Vibe Coding, AppSec, and the New Threat Surface

Vibe Coding, AppSec, and the New Threat Surface

Source: YouTube · HackerOne · published May 21, 2026 · 17:50

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The role of the CISO is undergoing a fundamental shift, moving away from managing operational security tasks toward building scalable systems and strategic oversight 0:00.

Key Takeaways:
• The priorities of the CISO office have changed drastically compared to just five to six years ago, reflecting a new era in security leadership 0:00.
• Modern CISOs face an increasingly difficult job that requires them to create systems that scale beyond their own capacity rather than handling every detail personally 0:06.
• It is unsustainable for a single CISO to have offensive security and application security bundled into their daily tasks; these operational burdens must be delegated or automated 0:10.
• There is a fundamental change in what a CISO should care about, emphasizing strategic governance over tactical execution 0:28.

This evolution highlights the necessity for CISOs to focus on high-level strategy and team scalability to effectively manage modern cyber risks.

Sources:

  • 0:00 Discussion on the changing priorities of the CISO office over the last five to six years.
  • 0:10 The challenge of bundling offensive and application security into daily CISO tasks.
  • 0:28 The fundamental shift in CISO responsibilities toward scalable systems.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What the office of the CISO's priorities look like today is so much so vastly [music] different than what it was even five five to six years ago. The CISO's such a difficult [music] job. The last thing you want to do is having offensive security, application security kind of bundled into your daily tasks. [music] Right, as a CISO, you want to create systems that scale beyond you. It's too much [music] for one person. Way too much for one person. So, >> [music] >> what we're seeing now is this fundamental change in what [music] a CISO should care about. Welcome to Exposed, our video series where we talk about what actually matters in security. And today's guest is Sid Nanda. He is the staff product manager at HackerOne. Uh but Sid has also led MDR product teams and CTM platform strategy for…