AI, Pentesting, and Better Security: A Conversation with Caroline Wong
I’m always suspicious of the “straight-line career” story, especially in cybersecurity and Caroline Wong’s path into the field was anything but straight: a little family pressure, a summer internship chosen for its zip code, and an IT hiring freeze that nudged her toward information security.
And honestly, that is part of what makes her so interesting. There is no polished “I knew from day one” here, just a series of practical decisions that eventually became a career. In a conversation with Prescient Security’s KC Garza, Wong moved easily from her unconventional start in security to Brazilian jiu-jitsu, AI, pen testing, governance, and the stubbornly human problem at the center of it all: getting people to fix what security teams find.
The most important part of the conversation, at least to me, was not the shiny AI story. It was the reminder that finding a vulnerability is often the easy part. The harder part is getting an organization to do something about it.
Want to watch the full podcast with Caroline?
Contents
- The accidental origin story of a cybersecurity leader
- Will AI replace human pen testers? Her answer is more useful than a yes or no
- The scariest threat in the room is still not AI
- The biggest pen testing problem is remediation
- AI in security: show the demo or spare us the slide
- The hidden issue nobody understands yet: token costs
- What good AI governance actually looks like
- The real throughline: less hype, more usefulness
The accidental origin story of a cybersecurity leader
Wong tells the story with the kind of candor I wish we heard more often in cybersecurity. No grand five-year plan. No childhood dream of becoming a CISO. Just a series of choices that happened to lead somewhere interesting.
Caroline Wong originally planned to study dance or psychology, but her father’s influence led her to pursue electrical engineering and computer science at UC Berkeley. Her entry into cybersecurity was more a coincidence, it started with an internship at eBay in IT project management, chosen primarily for its proximity to her boyfriend's family and turned into a full-time career in information security after an IT hiring freeze blocked her from other roles.
The rest, as she put it, was history. Two decades later, Wong has worked across in-house leadership roles, chief of staff roles, startup environments, consulting, and product organizations. Across all of it, one theme has stayed constant, she genuinely loves the field, and especially the people in it.
Will AI replace human pen testers? Her answer is more useful than a yes or no
When Garza asked whether AI will replace human pen testers in five years, Wong refused the easy headline. Her answer was basically, maybe, but that is probably the wrong frame.
She pointed out that when she was growing up in the 80’s and 90’s, nobody was dreaming of becoming an information security executive because the role barely existed yet. Security work evolves. Titles change. Technology reshapes the terrain. Smart people do not disappear; they move into the next version of the problem.
That is why Wong prefers human plus AI over human versus AI.
In her view, the best use of AI is not replacing the creative core of technical work. It is offloading the repetitive, boring, low-value parts of the job so practitioners can spend more time on what humans are uniquely good at. That matters especially in pen testing, where creativity is the whole point. Great testers do not just follow checklists, furthermore they improvise, chain ideas together, notice weird behavior, and think sideways. That is something that is difficult to automate, and even where automation improves, the human role may simply become more strategic and more imaginative.
The scariest threat in the room is still not AI
One of the funniest moments in the interview also happened to be one of the truest. Asked which is scarier - an AI-powered attacker or an untrained employee with admin access - Wong answered immediately without having to think about it: the untrained employee. No contest!
It landed because everyone in security knows some version of this story. We love to imagine futuristic attack paths, but many breaches still begin with human messiness, ranging from too much access, too little training, and too much trust in systems nobody is really watching. That answer also captures Wong’s larger worldview which comes down to her being interested in AI but not hypnotized by it.
Wong is now working with Axari, where the original idea was born of what if every CISO had a chief of staff? That concept resonated because most security teams are not overflowing with support. Only the best-resourced organizations can afford layers of security team stuff but many teams are simply trying to survive the week. Axari’s upcoming product wants to give every security professional a digital twin capable of helping with real work. That ambition reflects a real pain point in cybersecurity. Security teams do not usually lack tools but more so time and capacity. Wong is interested in systems that actually do the work and for burned-out teams that distinction is huge.
