CERT-In's new AI threat advisory sets patching expectations in hours, not weeks. The operating model it demands runs straight through the channel — and previews where global standards are heading.
For most of the last two decades, vulnerability management in Indian enterprises ran on a comfortable rhythm. A vendor disclosed a flaw, the security team assessed severity, the change-advisory board met, and somewhere between two weeks and two months later the fix went in. The cadence felt aggressive because it was, against the threats it was designed for. Attackers worked at human speed. Weaponisation took weeks. Defenders on a monthly cycle were not catching up, but they were not falling decisively behind either.
That model is now formally obsolete in India.
On May 25, the Indian Computer Emergency Response Team (CERT-In) issued a 38-page advisory titled "Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure." Section nine contains a remediation table that represents the most significant change in Indian enterprise security expectations in years. It tells organisations to patch, mitigate, or remove known exploited vulnerabilities on internet-facing and crown- jewel systems within 12 hours where feasible. Critical externally exposed vulnerabilities get one day. A known exploited vulnerability on internal systems also carries a one-day expectation "unless compensating controls are implemented and documented." Critical internal vulnerabilities get three days. High-severity vulnerabilities get five.
These are advisory expectations, not statutory deadlines. But anyone watching Indian cyber regulation evolve since the 2022 six-hour incident reporting directive knows the trajectory: today's advisory expectation is tomorrow's audit question, and the year after that, the regulatory floor.
The rationale CERT-In offered is direct. "AI-assisted cyber exploitation reduces the time required for adversaries to identify, weaponize, and exploit vulnerabilities, exposed services, weak identities, insecure APIs, and misconfigured systems," it said. The agency described threat actors using AI to automate attack surface discovery, vulnerability analysis, exploit chaining, and malicious code generation. The tooling, it warned, can let "even non-expert / semi- skilled / untrained threat actors to launch sophisticated cyber-attacks at scale." Agentic AI raises the prospect of "automated multi-stage cyber operations involving reconnaissance, exploitation, persistence, lateral movement, and data exfiltration."
The asymmetry is the point. If attackers are compressing their kill chains from weeks to hours using AI, defenders running monthly cycles are no longer slow. They are structurally exposed.
READING THE TIERS HONESTLY
The 12-hour figure is the line that will dominate coverage, and it is also the line most likely to be misread. The advisory does not demand 12-hour patching across the estate. It reserves that window for containment on internet-facing and crown-jewel systems where exploitability is already visible, then steps the obligation outwards in proportion to exposure.
That distinction is not cosmetic, said Sanchit Vir Gogia, chief analyst at Greyhound Research. The 12-hour figure covers containment on a narrow set of exposed assets, not patching across the estate. The five-day window for high-severity vulnerabilities is comfortable for most enterprises. The pressure point sits in the middle of the table. The three-day window for critical internal systems is where the pressure bites, Gogia said, because internal fixes trigger change-board friction in finance, telecom, healthcare, and OT-heavy estates where uptime sensitivity governs every decision.
For enterprises still running weekly or monthly patch cycles, the expectation forces a change in operating model, not just speed. The barriers are operational rather than technical. Most Indian organisations lack real- time asset visibility, automated prioritisation, and cross-functional response playbooks — the very capabilities the advisory now assumes as baseline.
Both the agency's framing and Gogia's reading converge on one diagnosis. The bottleneck is not patch deployment. It is visibility. Teams lose their first hours establishing whether the vulnerable asset even exists, who owns it, what it connects to, and whether isolating it breaks something else. "They are fighting organisational latency, not technical weakness," Gogia said.
THE CONTAINMENT SHIFT
The most strategically important move in the advisory is not the clock itself but what CERT-In allows in lieu of patching. The remediation table leans heavily on compensating controls and temporary mitigations. Organisations can fall back on documented controls for internal systems. Where no patch exists, they can apply "isolation, access restriction, WAF/API protection, enhanced monitoring, or feature disablement until remediation becomes available."
On the surface, that reads as a softening. In practice, it is a structural reframing.
The reliance on compensating controls makes the timelines more achievable, because it acknowledges the realities of patching complex environments. But it shifts the real burden onto comprehensive asset visibility and real-time exposure management. The controls work only if an enterprise can already see the exposed asset, identify its owner in minutes, and push controls at speed, Gogia said. If a team cannot isolate, restrict, or monitor quickly, the problem was never patch cadence. The problem was that the enterprise did not know its own exposure. The advisory, he said, "pushes vulnerability management out of periodic compliance and into continuous exposure management."
That distinction is the one Indian channel partners need to understand most clearly. Vulnerability management is administrative. It measures backlog. Exposure management is operational. It measures survivability. The advisory has moved the goalposts from one to the other, and the gap between what most Indian enterprises run today and what the advisory expects is precisely the gap channel partners are about to be paid to close.
