In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across the software development lifecycle.
We dig into AI’s accelerating impact on AppSec and the SDLC, the productivity-versus-risk equation now that agentic coding tools are landing pull requests with minimal human review, and the so-called “Vulnpocalypse” – the explosion of CVEs, AI-generated code, and the widening gap between vulnerability discovery and remediation capacity. We explore whether legacy AppSec tooling categories like SAST, DAST, SCA, and ASPM can keep pace, or whether they’re being fundamentally reinvented for an agentic world.
Katie also shares her perspective on the rise of autonomous pen testing and offensive security agents, what it means when attackers operate at machine speed while defenders are still triaging tickets, and how practitioners, CISOs, and security leaders should be rethinking team structure, skills, and governance for an agentic SDLC.