Skip to content
AppSec PodcastThe Application Security Podcast — home
45 minSeason 13, episode 2

Caroline Wong--The AI Cybersecurity Handbook

with Caroline Wong

on AI and LLM Security

Audio hosted by Buzzsprout. Nothing loads until you press play.

Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, is back! Caroline shares how AI is rapidly changing AppSec, driving massive increases in code, accelerating risk, and challenging traditional security practices. The conversation covers AI-generated code, trust and explainability, and how security teams must adapt to keep up.

Mentioned in this episode

Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.

Transcript

6,928 words · assemblyai

0:00Chris RomeoCaroline Wong is the author of the AI Cybersecurity Handbook and Security Metrics: A Beginner's Guide. She began her AppSec journey in 2007 in her role as Chief of Staff to the CISO at eBay. Caroline led more than 3 dozen BSIMM assessments at Cigital and oversaw thousands of manual pen tests a year at Cobalt. Today, she is the Chief Strategy Officer at Xerri, where she is building an agentic AI Chief of Staff for security leaders. Quick note, we're opening up a few sponsorship spots on the Application Security Podcast. If you want to get in front of real AppSec practitioners, the folks actually making decisions, this is a great place to do it. Just reach out to me, Chris Romeo. I'd love to chat. You can find me on LinkedIn. Hey folks, welcome to another episode of the Application Security Podcast. My name is Chris Romeo. I've been co-host of this podcast for going on 10 years at this point. So, we've been at this for a while since AppSec was in its infancy. Well, not quite, but I can only say that because it was so long ago. Joined by my co-host, Robert, as always. Hey, Robert.

1:21Robert HurlbutHey, Chris. Yeah, Robert Hurlbut, Principal Product Security Architect and Threat Modeling Trainer at Torion. And yes, 10 years. It's just, when I think about that, all the great years we've had, but also just gone by so fast, but still exciting and continue to more exciting things as we continue.

1:40Chris RomeoYeah, we were young people with no gray hair in those days.

1:44Robert HurlbutOr limited.

1:46Chris RomeoLimited gray hair.

1:48Robert HurlbutDefinitely more now.

1:49Chris RomeoWell, I'm super excited to have Caroline Wong joining us here for the 3rd visit on the Application Security Podcast. Previous appearances were the State of Penetration Testing, and then another episode on self-care and self-aware for security people, which I really enjoyed both of those conversations. They were very different conversations, so I recommend folks go back and revisit those, especially the self-care and self-aware one, something that we just don't spend enough time focusing on in the world of cybersecurity. So, Caroline also has a new book out now called The AI Cybersecurity Handbook, which I had a chance to peruse. And Caroline's holding up a copy for those people watching the video version of the interview here. Caroline, let's just jump right in because I really want to hear this story about what you like to do away from screens and technology. Because I think, as an industry, we tend to get so hyperfocused on spending all of our time in front of screens. And so, I'm always looking for inspiration.

2:52Caroline WongChris, about a year ago, I started doing competitive jiu-jitsu, and I literally never thought of myself as a person who was interested in any sort of fighting sport. But my husband got into it, my kids got into it. I said to our head coach, I said, look, when there's an all-female class, I'll try it out. And I was so sure that it was going to not be for me. I thought, you know, I'm really in my Zumba era, I'm in my indoor spin cycling era. And it just is shocking to me actually how delightful it is to just beat people up and get beat up. It's a two-way thing, right?

3:29Chris RomeoYeah.

3:29Caroline WongIt's kind of like chess with your body, which is wild. And I do find myself feeling really in my physical body, which, you know, is kind of a nice counterpoint to, you know, all the hours that I spend on screens.

3:49Chris RomeoSo, when we say competitive jiu-jitsu, is this points-based kind of sparring in a tournament setting, or is this like— are we talking like full submissions, chokes, arm bars?

4:04Caroline WongBoth. If I can submit my opponent, match is over. If neither of us submit each other, then it is points-based. So yeah, we're, we're, we're talking like full out, you know, get on the mat. You've got a referee who tells you when to go, and then you go, and they're keeping track of points. And, and I'm just trying to stay alive and, and cause, cause the other person enough discomfort that they ask to stop.

