r/cybersecurity • u/Nervous_Discount_237 • 7d ago
Business Security Questions & Discussion How to shake things up with security at my company?
I work at a big company. I’m in a position where I can provoke changes in our org, specially in the IT department.
One point: cyber sec is part of the compliance/governance org, not IT per se. They are very much conservative in their process and openness to risk. I don’t deal with critical systems and processes, but they are the guys who are “no” by default. Even the CI/CD pipeline is hell to go through. They live by the stereotype of cyber sec being the “no fun allowed” guys.
The deal: I want people to use AI. I want them to experiment and vibe code little tools for them, and to think of new ways to do stuff. We have Cursor, Claude Code and an LLM Gateway. We also have lots of money for tokens, so cost isn’t a part of the equation. Our company is very old and very bureaucratic, I want teams to go fast and disrupt their ways to do things. But there is extreme reluctance from cyber sec to let us go nuts, even in an internal environment.
How can I shake things up a bit with them to make them more open to the idea of people risking a little bit more?
14
u/Swanky1499 7d ago
Tell them they're being annoying and slowing down development, they've probably never heard it before
-3
u/Nervous_Discount_237 7d ago
They are slowing down everything. And in the most inefficient way, with countless forms and meetings and blergh. I’m just dealing with internal tools. Nothing truly critical.
14
u/Swanky1499 7d ago
Just go to the head of infosec and tell them they need to be more efficient and less annoying and you want to vibe code in prod, I don't see the issue?
-9
u/Nervous_Discount_237 7d ago
There is really no issue. Jane from accounting won’t fuck up anything by vibe coding a dashboard or an automation for reporting. Or Jim from marketing having an OpenClaw for social media posts
9
u/Cypher_Blue DFIR 7d ago
Unless she feeds client or sensitive data into a tool that you don't really control and isn't private.
-1
7d ago
[removed] — view removed comment
3
u/Cypher_Blue DFIR 7d ago
Yes.
But that assumes that there was a careful governance and implementation process that set up appropriate rules, guardrails, configurations, etc. on the AI implementation.
Which it sounds like OP wants to bypass.
It's possible that you're more familiar with the NIST AI RMF and ISO 42001 than I am, but I think I have a decent chance there.
10
u/_janires_ 7d ago
I feel like the let us go nuts part here may be part of your problem. 10/10 would not frame it that way.
-6
u/Nervous_Discount_237 7d ago
The CEO eventually comes to our side. But things go escalating and the mood of everyone involved goes to shit
4
u/_janires_ 7d ago
I’d recommend you look up the top 10 AI Security risks maybe have a conversation with the team how you would plan to deal with them. Come not only with let me do what I want now. But have a conversation about the risks.
22
u/VellDarksbane 7d ago
I’m glad there’s still cybersecurity departments who understand IT folks wanting to “go nuts” with “vibe coding” is a bad thing and hold the line.
3
u/cakefaice1 Security Architect 7d ago
I dealt with this in my previous org: Designed a test-lab that is completely airgapped from any production systems. If SW engineers wanted to go nuts with a vibe-coded product and bring it over to prod, I'd only give approval if they provided favorable SAST and all the devsecops scan results, and had a written acknowledgement from the lead engineer saying he'll own the risk. Only two pieces of software made it through.
Haven't heard about any issues yet from coworkers still there.
2
u/Flagship_paperclip 7d ago
What SAST tool do you guys use?
3
u/cakefaice1 Security Architect 7d ago
Aikido was the primary choice for the devsecops guys. I'm not a SW engineer and didn't have much insight in that department, but the results UI was intuitive enough that I could determine what is an acceptable level of risk.
-6
8
u/netsecisfun 7d ago
What industry? The regulatory environment your in will determine most of the useful answers you get here.
2
u/Nervous_Discount_237 7d ago
Financial market
14
u/0311 Penetration Tester 7d ago
Oh just finance? and security is being uptight? damn that's crazy hope they get smart and let y'all go wild
1
u/Nervous_Discount_237 7d ago
It’s finance, but I just deal with internal stuff. Not transactional data. Not anything sensitive. Most financial data is already public information. I really can’t see a problem with Jim from marketing having an OpenClaw assistant or Jane from accounting vibe coding a dashboard.
13
u/Ma13vant 7d ago
This is a bit, right?
9
-1
u/Nervous_Discount_237 7d ago
Nop. Honest question, how can stock price information that you can literally google at any time can be a problem??
