
The AI Workflow that Fixes AppSec Silos.
Source: YouTube · Cloud Security Podcast · published Nov 4, 2025 · 1:11:39
The shift to AI-driven development demands a cultural transformation from security as a blocker to a partner in safe innovation 0:38. Traditional security gates are no longer viable due to the unprecedented speed and volume of code generation 0:28.
Key Takeaways:
• Traditional security models have failed because they cannot keep pace with the new landscape of application security threats 0:05.
• The volume and speed of code produced by AI make it impossible to apply traditional security gates effectively 0:26.
• Security leaders must shift their mindset from being a "department of no" to a "department of safe yes" 0:38.
• AI's reliability is often overestimated until firsthand knowledge reveals potential mistakes in its outputs 0:16.
Embracing this new reality requires integrating security early in the development process rather than treating it as an afterthought.
Sources:
- 0:05 Discussion on how AI has changed the application security landscape.
- 0:16 Commentary on AI's limitations and the need for firsthand knowledge.
- 0:26 Explanation of why traditional security gates are unworkable with current code volume.
- 0:38 Proposal to change security culture from denial to enabling safety.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Why do you feel the traditional security models don't work? >> It has absolutely changed the landscape from application security perspective. We are now expected to know more about the latest threat vector which is out there. >> AI seems to know everything until it's a topic where you have the firsthand knowledge. That's when you know that there might be mistakes. >> The speed of writing the code and the volume of code that security teams have to secure >> is unparallel. It's absolutely impossible to use our traditional security gates. >> What would that look like? >> Security leaders, we have traditionally been recognized as a department of no. I think we have to change our mindset from department of no to you know department of safe. Yes. If you have been tackling AI security in your org…