:07:13.040 --> 00:07:26.959
Interestingly enough, I also took the Natera redacted data to do the additional enhanced due diligence to put additional actions that we could put in place for specific vendors.
00:07:27.839 --> 00:07:31.279
And then monitoring-wise, obviously you can see some alerts.
00:07:31.600 --> 00:07:35.839
It was able to let me go down here, settings.
00:07:36.079 --> 00:07:58.319
Oh yeah, DDQs and answers library and a full AI capability to match questions to answers banks, which I think we've struggled with with some of the external tools, but at least some basic capability to log an incoming DDQ, drop in the questionnaire, and then have it match to the current uh answer set that we have.
00:07:58.639 --> 00:08:12.560
And then obviously risk register, being able to roll all those findings up, get some specific reports that you can push to um Excel or uh uh I guess PDF PowerPoint.
00:08:12.800 --> 00:08:15.040
Um and then also custom framework building.
00:08:15.120 --> 00:08:21.920
If we aren't gonna use a standard assessment, we can you know create a custom framework itself to be able to use that for that.
00:08:22.639 --> 00:08:32.320
Anyway, that's the quick demo, not being an SE SE, just to kind of say, you know, I haven't touched code in 20, 20 some years.
00:08:33.600 --> 00:08:48.000
It was able to fully build out the database schema, I think over 10,000 lines of code to support it and do it all based upon business requirements and vibe coding and specific accelerators that we could load in.
00:08:48.320 --> 00:08:49.759
So pause there.
00:08:49.919 --> 00:08:59.600
And by the way, I very carefully chose specific accelerators that were out of date and not that recent, andor not something that every other company would do.
00:08:59.840 --> 00:09:08.000
But let's assume I'm not a cybersecurity CEO and I don't necessarily understand the risks of putting this stuff in there.
00:09:08.080 --> 00:09:11.039
Let's assume I dumped our entire SharePoint library in.
00:09:11.840 --> 00:09:14.879
So let's start with Chris first.
00:09:15.039 --> 00:09:27.679
As the CISO, what controls would you want to put in place if you knew I and three other people within their jobs were going to be doing this without a lot of IT and our current acceptable use policy?
00:09:27.759 --> 00:09:31.039
Obviously, it doesn't contemplate something uh this advanced.
00:09:31.840 --> 00:09:32.720
What's your thoughts?
00:09:32.879 --> 00:09:35.519
And really our clients are facing this as well.
00:09:35.679 --> 00:09:42.320
Like, how do we help them get in front of kind of some of the this freight train that's moving, whether we're on the train or not?
00:09:42.639 --> 00:09:42.879
Okay.
00:09:43.039 --> 00:09:43.600
Holy moly.
00:09:43.759 --> 00:09:44.639
All right, so so here.
00:09:44.879 --> 00:09:46.480
So let me let me take a second.
00:09:46.639 --> 00:09:56.000
Um I and this this this is aimed at us in general, everyone using AI, like as cyber practitioners.
00:09:56.320 --> 00:10:10.080
I'm not quite sure why this is so confusing for everyone to kind of get their arms around when we think about we've done this over and over again with technologies that come have come up, right?
00:10:10.559 --> 00:10:14.240
Internet, cloud, you name it, over and over again.
00:10:14.960 --> 00:10:21.840
And this one is obviously a little different, that it's very fast-paced, it's moving way faster than we can all imagine, and leaps and bounds, like you said.
00:10:22.399 --> 00:10:25.440
But the same concepts apply that we've done for 30 years.
00:10:25.919 --> 00:10:32.559
It's make sure that we're taking the things that we know, the things that we've done, the risks that we've managed, and apply them to a new technology.
00:10:32.720 --> 00:10:33.759
So, how to do this?
00:10:33.919 --> 00:10:37.279
The answer is yeah, CEO, go to town, have fun.
00:10:37.519 --> 00:10:40.080
However, what would we do on any other platform?
00:10:40.320 --> 00:10:49.759
We'd say, make sure you have your third-party risk assessment done, make sure the data is being properly controlled, make sure the vulnerabilities are being managed, make sure you're managing access in an environment, right?
00:10:50.000 --> 00:10:55.279
And I know these aren't a CEO waking up in the morning going, I'm gonna go do this, but that's happened.
