The AI Security Edge – Application Security and AI with Francesco Cipollone | Ep 8
Caroline Wong welcomes Frank – Francesco Cipollone – to The AI Security Edge podcast for a somewhat controversial discussion about the upcoming AI Security Manifesto. The manifesto is Frank’s way of pushing back on AI hype. It stresses human-first, AI-second, responsible adoption, and a focus on using AI where it truly enhances workflows rather than replacing people or chasing trends.
Transcript
Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders who are shaping the future of digital defense. I'm your host, Carolyn Wong, tech Strong TV podcast features your favorite video series, industry thought leader commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders.
The AI security edge dives deep into the evolving cyber battlefield where AI-driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back. Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, we hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense.
Today's guest, let see if I can say this right. So there's an American version, which is Francesco Sip, but then I'm gonna sip, poona, sip. I tried.
And then, and then, and then the proper version. We're gonna try Francesco Chip. Yes.
Boom. Way better now. Okay.
I'm like extremely proud of myself for that, but you know, just, I think that might have been like a onetime thing. So we're gonna call you Frank. Frank, thank you so much for joining us.
Frank. Frank is a cybersecurity leader, entrepreneur, and thought provoker. He is at the forefront of application and cloud security.
The most important thing that you need to know about Frank is that he was a practitioner, and now he's a CEO. He is the founder and CEO of AppSec Phoenix, also known as Security Phoenix, a company that is pioneering contextual, risk-based vulnerability management from code to cloud. Frank has done all sorts of cool stuff at HSBC, at AWS, at the UK and Ireland chapter for Cloud Security Alliance.
He's a professor at Ions. He is a multi award-winning podcast host. It's actually weird for Frank to not be the host right now.
He's a regular keynote speaker, he's an author. He writes books, white papers, articles, and, uh, he's also a self-taught artist and a former professional skydiver. So if this is the first time you're meeting Frank, I'm so excited for you because you know what, Chad cheap t uh, there, which is actually like, that's an AI use case, right?
Um, if this is the first time you're meeting, Frank bore you in for some good stuff because there's so much good stuff. Frank, welcome Caroline, as always, you shine. Thank you for having me.
So Frank, what your find all this stuff, Everyone. Uh, literally it's chat, GPT. So everyone on this podcast, I, I like to ask the same questions, but, but you're not like a, you're not like a typical podcast guest.
Not really. And so I'm gonna ask you a different question, which is tell me what you actually really think about all this AI stuff. Tell me the real brutal raw truth.
It's a bubble. Uh oh, Uh, it's a cool Bubble. Okay.
Okay. Tell us more about this bubble. com or not as experience.
Instead, right now, we have organizations still trying to figure out how to prioritize vulnerability, how to do cloud, how to do software, while attacker extremely enthusiast about, Hey, let's use this technology, or let's weaponize the model that are trying not to do it. And I think Tropic has published, uh, a recent playbook on how attacker are creating new method and way, and they, of course, they're trying to stop, they're trying to ban them, they go through, but we start seeing case where LLM are weaponizing vulnerability or are being used to attack ransom. So AI has lowered the barrier of, of, of access for cybersecurity professional, but also for attacker.
And we were overwhelmed before, like I think right now the difference between the dotcom bubble and right now is we're seeing this technology put exciting, but we're seeing it as faster growing as a weapon and as any new technology, we are seeing the rush to market. Of course, Trump insecurity read us as MCP because API security wasn't hard enough, so we needed to have GraphQL. And one of my good friends is saying, I love any GraphQL because I can hack the way through it very easily.
And because that wasn't sufficient, we had to create MCP. Actually, we release our MCP server and we shut it down for security concern. I'm proud to say it because we did a threat model on that and saying, that's not good enough.
But how many people out there are throwing the MCP out in the ward and saying, yeah, it's secure enough, right? Frank, I I have to pause you for a moment because there are folks listening and watching who know what GraphQL and MCP are good for you, and there's people who don't. So for the folks who don't give us a little bit of background, talk to me as though I'm my 75-year-old mother-in-law, or my 10-year-old daughter.
I, I think you might be right. I, I get over excited about technology sometime and I think that everybody lives in the world of stuff that my brain leaves. Um, sometimes Only the really smart ones, All the crazy one.
Uh, but thank you for the compliment. I think when we look at the internet, we had the history of API that were soap XMLs, a very ancient way to pass data through a system that expose a web interface, and then we kind of settle on rest API. That is the standard method where we taught really, really well and long about how to secure those things, how to create that entity.