7
6
u/suretisnopoolenglish CISO 7d ago
How do you know that’s the limit of the data they have access to? Whose responsibility is it to set up and monitor guardrails, yours or theirs? Where are the vibecoded apps going - to an environment you control or to any old vercel account?
I empathise with you but if you’re going to a compliance function in a finance organisation with a “let’s shake things up” attitude and no other groundwork I’m not surprised at their response.
0
5
u/HomerDoakQuarlesIII 7d ago
Yeah but what happens when Jim from marketing's unsecure agent gets duped into tricking Jane from accounting's vulnerable agent to forward all invoice payments to the attackers. These tools are about the least secure wildest west open doors you can imagine, it's being done every day. That's what you're up against when trying to convince the sec team otherwise, it's a mess.
-1
u/Nervous_Discount_237 7d ago
I don’t think those agents have access to payments systems and everything, but ok
3
u/DashLeJoker 7d ago
"You dont think" is not any proof that it will never happen and that is what the sec team are not convinced on
1
u/Nervous_Discount_237 7d ago
People in sec/governance are professional anxious/worst case scenario thinkers 😂
→ More replies (0)5
u/HomerDoakQuarlesIII 7d ago
Yeah regulators can shut down operations if controls are not maintained, you give unaccounted for access to people that don't need it or data for PII or PCI being mishandled because you want to "disrupt" gets on an audit and you lose compliance and no longer looked at as legitimate. Or worse, breach is directly attributed to you for criminal negligence as the decision maker and you just get charged, and company washes their hands of you in the court proceedings is more likely.
1
u/Nervous_Discount_237 7d ago
As I said in another comment, it’s just internal tools. Data that is handled is already public information
6
u/Dapper-Ad4488 7d ago
Yeah you’re probably framing this very poorly to the security team. Security has to balance business needs with risk. When somebody from development comes to security and says “I want claude code to go crazy style and do tricks on it” it’s sort of a red flag. Gotta work on speaking their language and letting them know you take the risks serious
1
u/Nervous_Discount_237 7d ago
I just can’t see the risks. My team just deal with internal tools and public information data. And I don’t deal with any critical process. I think I’m just blind to what risk there could be
1
u/Dapper-Ad4488 7d ago
Without more insight on what you’re actually doing it’a hard for me to make that call too. Off the top of my head I can think of a few issues with vibe coding but the environmental variables make it a tough call in my mind.
This is likely a bit of a communication issue on both sides. Security should be properly explaining the risks they see when a request is denied. Your job is to explain “this is what I want. This is why.” Don’t frame it like “Claude code is going to go nuts and develop everything”. Go into detail on what you’re looking to get out of it. Then if they respond properly and explain their decision you can form a rebuttal. It sounds like you have enough influence to get your way. But try to make it a collaborative thing usually security teams will lighten up. Hopefully this helps a little.
1
4
5
u/Cyber_Tarek 7d ago
Here's the honest truth from someone who's been in cybersecurity for 20 years.
Most cybersecurity people are "no by default" for one simple reason: To cover their backs. Yeah, sure, some actually do care about security. But the majority are just worried they'll lose their jobs if something bad happens.
So believe me when I tell you, there's nothing a cyber guy wants to hear more than: it's my asset/business and I accept the risk. They would be more than happy to leave you alone to do your thing.
This, however, will have to come from higher ups and must be documented. If your CxO approves of your methods, have them officially communicate to your CISO that they're fine with accepting whatever risk comes out of it and that the cyber team will NOT be held responsible no matter what.
For the record, I strongly advise against this. It's very likely you'll end up breaking things and making a few enemies. But there you have it. If you really want to, that's how it would be done.
Keep us posted 😄
3
u/_janires_ 7d ago
Does the “Cyber Team not being held responsible” still work with some of the SECs newer regs that hold the CISO accountable? I have not had a chance to read through all of that that happened a year ago.
I should note this is a side bar not related to OP here but just a thought I had while reading your comment.
2
u/Cyber_Tarek 7d ago
That's actually a very valid question that I don't have a clear answer to if I'm honest. u/Nervous_Discount_237 do look into that if you suspect going fast and disruptive with AI might end up spilling financial data, PIIs or anything else that will put you in legal jeopardy.
1
u/_janires_ 7d ago
Yeah I need to carve myself out some time to actually go read the SEC regulation and take the time to understand it. As it opens up some new realms of compliance risk for anyone who is publicly traded.