The biggest pen testing problem is remediation
Wong’s view of pen testing is refreshingly unromantic. Finding vulnerabilities matters, of course. It is technically difficult, and it is often the most impressive part of the engagement. But it is still only the beginning. The real battle starts with fixing them. Once a report lands, someone has to identify the owner, negotiate for time, interrupt other priorities, get engineering buy-in or escalate and keep the issue alive long enough to see it resolved. That makes it transform from a technical challenge to a people-and-process challenge. And in many organizations that is harder than the test itself. The security industry often celebrates detection, discovery, chaining, and exploitation because those things demo well. But many security leaders are drowning not in a shortage of findings, but in a shortage of organizational momentum.
Wong is especially interested in the idea that AI could help here. AI can take over tasks like e.g. tracking down system owners, assisting with prioritization, clarifying what needs to be fixed, and helping security teams move remediation through the machinery of the business. If that happens at scale, it may be one of the most useful applications of AI in security.
Garza and Wong also discussed the shift from slow, once-a-year pen tests to continuous testing. Instead of waiting months for the next report, teams can see what changed, what was fixed, and what still needs attention which makes security harder to ignore.
AI in security: show the demo or spare us the slide
Next up Garza brought up Black Hat and a complaint everyone who attended has heard. This year every booth, every vendor, every pitch deck suddenly has AI on it. Wong’s response was crisp and deeply relatable. Some vendors are doing meaningful work. Some are not. And too often, buyers are expected to be impressed by claims that become suspiciously vague the moment you ask one simple question: How?
She described visiting a major cyber vendor that claimed AI could find attackers hidden in the noise. She kept asking for details. How exactly? What does the architecture look like? What is the mechanism? What is actually happening under the hood? Crickets. That captures the current market perfectly. Real innovation and pure marketing speech are standing next to each other and are often dressed the same. A practical rule from Wong: enjoy the PowerPoint if you must, but ask for the demo and the architecture.
The hidden issue nobody understands yet: token costs
One of Wong’s most interesting observations had nothing to do with attack paths or model capabilities but is all about the money behind it. She argued that many organizations still do not truly understand what AI usage will cost at scale, especially once today’s subsidized-feeling pricing gives way to more realistic economics. Token costs remain abstract for a lot of teams and those budgets are blurry. Today plenty of organizations are using AI heavily without being able to predict what their long-term spend will look like.
That is not a small issue, since security leaders need to know when AI is genuinely more efficient and when a human doing the work is still the better bargain. Maybe even the sharpest anti-hype points in the whole discussion: powerful does not mean free, and faster does not always mean cheaper. Or, in Wong’s far more memorable words, the industry may be enjoying the good drugs at very good prices. The real test comes later.
What good AI governance actually looks like
When Garza asked what matters most for a CISO building an AI governance program, Wong’s answer was quite practical: Do not shut it down by default.If security leaders take a reflexively anti-AI stance, employees will still use the tools, but they just will not tell you. And this in turn leaves security teams with blind spots around, use cases, and risk exposure.
Wong recommends a more open model built on curiosity and tracking:
-
Know who is using AI.
-
Know which tool they are using.
-
Know the use case.
-
Know the data sensitivity involved.
-
Know which executive owns the risk conversation.
From there, organizations can build risk tiers around AI use cases and make more informed decisions. And it comes back to an old security truth, that if you want visibility, you need a culture where people can safely disclose what they are doing.
What I appreciate most about Caroline Wong is the fact that she understands the technical details without using complexity as a status symbol. She wants to make hard subjects useful and not just perform expertise for its own sake. Security only works when understanding spreads, and that translator-minded approach is what makes her voice so effective. Her mindset is especially relevant since she is a successful author of three cybersecurity books that are interesting and most of all easy to understand.
The real throughline: less hype, more usefulness
For all the topics covered in this interview from AI agents, digital twins, continuous testing, governance frameworks, token economics, Black Hat hype, and yes, Disney rides, the common thread was consistent. Wong is not anti-AI! She is actively building and writing in the space. However, her focus is on utility over easy spectacle. Instead of the all present hype about whether AI will “replace” humans, he prioritizes practical questions like “Can AI reduce drudgery, improve remediation, or empower teams?” And that focus is refreshing. In an industry currently overflowing with noise, Wong’s perspective remains useful by centering on what actually helps teams do their jobs.
Wong said readers can find her on LinkedIn or follow her work at aicyberhandbook.com, and pick up her book, The AI Cybersecurity Handbook, for a practical guide to navigating AI and security.
Want to learn more about AI pentesting? Get in touch to see how Prescient Security can help.