
Helping AI agents understand what secure means for your business #06
Second part of my conversation with Erlend OFTEDAL - AppSec and AI security researcher. CHAPTERS (01:23) - DORA state report (link below), improved delivery throughput, but also increased delivery stability (05:25) - Planning stage: shifting the focus from attacks to defensive code and security principles (09:03) - Teaching AI agents to write more secure code is sort of the same thing as teaching developers to write more secure code (12:08) - Planning stage: the typing was never the bottleneck. The thinking was (15:45) - With AI writing code, how do you bring security into the development process? (20:29) - Security team being able to ask AI how secure the code is (22:38) - What we need to do right now + AppSec and AI agents (27:21) - Choose the right AI agent for the right purpose (e.g. Claude vs Opengrep) (32:03) - Leverage AI to analyse legacy code to find vulnerabilities, Firefox example, etc. (38:22) - Last words LINK MENTIONED 2025 DORA State of AI-assisted Software Development report: https://cloud.google.com/resources/content/2025-dora-ai-assisted-software-development-report GUEST Erlend OFTEDAL- AppSec and AI security researcher LinkedIn: https://www.linkedin.com/in/erlendoftedal/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.