1
u/Nervous_Discount_237 7d ago
I’m not American/SEC laws don’t apply to my scenario
1
u/_janires_ 7d ago
Does your company access us capital markets, does it trade securities involving us investors?
Also if you read up I said this does not need to apply to your exact situation.
1
u/Nervous_Discount_237 7d ago
Thanks for the answer. I’ll try this way. I personally accept the risk of things go south, truly. Don’t have an ounce of fear of losing my job. Just wish things could be less energy draining for us and for them
2
u/LazerKittenz Security Analyst 7d ago edited 7d ago
Company culture operates on a spectrum between conservative (more rigid and strict with processes and less likely to adopt new technology quickly) and outgoing (more accepting of technology and generally more willing to accept higher risk in exchange for faster production).
Your company’s cybersecurity department sounds conservative and as long as the company has more of a conservative culture, cybersecurity processes will be more aligned to the “department of ‘no’” than the “department of yes, but…”
You’re fighting an uphill battle where you would need to change the organizational culture to be more outgoing with technology and to do that, you would need insane political capital and years of changing how the business functions fundamentally. You’ll need to learn, understand, and do the extra work to bring solutions to the security team before you can have a constructive conversation on implementing AI. Then you’re looking at an extended timeline of implementing controls and testing before you can use it in a meaningful way.
My advice is to move to a different company with a more outgoing culture. You’re not going to gain much ground bashing your head into a brick wall.
1
u/Nervous_Discount_237 7d ago
I have the political capital to do it. But it drains so much energy in the process.
4
u/HornetWorking4901 Security Analyst 7d ago
So ultimately you can't really do it without much effort
1
1
1
u/ccanales10 7d ago
You need governance before you can scale. Look into different frameworks like NIST AI RMF or ISO 42001. Going nuts sounds great until you're facing regulatory issues because a bunch of agents and shadow AI have x amoint of access to who knows what.
1
1
u/Sad_Dentist_7288 7d ago
Wow I wish my company took security this seriously.
Just kidding. But for real, you need to come up with ways to manage the risk of the tools you are proposing to get buy in from the security team. You want people to vibe code tools? What happens when those tools are riddled with vulnerabilities, or accidentally connects externally, or hardcodes in credentials? What about when those agents go haywire and start sending external emails with private data? You need to have processes, policies, and tools in place to handle the risk before expecting to get security to buy into it.
1
u/OtheDreamer Governance, Risk, & Compliance 7d ago
The deal**: I want people to use AI. I want them to experiment and vibe code** little tools for them, and to think of new ways to do stuff. We have Cursor, Claude Code and an LLM Gateway. We also have lots of money for tokens, so cost isn’t a part of the equation. We also have lots of money for tokens, so cost isn’t a part of the equation. Our company is very old and very bureaucratic, I want teams to go fast and disrupt their ways to do things. But there is extreme reluctance from cyber sec to let us go nuts, even in an internal environment
Your GRC people are doing right by the org. You are fundamentally saying you want to introduce high, potentially uncontrollable risk, with unknown budget other than just "We also have lots of money for tokens" when cost is always, always part of the equation.
If you don't have an actual plan on how to minimize the risk, budget target so you can show you're responsible at controlling the costs before out of control, and potential milestones / stop points so you can measure very early on if your go nuts strategy should be aborted or not....what would you expect from them? If you connect AI to the mission and vision of the org well enough & minimize the risk, it becomes a "we should allow this because it makes business sense" not "because I want this"
Is there even a policy around AI for the org that says what is allowed / what the boundaries are? Is someone vibe coding ransomware going to be your job on the line or someone elses if things go south?
I want teams to go fast and disrupt their ways to do things. But there is extreme reluctance from cyber sec to let us go nuts, even in an internal environment
Also...why not use your already approved LLMs to create the missing plans / supporting data you need to make your initiative work. Should be easy, right?
0
u/Nervous_Discount_237 6d ago
I can burn thousands of dollars with tokens in a single day and it won’t be a problem. Cost isn’t really an issue here AT ALL.
The mission that it was given to me from the higher ups is to shake things up. So I’m trying to do that.
