Interview with Colin Bell, AppScan Field CTO at HCLSoftware

Interview with Colin Bell, AppScan Field CTO at HCLSoftware

🎙 Shira Rubinoff 👥 937K 📅 January 20, 2026 ⏱ 12 min 👁 163K 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

AIapplication securityDevSecOpsvibe codingCISO

Summary

In this interview, Shira Rubinoff speaks with Colin Bell, Field CTO at HCLSoftware, about the transformative impact of AI on application security in 2026. Bell highlights that AI is shifting from a helper to an active participant in software development, leading to practices like ‘vibe coding’ where developers generate code through prompts. This shift means security can no longer be a final check but must be integrated in real-time. Bell emphasizes that developers may not fully understand AI-generated code, creating challenges for audit and governance. He argues that human expertise remains crucial, but its role shifts to architecture and oversight. For CISOs, Bell advises treating AI as a new kind of developer that needs training, auditing, and continuous security integration. He stresses the importance of continuous security testing and independent checks. Bell concludes with a tip that security belongs to everyone, not just the security team, and should be embedded throughout the organization.

153 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical insights from an industry expert on the evolving role of AI in application security. Bell provides a clear argument that AI’s integration into development requires a shift in security practices from periodic checks to continuous, integrated processes. He supports his points with analogies (e.g., industrial revolution) and logical reasoning, though the argumentation is largely anecdotal and lacks empirical evidence. The discussion is coherent and addresses key concerns for CISOs, but it does not offer detailed technical solutions or data-backed claims.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on expert opinion rather than peer-reviewed research. The only source provided is a link to HCLSoftware’s AppScan product page, which serves as a reference for the discussed tool but does not substantiate the claims. The title accurately reflects the content, which is an interview, and the discussion stays on topic. No comments were provided for analysis.

169 words

Title / Content Match

The title accurately reflects the content, which is an interview with Colin Bell on AI's impact on application security.

Quality & Reliability

7/10

The discussion is based on the expert opinion of a field CTO, providing practical insights but lacking empirical data or citations. The claims are plausible and align with industry trends, but the absence of specific references or data reduces the verifiability.

Key Moments

Cited Sources

  • HCL AppScan — Referenced as the product associated with the interviewee's role.

Concurring Sources

  • HCL AppScan — The product discussed aligns with the need for continuous application security testing.

Contribution & Novelties

The interview provides a forward-looking perspective on how AI will reshape application security, emphasizing the need for continuous security integration and the evolving role of developers. It introduces the concept of ‘vibe coding’ and its security implications, which is a relatively new topic. The discussion offers practical advice for CISOs, such as treating AI as a developer and maintaining independent audits.

Pour aller plus loin :

  • Vibe coding — Provides background on the term and its implications.
  • DevSecOps — Explains the integration of security into DevOps practices.
  • OWASP Top 10 — Relevant for understanding common application security risks.

98 words

Radar Profile

The radar profile shows a balanced performance across all metrics, with slightly higher scores in quality and reliability, indicating a solid but not exceptional content. The low quantity of information suggests a concise discussion, while the technical level is moderate, suitable for a professional audience.

Reliability 7/10