Vibe coding is shadow IT in disguise, says Tricentis CISO

A MacBook with lines of code on its screen on a busy desk

When cloud and SaaS arrived, security teams spent years chasing software they did not know employees were using. Erika Dean, CISO at Tricentis, says vibe coding is setting up the same problem all over again.

The Core Risk

AI tools like Cursor and Claude let non-engineers build functional applications without touching a traditional development pipeline. The appeal is obvious. The security concern is not whether the code works. It is whether anyone in the security org knows the application exists, what data it can reach, and whether it ever went through any review process.

Dean puts the real danger clearly: an informal tool gets shared among teammates, gets wider adoption, and eventually touches production data. At that point it is operating like a business application, but with none of the governance that would normally apply.

What the NCSC Has Already Said

The UK’s National Cyber Security Centre has flagged vibe coding as a concern, specifically calling out the risks of relying on AI-generated code without appropriate security controls in place. The policy conversation is catching up, but most organisations are still in the early stages of governing AI-assisted development.

What Dean Says CISOs Should Do

  • Provide approved AI development environments that automatically enforce testing and security controls, rather than letting employees reach for consumer tools independently.
  • Set a clear threshold: any application that touches production data should go through the same security review as any other production software.
  • Apply the same standard to applications that connect to internal systems, handle sensitive information, or become critical to business processes.
  • Extend governance visibility beyond traditional engineering pipelines to anywhere AI-assisted development might be happening.

Dean’s framing is worth keeping: the question is not whether a human or an AI wrote the code. It is whether the organisation can account for the application, understand its risk, and apply the right controls before it reaches production.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo