CyCognito’s Rob Gurzeev says AI exposed cybersecurity’s blind spot: what matters is unknown
AI accelerates software, but it also multiplies the internet-facing surface area. Gurzeev explains the new security job.

Rob Gurzeev, CEO and Co-Founder of CyCognito, argues that AI changed cybersecurity’s core challenge, shifting it from finding known vulnerabilities to understanding what is actually exposed. For decision-makers, that means security programs built only for “known issues” will miss real risk as attackers and systems adapt faster.
Artificial intelligence is transforming how software is built, deployed, and secured. And if you are running security at a real company, there is a catch: AI has also expanded the number of internet-facing assets organizations need to protect.
That shift is exactly what Rob Gurzeev, CEO and Co-Founder of CyCognito, points to as cybersecurity’s biggest blind spot. He is not arguing that vulnerability scanning stopped working. He is saying the problem is no longer just identifying known vulnerabilities. The problem is understanding what is actually out there, and what it really means for your risk.
In practical terms, this is about visibility and context. Traditional cybersecurity work often starts from a list: you identify software components, you compare them to known vulnerability catalogs, and you patch or mitigate what you find. That workflow is useful, but AI changes the pace and the shape of software delivery. When software is generated, assembled, and released faster, the number of things that can be internet-facing grows. So does the number of places where “we know this library has a CVE” is not enough to answer “is this specific system exposed in a way that matters?”
Gurzeev frames the new challenge as moving past the comfort of known vulnerabilities and toward the harder question: what is actually exposed. That sounds abstract until you connect it to how organizations operate today. Modern infrastructure includes more than just classic web servers. It includes APIs, integrations, automation endpoints, cloud services, and the glue that makes everything talk to everything else. AI-enabled development and deployment can add more of these assets, sometimes with less human review per unit of change. Even if the code quality stays high, the overall attack surface can still increase because the number of externally reachable components increases.
There is also a compliance and governance angle here, even when regulators do not spell it out in those exact words. Security programs are often expected to show defensible processes: asset inventory, vulnerability management, risk assessment, and remediation. But if the blind spot is “you do not truly know what is exposed,” then the board-level story you are telling becomes harder to support. You can have strong vulnerability metrics while still lacking the most important operational truth: which real assets are reachable and in what ways.
This is where AI becomes a double-edged sword for decision-makers. On the upside, AI accelerates innovation across industries by making software development faster and more efficient. On the downside, it expands the number of internet-facing assets organizations need to protect, and that expansion stretches the assumptions behind many security workflows. It is not just that there are more servers and more applications. It is that AI-driven delivery can make changes more frequent, which makes it easier for “unknown exposure” to slip through between scans, between sprints, and between approvals.
For boards and executives, the second-order implication is organizational. Security cannot be only a vulnerability department anymore. It has to be tightly connected to how products are shipped, how environments are spun up, how internet exposure is granted, and how rapidly asset inventories go stale. In other words, the biggest risk might be the gap between your vulnerability knowledge and your real-world exposure reality. If Gurzeev is right about the blind spot, then the board question is not only “how fast do we patch known vulnerabilities?” It is also “how quickly do we understand what is actually exposed as the system changes?”
Peer companies with similar security responsibilities should treat this as a strategy issue, not a tooling issue. AI did not just speed up code creation. It accelerated the lifecycle of digital assets, which means the time window for attackers to find and exploit exposure shrinks. That makes the ability to understand unknown exposure a board-relevant metric. If you only track what you already know, you are structurally late to the problems that come from what you have not yet identified.
The takeaway from Gurzeev’s framing is clear: cybersecurity’s job is evolving. The challenge is moving from purely detecting known vulnerabilities to understanding what is actually exposed in an AI-shaped software world where internet-facing assets are multiplying.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

EU slaps AliExpress with record $625M DSA fine for counterfeit and safety failures
The European Commission says AliExpress did not mitigate illegal, unsafe, or counterfeit risks, and that delay is now expensive.

FBI arrests 21-year-old who allegedly stole $200,000 via malware Steam games and UberEats gift cards
Zyaire Dontaevious Zamarion Wilkins allegedly used weaponized Steam games to steal crypto and spend it through traceable gift cards.

IC3 warns scammers impersonate the FBI and promise stolen-fund recoveries on social media
The bureau’s message is blunt: any IC3 or FBI contact offering recovery is fake, often with AI videos and spoof sites.

