From “Shift Left” to “Vibe Coding”: Redefining Secure Development with Ox Security’s CEO Neatsun Ziv
Neatsun Ziv, Co-founder and CEO of Ox Security, critiques the shift left approach in software security and introduces vibe coding as a proactive method to ensure secure code. The conversation emphasizes developer accountability and the shared responsibility model, while also addressing the skepticism developers have towards AI in coding. An upcoming Vibe Sec online conference is announced.
Transcript
Hey everyone, it's Alan Schmo. Welcome back here to Text Drunk tv. I'm happy to have my friend Tson Ziv Nisson, co-founder and CEO of Ox Security here on Text Drunk TV with us.
Mitson, welcome back. How are you? Great.
It's a pleasure being here again. Always a pleasure to have you on. So Meetin, look, not everyone watches every interview we do on text Drunk tv, believe it or not.
But, uh, they may not have seen me talk with you before, though you've been on a number of times. For people who aren't familiar, why don't you give them a little bit about your background and how you came to found or co-found OX security? Uh, sure.
Uh, so about 15 years ago, I joined, uh, checkpoint. Uh, and for about 10 years I led the cybersecurity business unit over there. And it was a pleasure to see how a big company and the super impressive company is growing from the inside.
But then we started seeing the world is starting to move to code and we asked ourself, okay, where is it going? What's, what's next? How is this going to evolve?
And we understood that the code is the essence of everything. And we said, if we can find better ways to secure code, that would be an amazing future. So we tried different products in the market, we tried implementing Shift left, and I think we kind of got to the consensus that shift left is dead, it doesn't work.
And this is how we started our journey saying, um, you know, it's, there's so many different opportunities to help other people, uh, protect themselves from software supply chain, from EC risk, from cloud risks across the board that are just risks and it needs to be easy for the developers. Excellent. Well, that, that really was the problem with the devs sec, uh, shift left is it wasn't easy enough.
It wasn't easy, easy enough for security people, let alone easy enough for developers and, and developers. It's not that they wanna make insecure code, but you can't expect them to be security professionals either, right? They're, they're developers, they develop code, they're not security pros, but this is what led, of course, to the founding of OX Security, that's OX security and give us kind of a low down on OX security and what it does needs.
So think about OX as the platform that connects to your current environment, from code to build to cloud, to understanding your APIs, your data sources, your threat modeling, your runtime environment. And from this goes back to the developer's environment and inside development environment, especially in Vibe coding world is able to inject this as a dynamic context into the Vibe coding agent. So new code is actually written with security guardrails built into the code.
So instead of thinking about it in the old way that we had like Waterfall and then we had to do quarterly scanning, and then we moved to CICD and it was a gate, and then we started automating Jira tickets, it's why are we creating those problems? Let's give the right context to the vibe coding agent saying, Hey, this is going to be an API that is externally facing. Why don't we take this and make sure that we build a code in the first place with those five protections?
'cause we already have the context. We already know how to explain to a developer, why aren't we explaining it to a vibe coding agent that can take this and actually do this for you? And I think this is kind of the, the latest announcement that you've done with aox, which is what we call vibe sec Vibe security.
I love it. Vibe sec. But well, look, I remember sitting here on the set of Textron Gang the first time I heard Vibe coding and kinda laughing and thinking, oh, this, what kind of joke is this?
It's no joke, right? It's a real, It's it's Q2 2025 right now. It's like mm-hmm.
Like yeah, imagine that. Right? And here we are going into Q4, but so Vibe sec Now, vibe SEC is to prevent vibe, code vulnerabilities, right?
To bring better vibe, better quality vibe code, let's call it that. Is that fair? I think it, It, it is fair.
I'm saying that there are two, actually two different kind of problems. One is new code generated, and of course it has its own varied. It's like, okay, I'm using VI coding, there's a lot of drift.
How do I make sure that my security, um, I would say restriction right now actually being kept in the code and nobody's removing them. Simple questions. Other questions?
Yes, I understand this is going to be super important. When do I need to implement, uh, rate limit? When do I need to implement, uh, flags to make sure that I'm protecting from CSRF?