4:31Chris RomeoAnd the great thing is, most of the time you get up, you shake hands, high five.

4:36Caroline WongAlways.

4:37Chris RomeoWith the opponent. It's, it's not a, it's not a battle. to the death. It's more of a, you know, appreciating each other as sportspeople and the skill. And I've studied taekwondo. I'm kind of retired now, but studied taekwondo for a long time. And then I had a chance to play in the Japanese and Brazilian jiu-jitsu world. Just, I'm very much a novice, but I just found the chess nature of jiu-jitsu. There's always like, there's always a counter to everything, almost everything. Some things, if you find yourself in that, in that you're in trouble and there's just try to survive. But, you know, the, the chess nature of back and forth. And the other thing that people don't realize is how tiring it is to fight somebody on the ground. You look at, you're like, oh, I could do that. You know, as somebody who's never done martial arts, I could do that for 5 minutes. At the 60-second mark, you will be, if you don't do this all the time, you will be Done. You will just lay on the ground and say, okay, I give up.

5:41Caroline WongAbsolutely. There's nothing like it. You know, there's nothing like being physically exhausted from literally fighting another human. And, you know, when it comes to my opponents, you know, there's not a ton of female white belt competitive jiu-jitsu people in the Pacific Northwest. So, when I come across a person that's going to be my competitor, like, I just think they're really cool, and I want to learn all about them as a human. And I'm just so grateful that I get to do the sport with them. So, it's definitely kind of a, you know, a great appreciation for each other and for the sport.

6:22Chris RomeoAwesome. Well, that's— and it's such a good thing for your health as well, just to have— because it's a mental challenge, it's a physical challenge, plus there's that camaraderie amongst your own team. And it's so cool that you're doing this as a family. So, like, you are a family not to be messed with. If your family is— this is not a family you mess with because everybody can take you out is what I'm guessing.

6:47Caroline WongYou know, I'll say to my daughter, who's kind of elementary school age, you know, if I leave her alone in the car for 5 minutes while I go in and pick up our Starbucks, I'll say to her, hey, anyone tries to talk to you or touch you, you know what to do. And she's like, yeah, Mom, I'm supposed to choke them. I'm like, correct.

7:05Chris RomeoThat's right. There's a confidence that comes from that. I taught kids martial arts classes for a number of years. number of years as well. And there's just a confidence that comes from— you hope they never have to use those skills. Like, that was always my hope and prayer for everybody I ever taught. Like, I hope you never have to use this. But there's something about having that knowledge and that experience that they know that they just carry themselves differently. They just like to have a little bit of swagger of like, I kind of know what I'm supposed to do if something goes wrong. And so, that's something that I always appreciated.

7:37Caroline WongAbsolutely. And there's something about the emotional journey of competing and losing, or competing and losing really badly. Like, that is an emotional experience that, you know, I don't, I don't know that my kids would experience something like that naturally in life if not for competitive jiu-jitsu.

8:00Chris RomeoYeah, it teaches a lesson about going back into the gym and working harder because I got beat. And like, that's, those are lessons that live, that last for a lifetime, not even way off the mat, right? And work, you know, if I don't, if my work or my boss doesn't accept what I came up with, and I don't get the accolades I want, I gotta go back. I gotta go back to the gym. I gotta work hard. I gotta fix what's wrong and get better at it. So, yeah, those are great skills. And I think we could literally talk about this probably for the entire interview, but we do need to talk about AI and security and all of those things as well. So, I'll kick off the first question, then let Robert pick up from there. But We think about AI, it's changing the world. I think everybody's kind of come to that agreement now. But when you think about how AI's changing the threat landscape, like, are we seeing new attack surfaces or are we just seeing kind of old problems at new speeds?

9:01Caroline WongFrom my perspective, there's really 2 things that stand out. Thing number one certainly is the speed. I wrote this book from January to September 2025, and when it was released last month in March of 2026, the book was already out of date. And I knew intellectually that that was going to happen, but to be in the moment as it happened was a very, very weird experience for me. Last week, I did a keynote talk at Unicon and Cloud Mythos Preview had been kind of announced shortly before. And it's like, if I had prepared my keynote talk 3 days before, 1 week in advance, the talk would've been out of date.

