TL;DR
AI makes it trivially easy for anyone in an organization to deploy internet-facing applications, often outside established security processes. CyCognito CEO Rob Gurzeev says the resulting blind spots are more dangerous than known vulnerabilities. His answer: continuous, outside-in attack-surface mapping that validates what is actually exploitable rather than scanning a known asset list.
Artificial intelligence is transforming how software is built, deployed, and secured. While AI has accelerated innovation across industries, it has also expanded the number of internet-facing assets organizations need to protect. According to Rob Gurzeev, CEO and Co-Founder of CyCognito, the challenge is no longer just identifying known vulnerabilities. It is understanding what is actually exposed, how those assets connect, and how attackers can exploit them.
Drawing on years of experience in cybersecurity and intelligence, Gurzeev believes many organizations still operate with an incomplete view of their attack surface. That gap, he says, is becoming more dangerous as AI makes it easier than ever to create and expose new applications.
A security mindset built on finding the unknown
Gurzeev’s path into cybersecurity began long before AI entered the picture. As a teenager, he spent time exploring computers and Internet Relay Chat (IRC) communities, where curiosity about hacking first took hold. That interest eventually led him to an intelligence unit, where he worked on reconnaissance and attack-surface operations.
“Honestly, this work chose me more than I chose it,” Gurzeev said. He explained that the role often started with little more than a name and required finding “the path of least resistance into something that mattered.”
Those experiences continue to shape how he approaches cybersecurity today. “I was taught you never actually know what reality is. You have to go find it. Validate it,” he said. “Most of the security industry was built the other way around, on the assumption that you already know where your stuff is. That gap is the whole reason CyCognito exists.”
Mapping the attacker’s view
CyCognito approaches security by working from the outside in, beginning with nothing more than a company’s name. The platform maps everything exposed to the internet, including forgotten or unmanaged assets, then tests those systems to identify weaknesses that could be exploited by attackers.
“In a nutshell, we map everything a company has exposed to the internet, then trace the handful of paths that actually lead to its internal networks and sensitive data,” Gurzeev explained.
Rather than relying solely on vulnerability scans, the platform validates which weaknesses are genuinely exploitable. According to Gurzeev, “If I had to name the one thing that makes us unique, it’s that our platform thinks like an attacker. That should be obvious. It isn’t.”
The scale of today’s attack surface
Modern enterprise environments have grown far beyond what traditional security programs were designed to manage. Gurzeev estimates that a large enterprise typically exposes around 100,000 applications, devices, and cloud assets to the internet, while some organizations have significantly larger footprints.
“Our single biggest customer has around 100 million things an attacker can interact with from the outside,” he said, adding that external attack surfaces change by one to three percent every day.
Despite that scale, many organizations continue to focus security efforts on only a small fraction of their environments. “Most security effort goes to a few hundred or a thousand key assets. What about the rest?” Gurzeev asked. “Guarding the front door while you leave the windows open is not a strategy.”
AI is expanding the problem
The rapid adoption of AI has made creating and deploying applications much easier across organizations. Employees outside traditional development teams can now build internet-facing tools using AI-powered coding assistants, often without going through established security processes.
“Today, anyone and everyone can deploy an app,” Gurzeev said. “Someone in HR or finance can spin up an application with a tool like Claude Code or Lovable and expose it to the internet, on purpose or by accident.”
He believes AI has shifted from being a supporting technology to becoming part of organizations’ core infrastructure. “As recently as six months ago, AI was bolted onto the edge of the business. Now it runs through the core, which means these systems aren’t adjacent to the attack surface anymore. They are the attack surface.”
The challenge extends beyond application growth. Gurzeev pointed to research suggesting AI-generated code introduces vulnerabilities at significantly higher rates than code written entirely by humans. More importantly, he argued that much of this software bypasses the secure development processes organizations have spent years building.
“The honest answer is we’re defending more of something less safe, and we can’t yet measure exactly how much. That uncertainty is itself the risk,” he said.
Continuous testing for an AI-driven era
As attackers increasingly adopt AI, Gurzeev argues that periodic assessments are no longer enough. Security teams need continuous visibility into what is exposed, what can actually be exploited, and which issues require immediate remediation.
“Keeping up takes three things, all continuous,” he said. “Know what you have exposed right now. Know which of it an attacker could actually break into, across all of it, not a sample. Fix what matters in hours.”
CyCognito’s latest release focuses on continuous AI security testing by combining full attack surface discovery with AI-powered validation. Rather than limiting advanced testing to a small number of high-priority assets, the platform maps an organization’s entire internet-facing environment before applying AI where reasoning is needed most.
According to Gurzeev, the platform continuously performs more than 100,000 automated checks for known issues, allowing AI to focus on identifying complex attack paths that conventional scanners often miss. As those attack chains are validated, they become repeatable automated tests, expanding coverage over time.
Looking ahead, Gurzeev remains optimistic that defenders can regain the advantage. “The winners won’t be the ones who spend the most,” he said. “They’ll be the ones who use it most efficiently, getting the most out of every dollar of compute by pointing it with context instead of running it blind. Do that, and defenders catch up.“