When do I need to to make sure that I'm protecting myself against, uh, for example, parameter injection? All of those come into play by understanding the broader system and injecting them. That's absolutely fair.
The second thing is you already have a lot of backlog. Some of those things are getting very close to the SLA saying, Hey, there's a high issue here. We already agreed it needs to be fixed within 30 days.
How do we interact with the developer and make it easy for them saying, Hey, you're getting to this SLA in, in 24 hours. Would you like me to fix it for you? So we won't be on the exception list.
And with a simple yes, since we already had the, uh, agenda remediation for a few quarters, we just integrated in saying, why don't you just bring everything to the developer in an easy way, just, do you want to fix it? Yes. Done.
And instead of making the developer upec practitioners we're saying, no, no, that's, we, we've tried it for 15 years. Shift left, failed us, right and left. The only way to go is simply going back to the vibe coding saying, Hey, do this for us.
We're a new age in an AI age. We don't need to do the shift or lift and shift like we used to do. We can do it smarter in modern ways.
Vibe sec. That's what easy we're calling it. Vibe sec.
Hey, I love it. I I love that you, you kind of went out there and branded it. Um, so it needs in the, I I guess the question becomes who's responsible for making sure this is indeed working right?
That the code is in fact secure, that these vulnerabilities never get generated? Is, is this like something the developer now gets to do? So it, what you're really telling me is maybe you took a second bite at the Apple, a shift left, and maybe we'll get it right this time.
Or is it No, we still, we get it. The developer's not a security person, but with, with Vibe Sec and, and the security team, we can, we can, you know, in essence, head this off at the pass before the developer gets him, you know, has to do it himself. Uh, I think that the answer is that even though it's not a very, I would say nobody likes to say it out loud, developers don't feel accountable for security.
Yes, they do it because they're forced to. Yes, if you implement enough culture and incentives and guild and, and you, you build around, you will get corporation. But it was always security's accountability to make it happen.
Now, we invented a few models in the industry like shared responsibility. Now for me, whenever I'm hearing shared responsibility, I'm, I'm hearing it's like, okay, if something goes wrong, who's the person that I'm blaming? And somehow it's security.
So security is accountable, it's developers are responsible. And while collaboration is probably the ultimate goal to make it happen, and you need the developers security need to create the culture, the rhythm, the agreement, the alignment, it's up to them to make it happen. And in this new world, we're saying, Hey, if we don't need the developer not in a bad sense, in the sense that we don't need to bother them with that, we can actually tell them, Hey, this is kind of what we need to do in order to pass security instead of bothering them.
I think it's a way better way for everybody to, to enjoy this benefit. And if we're getting it out of environments like cursor and copilot and, and cloud cloud, we should definitely take advantage of this to make sure that we're, we are delivering the best and the be and the most secure products out there. I agree with you.
I agree with you. Um, so look, our audience is a little of this, a little of that. We've got a, a lot of cybersecurity people we've got, but we also have a lot of developers.
We have a lot of cloud native engineers, DevOps engineers, uh, platform engineers. Where does this, where do you, where do you put this, right? Who, you know, who, who's responsible for getting this rolled out and getting it out there?
I think that, uh, 95% of the time it's the application security team or the product security team. These are the guys that are accountable to make it happen. It's always the CSO organization.
Even though we, we've seen developer teams that are trying to implement this, it's one of those program that unless you've got ongoing support and tracking and monitoring, end, end, end, end, end, uh, you're, you're constantly be accommodating backlog. So somebody needs to be accountable. It's not something that you can do just as you go and swing it.
You, you kind of need to have an accountable person saying, I understand the products we're really seeing have access to our data. It has access to our customers. We need to protect them.
Usually at this point you have somebody saying, I'm accountable for product security. Fair enough, fair enough. Um, a lot of people are, uh, what I'm trying to think of a, a, uh, a, a de a delicate way of saying this, but a lot of people are falling out of love with the whole AI vibe, coding thing, let's say, right?
Where you know, it, it's, you know, in recent study we saw 90% of developers are using AI to generate code. 40% of them don't trust it. Two thirds of them, almost 65% say it, it, it, it, uh, injects instabilities into the code, but yet 90% of them are using it, right?