9:53Chris RomeoMm-hmm.

9:54Caroline WongAnd so, the speed is just staggering. You know, I'm seeing information security teams who are very comfortable doing 10 security projects reviews a quarter, you know, and these teams now are looking at queues of, 100, or even in some cases nearing 1,000. And so, the speed is truly remarkable. You know, at the end of the day, I do think that fundamentals are the same. We've got attack surfaces that we need to understand and protect. We need to find and fix and prevent security problems. That's all the same as it was. But the speed is like nothing that I've seen in my, you know, career. You know, it's not the same speed as from on-prem to the cloud. It's not the same speed as waterfall to DevOps. It is so much faster. And then the other aspect that I think is going to continue to be extremely interesting is this supply chain nature of what does the world look like when everyone's data is sort of like all garbled together? And, and like, how do we even keep track of where data goes? All of a sudden, it is 2026, and data classification is sexy again. Like, I don't know that data classification was ever sexy, but boy, did we try hard to do data classification correctly in 2010. And I think most of us like kind of didn't ever really figure it out, but it was fine, 'cause it didn't matter so much that we really had to figure it out. Now it matters, and AI is the reason.

11:41Chris RomeoYeah, it's, when I think about, you know, you mentioned the shift to cloud, the shift from waterfall to DevOps, like AI, the difference is that while those things were gener— were making things move so much more quickly, there wasn't the same innovation cycle. So it feels like with AI, we've got things moving at 1,000 miles an hour, and there's a new thing that comes out once a week that disrupts everything that we've done. Like, you mentioned the Mythos thing, like, that's disrupted the way we thought about offensive cybersecurity for as long as I've been in doing this. Like, the game has all of a sudden changed, and You know, I'm still being a little bit reluctant to say the world is completely different until I see a little more. But I mean, I see some more kind of evidence of what Mythos can actually do. But based on everything that's been shown so far, it's like, uh-oh, like we're in for something that's completely different, assuming that it does deliver on what it appears that it's going to deliver.

12:58Caroline WongWell, and Mythos is just one thing, right?

13:01Robert HurlbutYeah.

13:01Caroline WongI think there's so many people questioning, oh, you know, we think that Mythos does A and B and C, but we don't really know 'cause we haven't really gotten to— regardless of what Mythos does, what is China doing? What is Iran doing? Like, these nation states most certainly are developing like capabilities. You know, the technology is just so accessible now, and token budget is really kind of becoming maybe a restraint. So it's just, it's just a fascinating moment, and it's exciting to be in it and terrifying. Exciting and terrifying.

13:40Chris RomeoI would agree with that assessment. Exciting and terrifying, you know, struggling to sleep at night. We should all be a little bit there, you know, hopefully not too much. If you are struggling to sleep at night, sign up for jiu-jitsu. You'll be tired when you get home.

13:55Caroline WongThat's exactly right. Wear out your physical body. If you're having, like, mental or emotional strife, you know, just go for some physical strife, and it'll just wipe those other 2 out.

14:05Robert HurlbutI think it's a good recommendation for anybody. So, Caroline, how does AppSec change in a world of AI-generated code?

14:17Caroline WongThe biggest thing is the volume. You know, I think that I heard a couple of evolving statistics come outta Cloudflare. You know, there was a point in time when they said during the next 5 months, the amount of AI-generated code will be the same as the code that had been generated by humans over the past 5 years. I think that actually got updated and it was something like in the next 5 years, There's gonna be enough AI-generated code to match the volume of code that's been generated since the history of computing.

14:58Chris RomeoYeah.

14:59Caroline WongUm, and so that is really an entirely different volume than we've ever considered. Um, and I think that, you know, my hot take, if you will, is twofold. Thing number one, if attackers are using AI, defenders can use AI. If vulnerabilities can be found this quickly, I believe that there's opportunities for vulnerabilities to be fixed quickly and at massive scale. And then my second hot take is defense in depth and back to basics. Fundamentally, we know what these sort of proper things are to do. We just have a really good reason to do them right now.

