BSides Joburg 2026

Turning Roadkill into braAI-VibeSDLC
2026-07-25 , Track 2

Anyone got a light? When the CEO or product people send you a zip or github project do we burn or braai? Corporate and enterprise level AI enabled development is another beast in of itself. This talk reflects 3-6 months of rolling out claude code enterprise to 200+ engineers securely, turning agentic roadkill into a product with AI-SDLC and how you can shine the light in the generative darkness.

Often the discussions start with a solution seeking a problem. Ample opportunity to search for problems that kill the project. Who is this for? Why? How much will it cost? Saving $3000 a year on SAAS licence can often translate into $30000 engineering time and fines way above that when you vibe-exfiltrate your company's data.


Remember that scene where Grommit lays out the track while the train is going down an unbuilt section in Wallace & Grommit. Well thats what enterprise, AI coding agents and AI productivity tools rollouts are like in 2026. CTO says we need AI agents yesterday, MDM reports everyone has had it for a year anyway and your CISO says what are our controls.

This is the war stories of a SOC and DevSecOps team rolling out agentic controls as we figure things out. This is a pro-active vs reactive story of all the disucssions, policy work, controls and incident response over the period.

The talk will cover the following topics:

  • Rolling out claude code enterprise
  • AI agent controls
  • Sandboxing
  • MDM and EDR
  • OTEL for Agents
  • Costs: economic, incident, cognitive load
  • SDLC in the agentic era.
  • When automation goes wrong.
  • Security team leading the way with the torch of controls, education and setting the standard.
  • Opportunities for security team to use the tools for creating tools, vuln discovery.
  • Security validation testing on these controls

Takeaways:

  • Agents, LLMs, etc pros and cons.
  • Infosec, Dev, Devops, Infra, etc have always been early adopters. Better they debug tech than the general public debugs medical answers.
  • SDLC is still relevant, might need tweaks
  • Ownership is key, claude doesn’t own your code, your responsibility remains
  • Trust but verify
  • Sandboxing is back
  • Enterprise is king ($$$$)
  • Manage risk, enable efficiency
  • Lead by example, get devs interested and involved.

DevSecOps Lead, AI/ML. Hacker, tinkerer, builder, breaker.

BSIDES Cape Town organiser.