
TL;DR
Artificial intelligence makes it easy for anyone in the organization to deploy internet-connected applications, often outside of established security processes. Rob Gurzeev, CEO of CyCognito, says emerging blind spots are more dangerous than known vulnerabilities. His answer: continuous, out-of-the-box attack surface mapping that validates what’s actually exploitable, rather than scanning a known asset list.
Artificial intelligence is changing how software is built, deployed and secured. While AI has accelerated innovation across industries, it has also increased the number of internet-connected assets that organizations must protect. According to CEO and co-founder Rob Gurzeev CyCognitothe challenge is no longer just to identify known vulnerabilities. It’s about understanding what’s actually exposed, how those assets are locked down, and how attackers can exploit them.
Based on years of experience in cyber security and intelligence, Gurzeev believes that many organizations still operate with an incomplete view of their operations. attack surface. As artificial intelligence makes it easier than ever to create and expose new applications, this gap is becoming more dangerous, he said.
A security mindset built on finding the unknown
Gurzeev’s path to cybersecurity began long before he got into artificial intelligence. As a teenager, he spent time exploring computers and Internet Relay Chat (IRC) communities, where his interest in hacking first emerged. This interest eventually led him to the intelligence division, where he worked on intelligence and ground attack operations.
“To be honest, this job chose me more than I chose,“Said Gurzeev. He explained that a role often begins with a name and requires finding “the path of least resistance to something important.“
These experiences continue to shape how he approaches cybersecurity today. “I was taught that you never know what reality is. You have to go find it. confirm,” he said. “Most of the security industry is built on the opposite assumption that you already know where your stuff is. This loophole is the whole reason CyCognito exists.“
Mapping the appearance of the intruder
CyCognito, let’s start with something other than the company’s name, approaches security from the outside in. The platform maps everything exposed to the internet, including forgotten or unmanaged assets, then tests those systems to identify vulnerabilities that could be exploited by attackers.
“In short, we map everything a company has exposed to the internet, then actually trace the multiple paths that lead to its internal networks and sensitive data.Gurzeev explained.
Instead of relying solely on vulnerability scans, the platform verifies which vulnerabilities are actually exploitable. According to Gurzeyev,If I had to name one thing that makes us unique, it’s that our platform thinks like an attacker. This should be obvious. It is not.“
The scale of today’s attack surface
Modern enterprise environments have grown far beyond what traditional security software was designed to handle. Gurzeev estimates that a large enterprise typically exposes about 100,000 applications, devices and cloud assets to the Internet, with some organizations having significantly larger footprints.
“Our largest customer alone has about 100 million things that an attacker could contact externally.” he added that foreign attack surfaces change by one to three percent every day.
Despite this scale, many organizations continue to focus their security efforts on only a small portion of their environment. “Most security efforts go to a few hundred or thousands of key assets. And the rest?Gurzeev asked.Protecting the front door while leaving the windows open is not a strategy.“
AI expands the problem
The rapid adoption of artificial intelligence has made it much easier to build and deploy applications across organizations. Employees outside of traditional development teams can now build internet related tools using Coding assistants powered by artificial intelligenceoften without going through established security processes.
“Today anyone and everyone can deploy an app,Gurzeev said.Someone in HR or finance could spin up an application with a tool like Claude Code or Lovable and expose it to the internet, intentionally or accidentally.“
He believes that AI is moving from being a supporting technology to becoming part of organizations. basic infrastructure. “As recently as six months ago, AI was pinned to the edge of business. Now it goes through the core, meaning these systems are no longer adjacent to the attack surface. They are the attack surface.“
The problem goes beyond app growth. Gurzeev pointed to research that suggests AI-generated code introduces vulnerabilities at a significantly higher rate than code written entirely by humans. More importantly, he argued that much of this software bypassed the program secure development processes have spent years building organizations.
“The honest answer is that we are defending more of something less secure, and we can’t yet measure exactly how much. This uncertainty itself is a risk,” he said.
Continuous testing for an AI-driven era
As attackers increasingly embrace AI, Gurzeev argues that periodic assessments are no longer enough. Security teams need constant visibility into what’s exposed, what’s actually exploitable, and what issues require immediate remediation.
“To continue requires three things, all continuous,” he said. “Now know what you are exposing yourself to. Know which of them an attacker can actually access, not the example. Fix what’s important in hours.“
CyCognito’s latest release focuses on continuous AI security testing by combining full attack surface discovery with AI-powered validation. Rather than limiting advanced testing to a small number of high-priority assets, the platform maps an organization’s entire internet-facing environment before applying AI where justification is most needed.
According to Gurzeev, the platform continuously performs more than 100,000 automated checks for known problems, allowing the AI to identify complex attack paths that conventional scanners often miss. As these attack chains are validated, they become iterative automated tests, expanding their scope over time.
Looking ahead, Gurzeev hopes the defenders can regain the upper hand. “The winners won’t be the biggest spenders,” he said. “They will be the most efficient users of it, getting the most out of every computing dollar and contextualizing it instead of blindly. Do this and the defenders catch up.“