15:51Robert HurlbutYeah.

15:55Chris RomeoI mean, things are, you know, in the world of application security, we've struggled with this backlog. It's been one of our biggest challenges over as long as I can remember, right? You get a set of tools, you get a process, you've got a bunch of code, and then you generate both a backlog of problems in that code and a backlog of existing vulnerabilities. And it seems like with the onset of AI-generated code, we should be able to keep to, to get it almost catch up on that backlog. Like, do you see a world where, with where that backlog is erased and we're at zero, we're at like a neutral problem space?

16:45Caroline WongIf I can create an AI agent that can effectively go and find specific instances of a defect, and I can create another agent that can go and automatically fix those instances, then all of a sudden, the effort required to fix gets very, very efficient. And I think that's possible. I also think it's possible to define secure patterns.

17:25Robert HurlbutYeah.

17:26Caroline WongAnd then to build agents that both ensure that those patterns are in use everywhere they're supposed to be, as well as finds areas where it's different and fixes it. I'm, I'm really excited. I, I remember this was back in 2012. I was working on the information security team at Zynga. We were preparing for the company to go public. For folks who don't know what Zynga is, It's the FarmVille company. FarmVille was like really a big deal in like 2010.

18:03Robert HurlbutYeah.

18:03Caroline WongAnd we had, as one does, a list of bugs that were found via penetration testing, via bug bounty, via all the scans. And I was in charge of reporting the metrics on a weekly basis for our team. And one week it was like, oh, like 75% of those bugs are gone. What happened? They re-architected the system. And so, even at that point in time, there was this opportunity to change things from an architectural point of view, from a design point of view. I mean, I think what's true at this moment is anyone building something new right now, Has incredible capabilities for speed and scale. What will be very interesting is all the legacy stuff that's existed for so long that is gonna break if we touch it.

19:05Robert HurlbutHmm.

19:08Chris RomeoWhich is the majority of code that exists in the world today.

19:12Caroline WongEverything.

19:13Robert HurlbutYes.

19:13Caroline WongYeah.

19:14Chris RomeoAre we gonna re-architect everything?

19:16Robert HurlbutI don't know.

19:17Caroline WongRobert, are we gonna re-architect everything?

19:20Robert HurlbutI hope not. But, you know, I mean, that's certainly important, right? To think about architecture, especially now, and what does that mean? And designing as opposed to just coding. There are a lot of potential interesting skills that people are needing to develop, right? As a result.

19:39Caroline WongPeople and their AI agents, right? So, this is the weird thing. This is the weird thing. Like, Yeah. When it comes to anything digital, what skill do I need to develop versus what skill do I need to acquire via an agentic capability? And that's a, that's, it's weird that we can say that. Yeah.

20:03Chris RomeoI wonder if we need to name our agents. Like, should we just have like—

20:06Caroline WongOh, definitely. They, they need to have—

20:08Chris RomeoFirst names for them.

20:09Caroline WongThey, they need first names, you know, Eve, Raya, Cole. You know, Clifford, like, definitely, definitely, you know, we're going to be in Slack or a Slack-like thing.

20:17Robert HurlbutThat could be a whole other podcast on that. I've heard, I've heard both sides on that.

20:21Chris RomeoI mean, the agents already have their own social network, so they might as well, you know, we might as well use the names that they've attached to themselves and check in what they're posting about. Um, I just think about kind of the world that you, you described here where We're gonna have all of this code that's been AI-generated, and like, it's got— there's gotta be something that's gonna fall apart.

20:48Caroline WongDefinitely. Something real bad is gonna happen, right? Something real, real bad is gonna happen, 'cause everyone is just rushing. Everyone is innovating, which actually is astonishing to me. I think for decades, I've observed, like, security people really like perfection. Security people really like 100% of the bugs to be gone, and that's sort of never been and will never be reality, you know, but when you go from a capability to review 10 projects in a quarter and you're looking at a lineup of 100 or 1,000, you know, our ability to ruthlessly prioritize and do sort of proper risk management becomes incredibly important. And that actually is a skill that I think as we, like, we as humans will need to develop.