00:10:55.360 --> 00:11:01.039
That's happened with Dropbox and Box, the whole file sharing thing we went through many years ago that everybody was using.
00:11:01.120 --> 00:11:02.720
It took us a while to get our arms around.
00:11:02.879 --> 00:11:04.000
But ultimately, what do we do?
00:11:04.080 --> 00:11:12.080
We applied the same concepts in a different way, more advanced and more complicated as we as we continue to advance technologically.
00:11:12.320 --> 00:11:13.919
But I think the same thing here, guys.
00:11:14.000 --> 00:11:14.960
Like, how are we gonna do that?
00:11:15.039 --> 00:11:21.279
The answer is yes, go and do it with these controls and applying the controls that we've done over and over again.
00:11:21.840 --> 00:11:23.840
And how do you feel on blocking, right?
00:11:24.000 --> 00:11:30.080
Because like when I when I was on the corporate side a decade ago, cloud storage came out, we had some insider threat.
00:11:30.320 --> 00:11:38.879
The legal reaction was we'll block block it all, we'll we'll pinhole access to the stuff that are our approved tools, but then we saw the problem squishing around.
00:11:39.039 --> 00:11:45.039
People were going to home personal devices to get their work done in other ways or use their preferred, you know, cloud.
00:11:45.519 --> 00:11:45.679
Yeah.
00:11:46.159 --> 00:11:47.360
There has to be some control there.
00:11:47.440 --> 00:11:49.279
We can't go, well, we'll use what you want, right?
00:11:49.360 --> 00:11:50.480
Because there's a couple things.
00:11:50.559 --> 00:11:57.840
You're managing cyber risk, but then you're also managing the optics of risk or the culture of risk, right?
00:11:57.919 --> 00:12:05.360
Saying if a company takes a stance, go use anything you want, have fun, who's where does that where's the responsibility for that risk lie?
00:12:05.519 --> 00:12:06.320
The company, right?
00:12:06.559 --> 00:12:18.480
If you're sitting there going, well, here's our approved, you can't use these things, and something happens, that positions the company very differently in that risk conversation when opposing council is going, why did this happen, or how'd you let this happen?
00:12:18.639 --> 00:12:20.240
Well, we were like it was a free-for-all, right?
00:12:20.320 --> 00:12:20.480
No.
00:12:21.200 --> 00:12:24.960
That person violated the policy and the technical controls and ended up doing X.
00:12:25.600 --> 00:12:26.639
Different conversation, right?
00:12:27.120 --> 00:12:32.000
So I do think I do think there is the need for reasonable blocking.
00:12:32.399 --> 00:12:41.600
I do, however, like anything, you can't say don't use box or dropbox and not provide the employee base with something else, because that's silliness, because that's exactly what you said.
00:12:42.320 --> 00:12:43.840
People are just gonna go around and figure it out.
00:12:43.919 --> 00:12:46.799
I'm gonna use mega upload to share with my vendor, right?
00:12:47.039 --> 00:12:54.000
So ultimately, looking at this, it's you can't do this, but we're offering this, and it's just as viable as the other ones.
00:12:54.159 --> 00:13:03.840
And then over time, as we continue to advance in AI world, opening more and more capabilities and abilities, we get our ability to manage risk in the technology.
00:13:04.080 --> 00:13:04.399
Yeah.
00:13:04.720 --> 00:13:11.759
Michael, you've been a proponent of of vibe coding and product development and alignment of the process stuff.
00:13:12.000 --> 00:13:17.519
Obviously, you, similar to me, practitioner in cyber, know some of the precautions and dangers to avoid.
00:13:17.679 --> 00:13:25.360
As you, as you were leaning into it and approaching it, like as a as a as a leader, you know, in the company, like what did you think about?
00:13:25.519 --> 00:13:31.759
How did you self-regulate maybe some of the things you could have did done but didn't want to, didn't think it was the right thing to do?
00:13:31.919 --> 00:13:36.639
What was your what was your thought pattern as you were exploring into this stuff?
00:13:37.039 --> 00:13:52.960
Yeah, so like when I did the like with Assessor kind of the the first round with it, um that was very, very heavily on taking taking what we have and building from scratch to uh to kind of mirror some of it and then expand.
