Rob Gurzeev on Why the Biggest Cybersecurity Risk May Be What Organizations Don’t Know They Have
The rise of AI is adding another layer of complexity by dramatically lowering the barrier to software creation. Applications can now be built and deployed by people who may not traditionally have worked within formal software development or security processes.
You're reading Entrepreneur United Kingdom, an international franchise of Entrepreneur Media.
For years, cybersecurity teams have built their defenses around a relatively straightforward premise: identify the systems that matter, find vulnerabilities in those systems, and patch them before attackers can take advantage. But as enterprise environments become more distributed and AI makes software development faster and more accessible, that model is facing a fundamental challenge.
The problem, according to Rob Gurzeev, CEO and Co-Founder of CyCognito, is that organizations are often defending only the parts of their environments they already know about. Meanwhile, attackers are free to look everywhere.
“Known flaws still matter. The problem is treating them as the whole map,” Gurzeev said. In his view, the security industry needs to spend less time assuming that the full environment is already understood and more time continuously discovering what is exposed and determining how those assets could be chained together.
The attack surface is moving faster than security teams
The scale of the modern enterprise makes that challenge increasingly difficult. Gurzeev estimates that a large organization can have roughly 100,000 applications, devices, and cloud assets exposed externally, while some enterprises have far more.
The bigger issue is that this environment is constantly changing. Across CyCognito’s customers, Gurzeev said the typical external attack surface changes by one to three percent every day.
That creates a mismatch between the pace of the environment and the way many security programs operate. Security teams may prioritize a few hundred or thousand critical assets, but attackers do not have to follow the same prioritization.
“Every exposed asset can be an attacker’s stepping stone into your network,” Gurzeev said. “Guarding the front door while you leave the windows open is not a strategy.”
The challenge is not simply that there are too many vulnerabilities to address. It is that organizations may not know which assets exist, how those assets connect to one another, or which seemingly insignificant system could provide a route toward something more valuable.
Attackers don’t see security tools as separate categories
This is where Gurzeev believes traditional vulnerability management can fall short. Security tools tend to break complex environments into categories: applications, cloud infrastructure, devices, vulnerabilities, and other individual components.
Attackers, however, see a connected environment.
“The worst incidents don’t fit that shape,” Gurzeev said. “They live in how systems connect and what an attacker can chain together, which no scanner has a rule for.”
That could involve an AI service exposing sensitive information or an AI agent being manipulated through instructions hidden in a document. Neither necessarily resembles the conventional vulnerability that appears in a database and receives a patch.
“Nothing matches, so nothing flags,” Gurzeev said. “And the things that aren’t on the list are what get you breached.”
This shift also changes the meaning of speed. Historically, organizations could operate on a cycle in which vulnerabilities were discovered, assessed, prioritized, and eventually remediated. But as attackers gain access to AI-powered capabilities, the time available to defenders is shrinking.
“That gap used to be days. Now, anyone, anywhere, can break into a complex system in minutes,” Gurzeev said. “When a threat lands, you need to know where you’re exposed within minutes, not next quarter.”
AI is turning the attack surface into a moving target
The rise of AI is adding another layer of complexity by dramatically lowering the barrier to software creation. Applications can now be built and deployed by people who may not traditionally have worked within formal software development or security processes.
“Someone in HR or finance can spin up an application with a tool like Claude Code or Lovable and expose it to the internet, on purpose or by accident,” Gurzeev said.
These applications may also connect to internal systems, databases, and other business services, creating potential paths that are difficult to identify through traditional security processes.
At the same time, AI-generated code is increasingly entering production environments. Gurzeev argues that the concern is not simply the percentage of code written by AI, but the fact that much of it can bypass the secure development pipelines established for human developers.
“The flaws we spent a decade training developers out of are now arriving in production at machine speed,” he said.
That creates a paradox for security teams: they are being asked to secure more software, more quickly, across an environment that is changing continuously, while having less certainty about exactly what has been deployed.
The new security race is about efficiency
Gurzeev’s answer is not to abandon traditional vulnerability management, but to put it in a broader framework that combines discovery, validation, and remediation.
“Keeping up takes three things, all continuous,” he said. “Know what you have exposed right now. Know which of it an attacker could actually break into, across all of it, not a sample. Fix what matters in hours.”
CyCognito’s approach combines continuous attack-surface management with AI-powered security testing designed to simulate how an attacker might reason through an environment. The goal is to apply advanced testing across the entire external footprint rather than concentrating expensive AI-based analysis on only the most obvious assets.
The model also uses automated checks for known issues, allowing AI-based testing to focus on attack paths that require more contextual reasoning. As validated attack chains become repeatable tests, the system can continue expanding its coverage.
For Gurzeev, this could ultimately determine whether defenders regain an advantage in the AI era. The future, he argues, will not necessarily belong to the organizations with the biggest security budgets, but to those that can make the most effective use of AI.
“The winners won’t be the ones who spend the most,” Gurzeev said. “They’ll be the ones who use it most efficiently, getting the most out of every dollar of compute by pointing it with context instead of running it blind. Do that, and defenders catch up.”
For years, cybersecurity teams have built their defenses around a relatively straightforward premise: identify the systems that matter, find vulnerabilities in those systems, and patch them before attackers can take advantage. But as enterprise environments become more distributed and AI makes software development faster and more accessible, that model is facing a fundamental challenge.
The problem, according to Rob Gurzeev, CEO and Co-Founder of CyCognito, is that organizations are often defending only the parts of their environments they already know about. Meanwhile, attackers are free to look everywhere.
“Known flaws still matter. The problem is treating them as the whole map,” Gurzeev said. In his view, the security industry needs to spend less time assuming that the full environment is already understood and more time continuously discovering what is exposed and determining how those assets could be chained together.