Safety reposted this
🤖 If you’re a CISO and you’re not experimenting with AI and AI development tools, you’re falling behind. But not because of what you might think… You just simply won’t be able to keep pace with what’s required to SECURE these development workflows. 3 things CISOs should be doing/thinking about in order to secure AI development in your organizations: 1) Know your stack If you don’t know what AI tools are being used on your developer workstations, you’ve already lost. Of course it’s impossible to know *everything*. But you should have a pretty good idea of the totality of tools being used in your environment. Don’t rely on your team for this. You have to know. Both for strategic reasons. Like should you be using Claude or Codex and why. But also for security reasons. Like when zero days and vulnerabilities and supply chain attacks affect those products. Because there’s no shortage of those… Knowing what you have is foundational to IT/Security and it’s foundational to the CISOs role. 2) Know the technology CISOs need to be the most prepared and informed person in the room. How else can you make good decisions if you’re not? The best way to learn and understand new technology is to use it yourself. It’s not enough to know you have Claude and Codex in the environment. You have to know what those tools can do! Play around with Claude or Codex. Try to “vibe” code something. Spend some time playing around with these AI development tools. Firstly, it’s super fun. Secondly, you will begin to understand how they work at a high level and what their capable of. Pay attention to what the model is doing after you give it a prompt. Is it searching the internet? Reading your local files? Modifying local files? Running commands on your behalf? Communicating via APIs on your behalf? 3) Talk to developers Anyone whose been in this position knows how empowering and awesome it is. That is, when your boss or leadership team come to you and ask you “how can I help you be more successful?” It sounds silly but that really does make a difference. Now just change it slightly. “How can I help you be more successful and where are there potential security gaps we should address?” You’re no longer mandating security controls. You’re no longer demanding they do their work in a certain way. You’re honestly trying to meet them where their at and help them do their work, efficiently and securely. That’s where Safety comes in. What I like about Safety is that they are focused on securing modern developer workstations without requiring changes to tools and workflows developers already use. Safety gives security teams visibility and governance over the modern developer workstation: packages, AI coding tools, MCP servers, IDE extensions, containers, and local developer tooling. If you are responsible for securing developer workstations in the age of AI-assisted development, check out Safety. (link in comments) Thank you to Safety for sponsoring this post.