So I think rest API has been around for very long time, but for rest API, you had to create basically endpoint for everything that you want to do. And that is means development. So some of the dev team has said, why not throw caution out of the wind and open everything to everyone?
Just query whatever I want and I expose anything that I want. Because that has worked out well for us in the past. So that was the history of GraphQL that you can secure, but it is really difficult to constraint or provide access control because fundamentally you can tell, gimme the information about this, this, and that.
And GraphQL would say, gladly, here you go. Uh, do you have the permission to see that stuff? Hopefully you have your pass through credential or pass through authentication configured.
Most of the time you probably don't. So you create just access to your data lake and if you're lucky, you just see what you wanna see. Um, but it's very difficult to control.
Now, MCP have been built in a rush on a protocol that has two or three version and eight to a was the evolution of the MCP protocol, but authentication was nowhere to be seen. And all to authentication token being passed through or authentication and authorization have been kind of left in the world. So we're seeing MCP being exploded up, down left and right because it's a new technology and because it just rely on not very strong foundation of authentication and access control.
And that's one of the reason why we shut down ours because our API will build with Phoenix security with specific method in mind. So we put, uh, an MCP server in front of it, and it gives, it gives you access in a different way that we want. And we expected, so we did a, like any security folk would do a threat monitoring exercise.
We de the things not secure enough and we say, you know what? Let's leave the hype to the hive and I'd rather not get hacked than feel late for few weeks. Um, and that's what we did, but I think we won the few that actually take that in.
That's so interesting. Uh, humans want to use technology to share information and then they end up sharing it with people that they didn't wanna share it with. And if you're intentional about putting some calls, controls in place, then it takes more time.
It takes intentionality. Um, and now we have not only automation, but we have ai. So the problem is just worse, more data, more places for that data to be more places in our supply chain to poison and to steal information from.
And so Frank, I think yeah, please. When you Have, we have, I've been thinking about this very hard and very strong, like why HLM seems so attractive. It's like, why is so easy to get caught into the perception that we have an answer?
And the answer was there is the fact that LLM always give you an answer despite that it's good or wrong or whatever, or whatever position you have, you always get an answer. It might be wrong, but you always get an answer. So it feels that you're making progress despite that you are actually making progress or not.
And that's the intoxicating element of LLM. You don't know anything about API security, I'll ask LLM to do, teach me about API security. You don't have context, you haven't asked a specific things, but it will return you with some stuff.
Um, hey, I have this code. What does this code do? I wanna do these particular things.
It will give you an answer. It's probably wrong. But that's why the excitement, because the barrier of acquisition have been lowered, the fact that it doesn't always speed the right information is a different story.
And hence why people that understand how AI was built. I was building bias and network and neuro network back 10 years ago when AI wasn't cool. And me and my co-founder understand really well how AI was built and is just a variation of an ai.
And if you understand how it works and how to ask the right question, you become a superpower because it really 10 x you. And I think I'm, I'm surprised by the kind of things that if asking the right questions, it will give you the right answer or it will speed up your work, but also can slow you down tremendously. Or it can create a generation, I think of no brain coder and as an industry, I mean you in threat mode or was we, we, we go long time, me and you, and we are seeing the industry kind of trying to make an effort.
I think right now we are creating a generational of people that don't think securely or they don't even understand what a vibe coding. So that's a little bit my fear of creating a generation that doesn't have the understanding or the baseline understanding, but just go with it and vibe with it. And you can vibe secure coding.
I mean, our good friend Jimani has created a whole training about vibe coding securely. And I think you can, you just need to know what to do and what to ask and how to ask it. And you still need the principle to be in there because AI will not magically secure your application.
So Frank, uh, what I hear you talking about is a comparison. Uh, there is kind of like the no brain way to use ai. And there is on the flip side, a very powerful way to use ai.
And so my question for you is what advice do you have for our listeners to be, not the former, but the latter? How can we all learn to be the best users of AI and not the no brain ones? That is a great question.
And for that, we've broken our manifesto. What, what, what, okay. Uh, It's not yet public.
Okay. So we call, okay, oh my gosh, AI second Tell Us everything. Ai second human first, Ai second human first.
The manifesto tell us everything. So I've been thinking a lot about this, and I think with all this hype, we tend to, we tend to place AI first. You see a lot of company coming out and saying, we are AI first.
AI is gonna solve all of the problem in the world, and it's so cool and it's whatever. No, AI is just a tool. And like blockchain was just a tool.
