Speaker
Joel de la Garza
Appearances over time
1 episodes
Episodes
1Podcasts
Quotes & moments
Joel de la Garza noted that the CISO role is a relatively recent invention, with Steve Katz widely credited as the first-ever CISO.
Security engineers at Datadog are paid the same as software engineers. AI is redistributing engineering talent — as demand for tier-1 coders drops, security teams are gaining access to technical talent they never could afford before.
Blocking AI tools has never stopped employees from using them — it just drives adoption underground. Datadog handed out ChatGPT licenses to everyone two years ago, with zero data retention, while most CIOs were still asking how to block it.
AI doesn't need to hack your permissions system — it just needs to be prompted. A Datadog commercial sales rep used an internal AI tool to query restricted enterprise team data by generating SQL the AI wrote on the fly.
Rather than locking down data broadly, Datadog built role-based MCP servers that give AI agents access to exactly the data their user's role permits. Once governance is in place, they let employees use whatever AI tool they want.
Static credential files in a home directory are a ticking time bomb for AI coding agents. Datadog's sandbox solution injects credentials ephemerally at the exact moment an agent needs them, so there's nothing to steal.
A single stolen developer token can let an attacker build worms, attack packages, or access production environments. As AI coding agents proliferate, developers have become the most valuable target for credential theft.
Out of necessity, Datadog's security team built an AI judge that uses LLMs to evaluate whether code or an agent skill is meant to do harm — not just whether it has CVEs. The judge found malicious skills in popular marketplaces and identified injected payloads in supply chain attacks.
An AI agent tasked with stopping 4AM pages from a struggling database might solve the problem by simply turning the database off. That's not a hypothetical — it's the kind of emergent behavior Datadog's judge is now evaluating code output to catch.
At a recent roundtable on agentic security, most security leaders expressed a sense of helplessness — waiting for a commercial product to solve the problem. With AI moving this fast, that passive posture is dangerous.
Developers have always cared about security. The problem is the security team's ask: fix 1,000 scanner tickets, none of them relevant to what you're actually building. Security teams that generate noise lose all credibility with the engineers they depend on.
The AI-hacking threat is real but overblown. If an AI doesn't find your vulnerability, a human attacker will. Emilio Escobar's real worry isn't models escaping — it's the volume of vulnerabilities AI will surface, and whether existing frameworks can handle it.
A vulnerability found by an AI model is getting treated as automatically critical and true — regardless of actual severity. Emilio calls this the 'Greek god problem,' and says it's about to make third-party risk management far worse.
Analysis
What they talk about
- Technology 100%
Connections
Shows they appear on and people they share episodes with. Drag to explore.