The rapid adoption of AI tools has produced a little-discussed side effect: it has caused the enterprise attack surface to explode. Rob Gurzeev, CEO and Co-Founder of CyCognito, argues that the real cybersecurity blind spot is no longer the endless backlog of CVEs to fix, but the ability to understand what an organization actually exposes on the internet. This thesis overturns decades of security priorities and calls the architectural choices of IT teams into question.
The problem has deep roots, but AI has made it structural. The development of applications based on LLMs, the proliferation of cloud services, and shadow IT initiatives by business units generate dozens of endpoints, APIs, and web interfaces every day that no security team has ever inventoried. These ghost assets remain invisible to traditional vulnerability scanners, which by definition can only check what they already know. While organizations fight the known-patch battle, attackers use automation tools to map exposed infrastructures in real time, finding entry points precisely among the forgotten assets.
Gurzeev’s perspective goes beyond traditional vulnerability management and touches on infrastructure governance. In a scenario where any new AI-powered service can open a window, knowledge of the network inventory becomes a priority for national security, not just corporate. Analysts estimate that the cost of unmanaged assets now accounts for a significant share of the security TCO, and regulations such as GDPR and DORA now require enterprises to have complete and continuous control over their systems.
Here lies a crucial point for those evaluating technology deployment. Scanning the entire attack surface from the outside with cloud-based tools can reveal some gaps, but it means sending sensitive network topology data to third-party providers. For banks, defense, healthcare, and all organizations operating under strict data sovereignty regimes, this is unacceptable. On-premise scanning, on the other hand, enables discovery without information leaving the corporate perimeter. This shift affects not only cybersecurity but also infrastructure: building a self-hosted asset discovery system requires local compute and storage, orchestration, and integration with SIEMs, but it gives the organization full control over its data.
Some observers note that introducing AI models for asset analysis — trained on on-premise environments — could further accelerate anomaly detection and improve classification accuracy. This path is still rarely taken, but it aligns with the digital sovereignty trend: local inference reduces exposure risks and enables continuous monitoring even in air-gapped environments.
Ultimately, Gurzeev’s reflection exposes a paradox. We responded to AI by creating more AI-driven security, but we multiplied the number of targets. The real challenge today is not to strengthen the defenses we already know, but to learn to see what we don’t know we have. And to do this without compromise, our gaze must remain within the boundaries of our own infrastructure.
💬 Comments (0)
🔒 Log in or register to comment on articles.
No comments yet. Be the first to comment!