Skip to main content

Caroline Wong

Engineer

Aug 12, 2026

MoHOST
10:17
So what does that look like? What does that signal look like when you're trying to automate something at that level and make the human a little bit more efficient?
10:25
You know, I have to say like I am and have always been kind of wildly optimistic about things.
10:31
When I look at AI, I'm like, okay, if I think about my day and the type of things that I enjoy doing in my job and the type of things that I would kind of rather not do, how can i just have ai do all of that like expense reports i think is like a perfect example like i don't know that any of us get a lot of joy out of doing expense reports you know what we're building in terms of our digital twins is if i can just sort of like say hey caroline's digital twin uh you've got access to everything that i do go and do this go and do this research for me you know, go and take a look at this control and actually compare it to my entire policy library and let me know what that's looking like.
11:12
Hey, here's a new piece of information.
11:14
You know, how does this change what my risk register says? Oh, you know, one of the vendors that I've been working with, like they actually just had a change.
11:22
How does that affect my third party vendor risk management? So I think what I'm seeing is security teams we're made of humans, and then we were using legacy security technology.
11:37
I think that the future that's coming at us fast and furious is security teams who then have to figure out how to do risk management for all the AI agents, how to use AI agents to help us with that.

14 MINS LATER

MoHOST
25:44
So I guess where do traditional security controls like really still need to remain foundational and like owned by humans or like processes that we can still have autonomy over versus like, OK, well, like, how do we like really pick the ones where we can just kind of we are OK with losing access to them?
3:30
c the blanket web application firewalls or WAF shield leave the application discovery running in the background and immediately deploy a broad signature based rule across your edge or WAF to drop incoming string patterns matching the proof of concept lastly d the technical evacuation instantly invoke service mesh controls to isolate your highest risk internet facing application segments into a strict zero trust sandbox, breaking peripheral business workflows, but cutting off external input vectors.
4:08
When I'm looking at these different scenarios, then I am interested in understanding what the latest SBOM says.
4:19
I am interested in the Delta because ultimately I really need to know if this extension, if we're even using it, I need to know if we're affected.
4:33
And so that's why A is one of my possibilities.
4:39
I also really like B.
4:41
A has problems, right? Because whatever the S-bomb shows is a point in time.
4:49
Some time has gone on since then.

7 MINS LATER

11:59
The architectural pivot refused to alter the data, but pivot the presentation entirely away from vulnerability counts to focus on your active containment metrics, showing the board what percentage of the network has been isolated.
4:42
What, what's your kinda level? Like, do you have to kind of retain a certain level of fitness to be able to be invited back?
4:50
So, uh, the club does cater for people of different levels.
4:53
I think that I try to maintain a certain fitness level.
4:56
It's actually really hard with winter and the rain and things like that.
5:00
Um, but they do...
5:01
So, like, when you, when you sort of figure out who you're gonna guide, um, typically I think it's like your running pace plus 30 seconds, um, to sort of figure out, because it is sort of harder to run plus talk, plus kind of think about where you're going and notice potential hazards.
5:16
Um, but yeah, it does, it does definitely add the pressure because you do sort of think, "Oh, shit, I don't wanna let someone down," when you're running along.
6:44
Yeah

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.