00:13:53.200 --> 00:13:57.440
So I wasn't taking anything of ours and putting it into another tool.
00:13:57.519 --> 00:14:05.360
Uh I was pulling it up and saying, I like the outline, I like the structure, I want to use this as a foundation, but I'm building it on my own.
00:14:05.600 --> 00:14:12.480
Um to, you know, so it takes a few extra hours up front to kind of build that, but then all the additional functionality.
00:14:12.559 --> 00:14:19.360
And so kind of some of the more recent side projects, taking sanitizing all of those things like on my own.
00:14:19.600 --> 00:14:25.679
And then then I'm comfortable running those those documents and and things through through the platforms and stuff like that.
00:14:25.840 --> 00:14:33.600
But I mean, some of the key things I looked at is like from a security perspective, I know the one you just showed, you're running it locally.
00:14:33.679 --> 00:14:39.039
Um, however, if somebody got a hold of your device locally, is now local to them also.
00:14:39.200 --> 00:14:40.159
So there's one issue.
00:14:40.320 --> 00:14:49.120
The other thing is if if you were to take the next step and say, well, I'm already running it locally on my own, I'm gonna share it with the team, and you just go and post it somewhere else.
00:14:49.279 --> 00:14:53.279
Are you posting in a hosting place that is safe, secure, vetted?
00:14:53.519 --> 00:15:04.240
Have have you run any like uh security testing against it, not like full-blown pen tests, but have you done any security checks to see um kind of what the access control and stuff like that is?
00:15:04.320 --> 00:15:15.679
So those are those are things where I've kept it very much internal, sanitized at my own, or again, looked at it, built it from scratch, and then expanded upon with minimizing what I share with some of those tools.
00:15:15.919 --> 00:15:16.559
Yep.
00:15:17.440 --> 00:15:36.559
For people in marketing or ops outside of IT, outside of cyber that are jumping into this, how many without guidance, Chris, to your point, without without any kind of structure governance, uh, happy path, here's the job aid to do it the right way, how many people outside of IT and cyber do we think are thinking like Michael is?
00:15:37.519 --> 00:15:38.159
Not many.
00:15:38.320 --> 00:15:42.879
And I actually just saw three posts on LinkedIn with it yesterday alone.
00:15:43.120 --> 00:15:57.519
Two of them were legal firms where junior and senior attorneys are just dumping everything client documents, client meeting transcripts, everything, no sanitizing because no one told them that they couldn't.
00:15:57.679 --> 00:16:04.080
And to them, I'm saving 40 hours a week because I can dump it in there, and I've not been told I can't do it.
00:16:04.240 --> 00:16:05.759
So it's making my job easier.
00:16:05.919 --> 00:16:12.080
So literally three cases that I saw, I read them yesterday, but they all happened within the last two weeks.
00:16:12.320 --> 00:16:15.120
Um, so yeah, I would say not many.
00:16:15.519 --> 00:16:19.600
The thing about it is like a lot of us want to enable the technology.
00:16:19.679 --> 00:16:26.399
There are CISOs that don't, but trying, you know, trying to hold it back or say, hey, we're not gonna get into this yet, it will find a way.
00:16:26.799 --> 00:16:30.080
The Jurassic Park quote, like life, life will find a way.
00:16:30.159 --> 00:16:31.200
And it's the same thing here.
00:16:31.279 --> 00:16:33.840
People are going to find a way to innovate.
00:16:34.000 --> 00:16:36.799
If you're telling them they can't, they will they will find that way.
00:16:37.120 --> 00:16:40.879
Todd, from an identity standpoint, you we were chatting in the office earlier.
00:16:41.039 --> 00:16:48.960
Like this kind of expands the aperture of identity and managing, you know, different forms of bots and agents and things like that.
00:16:49.120 --> 00:16:53.120
Like, how do you think companies are faring in that early battle?
00:16:53.600 --> 00:16:55.919
I'm not sure the identity teams are truly ready for this.
00:16:56.000 --> 00:17:04.480
And if you if you work through how some of these code, you know, these these vibe coding tools are working and how they're setting it up, one of the first things you need is access to that data.
