Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cyber pros must grasp the vibe coding nettle, says NCSC chief | Computer Weekly

By Computer Weekly by By Computer Weekly
March 24, 2026
Home Uncategorized
Share on FacebookShare on Twitter


Cyber security professionals must embrace a narrow window of opportunity to develop safeguards around AI-enhanced software generation – popularly known as vibe coding – or risk losing control of the narrative and exposing organisations to cyber attacks and other disruptions, National Cyber Security Centre (NCSC) chief executive Richard Horne has said.

In a keynote speech delivered at the annual RSAC Conference in San Francisco today, Horne called on the security community to work together to develop safeguards around vibe coding, highlighting how modern-day society faces ongoing and fundamental issues with technology thanks to exploitable vulnerabilities.

However, Horne also argued that while it was true insecure software produced without human eyes on the code could propagate vulnerabilities far and wide, well-trained AI tooling could yet create software that is secure-by-design, which would be transformative for cyber security outcomes throughout its lifecycle.

“The attractions of vibe coding are clear. Disrupting the status quo of manually produced software that is consistently vulnerable is a huge opportunity, but not without risk of its own,” he said.

“The AI tools we use to develop code must be designed and trained from the outset so that they do not introduce or propagate unintended vulnerabilities.”

Horne said cyber pros also have a responsibility to ensure that the future in which vibe-coding and other AI code-generation tools are widely adopted proves to be a “net positive”.

New paradigm

In a thought leadership blog published alongside Horne’s speech today, senior NCSC technical leadership argued that while vibe-coding poses an “intolerable risk” for many organisations as things stand, the trend offers “glimpses of a new paradigm”.

Indeed, wrote the agency’s architecture CTO, AI-backed coding could ultimately prove to be as much a technological revolution as software-as-a-service (SaaS) – pioneered at the turn of the century by the likes of Salesforce – proved to be.

While careful not to state that organisations will suddenly use AI to whip up a replacement for their CRM tools or other platforms, the NCSC said there are now clear indications that the cost versus effort curve for ‘bespoke enough’ software is shifting and as such, more and more organisations will soon begin to make different choices when it comes to software.

Given the many security concerns around SaaS – such as appropriate authentication and access controls, misconfigurations, and third-party risks –  which have never really been fully addressed to the satisfaction of all, this therefore raises the question of what technology, guardrails, platforms and assurances does the security community need to have in place to ensure that the vibe-coded future is safer than the status quo.

Things to consider

Some of the safeguards that security leaders need to start to advocate for are obvious, said the NCSC. For example, AI models must be schooled in security-by-design, humans need to have confidence in the provenance of the model and trust that it hasn’t been badly-developed, and thought needs to be given to how AI can be used to review both human- and AI-generated code.

But there are also more nuanced questions, such as how to use deterministic architectures to limit what code can do should it prove malicious, compromised or unsafe, what platforms need to be designed to host AI-generated services that implement the needed controls to protect data and users, and how AI might be used to ensure the security hygiene of software through practices such as documentation, test cases, fuzzing, or updating threat models.

The NCSC noted the possibility of a future where AI code is more restricted and locked down than even the most secure on-premise or SaaS products ever were.

Ironically, it concluded, this may at long last address the unsolved security issues that still dog SaaS and that have prevented the last, most cyber-conscious hold-outs from going all in on the cloud.



Source link

By Computer Weekly

By Computer Weekly

Next Post
Jamie Dimon says Iran war makes Middle East peace prospects better in the long term

Jamie Dimon says Iran war makes Middle East peace prospects better in the long term

Recommended.

SmallRig annonce un changement stratégique lors de ses débuts au CES, en recadrant l’innovation en matière d’imagerie autour de la création quotidienne.

SmallRig annonce un changement stratégique lors de ses débuts au CES, en recadrant l’innovation en matière d’imagerie autour de la création quotidienne.

January 21, 2026
PC AGE Offers 0/Month Stipend & Scientifically Validated Computer Aptitude Test to Help Women Break Into High-Paying IT & Cybersecurity Careers

PC AGE Offers $200/Month Stipend & Scientifically Validated Computer Aptitude Test to Help Women Break Into High-Paying IT & Cybersecurity Careers

June 19, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio