When cloud and SaaS arrived, security teams spent years chasing software they did not know employees were using. Erika Dean, CISO at Tricentis, says vibe coding is setting up the same problem all over again.
The Core Risk
AI tools like Cursor and Claude let non-engineers build functional applications without touching a traditional development pipeline. The appeal is obvious. The security concern is not whether the code works. It is whether anyone in the security org knows the application exists, what data it can reach, and whether it ever went through any review process.
Dean puts the real danger clearly: an informal tool gets shared among teammates, gets wider adoption, and eventually touches production data. At that point it is operating like a business application, but with none of the governance that would normally apply.
What the NCSC Has Already Said
The UK’s National Cyber Security Centre has flagged vibe coding as a concern, specifically calling out the risks of relying on AI-generated code without appropriate security controls in place. The policy conversation is catching up, but most organisations are still in the early stages of governing AI-assisted development.
What Dean Says CISOs Should Do
- Provide approved AI development environments that automatically enforce testing and security controls, rather than letting employees reach for consumer tools independently.
- Set a clear threshold: any application that touches production data should go through the same security review as any other production software.
- Apply the same standard to applications that connect to internal systems, handle sensitive information, or become critical to business processes.
- Extend governance visibility beyond traditional engineering pipelines to anywhere AI-assisted development might be happening.
Dean’s framing is worth keeping: the question is not whether a human or an AI wrote the code. It is whether the organisation can account for the application, understand its risk, and apply the right controls before it reaches production.
