SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Check Point CTO on AI's double-edged sword

Check Point CTO on AI's double-edged sword

Wed, 22nd Jul 2026 (Today)
Donovan Jackson
DONOVAN JACKSON Interview Editor

The numbers tell a stark story. In 2018, the median time from a vulnerability's public disclosure to its exploitation in the wild was measured at up to two years. But now, the window has collapsed to days or even hours. Recent industry data suggests the median now sits around 10 hours for a growing share of exploited vulnerabilities, while security vendor Check Point has said more than  70% of attacks targeting known vulnerabilities are hitting as zero-day exploits, before patches are widely available.

This compression is one of the clearest signals that AI is accelerating both attack and defence in cybersecurity, and Check Point Chief Technology Officer Jonathan Zanger argued the shift is historic in scale.

"We live in an era where the biggest shift in cybersecurity is happening… it's as big as the popularisation of the internet was from a security perspective," Zanger told TechDay. "And it means that a lot of the concepts we developed over the years of how to secure systems must adapt, and fast."

Zanger's comparison is bold. Prior technological waves like the move to cloud, the explosion of mobile devices, or the industrialisation of ransomware, forced major changes in security architecture.

Whether AI represents a leap of similar magnitude is debatable, though there is certainly a case to be made. As the millennials like to say, Zanger comes with receipts: "For example, in software development. You can be way more productive. You can leverage your expertise to be multiple times better. You can start programming with minor and minimal knowledge," he continued.

The boost is available to everyone, including the bad guys. "Threat actors benefit from the same productivity gains when conducting cyber espionage, deploying ransomware or developing malware," he said. "The unit economics of conducting a cybercrime operation have changed."

On the defence

He said the benefits of AI extend well beyond software development to multiple realms of human endeavour. Including, of course, to infosec. "It enhances our ability as defenders to do a better job. For example, we always analyst teams monitoring threat groups on the dark web, on Telegram channels, investigating vulnerabilities. AI scales these operations, eliminating bottlenecks."

This is an attractive vision, but it comes with limitations. AI systems can hallucinate, produce false positives that overwhelm teams, or miss novel attack techniques. Over-reliance on automated systems risks creating blind spots, especially if the underlying models are trained on incomplete or biased datasets. Security teams still need skilled humans to interpret outputs and make high-stakes decisions.

Tasked with embedding AI across Check Point is a substantial responsibility. Asked how he's tackling it, Zanger said he takes two perspectives. "One is that AI is an incredible enabler for cybersecurity practitioners; our mission is to empower our customers so they can provide better and more efficient cybersecurity, and as it has done in software development, [AI advantages] will be true for cybersecurity practitioners. Our mission is to look at their day-to-day operations, and help them be 20 times more efficient. And this is extremely inspiring."

The second part, said Zanger, is leveraging AI tools to deliver better mechanisms protecting against zero day attacks 'where its AI defender versus AI attacker'. "On one hand I'm looking at what our customers need and how they're going to evolve; on the other, at how threat actors are behaving."

Complexity, scale, and speed 

Zanger said customers consistently cite three challenges in securing their enterprises: scale and complexity of hybrid environments (on-premises, cloud, SaaS, remote work) plus the rise of AI agents; the shrinking window between vulnerability discovery and exploitation; and the emerging need to secure AI-driven workflows. 

"Instead of just asking for help solving complexity, they're asking us to accelerate the operation as much as possible," he confirmed.

AI can help, by correlating signals across vast datasets, prioritising alerts, and enabling faster response. However, it is not a complete solution. Many organisations still struggle with basic hygiene, fragmented tools, and skills shortages. There's already an element of risk in inevitably heterogeneous environments, and almost always an element of disorder where practical realities don't quite match architectural schematics. Adding sophisticated AI layers on top of messy environments can increase complexity rather than reduce it.

Embedding AI 

Zanger outlined three main areas of focus for embedding AI at Check Point, starting with leveraging frontier models to strengthen core security capabilities, reinventing security operations so practitioners can work faster and more accurately, and securing the new AI layer as networks increasingly incorporate autonomous agentic systems that can reason and act with minimal human intervention. 

The third area is especially important and underexplored in most vendor discussions. Agentic AI introduces new attack surfaces: compromised agents could autonomously exfiltrate data, move laterally, or make damaging configuration changes. "We need to secure the new pure AI interface, for when networks evolve to have agentic transactions," Zanger stressed. "And that requires us to develop new models and new capabilities."

It's high level right now, but coming and fast. As the industry figures out what robust controls for agentic systems will actually look like in practice, it may be that the winners in a societal transition might not be those adopting AI the fastest, but those who do so most thoughtfully.