Charl Cilliers
Charl Cilliers is a technology executive at Foci Solutions. He works in enterprise .NET and platform security, with a long-running interest in the layer where software meets hardware. Outside of work he's a maker and electronics tinkerer: 3D printers, CNC, SDR and a steady stream of microcontroller projects, usually with one of his kids nearby. He has a low tolerance for tools that generate work without reducing it, in roughly equal measure at the office and in the garage.
Session
Your scanner found multiple vulnerabilities in your base image this morning, and your release is blocked until every one of them is triaged out of the queue. Most of them will never be fixed, and for most of them that is the correct outcome.
The catch: you work on government code, so you can't hand the problem to the tools built to solve it.
The agentic CVE-analysis platforms want to embed your source. The good commercial suites cost real money and still phone home. And the rules about AI and sensitive code are only getting tighter.
So this talk is about a question I had to actually answer on a live government program: how do you supercharge vulnerability triage using the most powerful tools available, without a single byte of privileged code or infrastructure leaving your boundary?