Internet Security Auditors Blog

TechDay Chamber of Commerce of Bogotá 2026 Business Event

Written by Edwin H. Garzón | Jul 31, 2026, 12:00:00 PM
The CCB Tech Day 2026 was much more than a business event. It was the stage where innovation came to life and where technology ceased to be a promise and became a tangible experience. In the city of Bogotá, attendees had the opportunity to see, touch, and operate technological solutions in real time, interact with experts, discover the trends that are redefining the future, and experience firsthand the impact of digital transformation.



The third edition of CCB Tech Day took place on July 23, 2026, at the Ágora Bogotá Convention Center, with free admission for entrepreneurs, business owners, and professionals from the region. During a full-day event from 7:30 a.m. to 6:30 p.m., more than 3,500 attendees experienced 48 immersive activities designed to understand how artificial intelligence, data, cybersecurity, drones, robots, and digital ecosystems are transforming businesses today.

This was not an event focused on speeches, but rather on practical demonstrations, themed rooms, and hands-on experiences where each participant was able to ask questions, test solutions, and gain actionable insights for their organization. In this edition, more than 100 organizations committed to innovation came together. Their purpose was clear: to use technology, AI, and data to drive the future of business in Bogotá and the surrounding region, closing competitiveness gaps and bringing companies closer to practical solutions.

Our participation in the event, opening the cybersecurity track, consisted of the workshop "Vibe Coding vs Secure Coding: When AI Codes, the Pentester Hacks," where we put an uncomfortable truth on the table: AI-generated code accelerates development, but it also multiplies risks when there is no human judgment behind it.


 
In this session, we explored the evolution of software development from traditional approaches to the current trend of vibe coding, where prompts replace many requirements and engineering best practices. We explained how to use AI responsibly, why it cannot be trusted 100%, and why human intervention remains essential to ensure quality, compliance, and security.

AI, Speed, and Vulnerabilities



During the workshop, we demonstrated the vulnerabilities and poor development practices that can arise when artificial intelligence assistants generate code without adequate supervision. We analyzed common issues such as authentication and authorization flaws, information leakage, insufficient input validation, and improper error handling that could go unnoticed until reaching production environments.

We also presented a comparison between traditional software development and the approach known as vibecoding. While the traditional developer understands requirements, designs the architecture, evaluates risks, tests each component, and assumes technical responsibility for the outcome, vibecoding often prioritizes speed through natural language instructions, accepting generated code without fully understanding its functionality, dependencies, or security implications.

Live Practical Lab



In the laboratory session, we built a complete clinical platform using a single prompt, including patient management and medical data functionalities. We then performed a live penetration test against the generated application, demonstrating to the audience how it was possible to exploit security flaws resulting directly from AI-driven coding decisions.

This exercise allowed attendees to observe, in real time, the gap between "software that works" and "software that withstands attacks."

Workshop Closing and Conclusions

 

We concluded the workshop with a clear reflection: artificial intelligence can accelerate software development and significantly increase productivity, but it cannot take responsibility for the security, ethics, or impact of the systems it helps create. Although AI models are capable of generating functional code within seconds, they do not independently understand the complete threat landscape, risk model, business rules, or regulatory requirements that must be respected in a real-world environment.

For this reason, we emphasized that all AI-assisted code should be reviewed, tested, and validated by developers, software architects, or pentesters with the technical expertise required to identify vulnerabilities, strengthen security, and guarantee quality before deployment into production. The difference lies not only in who writes the code, but in who understands it, challenges it, validates it, and ultimately takes responsibility for its consequences.

The final message to attendees was unequivocal: software developed exclusively with artificial intelligence, without technical oversight and without review and hardening processes, can hardly be considered truly secure. In this new era of AI-assisted development, combining the speed and productivity offered by artificial intelligence with human expertise in architecture, software development, and offensive and defensive security represents the strongest strategy for building reliable, resilient applications capable of facing current threats.

Final Reflection

Artificial intelligence is transforming the way we develop software, but it is also changing how we must protect it. In an environment where code can be generated in seconds, security cannot be treated as an optional step; it must be a continuous process that accompanies the entire software development lifecycle.

At Internet Security Auditors, we believe that innovation and security must move forward together. For this reason, we support organizations across multiple industries in identifying and mitigating risks through specialized services such as penetration testing (Pentesting), security assessments for web, mobile, and desktop applications, source code reviews across multiple programming languages, ATM security assessments, API testing, infrastructure security reviews, wireless network assessments, Active Directory evaluations, Red Team exercises, cloud environment security assessments, and other business-critical components.

Our commitment is to help companies develop solutions that are more secure, resilient, and prepared to face present and future threats. Because, ultimately, the trustworthiness of a system depends not only on whether it works, but on whether it can withstand real-world attacks.