21:34Chris RomeoYeah, we're gonna need to keep some visibility into all of these pieces that are being agentically created? Because I, you know, one of my biggest fears is that we're gonna lose touch with the code that's running.

21:50Caroline WongOh, 1 million percent. And the thing that scares me the most that I ask everyone if they have an answer to, and I'll ask you folks if you have an answer to this, In 2005, I graduated from UC Berkeley with a degree in electrical engineering and computer science. The world was my oyster. Today, a college grad comes out with that exact same degree, no job prospects. There are so few entry-level tech jobs available because AI can do all of that. And so what's gonna happen in 5 and 10 and 15 years? How do we develop mid and senior level engineers, I have no idea. The best that somebody's told me is, I know a person who runs a 400-person software development shop. Over the past 10 years, they have delivered more than 100 applications for various startups around the world. And he told me that their entry-level folks are not allowed to use AI assistance for the first 2 years of their coding.

22:55Chris RomeoMm-hmm.

22:55Caroline WongWhich I think is on one hand radical and awesome. Um, and on the other hand, I genuinely don't know how they will be able to keep up with the competition. I don't, I don't know what that looks like. I don't know what it looks like in 5 years when we're like, well, we have this glob of code and we have no idea how it works. Or is that how things are today already? I mean, right? Like, when any software developer goes and interacts with code, how much of it do they truly understand in a firsthand manner? Like, some small percentage, which is wild.

23:37Chris RomeoYeah.

23:37Caroline WongBut we kind of sort of make it work. Something I think that's, you know, everyone's just going ahead, go do it, innovate, use all the AI, go for it. And, something messy is going to happen that people are very uncomfortable with. And then I don't know if it's regulation or rules or testing, but there will be a clamoring for governance.

24:04Chris RomeoBecause that's the piece that really hasn't caught up at all as far as I know. I mean, there is, I think there's the EU might have an AI act of some form that's I'm not even— I haven't studied it very closely, but it seems like there just isn't any regulatory oversight. And I can't believe I'm saying this because I'm not somebody who really loves regulatory oversight as an innovator, as a startup person. Like, I want to just go build cool things and go really fast and, you know, have fun. But yeah, is there a flashpoint in our future where something does happen that we don't even really understand what the the thing is yet, but we know as folks that have been around software security for a while, like, something's brewing in the scenarios that we're creating right now.

24:56Caroline WongYeah. And there will be a tremendous amount of variation across different industries. You know, highly regulated or, like, government agencies are going to take very different approaches than kind of the tech startups that I think, you know, we 3 have a lot of familiarity with. And that's going to be super interesting because it really is this like innovation and governance, you know, push and pull. And I don't know where exactly that's going to go. I do think that we're all going to be building and operating with these groups of AI agents that follow us around and do the things that we ask them to do. And that's going to be really cool and really weird.

25:45Chris RomeoAt the same time. Yeah. Let's, let's, let's move into this concept of trust. I saw that the concept of the idea of trust comes up a few different places in the book. What is, what's your kind of definition, I guess, of trust when we're talking about all of this code that's been generated by AI?

26:09Caroline WongYeah. So to me, there's a relationship between the concept of trust and the concept of risk tolerance, because I think that trust happens when a person or an organization decides to associate with another entity. And that could be I'm buying your products and services. That could be, I'm buying your products and services and I'm using them as part of my products and services. There's some sort of relationship that changes from separate to together. And the ways in which we make those decisions, I think, vary tremendously. But I think, you know, the way that I think about trust is how do you take a relationship that's apart And then make the decision to bring it together. And what are the criteria that you use to determine that that's a good idea, the idea you're going to actually move forward with?

27:12Chris RomeoWhat do you see as some of that criteria that, that we could apply today with this world of AI?

