Yair Grindlinger — Surf AI
The best defenders do not wait for the future to settle.
The modern CISO does not have a visibility problem. They have an action problem.
For years, security teams have been buying tools to see more: more identity data, more endpoint signals, more cloud findings, more SaaS alerts, more vulnerability detections, more evidence that something, somewhere, might be exposed. The result is not clarity as much as volume.
Yair Grindlinger has spent enough time with CISOs to know the pattern. That insight began taking shape during Yair’s six years at Proofpoint, where he worked with CISOs to understand which security problems were still too big, too manual, and too operationally messy to solve with another dashboard. He spoke with CISOs across medium and large enterprises, and the same challenge kept coming back. These organizations had 50, 60, sometimes close to 100 security products. They had hundreds of thousands, if not millions, of assets to protect. They had alerts, detections, dashboards, and insights coming from every direction, but no reliable way to turn all of that into action.
Operationalizing cybersecurity, in Yair’s view, has become the central challenge for security teams.
That problem existed before AI, before cloud, before SaaS sprawl, before hybrid work, before every company became a collection of identities, tokens, certificates, cloud resources, applications, data, and third-party integrations. Cybersecurity has always had a hygiene problem. But the modern enterprise made that problem bigger, faster, and more dynamic than people could reasonably manage by hand. Now AI has added pressure from both sides: attackers have it, employees are using it, and enterprises are deploying it.
The question for security leaders is no longer whether AI will enter the organization. It already has. The question is whether defenders will use it well enough to keep up.
That is the thesis behind Surf AI, the company Yair co-founded two years ago. But it is also the thesis behind how Yair thinks about this moment in cybersecurity. AI did not invent the hardest problem in security. It made the old problem impossible to ignore.
Everybody Needs to Up Their Game
Yair is not interested in turning AI into science fiction. When people talk about AI-powered attackers, the conversation can quickly become abstract: autonomous hackers, self-directed malware, shadowy foreign models. Yair’s explanation is more grounded. AI does not necessarily create a brand-new attack path. It makes every step of the existing attack chain faster, cheaper, and more scalable.
The first step in an attack is research. Who works at the company? What infrastructure do they use? Which people are worth targeting? What systems are exposed? AI makes that intelligence-gathering easier. Then comes the path in: phishing, social engineering, vulnerability discovery, malware, tools for persistence, tools for exfiltration. AI improves each step because it lowers the cost of producing convincing content, finding weak points, and moving quickly once an opening appears. Attackers are not doing something entirely different. They are doing what they already did with more speed and less friction.
That is why Yair believes every security team has to raise its game. The attacker already has.
Security teams cannot respond to an AI-accelerated attacker with a human-paced operating model. If attackers can research faster, find vulnerabilities faster, and exploit faster, defenders have to reduce exposure before the breach begins. Detection and response still matter, but if the only plan is to catch the attacker after they are already inside, Yair thinks the organization is starting too late.
The work begins with exposure reduction: which assets are vulnerable, which identities are overprivileged, which tokens are unknown, which certificates are weak, which cloud resources are open, which data is exposed externally, which dormant assets still create risk, and which alerts are actually the same underlying issue showing up across different tools. In the old model, security tools identified problems and humans tried to interpret them. In the new model, Yair believes security needs to become a system of action.
From Insight to Action
For a long time, more visibility was the promise of cybersecurity software. The tool would tell you what it saw. Then it was someone else’s job to decide whether the signal mattered, what asset it applied to, who owned that asset, what the blast radius might be, whether remediation would break something, and who needed to approve the change.
That worked when the environment was smaller. It does not work when a large enterprise has millions of assets and dozens of tools generating overlapping alerts. Yair draws a clear line between a system of insight and a system of action. A system of insight gives the security team information. A system of action turns that information into a more secure environment.
That distinction matters because many breaches are not caused by a total lack of warning. There were signals. There were alerts. There was evidence of exposure. The problem was that the signals did not become action quickly enough. At enterprise scale, it is no longer realistic to expect humans to review, interpret, and act on every alert manually.
AI arrived at a moment when that bottleneck had become unavoidable, but AI only helps if it understands the environment it is acting inside. A general model cannot safely remediate an enterprise security issue without knowing what the asset is, who owns it, who administers it, what other systems depend on it, what happens if you change it, and what risk the company takes if it leaves the exposure alone.