Let's try not to create solution before we have problem to solve Engineers. And I know, right? But in general, if you, if you treat AI or LLM or vibe coding as a technology, as a tool, and you learn how to use it, you become really powerful.
And I think in few years that's what's gonna distinguish the people that talk about by coding LLM, but they don't know how to use it to people that have experience and know when to use surgically technology for that experience. And hence why we say human first, empower by technology like an LM, like a chatbot, like an AI tool to 10 x their capability. But ultimately you'll never be able to fire an ai.
So decision will never be able to be delegated to an agent. But an agent can 10 x your engineers. So if you train your engineer well, junior and senior to use technology in the proper way, then you have a force of nature.
And I think our attackers have understood that. Well, first, some haven't. Some vibe codes write me the, um, what was it, what's a ransomware letter for the FBI for the director of FBI?
Because we have all of that data. Uh, and somebody has came up with the same kind of things with Google without any proof and without proofreading or so on. But in general, you have people that understand this technology and they wanna use it and AI second, and you have people that put AI first and they will be left second.
Yeah. And hence the manifesto. You know, I'm so excited for this because it truly is the message the world needs to receive right now.
You know, a year ago, and still today, every board on the planet wants everyone to use AI for everything. You know, every engineering team is being told Use ai, use ai, use ai. No one is talking about how to do it properly, how to do it.
Well, boy, is there a difference between doing a thing Yeah. And doing it Well, I, I can't wait. I can't wait.
Who, who, who, uh, who's coming up with this manifesto? Tell us about the creators. So I generate the first idea.
I sent a few of the leader that you well know, Azar, a few others that have done their first pass on it. Um, few other CISO and, uh, thought leader as well have contributed on it. We'll have the full, I think we have 25 right now, reviewers.
We try to mix practitioner and CSO alike and non technologists to actually come up with a message that was sustained by both practitioner in security, field leader as CSO in the security field and non practitioner to actually write something. And we wanted to keep it purposely short with 10 commandments that really say, think about these things securely and think about this as a technology. Like that's the underlying, I mean, we can go through the manifesto, but that's the underlying message of the manifestos.
Like, use tech, use this technology as a technology, use it wisely. Like by code. Absolutely by code the hell of things.
Um, as A-C-E-O-I push for AI adoption, not AI first, but AI adoption to all my engineering community. But also we have guard rails and we have methods of embedding things. And we are actively researching how to insert secure prompts in the by coding thing.
So they will always return a secure vibe coded message or prompt. Like that should be the core of what we do. And the core message of what we do.
It shouldn't be, if you don't use, uh, vibe coding tool by Tuesday you are fired like some CEO have put. Yeah, I think that's the wrong message because that's, that create that people will adopt, people will adopt and people will make mistake because it will delegate thinking to the technology. Well, this should be a thinking eight.
It shouldn't be an outsourcing. And I might be unpopular in this opinion, but I'd rather us going forward with the eyes well open rather than creating, what was it, the movie Terminator? Sorry, I had to throw it in there.
You know, Frank, what I like about this is what I'm not hearing from you is I'm not hearing any fear. What I'm hearing actually is a sense of empowerment. You recognize the power that we have as humans.
You know, do we store tremendous amounts of data in our heads? Yeah, we do actually. You know, do we have decision making?
Do we have discretion? Do we have judgment? Yeah, we, we do actually, you know, and so I'm delighted to hear this sort of elevation appropriately of the human, uh, and who is in charge, right?
The human or the machine better. You can fire, You can fire a machine like ultimately comes down to that. Like you wouldn't be angry at the machine because it does machine job or it doesn't error or it has a bug.
Ultimately technology's technology. And we need to recognize this as a technology. That's we, that's what we, in Phoenix, we created our AI agent as co pilots that aid decision making process, but empower people to make those decision.
Ultimately, we present three remediation plan. We don't know better than the engineer. We give you guidance, we give you insight, we give you direction.
And we say, based on this, and we explain the reasoning as well based on this, this is why we doing specific things. But then if you think that fixing things by a specific asset or fixing things by a specific threats attack vector is better, choose that remediation method. So we want to empower instead of replace human cool and security engineers.
I love it. And a lot of people are scared right now because they, yeah, this technology feels like is is AI is gonna replace or go or come for my jobs? If that's the fear, then you're in the wrong job.
You need to elevate yourself to use technology. I think that's where the fear come from. And you have I think two sides of people that fear a technology because they feel overwhelmed.
And by all mean this uh, scary technology because it seems to be able to do everything and nothing. So either you embrace it or you be left behind. And that's the hard truth.
