Featured by Newsweek & World Class Media Outlets
Brian Roche

Brian Roche

CEO
Veracode
07 July 2026

Veracode is an application risk management company that helps organizations identify, manage, and govern software security risks by testing code, monitoring vulnerabilities, and providing software trust and governance solutions.

Could you start by telling us a little about your background and what brought you to Veracode?

I came to Veracode through a combination of software engineering, cybersecurity, and operating large-scale technology platforms. Most recently, at Medidata,  I led cloud operations and platform engineering as Chief Architect, in addition to being the executive sponsor for the Moderna and Johnson & Johnson clinical trials. When those trials became targets for nation-state attacks, I found myself spending as much time focused on security and resilience as I did on architecture and i

That experience reinforced something I have believed for a long time: software has become critical infrastructure. That question ultimately brought me toVeracode, whereI became CEO. We are entering an era where AI is dramatically accelerating software creation, and I believe trust, governance, and accountability will become just as important as innovation itself.

Has the rapid adoption of AI created a mess from the point of view of cybersecurity?

I would describe it less as a mess and more as a fundamental shift in how software is created. For decades, software was written, reviewed, and secured by humans. Today, AI participates in every stage of that process. The question executives should be asking is no longer “Are we using AI?” The question is: “How do we know the software AI helped create is secure, compliant, and trustworthy?”

I firmly believe AI will change the world in ways we have never seen before. Every technology eventually faces disruption. The challenge is that people think linearly, while AI capabilities are improving exponentially. The question is not whether disruption will happen, but when and how quickly industries will adapt.

How do you assess the impact of advanced AI systems on cybersecurity today?

AI is already having a profound impact on cybersecurity — it can identify vulnerabilities faster and analyze vast amounts of code. But finding vulnerabilities is only  part of the problem. Enterprise security is ultimately about trust, accountability, and evidence. Organizations need to know what software they are deploying, what risks exist and whether they can demonstrate due diligence to customers, regulators, and boards.

Over the next couple of years, organizations will still need trusted systems that provide predictable security assurance. AI models will continue to improve, but today they are not yet capable of replacing the governance, trust, and attestation requirements enterprises need. The bigger question is not  finding vulnerabilities, but understanding which ones matter and which risks require action. That is  why the future of enterprise security will be defined by governance, trust, and the ability to demonstrate software integrity.

Has the emergence of these novel threats served as a wake-up call for organizations?

Absolutely. People need to recognize that if businesses are using AI productively, attackers are using it offensively. Large language models can already help create the building blocks for sophisticated attacks. The barrier to entry is lower than many people realize.

The real wake-up call is that organizations must start taking security and system integrity seriously. Attackers certainly are. Technologies can be used to bring businesses down, and while some AI announcements receive a great deal of attention, the reality is that many offensive capabilities are already available using mainstream models today. The deeper issue is that AI is accelerating the pace at which software is created, modified, and deployed — faster than traditional governance models were ever designed to handle. Security can no longer be treated as a downstream activity. It must become an integrated part of how software is governed from the beginning.

AI coding assistants are helping developers move faster. What security risks do they introduce, and how do you help clients address them?

Many organizations adopt AI because they believe it will increase productivity. In reality, developers often generate large amounts of code that become difficult to review and fully understand. At some point, people stop comprehensively reviewing what has been produced and simply check the code into production.

The challenge is that much of the code generated by large language models is not secure. Our research shows that 45% of AI-generated code contains security vulnerabilities. The issue is not that AI produces only insecure code — it is that organizations are now creating software at a scale and speed that makes traditional review and governance processes increasingly difficult. That is why Veracode is evolving beyond  identifying issues: we are helping organizations establish continuous visibility and trust across the entire software lifecycle.

Are there industries that still do not take software security seriously enough?

Historically, industries such as financial services, healthcare, and government led the way because regulation forced earlier investment. But that dynamic is changing. Software risk is no longer confined to heavily regulated sectors — every organization depends on software to operate, serve customers, and make decisions. IEvery company is becoming a software company, and software trust is becoming a universal business requirement.

We are seeing a broader transformation. Every industry will eventually face the same questions about software that previous industries faced around financial controls, cloud governance, and compliance. Regulators increasingly want to know what is inside software, whether it can be trusted, and whether organizations can demonstrate proper governance processes. We are seeing a broader shift from cybersecurity as a technical issue to cybersecurity as a business governance issue — and boards and investors are increasingly paying attention.

How important is regulatory accountability becoming for executives and security leaders?

It is becoming one of the most important shifts occurring in cybersecurity today. When I speak with CISOs, many acknowledge that regulators are not fully enforcing personal accountability, but they believe it is coming. The expectation is that organizations will need to prove the proper processes are in place and follow them consistently.

When regulators investigate a breach, they are not necessarily asking why an organization was breached. They are asking whether there was a documented process, whether it was followed, and whether leadership can demonstrate due diligence. Those questions are becoming central to cybersecurity governance, and executives need to understand the implications. I believe the future of cybersecurity will be defined as much by accountability as by detection — the organizations that succeed will be those that can demonstrate trust through evidence and repeatable processes.

You have spoken about a truly disruptive phase of AI in the next few years. How do you see that affecting Veracode and the cybersecurity industry?

I believe software security is entering a period of significant transformation. Many technologies across cybersecurity and cloud security will eventually be replaced or fundamentally transformed by AI. Anyone paying close attention to the trajectory of these models can see that change coming.

I also believe we will see some form of artificial general intelligence within the next seven years. We are not as close as some people suggest, but the direction is clear. As AI capabilities continue to evolve, our current business model will eventually become less relevant, which is why Veracode is  transitioning toward trust, governance, and software assurance.

Our focus is shifting toward governance and trust because we believe those will become the defining challenges of the AI era. This year, we are launching what we describe as an upstream software governance and trust platform. The goal is to help organizations understand exactly what is inside their software, track deployments, and provide evidence that their systems are secure and trustworthy. That transition is already underway.

Looking ahead over the next 12 months, what are your key priorities?

Our first priority is helping customers navigate the transition to AI-driven software development safely and effectively. AI fluency remains critical — but the bigger investment is in helping organizations establish trust across the software lifecycle as that transition accelerates.

More broadly, I expect AI adoption to accelerate across nearly every industry. Agent governance will become increasingly important as organizations deploy AI agents with growing levels of autonomy. Companies will need ways to control, govern, and safely manage those agents. I also think we will begin confronting major economic questions around workforce displacement and how societies adapt as AI takes on more tasks previously performed by people.

The companies that gain the greatest advantage from AI will not simply be the ones that adopt it fastest. They will be the ones that can scale innovation while maintaining trust.