In human workflows, that information lived in people’s heads, Slack threads, ticketing systems, old spreadsheets, institutional memory, and conversations across teams. Someone would figure it out eventually. But eventually is not good enough when attackers are moving faster.
That is where Surf’s product becomes relevant without needing to dominate the story. Yair describes the first job as understanding every asset well enough for automation to become responsible. Surf collects information from existing tools, organizes it into a graph, and trains models inside the customer’s own tenant so the system can understand the enterprise environment without sending sensitive data elsewhere. The output is not just another alert. It is an operating layer that can help agents move from detection to remediation, validation, and updating systems of record while keeping the right humans in the loop.
Every Enterprise Is Its Own Snowflake
One of the reasons cybersecurity remains difficult is that every organization becomes unique over time. Large companies do not have clean, universal asset maps. They have acquisitions, abandoned projects, cloud resources created by teams that no longer exist, service accounts, guest accounts, human identities, non-human identities, certificates, tokens, SaaS applications, data stores, cloud workloads, AI agents, and MCP servers. People change jobs. Admins and owners drift apart. Systems become business-critical without anyone remembering exactly how.
If a dormant asset is exposed, who owns it? If a vulnerability appears, which business process depends on the affected system? If a token is unknown, what happens if it is revoked? If a cloud resource is open, is it intentionally public or accidentally exposed? If data is shared externally, who approved it? If an asset is remediated, what breaks downstream?
Yair thinks about this in terms of ripple effect and blast radius. To fix something, you need to understand what happens if you do. To ignore something, you need to understand what happens if you don’t.
That is the practical reason he believes AI can improve security rather than simply create more risk. The right use of AI can help organizations find and close exposures faster than they could manually. It can distill overlapping alerts into one underlying problem, identify ownership, recommend remediation, communicate with the right people, update ticketing systems and CMDBs, and validate that the fix actually happened.
But none of that works if AI is treated like a generic intelligence layer sitting outside the enterprise. The model needs enterprise-specific understanding. Otherwise, it cannot distinguish between an asset that matters and an asset that only looks urgent.
This is where Yair’s optimism becomes more nuanced. He does not believe AI automatically makes companies safer. He believes AI gives companies the chance to become safer if they operationalize it correctly. Used well, AI can move an organization into a more secure posture than it has ever had. Used poorly, it can expose the organization more deeply than before.
The New Attack Surface Is the AI Stack
Yair’s optimism does not make him casual about risk. The more AI infrastructure companies deploy, the more attackers will try to turn that infrastructure against them.
AI agents are powerful. MCP servers are powerful. Internal systems that make it easier for employees to query applications, data, and workflows are powerful. That is exactly why they become attractive targets.
Yair uses MCP servers as a simple example. Unlike a rigid API, an MCP server can make it easier to communicate with an application or data source in a more flexible way. That flexibility is useful for employees and agents trying to get work done, but it can also be dangerous if the wrong actor can access it, prompt it, or use it to reach sensitive information.
The risk is not only that attackers will break in, but that they will convince the company’s own tools to help them. For years, some enterprise data benefited from a weak form of security by obscurity. The information existed, but it was hard to find because it was spread across systems, folders, tools, and teams. AI changes that. When an agent can search across the organization and synthesize information quickly, the crown jewels become easier to locate. That is useful for employees. It is also useful for attackers if access, identity, and data controls are not in place.
The future attack surface will not only be laptops, servers, cloud resources, and applications. It will be the AI layer itself: the agents, connectors, MCP servers, internal models, prompts, permissions, and data flows that companies use to move faster.
That does not mean companies should avoid AI. Yair thinks the opposite. Trying to block the wave is not realistic. Attackers have AI. Employees have AI. The business wants AI. The CISO’s job is not to stop it, but to make sure it is adopted securely.
Leaning Forward
Yair sees two postures available to security leaders right now: lean forward or lean backward.
Leaning backward means trying to slow the organization down, restrict new tools, and limit exposure by resisting change. That may feel safer in the short term, but Yair does not think it will work. AI is already inside the enterprise. Employees are experimenting with it. Business units want the productivity gains. Attackers are using it whether defenders approve or not.
