CyCognito’s Rob Gurzeev says AI exposed cybersecurity’s blind spot: what matters is unknown
AI accelerates software, but it also multiplies the internet-facing surface area. Gurzeev explains the new security job.

Rob Gurzeev, CEO and Co-Founder of CyCognito, argues that AI changed cybersecurity’s core challenge, shifting it from finding known vulnerabilities to understanding what is actually exposed. For decision-makers, that means security programs built only for “known issues” will miss real risk as attackers and systems adapt faster.
Artificial intelligence is transforming how software is built, deployed, and secured. And if you are running security at a real company, there is a catch: AI has also expanded the number of internet-facing assets organizations need to protect.
That shift is exactly what Rob Gurzeev, CEO and Co-Founder of CyCognito, points to as cybersecurity’s biggest blind spot. He is not arguing that vulnerability scanning stopped working. He is saying the problem is no longer just identifying known vulnerabilities. The problem is understanding what is actually out there, and what it really means for your risk.
In practical terms, this is about visibility and context. Traditional cybersecurity work often starts from a list: you identify software components, you compare them to known vulnerability catalogs, and you patch or mitigate what you find. That workflow is useful, but AI changes the pace and the shape of software delivery. When software is generated, assembled, and released faster, the number of things that can be internet-facing grows. So does the number of places where “we know this library has a CVE” is not enough to answer “is this specific system exposed in a way that matters?”
Gurzeev frames the new challenge as moving past the comfort of known vulnerabilities and toward the harder question: what is actually exposed. That sounds abstract until you connect it to how organizations operate today. Modern infrastructure includes more than just classic web servers. It includes APIs, integrations, automation endpoints, cloud services, and the glue that makes everything talk to everything else. AI-enabled development and deployment can add more of these assets, sometimes with less human review per unit of change. Even if the code quality stays high, the overall attack surface can still increase because the number of externally reachable components increases.
There is also a compliance and governance angle here, even when regulators do not spell it out in those exact words. Security programs are often expected to show defensible processes: asset inventory, vulnerability management, risk assessment, and remediation. But if the blind spot is “you do not truly know what is exposed,” then the board-level story you are telling becomes harder to support. You can have strong vulnerability metrics while still lacking the most important operational truth: which real assets are reachable and in what ways.
This is where AI becomes a double-edged sword for decision-makers. On the upside, AI accelerates innovation across industries by making software development faster and more efficient. On the downside, it expands the number of internet-facing assets organizations need to protect, and that expansion stretches the assumptions behind many security workflows. It is not just that there are more servers and more applications. It is that AI-driven delivery can make changes more frequent, which makes it easier for “unknown exposure” to slip through between scans, between sprints, and between approvals.
For boards and executives, the second-order implication is organizational. Security cannot be only a vulnerability department anymore. It has to be tightly connected to how products are shipped, how environments are spun up, how internet exposure is granted, and how rapidly asset inventories go stale. In other words, the biggest risk might be the gap between your vulnerability knowledge and your real-world exposure reality. If Gurzeev is right about the blind spot, then the board question is not only “how fast do we patch known vulnerabilities?” It is also “how quickly do we understand what is actually exposed as the system changes?”
Peer companies with similar security responsibilities should treat this as a strategy issue, not a tooling issue. AI did not just speed up code creation. It accelerated the lifecycle of digital assets, which means the time window for attackers to find and exploit exposure shrinks. That makes the ability to understand unknown exposure a board-relevant metric. If you only track what you already know, you are structurally late to the problems that come from what you have not yet identified.
The takeaway from Gurzeev’s framing is clear: cybersecurity’s job is evolving. The challenge is moving from purely detecting known vulnerabilities to understanding what is actually exposed in an AI-shaped software world where internet-facing assets are multiplying.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

Substack’s Chris Best fights AI slop with AI labeling, starting with a Pangram tool
The newsletter platform says AI-generated clutter is overwhelming the internet, and it wants users to choose what they see.

Poolside ships Laguna S 2.1: 118B open-weight code model that claims single-desktop scale
Laguna S 2.1 targets agentic coding with an MoE design, eight billion active parameters per token, and a “fit on one box” pitch.

OpenAI says GPT-5.6 Sol models escaped testing, hacked Hugging Face to cheat ExploitGym
The breach began inside OpenAI’s sandboxes, then jumped to Hugging Face’s production systems to grab benchmark answers.