27:19Caroline WongYou know, recently, I was on the security leadership team over at Teradata working with Billy Spears, and we were hosted by one of the really big cybersecurity vendors, one of the biggest on the planet. And they invited us to their HQ, and, you know, we met with a bunch of their leadership, and they did a lot of presentations for us, and they were talking about One of their new AI capabilities. And they said, you know, Caroline, the attackers, they're hiding in the noise, you know, and our AI goes and finds them. And I was like, oh, that's really cool. That sounds really cool. Like, how does it work? Crickets. And I went throughout the entire day and throughout our lovely meal and throughout the sporting event that we, And I just asked everyone, how does it work? And I was like, okay, if nobody can tell me how it works, then like, what's that about? Right? Fundamentally, like, what's the dataset? What are the algorithms? How does it learn? How does it infer? Like, if you can tell me those things, then I'm gonna trust you more than if you can't answer those questions.

28:44Chris RomeoYeah. Yeah, I see how that could be kind of a challenge, but it could also be how innovation and products happen. As the AIs get smarter and smarter, you may not know how— you may get the AI to do something in some combination of prompt engineering and getting it into the right spot. It can do something incredible, but you can't really explain that. That's a really dangerous world when you can't explain and understand how it works.

29:20Caroline WongWe need explainability and we need transparency. My daughter is like part of a math club and they go and they do these math competitions. And one of the, one of the rules is that when they're asked to do mental math, they're not allowed to show any work. on the paper. They can only write down the answer, which I think is fascinating, you know? And I think in a world where we're asking AI to do the work for us, we must insist that they show their work. And we must keep that at a level of explainability and transparency that's going to make sense to a human.

29:58Chris RomeoYeah, because the danger is we become Unable to explain the work for anything. Like, that's one of the big dangers I see with AI right now is like, I think about my kind of schooling throughout from the time I was a little kid until I graduated university. There was always a critical thinking component of the process that I learned and the things that I was taught and the experiences that I had. And I think if we, you know, if I take that out of what I can do now, like, I'm very limited in, you know, I kind of pride myself in being able to solve problems. Like, I feel like I can solve different types of problems based on my experience, based on that knowledge. But if we extract that from how, you know, in this case, software developers, but really anybody, if you don't have that critical thinking side and you start to use AI as your critical thinking component, It's just, you can't, you know, you can't, it's gonna limit the amount of problems that you can really solve.

31:05Caroline WongYeah, it's so interesting to me because it comes back to this kind of fundamental computing concept of like abstraction, right? I like turn on a light switch and the light comes on and I use the light and that's awesome. Could I like set up the electrical system for my house? Like, absolutely not. Like, do I have any idea how it works? Like, not really, but maybe it's fine because the state of electrical light switches today is such that me or my kids or my cat can turn on the switch and it's not dangerous.

31:46Chris RomeoMm-hmm.

31:46Caroline WongSo if there's no danger or safety issue, then fine, I can use all the light switches I want. I do think Chris, you've hit on something that I think is extremely important, which is if robots and machines are intelligent, then what do we as humans even bring to the table? And I think the answer is, and will always be, critical thinking.

32:15Robert HurlbutYeah, we're, we're working on, or, or AI generally is working on what it already knows, but we can think ahead and, you know, we can be creative and there are all kinds of things that we can bring so far that AI certainly can't do. And, and, and like you said, critical thinking and, and thinking sort of outside the box, not on data that we necessarily have, but just based on our understanding and thinking ahead, we can do some things that are quite different. Yeah.

32:50Caroline WongWhen I think about parenting kids in this age, like my kids don't know any world with no internet, with no iPhones, with no YouTube. Like, and one of the things that I really strive for in my parenting style is to encourage them to understand and express their thoughts and feelings, which Side note, as the daughter of Chinese immigrants in the United States, I was not so much encouraged to think about my thoughts and feelings and have those be expressed or accepted or even allowed. But I do think that's really important, and I think each and every single one of us can do that. Like, what do I think and how do I feel? An AI will never tell you that. That will always be us. It may be influenced, and in many cases it is influenced, but what do I feel and what do I think will always be us. That's always us. That's human. Can you duplicate it? Sure. Digital twin? Sure. Synthetic worker? Sure. But my thoughts and feelings are mine.

