Roey Vilnai, Director Cyber Research, Axonious.
Security Researchers: Digital Fighters Series

Axonius: “Not being knowledgeable enough about something is no longer an excuse”

Roey Vilnai, Director of Cyber Research at Axonius, explains why today's security researchers must treat their AI tools as team members as part of CTech’s Security Researchers series.

“AI has raised the expectations from researchers across all the different levels,” says Roey Vilnai, Director of Cyber Research at Axonius. Vilnai began his cybersecurity career as an officer in the IDF’s Unit 8200 before joining Cynerio as one of its first employees in 2018. Following the company's acquisition by Axonius in August 2025, he was appointed to his current role leading the cyber research team.
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Roey Vilnai Axonious
Roey Vilnai Axonious
Roey Vilnai, Director Cyber Research, Axonious.
(Photo: Axonious)
As Vilnai reflects, the AI revolution has granted unparalleled access to knowledge for practitioners across the board, including students, and resultantly, in the field, “not knowing something, or not being knowledgeable enough about something, is no longer an excuse for anything.”
You can read the entire interview below.
ID Card Company name: Axonius Founders: Dean Sysman, Ofri Shur, Avidor Bartov Year of founding: 2017 Current number of employees: 700+
Company Description:
Axonius is the asset intelligence platform for unified security operations and exposure management.
About Axonius' Security Research Team:
The Axonius Cyber Research team works closely with the product and engineering teams to make sure our work is tightly integrated with the Axonius Asset Cloud. Our work translates into value the customer can get from the platform. This can be in the form of insights on their data, better prioritization of issues, and detection analytics.
What’s unique about Axonius is that we cover more than 40 asset classes including security, software, SaaS, cloud, connected devices, and AI tools. The Axonius Cyber Research team is just as diverse, with backgrounds in network research, threat hunting, and data analytics.
What is your background in cyber, and what led you to specialize in security research?
I started my cybersecurity career during my military service in Unit 8200 in the Israel Defense Forces (IDF). I served for four years in different intelligence roles that are unrelated to cyber, and transitioned into a cyber research role only as an officer. After two years of serving as a cyber intelligence officer, I left the service and pursued a B.S. in computer science. During that time, I continued to do cyber work in other government agencies.
The most significant part of my career was in Cynerio, a medical device security company, which I joined as one of their first employees in 2018. During my time there, I built the data analytics pipeline, the cyber research team, and the data science team. After the acquisition by Axonius in August 2025, I was appointed to be Director of Cyber Research.
What does your security research team look like in action?
The relationship between product and research is an interesting one. The product team has an idea of what we need to build and deliver, and the research team has a good understanding of what we can achieve given the unique data Axonius has. Approximately half of the initiatives originate in the product team, and half in the research team. Eventually, we all work together to make sure the data and insights we give to customers are also easy to consume.
How does the research team influence your company at large?
The Axonius Cyber Research team is one of the youngest teams at Axonius and influential within the company. Before, Axonius was great at giving customers data that they could act on. But, it was up to the customer to find the insights they were looking for, define workflows, and decide how to act on these findings. We’re now shipping a much more holistic experience for the customer that is driven by the research my team does.
What has been your team’s most significant security discovery to date?
The Axonius Research team was originally founded as the security research team in Cynerio, which Axonius acquired in August 2025. Since Cynerio was a healthcare security company, research was focused on the healthcare industry. Not long prior to the acquisition, we researched many different information systems that are prevalent in the healthcare industry, including systems related to patient management, imaging, healthcare data analytics, and more.
Systems were prone to trivial script kiddy attacks, and could expose data of thousands of patients in a single API call. Due to the heavy regulation around healthcare data in the United States, the financial implications of this are huge. Healthcare has still a long way to go to be up to standard when it comes to data privacy and security.
Who or what is your 'Moby Dick'?
For us at Axonius, it's AI as an asset class. There are many startups that operate in the AI security domain, and all the major players have products in that domain. Still, there isn't a clear definition of what this domain is, and the space is extremely fragmented. I think Axonius is well-positioned to help organizations understand the AI assets in their environment, and I view this as a research endeavor as much as a product one.
How would you characterize the competition between research teams today?
Competition is intense. Security teams in the industry push to find and publish vulnerabilities first, but there's also a lot of sharing through conferences, open-source tools, and threat intelligence. When a major threat hits, most security teams end up cooperating because everyone benefits. Still, there's real pressure to be first, especially when reputation and hiring depend on high-profile discoveries.
What is your take on the future of the human security researcher?
Like in any other role in this industry, AI has been a huge disruptor. I tell my team all the time: AI has raised the expectations from researchers across all the different levels. I remember when I started my career in the industry as a student in Microsoft, my boss told me that every day I don’t crash production is a good day for me. Those were the expectations from someone just starting out their career in the company.
Now, my expectations for students at the same stage as I was back then are much higher. The access they have to knowledge is unparalleled, and so not knowing something, or not being knowledgeable enough about something, is no longer an excuse for anything.
As I see it, every researcher is a team of researchers: the human researcher, his buddy Claude, his colleague Gemini, and his friend ChatGPT. To succeed, you must work together with all of them effectively. And the most interesting thing about this is that I see my employees generally doing this successfully. I have students in my team that do much better work than I did when I was at that stage in my career.