00:17:04.640 --> 00:17:08.960
And it's easy to start with give me the documents and just let me throw it in here and let me read it in.
00:17:09.039 --> 00:17:10.559
That's one of the first places you start.
00:17:10.799 --> 00:17:15.519
But the second place you start is let me connect to my database, let me bypass the reporting tools.
00:17:15.680 --> 00:17:30.480
And IT teams over the years have been very good at going, I'm gonna control a sensitive credential, I'm gonna put it someplace secure, and then I'm gonna present that report to you that filters that data to you in the right way, in the right place, and I keep that sensitive credential safe.
00:17:30.720 --> 00:17:41.039
Now this has pivoted to where you're gonna have a lot of people that are not developers who are not practiced IT individuals going, I need that sensitive credential, I'm gonna put it on my laptop.
00:17:41.200 --> 00:17:48.480
It isn't gonna be encrypted, it's gonna be in a plain text file, and worse, that credential likely does not have MFA.
00:17:48.640 --> 00:17:49.839
It is probably completely open.
00:17:49.920 --> 00:17:53.680
It's gonna bypass those rules, and that is gonna explode and increase.
00:17:53.839 --> 00:17:59.279
And you're gonna have info stealers that are grabbed those, and those accounts, by the way, are also monitored less.
00:17:59.519 --> 00:18:03.519
It's the nature of security that that's why you try to put those things and hide them away.
00:18:03.759 --> 00:18:12.640
So you may see security teams come back and say, okay, you can do vive coding, but we've got to create an environment for you to do it securely, and that that doesn't include your laptop.
00:18:12.799 --> 00:18:14.640
That might be a place to start.
00:18:14.880 --> 00:18:20.480
Because some of the new technologies and methods to protect those identities are a little bit different than what most are used to.
00:18:20.559 --> 00:18:21.279
They're new products.
00:18:21.440 --> 00:18:23.279
And they're not geared to your average person.
00:18:23.359 --> 00:18:28.240
They're not geared to your finance person going, just give me access to the SAP data and let me start running reports.
00:18:28.319 --> 00:18:33.920
I'm gonna bypass Excel, I'm gonna bypass SAP, I'm gonna create my own reports here on the own.
00:18:34.240 --> 00:18:36.720
I think that's a challenge area that we're gonna have to work through.
00:18:36.880 --> 00:18:45.440
And I think security teams are gonna have to not only lean into new tools, they're gonna have to lean into new audiences that they typically haven't communicated to.
00:18:45.680 --> 00:18:53.359
They're gonna have to talk about development practices to non-developers, and that's gonna be an interesting convergence to happen.
00:18:53.519 --> 00:18:56.079
I mean, can you imagine talking about a credential vault?
00:18:56.319 --> 00:19:00.799
Not not a password vault, but a credential or an API vault to somebody in finance.
00:19:01.039 --> 00:19:08.799
Not to diminish finance, but I'm gonna guess using developer tools is is not their um not their forte of practice.
00:19:09.039 --> 00:19:09.119
Yeah.
00:19:23.359 --> 00:19:37.119
So it was really pushing me to set up what would have been a personal GitHub account, which would have hosted all the code, whether I set it to be public or private or whatnot, would have been up to my knowledge of you know whether I should do that or not.
00:19:37.279 --> 00:19:41.680
So to your point of like once you go online and it, you know, it'll help you get online real quick.
00:19:41.759 --> 00:19:44.240
It'll help you set up third-party app files.
00:19:44.400 --> 00:19:45.440
It's really helpful with that.
00:19:45.599 --> 00:19:47.440
Like probably saved me hours.
00:19:47.680 --> 00:19:50.480
But I think it's a slippery slope without the right guidance.
00:19:50.720 --> 00:19:51.680
Over to you, Michael.
00:19:52.000 --> 00:20:04.880
Yeah, so that was one of the two things I was gonna say was was the GitHub connection for sure, especially for people who aren't coders, probably don't even know what GitHub is or how to handle like how to even think about security within it.
00:20:04.960 --> 00:20:12.799
So that that's definitely one, and it is extremely helpful, and it'll do 98% of it for you and create walkthrough documents for the other 2%, right?