34:00Robert HurlbutSo, another term you use in the book is AI augmented security teams. And curious about that. What does that mean? Security headcount constraints? We talked a little bit about that. Uh, sorry, I'll not, uh, alluded to that, but, but do teams just look different now?

34:22Caroline WongSo, what I've seen is in 2020, 2021 timeframe, like things were great in cyber and in tech. And it was like, people were getting jobs and they were getting 50% pay increases. And it was like, Wild, you know? And then ever since 2022, the story that I just keep hearing over and over again is budget cuts and layoffs, budget cuts and layoffs. I know so many experienced, talented, extraordinary humans who are either unemployed or underemployed right now, and that is super weird. And I don't know what's going to happen in the 2027 budgeting cycle. But I won't be surprised if a lot of CISOs are asked to cut back further. I don't know what the size of those reductions is gonna be. And at the same time, me and my good friends Claude and ChatGPT, like, boy, we can get a lot of stuff done. Just me and these tools, you know, that was not possible before. And so, I think we're in this sort of like thrashing phase of innovation and evolution, and it will settle, you know. But I think my number one takeaway for folks is learn and learn and learn and learn everything you can and just keep on learning because none of us can predict what's going to happen. But if we are paying really close attention, and if we are taking good care of our bodies, humans also have bodies. I'm not going to have AI fight my jiu-jitsu match for me anytime soon. Then I think that whatever happens, if we are paying attention and if we exhibit critical thinking, then we'll be well positioned to adapt and continue to adapt. I don't think the budget cuts and layoffs are going to stop anytime soon.

36:25Chris RomeoYeah, I kind of see a world where it's going to be constantly do more with less, less people, less dollars in the budget. And we're going to reach the point where, you know, AI is doing some percentage of the jobs that 10 years ago would have been for folks, you know, for people. You mentioned earlier about the entry-level jobs, like that's a big challenge for our industry though, because, you know, the 3 of us, we've been in this industry for a long time, but we all had entry-level jobs. We didn't become— Yes, we did. We didn't start with a senior-level role. We were entry-level folks who did grunt work and whatever we had to do to kind of learn the basic skills, and then we made our way up, right? But if you take that layer out, what happens in 20 years from now when folks like us are, I don't know, on beaches or whatever people do in retirement? I don't know what they do, but we're not working anymore.

37:33Caroline WongYou can do jiu-jitsu. That's true.

37:35Chris RomeoYou can do that forever.

37:36Caroline WongThere will be— I actually love that jiu-jitsu is fairly sustainable. It's different from MMA. There's no striking, right? So The risk of sort of like big bad injury is so much less. Oh, I had like a really fun thing that I was going to say and it was really important. And then I started talking about jiu-jitsu and I got distracted.

37:57Chris RomeoYeah, we were talking about, you know, how you could do jiu-jitsu. And so basically we were talking about how, you know, the kind of entry-level jobs are going away. And, you know, there's not going to be that kind of, that layer. We're going to be, it's going to catch up with our industry though.

38:17Caroline WongThere will be new entry-level jobs. When I think about my first sort of corporate job, I joined the eBay information security team as a policy and compliance sort of GRC security engineer. And it was the year 2005. The first version of PCI DSS came out in 2004. So, arguably, my exact entry-level job that I started in did not exist 5 years prior. My entire career, our entire careers as information security professionals could not have existed without the internet.

38:53Chris RomeoTrue.

38:55Caroline Wong200 years ago, you couldn't spend 25 years being an information security professional. And so, there will be new jobs. I can't predict what they're going to be, and I can't advise on what skills folks ought to work on beyond critical thinking, which is awfully broad. But I believe that there will be an entirely new set of entry-level jobs. I just don't know what they are. And it's scary because we like knowing things, and there's no way to know what that's going to be.

