September 3, 2026

Vibe coding is fun. Security Incidents aren’t.

David Mundackal

I recently vibe coded a small macOS app. My intention was not to create a perfect product, but to explore whether this user experience (UX) would genuinely simplify developers' workflows. 

So, I opened my editor, asked AI for help, rewrote things whenever I felt like it, threw away code without thinking twice, and by the end of it, I had something people could use.

It was fun!

And honestly, that’s exactly what vibe coding should be.

The goal wasn’t to produce perfect software. The goal was to validate an idea.

If the experiment failed, I’d learn something. If the app crashed, I’d ship a fix.

If users loved it and it eventually needed to support thousands of people, that would become a different engineering problem. One that deserves proper architecture, testing, reviews, observability, and people with deep expertise.

Vibe coding helped me answer a question. But it wasn’t the final answer.

However, when it comes to an organization’s security posture, you don’t have the luxury of trial and error that vibe coding affords. 

Consider this: Your AI tool recommends a critical remediation. 

Do you approve it? On what basis? What evidence supports it? What's the blast radius if it's wrong? Which business-critical systems are affected? Is this an actual risk, or just another isolated finding? Can you explain the decision to your board? Your auditor? Your incident response team?

These are all important questions that must be answered quickly and with little margin for error.

The reality is, AI without context is reasoning in the dark.

Enterprise security isn't another side project. It isn't a weekend experiment. It isn't something to be released abruptly with subsequent corrections delayed to a later date. Every recommendation implemented carries potential consequences. Every permission you remove might disrupt essential business operations. Ignored alerts may escalate into incidents the following day. Overlooked configurations represent additional opportunities for malicious actors. The pertinent inquiry is not whether artificial intelligence can generate code or tailor-made solutions for your needs; we are already aware of its capabilities.

The real question is whether AI sufficiently understands your organization to recommend that you would genuinely trust.

Most organizations already possess highly effective security solutions, including identity providers, endpoint protection, cloud security, email security, compliance tools, and vulnerability scanners.

Each one is incredibly good at addressing the specific problem it was intended to solve. However, each also captures only a segment of the overall environment. 

This situation is comparable to the well-known parable of the blind men describing an elephant: one touches the trunk and perceives it as a snake; another grasps the leg and considers it a tree; a third feels the tail and assumes it is a rope. None is incorrect; they merely lack the complete perspective. 

Similarly, enterprise security often presents a fragmented view, where each tool reports an aspect of the truth, yet none provides the whole story.

Before You Take the Bet

“Risk comes from not knowing what you’re doing.” — Warren Buffett

I've always had a simple philosophy: understand the maximum cost of a decision before making it. This does not imply that I avoid risks. Quite the opposite. Sometimes I'll take a bigger bet. Sometimes I'll venture into uncharted territory driven solely by curiosity. I might develop a project over a weekend, experiment with a new technology, or pursue an idea without a definitive notion of its ultimate outcome. Nonetheless, these are choices I willingly accept as my own risks. I know the downside. I know who bears the consequences if I'm wrong. I can accept the chaos.

That's the difference.

Organizations don’t get to gamble that way.

Every new piece of contextual information enables more informed decision-making. Conversely, missing information amplifies uncertainty. Every decision carries a cost. A permission that's too broad. An ignored vulnerability. An exception that quietly becomes permanent. A policy that's disabled because "nothing broke."

None of these decisions happens in isolation. They ripple through identities, devices, cloud resources, applications, and compliance standards, ultimately impacting the organization’s business operations. So before deciding, wouldn't you want every piece of information that could help you understand the risk? Every dependency, relationship, historical change, and piece of evidence that explains why a particular situation may be considered risky. Equally important is understanding the reasons why immediate action might not be necessary in certain cases. After all, effective security is not about indiscriminately rectifying every issue. 

It's about understanding what matters, prioritizing what truly reduces risk, and confidently deciding what can wait.

Every additional piece of context reduces uncertainty.

Envision performing this task continuously, not manually switching between ten different dashboards, nor relying on a large language model to infer information based on a prompt. Avoid attempts to tokenmaxxing over the weekend in search of solutions that no single tool was designed to solve.

Challenges in establishing correlations can cause AI to hallucinate; however, an AI that understands your environment, continually develops context, correlates signals within your organization, highlights what genuinely matters, and explains why—rather than replacing your judgment—provides the essential context to enable superior decision-making.

The Discern Loop – Close the Gap

"AI can write software. Trust still must be engineered.”

AI is not here to eliminate risk; it is here to continually diminish uncertainty around that risk. The Discern Loop is our way of turning that premise into practice.

That means:

Only once the system has this grounded understanding does AI enter the loop. Instead of hallucinating patterns from raw logs, it reasons about a known, mapped reality: what’s exposed, what’s exploitable, and what’s material to the business.

You may never eliminate risk entirely. But with a system that understands first and lets AI reason on top of that understanding, you can make the gap between assumed and actual risk meaningfully smaller, every single day. That is the promise of The Discern Loop.

Experience the future of security
with a collaborative mesh
ecosystem powered by AI

Let's Talk