00:20:13.039 --> 00:20:24.319
The other thing is, Aaron, when you built this app, when you went to go use it, even for testing our demo, did you did you create a login page to where you had to log in to test what you were doing?
00:20:24.799 --> 00:20:28.880
I did, but but that's because I knew that I wanted security in it.
00:20:29.039 --> 00:20:36.400
If I just wanted to do straight up development and not be burdened with that stuff, um that that would be that would be an issue.
00:20:36.720 --> 00:20:37.279
Right, exactly.
00:20:37.440 --> 00:20:41.359
So how many how many people, even inside security, to be honest?
00:20:41.599 --> 00:20:44.400
I know security is doctors are the worst patients, right?
00:20:44.559 --> 00:20:48.400
So when people are creating these tools, I'm creating this tool to save me time.
00:20:48.559 --> 00:20:55.920
Why would I cause myself more effort by making myself log into a tool that I'm making to save time?
00:20:56.160 --> 00:21:02.480
So that it's just it's another one of those easy things of maybe it starts out, well, I'm the only one using it, so I don't need a login.
00:21:02.640 --> 00:21:05.039
But then, oh hey, Aaron, I want you to check this out.
00:21:05.200 --> 00:21:07.599
Uh no, there's no login, it's just us, it's fine.
00:21:07.680 --> 00:21:09.279
And then it does start to scale.
00:21:09.359 --> 00:21:14.319
So then it becomes hard to add add some of those security things once people have been using it.
00:21:14.640 --> 00:21:14.960
Yeah.
00:21:15.200 --> 00:21:20.160
Well, one last question for charismatically curious and CISO Chris.
00:21:20.319 --> 00:21:23.119
Wow, that was a four for four-word play of alliteration.
00:21:23.440 --> 00:21:26.720
Are you going to now block cloud code and kill my fund?
00:21:26.880 --> 00:21:29.200
Or what I did it while we were talking.
00:21:30.240 --> 00:21:35.279
And what are the next steps to protect our own stuff or protect me from my mayhem?
00:21:35.599 --> 00:21:36.160
I'll state mayhem.
00:21:36.880 --> 00:21:39.519
I don't know if I could protect you from that, Aaron.
00:21:39.920 --> 00:21:41.359
Um, let's see here.
00:21:41.599 --> 00:21:45.440
Uh no, I think I think it's a little we're in a little bit of a different situation.
00:21:45.680 --> 00:21:47.279
You understand the risk.
00:21:47.440 --> 00:22:12.240
So I think if you didn't, and uh we were a similar sized company, I would try to listen to what you're trying to do and get our arms around it to put the controls in on the Fly while you're doing your thing, or say, Hey, Aaron, we know you're on a full head of steam here, but pump the brakes for a second, let us organize some stuff, make sure we're at least doing some of the basics here for you.
00:22:12.559 --> 00:22:27.839
And then maybe get some agreements in place with Claude, get the enterprise, you know, kind of agreement in place, and at least get something there so we're not just using the publicly available version and there's no security controls in place.
00:22:28.000 --> 00:22:30.240
So something, not everything.
00:22:30.640 --> 00:22:37.279
And I did get coaching before I went to set up like a POC environment and turn off the training on our data and things like that.
00:22:37.359 --> 00:22:53.920
But there's more steps, you know, as we would progress that we we will and we will need we will need in actuality as well as we would advise for our clients, as their CEOs are probably doing this, and not just CEOs, but leaders and employees of all levels are you know experimenting, right?
00:22:54.000 --> 00:22:54.799
It's it's fun.
00:22:54.880 --> 00:23:07.359
Like one of our CIO clients said he spent six hours on a holiday weekend trying to set up an environment to help his CEO, not because he had to, but he was like, I'm actually having fun with this.
00:23:07.519 --> 00:23:17.119
So that when there's FOMO or fun, actually, Michael, the only reason I started vibe coding because I saw that you were doing it, and I'm like, well shit, I I gotta I gotta get caught up here.
00:23:17.200 --> 00:23:18.799
This seems like something I'm missing out on.
00:23:19.119 --> 00:23:30.480
I think one of the other things, so the the GitHub thing is is an easy way that security and IT can start to bring other people into uh kind of into the fold and encourage it, right?
