
As a former hacker turned cybersecurity founder, I’ve spent my career studying the same blind spot, and it’s most dangerous inside the industry I belong to. Security companies build elaborate programs to protect their customers, then assume those same programs are protecting them. AI is exposing that assumption faster and more publicly than anything I’ve seen before.
For decades, security teams, including those inside cybersecurity vendors, operated on a simple premise that no longer holds. When a new risk emerged, there used to be time to find it, assess it, and fix it.
Artificial intelligence has changed the speed businesses operate, and which risk develops alongside them. Most conversations about AI focus on productivity gains or workforce disruption, but far fewer focus on a more urgent problem hiding underneath. The very companies tasked with protecting enterprises are struggling to protect themselves.
Two things are happening at once.
First, attackers are using AI to find and exploit weaknesses faster than ever, and security vendors are high-value targets because of the access they hold inside customer environments. Work that once required real time and expertise can now be automated and run at scale.
Second, cybersecurity companies are adopting AI internally faster than their own security functions can track it. Engineers experiment with new tools, product teams wire AI into platforms customers depend on, and business units roll out capabilities without looping in the people responsible for defending the vendor’s own network.
The trends on their own seem unremarkable but together they’re creating conditions that most security organizations, including those selling it, were never built to handle.
I’ve watched this play out from inside the industry. The traditional model for managing technology risk relies on periodic review. A team finds an issue, opens a ticket, prioritizes a fix, gets approval, and schedules remediation. That process was never perfect, but it worked when organizations had time to spare.
This doesn’t happen anymore despite security teams that are skilled and capable people who understand the threats in front of them. The deeper issue is structural. The tools and processes meant to protect organizations were built for an era that moved at a snail’s pace compared to today.
New AI tools can be deployed in minutes and permissions expand without anyone noticing. Integrations spread across business units long before a security team even knows they exist. Meanwhile, attackers are using that same speed against us, scanning and exploiting gaps faster than most companies can close them.
The result is a widening space between how fast risk appears and how fast security teams can respond to it, and it’s one I see repeatedly when I talk to CISOs and security leaders across industries.
Every new AI deployment raises the same uncomfortable questions. What data can this system see? What actions can it take on its own? Who approved it? Who’s accountable if it goes wrong? A cybersecurity company can’t credibly ask its customers these questions if it hasn’t answered them internally first. Too often, nobody has a clear answer because the tools meant to monitor and enforce those answers haven’t kept pace with what they’re supposed to be governing.
This is what keeps me up at night as someone who has spent my career on both sides of the fence, first finding the problem and now building the systems meant to fix them. The hard truth is that most security stacks today are built to detect issues after the fact rather than provide a proactive solution. Detection without fast remediation just means companies find out about their exposure after attackers already have, and a breach at a security vendor doesn’t just cost that company, it puts every customer relying on their access at risk.
What I saw firsthand during my years in the Israel Defense Forces’ cyber division, and what I see now running a company built to fix this exact problem, is that attackers don’t need sophistication, they just need a single overlooked misconfiguration. AI has only made that search faster on their end while most defensive tooling still moves at the old pace.
Cybersecurity companies need to hold themselves to the same standard they sell. That means treating their own environment, not just their product roadmap, as the thing under threat: continuous, proactive visibility into internal misconfigurations, not just periodic audits. Remediation timelines measured in minutes, not the 120-day cycles that are still industry average. And clear ownership over every AI tool an employee or engineer introduces internally, with the same rigor applied to customer-facing controls.
The organizations that recognize this problem, and invest in it at machine speed rather than human speed, will be the ones positioned to actually use AI’s advantages instead of inheriting risks they can no longer see coming.
_______
Tal Kollender is the Founder and CEO of Remedio, an autonomous security remediation platform securing more than three million enterprise devices globally. She founded the company in 2019 and bootstrapped it to profitability before raising a $65M Series A led by Bessemer.
Join our LinkedIn group Information Security Community!