So 90% use it, and it's, that means a good chunk of that 90% think that it injects instability and code. It, it, they don't trust it, but they yet they're using it. What does that mean?
What does that mean for Vibe Sec? Is, is that a reason why we need Vibe Sec or what what do you, what's behind that? I, I think it's, it's a very good question because the answer is basically changing on a daily basis.
We are in a place that moves so fast with so many alternatives, and the models themselves change so fast. The the IDs change so fast, meaning cursor, every few days you, you'll see an update. Yeah.
And you're using, uh, right now Cox, CLI and you're using Claude, meaning, it, it you are still experimenting. We are still in the bleeding edge right now of this revolution. So if you're asking me, do I trust this?
No, I do not trust this. Do I use it? Of course I use it.
What do you mean? Like, if, if I'm not using this right now, I will find it very hard to do my job without AI and, and saying how come it, it doesn't make any sense. Like you don't trust it and it, it's become, yes, you are right now in the traditional, um, trust but verify in the sense that I will write something, I need to read it, I actually need to verify it and I need to do small changes.
And everybody knows that if you've got this long dash, then it means that it's written by eyes. So yeah, you kind of need to edit afterwards. So there are a lot of things that you need to understand and you need to understand how to work with this new technology.
It's not just, oh, I'm going to this technology and it'll be fine. You need to change yourself in order to be better with this technology. It's like, uh, when we, we started having Google like back in few good years ago, um, you need to learn how to search things.
It's not that you're just saying, I just want to search for it. It's like, you need to search, I need to add this word and that word. The same thing goes with ai.
You need to understand context and what does it mean? And this is kind of the fine line between getting the ultimate answer and getting and hallucination not enough data. You'll fall to this edge.
You, you'll provide enough data, you're going to get amazing results. So it's an ongoing process that I think that is accelerating super fast. Agreed, agreed.
You know what, we, we certainly live in a very interesting time right now where we're gonna see how these things all play out, unfortunately need some, we're almost out of time for people who want to, uh, learn more about Vibe SEC and what OX is offering with it. Where, what's the best place for them to go. So we are organizing an online conference, uh, called Vibe Sec K on the 4th of November.
Uh, I think we got got a few good thousands of participants already. Um, so how go over there? We're going to have a lot of collaborators, a lot of people telling us from the CSO perspective, from the AppSec perspective, from the dev perspective, from the research perspective, it's like, where are we going now when we are thinking about it?
It's, we used to have like a yearly conference on something, but at the pace of the, of the current evolution of these products, every quarter you kind of look backwards and say, oh my God, we didn't understand anything last quarter. We kind of need to rewrite the playbook. So we understand that this is just, uh, step number one and we're going to continue and do this as, as a public resource for everybody.
Excellent. That's November 4th. It's a virtual event or in person?
Virtual. Yes, it's a virtual event. We're gonna have a physical event In Q Q1.
Yeah. Oh, you gonna do a physical event in Q1? We are going to do it in Q1, uh, probably very adjacent to RSA.
Oh. So maybe the end of March, Maybe. Um, it's still not locked.
Alright, you'll let us know. Of course. We'll be at RSA, you know, we put on our DevSecOps event the Monday of RSA week in, in Moscone with them.
But then we're live all week on, uh, silicon, uh, not silicon alley, our broadcast alley, uh, video. So we'd love to cover it if you do it there. Let me go back to November 4th though.
November 4th virtual event. Vibe sec con ha. Is there a website or URL we can send People?
Yeah, it's vibe SEC io. Well, on OX website is OX security. Do I Ox security?
Yes. Ox security. That was it.
Exactly. And you could get and they could get to it from there. Exactly.
Perfect. Neat Sun as always. It's great seeing you.
Thank you very much. Keep up the great work. We'll be watching the development of vibes.
Sec. Pleasure seeing you. All righty.
Bye-bye. Bye-bye. Neat.
Sun Ziv here, co-founder, CEO of OX Security. We're gonna take a break. We'll be back in a minute.