Leaning forward means accepting the reality and building the capability to secure it. That does not mean reckless deployment. It means experimenting, testing vendors, understanding which tools fit the organization, and using AI to secure AI.
In Yair’s view, the best CISOs understand this. They see themselves as business enablers, not blockers. Their job is to help the company move forward while keeping it secure. That has always been the role, but AI makes the tension sharper. The organization wants speed. The attacker has speed. Security has to find a way to enable speed without losing control.
Yair has watched the major technology shifts that reshaped security: the internet, cloud, SaaS, and now AI. This time, he sees a level of recognition among CISOs that feels different. Security leaders understand the reality of the moment. They either figure out how to apply AI to secure their organizations, or they will be replaced by leaders who can.
It may sound blunt, but it is consistent with how Yair thinks about technological shifts. He does not romanticize control. He does not believe security wins by pretending change can be paused. The job is to understand the new environment faster than the attacker does and build the operating model to match it.
The Application Layer Matters
Yair is also clear that raw AI models are not enough. Enterprises are beginning to ask harder questions about cost, predictability, data exposure, intellectual property, and model control. If a company gives a large language model access to its internal information, what exactly is being shared? What is the cost of getting value back? Can the model be swapped if needed? Is the data staying in the right environment? Is the company exposing its edge?
This is where Yair believes the application layer becomes critical. Models are technology. Applications turn that technology into controlled value.
For security, that means using the right model for the right job, keeping sensitive data inside the customer environment when needed, relying on specialized models where they perform better, and making larger models switchable instead of deeply embedded. It also means designing systems that can use AI without sending the enterprise’s crown jewels to vendors unnecessarily.
Yair wants more Western open-weight models, more competition, and more specialized models, but his broader point is not geopolitical for its own sake. It is operational. Companies need to use AI in ways that improve productivity and security without giving up control of the information that makes them unique.
That is why Surf talks about the application layer. In Yair’s framing, the application layer is where raw AI becomes enterprise-grade: secure, predictable, cost-aware, and useful inside real workflows.
Cybersecurity Belongs to the Obsessed
Yair’s own path into cybersecurity started in the Israeli Defense Forces, but he is careful about what he takes from that experience. The advantage, as he sees it, was not secret knowledge. It was attitude.
He learned early that some problems have to be solved. Failure is not an acceptable outcome. That shapes the way a person approaches work: with persistence, urgency, and a belief that the thing can be figured out.
After the military, Yair joined a security startup that was sold to Computer Associates, spent time investing, built another cybersecurity company that was sold to Websense, built FireLayers, which was sold to Proofpoint, and then spent more than six years at Proofpoint before starting Surf. He has been an investor, entrepreneur, executive, and operator, but the throughline is the same. Cybersecurity moves quickly because every new technology immediately creates a security question. If you like standing still, it is the wrong field.
Yair jokes that he was never diagnosed, but he assumes he is probably hyperactive in some form. The industry rewards that kind of constant curiosity. There is always a new tool, a new attack surface, a new application, a new model, and a new way the other side might respond.
That is why his hiring philosophy starts with attitude. He does not begin with the degree or the exact prior role. Those things matter, but they are secondary. What he looks for first is obsession. Is the person driven enough to learn constantly? Do they experiment when something new is released? Are they self-taught? Do they have the grit to keep pushing when the answer is not obvious?
In Yair’s view, cybersecurity does not reward people who are merely interested. The field moves too quickly for casual curiosity. It rewards people who are slightly obsessed, who want to learn the new trick, test the new technology, apply it quickly, make mistakes, and try again.
It is not hard to see how that personal philosophy maps back to his view of AI and cybersecurity. The defenders who win will not be the ones who wait for the environment to settle. It will not settle. The only sustainable posture is to keep learning faster.
Yair is optimistic because he believes AI gives defenders a chance to move from overwhelmed visibility to continuous action. But his optimism is conditional. AI can make companies more secure, or it can make them more exposed. It can level the playing field, or it can tilt it further toward attackers. The difference will come down to who leans forward, who operationalizes faster, and who understands that in cybersecurity, speed without action is just more noise.
Cybersecurity has always belonged to the obsessed. AI just made that more obvious.