So it's better to embrace it, use it securely, and be at the front edge of this. But if you were doing spreadsheet yesterday, I'm sorry, this will be replaced. Yep.
Hard pill to swallow. Um, but I agree and uh, Frank, as we're kind of beginning to close up our conversation today, for folks, maybe today's the first time they've learned about Phoenix security. Tell, tell folks about Phoenix security.
So long story short, we were a bunch of practitioner that were leading AppSec and cloud set transformation in most of the banking world. And we wanted to solve a problem that is how do we align executive expectation to engineering action? One of the frustration that we had was when we talk to engineers as security practitioner and as security leader, we tell them, you shall secure your system.
And when they look at us and say, what does that mean? We don't have an answer, or if we have an answer is, well, you need to fix your vulnerability by SLA, oh, you should do threat modeling. Okay, teach me, I dunno, this is a template to use it goodbye.
I don't have time, we don't have scalability. So we wanted to empower, first of all, engineer to understand this is what security expect of you. And then we wanted to align that message with business expectation.
Because if it's not important for your boss as an engineer, you're never gonna be giving attention to a particular problem. So we wanted to solve the problem of security across application security and uh, cloud security. That is called vulnerability management.
That is a problem that we had for 20 past years and we wanted to solve it from a business perspective because that's the only way it actually work. And then in that journey we evolved that with asset inventory. That is also another big problem that we discover in the journey, saying, if we don't know who needs to fix what, how can we tell them to fix stuff?
So we open source our CMDB, yamo based CMDB to empower every engineer to declare this is what I own and I don't have to log into one ancient 1999, uh, black screen with green line system. I can just declare a yamo file inpo. And that's automatically configure Phoenix to say, this is the stuff that this team owns.
So if they have vulnerability and you expect them to fix it, we're gonna notify exactly who needs to fix what, where, and ex tell them why it is important. And in a nutshell, that's Phoenix. That Sounds really cool.
Frank, if you could go back in time and do the job that you were doing at HSBC, what would it have been like for you if Phoenix Security technology had existed? Well, it's funny that you asked because that's where Phoenix was born. Incredible.
We created that for ourself in there because we had that frustration because we couldn't translate an executive saying we should do security. An engineer saying, what does that mean? So we created a way for executive to report this is the percentage of security that we want to decrease.
This is the risk level we wanna go. This is the amount of money that we wanna reduce in terms of direct and indirect impact. And that very high level message that a non-technical, um, or risk base executive can express, could be translated to engineers saying, this is the vulnerability that you need to fix.
This is where you need to fix. And we as security were coming and saying, look, if you look at this library, this system, these things, you actually maximize your risk reduction. So you will look way better for your boss.
So instead of demonizing engineers who were coming and aiding them to get to their target faster, and look, that was four years ago. So it was a very, um, early stage Phoenix. But that's what the gamification from a business perspective and from an engineer perspective is what have enabled us to move from resolution time of 290 days to 20, 30 days.
Nowadays, it's not sufficient anymore because I think with the latest data that we've seen, expedition time fluctuate between three minutes and seven days, depending on what kind of data source you look. So 30 days is not anymore for critical, but if you don't know who does what, probably you are over a year of remediation. Yep.
Frank, last last thing that I'll invite you to consider doing with me. I want you to teach me how to say your name properly. Can we, can we try this together?
Let's, let's try. Please say it and I'll see if I can repeat. So I usually, it's a funny joke and my partner always makes fun of me because I say I go by Frank for friends.
And then if somebody doesn't call you Frank, it's like, does that mean that they're not your friend? So I don't realize it's, it is, it is something that is ingrained right now with me. But if you wanna try in the Italian way and you did it beautifully actually, uh, it's Francesco Chipola.
Francesco Polone. That's great. Yeah.
Okay. I'm so happy. Um, gosh.
Thank you. Thank you So much. You honor Italian now.
Thank you for your time today. Thank you for your wisdom. Thank you for the work that you're doing for our industry.
I cannot wait to read this manifesto and tell the whole world about it. Thank you. Brilliant.
I think you very man need it. But thank you so much for get having me on this side of the podcast. It's my pleasure folks.
Techstrong TV podcast feature your favorite video series, industry thought leadership commentary, analyst research on so many topics including AI and cybersecurity, but also DevOps, cloud Native Digital transformation. Uh, come on over to Techstrong TV podcast to find all of your great content. This has been the AI Security Edge.
I'm your host, Caroline Long, thanks for being with us today.