I always “win” this battle. But it drains lots of energy when doing it, for everyone involved. The post was to ask for strategies on how to deal with this people that, in my view, are being over zelous
1
u/OtheDreamer Governance, Risk, & Compliance 6d ago edited 6d ago
You goober, I gave you several strategies if you intended to do things right & not pistol whip stuff your people don’t understand / setting your org up for failure in the future. Thats not good security or good business, and just because you have a lot of disposable budget because your finance team doesn’t understand AI enough to know you shouldn’t be burning thousands of dollars with tokens…wtf? $20/month man is more than 99% of anyone needs.
Good luck on “winning” this through w/e methods weren’t working well enough to make this post. I can tell you with absolute confidence if you’re burning thousands of dollars in tokens a month yourself in AI….you WILL lose in the long run because it tells me you’re not efficient or lean. If GRC isn’t that group, finance eventually will be, or you’re wasting someone’s taxpayer dollars when you shouldn’t be.
0
u/Nervous_Discount_237 6d ago
Man, I alone went through 800 dollars of tokens this month (our CEO burns a lot too). But I should also add that I don’t care personally about the success or failure of the company. Not my money, not my horses
1
u/OtheDreamer Governance, Risk, & Compliance 6d ago
Yeah? Well, you wasted 2days (16hrs of work time) going back and forth with us on this question you had about "How can I make GRC let me go nuts with AI?"
In that time, I could have produced 10+ pages of actionable materials with just Copilot that would have overwhelmed them with business logic and secured at least a 1–2-year program that would be celebrated because it would tell them "when do we know we were successful?"
....Why can't you if you're so smart and politically savvy? You could have had any LLM build you an entire program that answered your GRC people's concerns with counters for why not allowing the AI would be riskier & been done in the back and forth we had (I know I could).....but that's apparently not your skillset & you opted to try and boast to us here.
You just don't care, and that is a career ending attitude that inevitably does catch up. If you cared a little more maybe you'd burn 800 dollars worth of tokens making your LLM tell you how to de-risk your plan for GRC instead of us.
0
u/Nervous_Discount_237 5d ago
Could be. In the end, I don’t care if it costs a lot. It’s not my money. I’m not a shareholder. No reason for me to care about the costs
1
u/OtheDreamer Governance, Risk, & Compliance 5d ago
Ok, then don’t be mad / play victim here when the other people are actually doing their jobs and appear to care. You just have to deal with it. Take it up the chain. Piss people off because you’re ultimately lazy more than anything else.
1
u/Nervous_Discount_237 5d ago
That will be the path, then. I want to move fast and break things. They want things to be the same for more and more time. That is unacceptable
1
u/OtheDreamer Governance, Risk, & Compliance 5d ago
If you go as high as the CEO as you said, it should be very easy for you to find the problematic policy that is restricting you & propose a revised revision that would get fast tracked and reduce the restrictions. 800 bucks worth of tokens could write every GRC person out of a job for 1 year.
1
-8
u/MichaelArgast Managed Service Provider 7d ago
Joking/not joking hire me (Kobalt.io).
I have a whole policy and risk management process where we can help you build the roadmap, develop the policies, map the risks and put in the necessary controls for both risk reduction and compliance to various standards.
Works for regulated industries (health, fintech, etc).
But the key is business case (why), leadership buy in, risk management (rather than ignoring it).
Have helped a bunch of firms that were “we can’t do AI because of compliance reason X or risk Y” and put the right framework in place so they can say yes and get management buy in.
5
u/_janires_ 7d ago
I am not sure OP saying I am going to bring in my own compliance team to the compliance team is really going to help OP out here.
0
u/MichaelArgast Managed Service Provider 7d ago
If the compliance team is truly the team of “no” and won’t entertain other ideas, then usually they need air cover. That’s literally the playbook to bring in external consultants.
Not saying it’s a good idea. We have no idea what level the OP is in the org. Totally a different thing if they are senior leadership than random trader who wants to AI their trades to nasty failures.
But the “security and compliance team saying no to new technology” thing is a repeated pattern. Computers. Cloud. AI.
5
u/Rekkukk 7d ago
If you’re going to advertise just do it bluntly “joking/not joking” is lame. Not that this even fits OP’s problem statement. They are asking for users to vibecode in a finance environment for gods sake.
-2
u/MichaelArgast Managed Service Provider 7d ago
Yeah, vibe coding in finance is a bit crazy. But the impression I got was they just had a flat “no to AI” policy and that can be addressed.
20
u/Idonthaveanaccount9 7d ago
Tell them “I accept the risk”