00:23:30.559 --> 00:23:38.559
Because this this is um there's a lot of things that finance would come up with that we would never consider being in a need or something like that.
00:23:38.799 --> 00:23:43.440
So I think that there it would be a miss if IT and security just shuts everything down.
00:23:43.680 --> 00:23:50.720
Whereas if it's, hey, we already have an enterprise GitHub or you know, a company repo that we use, bring them in.
00:23:50.799 --> 00:24:00.640
You can segment them off to a separate section so they can't access other production code, but you can bring them in, hook them up, say, hey, absolutely, like, you know, dump your code in here.
00:24:00.720 --> 00:24:02.079
It's at least more secure.
00:24:02.240 --> 00:24:09.839
Start with that, encourage it, but then at the same time, you're also encouraging and enforcing some of those basic security controls.
00:24:10.160 --> 00:24:13.519
Well, life will find a way whether we are protecting it or not.
00:24:13.759 --> 00:24:24.559
Had another CISO that we work with that, you know, I was sharing last at a at a uh breakfast coffee meeting across CISOs that um I was playing with Cloud Code and he was like, Oh yeah, I am too.
00:24:24.720 --> 00:24:26.000
And I said, Well, how are you doing it?
00:24:26.079 --> 00:24:31.519
He was like, Well, I've got an old, old Mac, MacBook, you know, company device, and I'm doing it all there.
00:24:31.599 --> 00:24:36.720
You know, so again, he was thinking about ways to not do it on his core laptop, but it was a company device.
00:24:36.880 --> 00:24:45.279
But anyway, I think it's more important for for us as practitioners if we don't know what these tools are, if we don't know what the potential is, we don't know what we're protecting.
00:24:45.680 --> 00:24:57.119
I think I think there's a little bit about kind of front-ending the conversation with business need and what should be done versus kind of open playing field, right?
00:24:57.279 --> 00:24:59.759
Because I think that's one of the first things you do to manage risk.
00:24:59.839 --> 00:25:04.160
If you say, well, everyone at every level of the company can go and tinker.
00:25:04.400 --> 00:25:04.720
Okay.
00:25:04.880 --> 00:25:11.680
Well, that's that's very broad, but number one, that's that's introducing more cyber risk than necessary because everyone's doing something.
00:25:11.839 --> 00:25:15.839
And then on the other hand, potentially waste of time for a company, right?
00:25:16.000 --> 00:25:29.279
Maybe there is some front-ending of this with a business process to develop business cases to allow people to focus on business supporting initiatives or code to rather than just kind of hey have an idea one morning.
00:25:29.359 --> 00:25:33.920
Now, when you get to the leadership team level, CEO, CEO going, I'm gonna go try something, that's different.
00:25:34.000 --> 00:25:35.519
That's a white glove VIP experience.
00:25:35.599 --> 00:25:37.440
They're gonna go and do that and you support them.
00:25:37.680 --> 00:25:44.960
But having the entire accounting team going, huh, I got an idea, and go to town typing, does that even support the mission?
00:25:45.200 --> 00:25:46.799
Does that support the business, right?
00:25:47.119 --> 00:25:54.160
So wasted time, and that's that's the first place you could probably reduce some of the cyber risk rather than having 30 people go tinker on a weekend.
00:25:54.400 --> 00:25:59.839
Maybe, maybe it's five people tinkering because it's an approved mission supporting idea.
00:26:00.000 --> 00:26:04.160
And they're being they have that scaffolding around them to go, yeah, go and give that a try and come back.
00:26:04.240 --> 00:26:05.279
Let us see how it works.
00:26:05.440 --> 00:26:08.160
So just some thoughts there, kind of riffing on what Michael.
00:26:08.400 --> 00:26:13.440
Well, thanks, Michael and Todd, for letting me steal the 10 minutes that turned into a full 30 minutes of your one-on-one.
00:26:13.759 --> 00:26:15.440
But I think this was a fun conversation.
00:26:15.599 --> 00:26:18.880
I think this is a uh special edition of Simplify and Cyber.
00:26:18.960 --> 00:26:19.119
Yeah.
00:26:19.839 --> 00:26:20.640
All right, see you guys.
00:26:20.799 --> 00:26:21.599
Thanks.