Rob Gurzeev on why AI has changed cybersecurity’s biggest blind spot

The TL;DR
AI makes it easy for anyone in an organization to install Internet-facing applications, often without established security procedures. CyCognito CEO Rob Gurzeev says the resulting blind spots are more dangerous than known vulnerabilities. His answer: to continue, without the attack of a map that verifies what is actually usable rather than scanning the known heritage list.
Artificial intelligence is changing the way software is built, used, and secured. While AI has accelerated innovation across industries, it has also increased the number of cyber-facing assets organizations need to protect. According to Rob Gurzeev, CEO and Co-Founder of CyCognito, the challenge is no longer just to identify known vulnerabilities. Understanding what exactly is exposed, how those assets connect, and how attackers can exploit them.
Drawing on years of cybersecurity experience and intelligence, Gurzeev believes that many organizations are still operating with an incomplete view of their attack landscape. He says that gap is becoming more dangerous as AI makes it easier than ever to create and expose new applications.
A security concept built in to discover the unknown
Gurzeev’s path to cybersecurity began long before AI entered the picture. As a teenager, he spent time exploring computers and Internet Relay Chat (IRC) communities, where his interest in hacking began. That interest eventually led him to the intelligence service, where he worked on reconnaissance and raids in the area.
“In fact, this job has chosen me more than I have chosen,” said Gurzeev. He explained that the role often started with a small name and needed to be found “the path of least resistance to something important.“
That experience continues to shape the way he approaches cybersecurity today. “I was taught that you will never know what the truth is. You have to go find it. confirm,” he said.Most of the security industry is built the other way around, on the assumption that you already know where your stuff is. That gap is the whole reason for CyCognito’s existence.“
Mapping the attacker’s perspective
CyCognito approaches security from the outside in, starting with the company name. The platform maps everything exposed online, including forgotten or unmanaged assets, and scans those systems for vulnerabilities that could be exploited by attackers.
“In short, we map everything the company has exposed online, and trace several paths leading to its internal networks and sensitive data,Gurzeev explained.
Rather than relying solely on vulnerability testing, the platform verifies which vulnerabilities are actually exploitable. According to Gurzeev, “If I had to name one thing that sets us apart, it’s that our platform thinks like an attacker. That should be obvious. That’s not the case.“
The scale of today’s attacks
Modern business environments have grown far beyond what traditional security systems were designed to handle. Gurzeev estimates that a large enterprise typically exposes around 100,000 applications, devices, and cloud assets to the Internet, while other organizations have much larger footprints.
“One of our largest customers has about 100 million objects that an attacker can access from outside,” he said, adding that foreign attack sites change by one to three percent every day.
Despite that scale, many organizations continue to focus security efforts on only a small portion of their environments. “Most of the security effort goes to a few hundred or even a thousand key assets. What about something else?” asked Gurzeev.Guarding the front door while leaving the windows open is not a trick.“
AI exacerbates the problem
The rapid adoption of AI has made creating and deploying applications much easier for organizations across the board. Employees outside of traditional development teams can now build web-facing tools using AI-enabled coding assistants, often without going through established security procedures.
“Today, anyone and everyone can use the app,” said Gurzeev.Someone in HR or finance can scan the app with a tool like Code Claude or Lovable and expose it online, on purpose or by mistake.“
He believes that AI has changed from being a supporting technology to being part of the core infrastructure of organizations. “As recently as six months ago, AI was pushed to the edge of business. It now passes through, which means that these systems are no longer near the point of attack. They are a point of attack.“
The challenge goes beyond app development. Gurzeev pointed to research that suggests AI-generated code presents risks at much higher rates than code written entirely by humans. More importantly, he asserted that much of this software bypasses the secure development processes that organizations have spent years building.
“The honest answer is that we are very protective of something that is not safe, and we cannot yet measure how much it really is. That uncertainty is dangerous,” he said.
An ongoing exploration of the AI-driven era
As attackers increasingly use AI, Gurzeev says periodic checks are no longer enough. Security teams need continuous visibility into what’s been exposed, what exactly can be exploited, and what issues need to be fixed immediately.
“Continuity takes three things, all of which are continuous,” he said.Know what you have revealed right now. Know which of them an attacker can hack into everything, not just a sample. Fix important in hours.“
CyCognito’s latest release focuses on continuous AI security testing by combining full attack surface detection and AI-powered authentication. Rather than limiting advanced testing to a small number of high-priority assets, the platform maps the entire organization toward the Internet before deploying AI where the thinking is most needed.
According to Gurzeev, the platform continuously performs more than 100,000 automated checks for known problems, allowing AI to focus on identifying complex attack methods that are often missed by conventional scanners. As those attack chains are validated, they become iterative, automated tests that expand coverage over time.
Looking ahead, Gurzeev remains hopeful that the defenders can regain the advantage. “The winners will not be those who spend the most money,” he said.They’ll be the ones who make the most of it, getting the most out of every computing dollar by targeting it with context instead of blinding it. Do that, and the defenders catch up.“



