<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-5MNKFGM7" height="0" width="0" style="display:none;visibility:hidden">

CIONET Trailblazer: Beyond the Hype: Why the AI Clock is Ticking for Every CIO

Published by Daniel Eycken
July 29, 2026 @ 10:08 AM

I recently sat down with Jelle Schroven, Regional Director Belux at Zscaler, to get past the industry buzz and talk about what’s actually changing on the ground. While much of the AI conversation focuses on what these tools can create, Jelle is focused on something more urgent: the shrinking window of time IT teams have to defend their networks. As AI models move from theoretical experiments to agentic reality, our traditional defences are being tested in ways we haven’t seen before. In this conversation, Jelle shares his perspective on why the 'wait-and-see' approach to AI security is no longer an option, and why Zero Trust has moved from a long-term roadmap goal to a 'must-fix' for this quarter.

The Threat: Scanners have existed forever. What actually changes when an AI model does the looking?

For years, IT teams could think about cybersecurity in familiar terms: patch software, update firewalls, train employees, and quickly respond when something goes wrong. That world is changing fast with the new generation of frontier AI models such as Mythos and Daybreak. Those models can now do what once required highly skilled hackers: Identify hidden software weaknesses and accelerate the path to exploitation.

Until now, defenders had a time advantage: Attackers searched for weaknesses, and defenders hoped to patch them before serious damage was done. Frontier AI is compressing the time between vulnerability discovery and exploitation from weeks to minutes; the window of opportunity to fix issues before damage can be done is collapsing. Even large security teams already struggle to fix their most serious weaknesses quickly enough.

The Urgency: Why is this a problem for this quarter for a CIO rather than for next year?

So far, security teams have worked on the assumption that attackers follow a familiar sequence of reconnaissance, exploitation, credential theft, privilege escalation, lateral movement and, eventually, data access or disruption. That sequence still exists, but it is no longer necessarily linear, manual, or slow.


Frontier models and agentic AI systems are beginning to compress the attack timeline. They can itemise exposed assets, test vulnerabilities, automate phishing workflows, dump credentials, probe internal systems and chain findings together at a speed that human defenders cannot realistically match through manual investigation alone. In this environment, the traditional idea of dwell time becomes increasingly fragile. If attackers can move from initial access to meaningful impact in minutes or hours, waiting to accumulate alerts, correlate signals and manually confirm intent is no longer good enough and creates an urgency for CIOs to react to the new situation now.

The Blueprint: With so many moving parts (identities, cloud environments, APIs), where should a team practically focus their energy first?

This machine-speed attack capability weaponises every minor misconfiguration and unpatched system, making every enterprise a potential target for immediate, widespread compromise, and most organisations are still fighting with outdated tactics.

Zscaler Hence, the fundamental first step is to drastically reduce exposure by taking things off the internet. If a system doesn't need to be seen by the entire internet, it should be segmented and isolated. Organisations have to implement a modern access solution that hides, protects, and isolates their assets. This buys organisations critical time and removes the immediate attack vector. The key to survival in the machine-speed generation is embracing a true Zero Trust security platform, which boils down to the granularity of access rather than relying on traditional hardware-based security.

The Architecture: How does this shift enterprise security architecture in practice?

Despite years of innovation, many organisations still rely on legacy IT architectures built for a very different threat landscape. They are relying on physical or virtual firewalls and VPN systems. This has now become a critical challenge: In an AI-driven world, the long-standing assumption that applications and services can safely remain exposed to the internet is becoming increasingly difficult to defend.

The network perimeter, once a stout fortress, has dissolved. Relying on traditional VPNs or firewall access to the network simply grants a compromised user or device a beachhead inside the network. The current AI-generated landscape demands that we implement true Zero Trust, ensuring devices are protected and isolated, connecting only to who and what they are authorised to access, and nothing more.

True Zero Trust operates on the principle of least privilege, segmenting access down to the individual application or service level. This means a device connecting to the network isn't allowed to see or communicate with anything it isn't explicitly configured to use. This extreme granularity is the only effective defence mechanism against machine-speed lateral movement, transforming a full network compromise into a contained, single-asset incident.

The Team: How should responsibilities evolve among security, infrastructure, and application teams to close this window?

I actually think this is where many organisations struggle today, as they still operate in silos. IT owns the enterprise platforms, shared AI capabilities, integration, and the technical foundation. Security is in charge of policies, guardrails, and risk management. HR plays a critical role in workforce transformation, skills, and adoption. The mistake organisations make is trying to centralise everything or decentralise everything.

I would rather suggest adopting a federated approach with centralised capabilities that should be built only once, like enterprise AI platforms, governance, security, model access, and reusable services. Then we empower the business functions to innovate on top of those shared capabilities because they are closest to the business problems they are trying to solve.

The Reality Check: What do you say to the CIO who is shorthanded, behind on patching, and worried this is just vendor hype?

Frontier AI changes the risk and threat landscape. This does not diminish the importance of cyber hygiene measures such as patching, detection, response, and user education. However, CIOs need to move beyond a patching-only mindset. Patching remains essential, but it is no longer sufficient on its own.

Risk must be prioritised based on exploitability, business impact, and exposure, rather than solely on technical severity scores. Fixing a flaw in a public-facing service that attackers can reach immediately is a far higher priority than fixing a vulnerability with a similar severity score in an isolated internal system.

The question is no longer simply whether a vulnerability exists in software; we must assume it does, but how long it remains exposed. For business leaders, the priority now is to reduce unnecessary exposure, modernise access architecture, and ensure that AI adoption is matched by an equally mature security discipline.

 --

You May Also Like

These Stories on CIONET Belgium

Subscribe by Email