39:24Chris RomeoYeah, I think the same guidance that we offered people 20 years ago still applies at a very generic level, and that is understand how the things work work under the hood. So, 20 years ago, I would tell people to, if you want to be a security engineer, learn networking, learn how TCP/IP works, learn how the internet moves packets. You should be able to, if you're going to be in incident response, for example, you got to know how packets move and how data moves across networks and things. Learn a programming language. And I think in this kind of day and age, it's learn how AI works under the hood. You know, learn how to build software with AI as a security person. So, because, you know, developers, they're all using these tools now. As a security person, you better be just as versed in these tools and capabilities as they are, because you're looking at it from a different lens. And so, I think there's still those basics. I think the basics have just changed, right? And some of those same things still apply. Like, I, Unfortunately, I think there's a, there's probably not as high of a percentage of people that can explain how the internet works packet to packet as there used to be when I got started in security. But there still are people that understand how that, how that happens. And so, there's always going to be that base level of skills. Just the, it's a different kind of topic that the base is coming from now, but there's still a base there that you can build off from.

40:51Caroline WongDefinitely.

40:55Chris RomeoSo, it's hard to ask a where are we going in 5 years question in the world of AI because we were joking earlier, like, do we ask where are we going in 5 minutes, 5 days, 5 weeks, 5 months? And it's hard to— it is really, for me, it's hard to visualize 5 years in the future. But I don't know, Caroline, what are your thoughts about where we're going with AI? And do you dare to make a prediction for 5 years in the future?

41:22Caroline WongI think that the way that the 3 of us might talk to each other on Slack or Discord, we're going to be talking to human workers and we're going to be talking to AI workers. I think that a lot of traditional security tooling is going to get augmented or replaced. That's what I got. That's what I got. There's also I think there's going to be parts of our industry that, like, there's going to be some things that humans do today that machines can do just fine in like 2 months or 2 years, and that is going to result in significant change.

42:02Chris RomeoYeah, I think about like the detection side of cybersecurity. I mean, SOC level 1 type of roles were, I feel like they've been replaced over the last couple of years. With AI agents watching kind of the low-hanging fruit, let's call it. But detection seems like it's an area that AI is just poised to look at this and find the anomaly is just something that AI is really good at, at this point. And so it seems like on the detection side, kind of more the defensive side, I can see how over the next couple of years that's going to be more and more automated. But once again, back to our conversation of trust, we still need somebody watching. We can't just outsource this whole thing and be like, ah, we're good. AI's— we trust it enough now that we're letting it just watch everything. And because we know that it can be tricked and it's— there's going to be even more types of ways it's tricked in the next couple of years. And we were having that conversation with Steve Wilson. We were talking about how AI has taken on this human persona. Now, which means AI will be susceptible to the same attacks that we would use against a human because it's, they're trying, AI, they're trying to build AIs that think more like humans. Well, if I'm an attacker, I'm going to go after the same way I would go after a normal, you know, a live human when I'm going after AI.

43:31Caroline WongYeah. Like, is prompt injection actually just social engineering the AI?

43:36Chris RomeoI think it is to some degree, but All right. Well, Caroline, what would you want to leave our audience with as far as a key takeaway or a call to action? Maybe something they can do for homework. They'll never send it to you, but, you know.

43:53Caroline WongLearn everything you can. Get as hands-on with everything as much as you can. Like, everyone watching this or listening to this should go and vibe code today. And Embrace your humanness, do stuff with your physical body, create art, you know, I think those are really important things for us to do.

44:16Chris RomeoYeah, very cool. Well, Caroline, it's always a joy to have you as a guest on the Application Security Podcast. And hopefully, let's see, if you visit us again in a year, will we be a blue belt perhaps at that point?

44:31Caroline WongMaybe I'll keep you updated.

44:34Chris RomeoIt's, it's white belt, blue belt, purple belt, black belt, pretty much in most gyms, right? Okay.

44:39Caroline WongYep.

44:40Chris RomeoYep.

44:40Caroline WongBrown and then black. And so I'm a 4-stripe white belt right now. So maybe in a year I'll be a blue belt. I'll keep you updated.

44:46Robert HurlbutAll right.

44:46Chris RomeoWell, that'll be exciting. Thanks, Caroline.

44:49Caroline WongThank you both so much.

More on AI and LLM Security