WHERE INDIA STANDS AMONG GLOBAL FRAMEWORKS
CERT-In's clocks are among the most aggressive of any national framework. The international comparison sharpens the point. CISA's Known Exploited Vulnerabilities catalogue, the closest analogue, sets due dates per vulnerability — commonly around two weeks, compressing to roughly a day only for emergency edge-device situations, Gogia said. Europe is tightening through "without undue delay" duties and 24-hour reporting for actively exploited flaws under the Cyber Resilience Act, rather than fixed enterprise- wide remediation clocks.
The structural difference matters. "CERT-In has set standing clocks by asset category rather than deadlines by individual vulnerability," Gogia said. Western frameworks have largely avoided that.
The signal for global standards is the part worth sitting with. India is not diverging from the international direction of travel, Gogia argued. It is previewing it. The fixed- clock model looks aggressive today because the rest of the world has not caught up, not because India is reading the threat wrongly. As AI compresses exploit timelines globally, other regulators will be forced toward similar fixed-clock thinking.
For multinationals operating in India, the consequence is immediate. Internal global SLAs designed before AI altered exploit economics now sit below India's expectation. Those firms will need an India overlay for exposed and crown-jewel assets rather than a single worldwide standard. The SLAs that once looked prudent now risk looking structurally slow.
The advisory also aligns India with global prioritisation norms. It directs organisations to use Known Exploited Vulnerabilities (KEV) prioritisation, Exploit Prediction Scoring System (EPSS) likelihood assessment, and bill-of-materials mechanisms including SBOM, AIBOM, QBOM, and CBOM. These are international standards CERT-In has made the assumed floor.
THE VENDOR QUESTION
The advisory's sharpest test for the channel is what happens when a fix depends on a third-party vendor who cannot deliver inside the window. The advisory's own guidance is to fall back on isolation, access restriction, and enhanced monitoring while documenting mitigation actions and escalation steps. Contractual clarity on patch timelines, the document makes clear, is no longer optional.
The enterprise still owns the exposure window even when the patch does not, Gogia said. "Procurement can no longer optimise narrowly for features, integration, and cost," he said. Vendor responsiveness during an exploit window is now part of operational resilience. The governance failure is not vendor delay. It is arriving at disclosure without the contractual right to force a response already in hand.
The implication for the channel is direct. System integrators and resellers who sit as the contractual interface between Indian enterprises and global vendors are holding a value proposition that did not exist 18 months ago: vendor responsiveness as a saleable service tier. Partners who can negotiate, enforce, and
operationalise faster vendor SLAs — and layer compensating controls when those SLAs slip — are selling something the advisory has just made structurally necessary.
The organisations that struggle most, Gogia said, are rarely the technologically immature ones. They are the operationally fragmented ones, where infrastructure, SOC, application owners, cloud teams, procurement, and vendors run on disconnected clocks. Channel partners who can sell integration of those clocks — through MDR, exposure management platforms, attack surface monitoring, or tighter operational governance — are selling the resolution to the fragmentation the advisory has just exposed.
WHAT IT MEANS FOR THE CHANNEL
Read commercially, the advisory creates demand across several product and service categories at once.
External attack surface management and exposure management platforms move from nice-to-have to baseline. The advisory's Phase I roadmap, covering zero to seven days, directs organisations to "identify critical assets and internet-facing systems" — a Phase I instruction most enterprises cannot complete with what they have on hand. Managed detection and response services gain a sharper commercial argument: the 12-hour and one-day windows assume detection and response capabilities most enterprises cannot staff internally. SBOM tooling moves up the priority list, with CERT-In naming SBOM, AIBOM, QBOM, and CBOM explicitly. Patch automation, prioritisation engines tied to KEV and EPSS, and orchestration platforms all benefit.
Underneath all of it, the consulting opportunity is the largest. Most Indian enterprises will not buy a single product to meet the advisory's expectations. They will need to redesign processes, redraw responsibilities between security and IT operations, retrain staff, and renegotiate vendor contracts. That work is the channel's, if the channel is ready to do it.
THE SLACK IS GONE
AI did not invent vulnerability management pressure. What it has done, as Gogia put it, is remove the remaining slack from the system. The monthly patch cycle was always a compromise. AI-assisted exploitation has made that compromise indefensible, and CERT-In has now written it into national expectation.
The advisory is advisory. It will not stay that way. The Indian enterprises and channel partners that treat it as a preview of statutory obligation — and start closing the visibility, governance, and vendor-management gaps now — will be ready when it stops being voluntary. The ones that wait will find themselves explaining to auditors, regulators, and boards why their clocks ran slower than the attackers'.
That conversation is coming. The advisory has just set the date.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
