CERT-In pushes shift to continuous cyber operations as AI shrinks exploit timelines
The agency’s new blueprint calls for continuous monitoring, rapid remediation, AI-aware SOC operations and tighter governance as AI-assisted attacks compress the gap between exposure and exploitation.
India’s cybersecurity agency CERT-In is pushing enterprises towards continuous cyber operations as AI-assisted attacks reduce the time between vulnerability discovery and exploitation.
In its latest blueprint on defending against AI-assisted cyber exploitation, the agency said traditional perimeter-led and periodic security approaches are becoming insufficient as attacks become faster, automated and more adaptive.
The document outlines how AI is accelerating attack surface discovery, exploit generation, phishing campaigns and malware operations, increasing operational pressure on enterprise security teams.
CERT-In said organisations should “shift towards continuous exposure management, rapid remediation, continuous monitoring and real-time validation of security controls” instead of relying primarily on periodic assessments.
The agency has highlighted the “growing risk from interconnected enterprise environments” built around cloud infrastructure, APIs, third-party integrations and software supply chains, where a vulnerability in one component can impact multiple systems and organisations.
The blueprint places strong emphasis on reducing exploitable exposure quickly.
CERT-In said internet-facing exploited vulnerabilities affecting critical systems should be patched, mitigated or isolated “within 12 hours” where feasible, while critical externally exposed vulnerabilities should be addressed within one day.
The agency also called for continuous situational awareness around newly disclosed vulnerabilities, exploitation trends and adversarial techniques.
AI-driven attacks increase operational pressure on enterprises
CERT-In said AI-assisted attacks are increasing the scale and speed of cyber operations by automating several stages of the attack chain.
It identifies automated reconnaissance, vulnerability identification, exploit generation and chained exploit execution as some of the key risks emerging from AI-assisted cyber operations.
The agency also warned that “AI is lowering the barrier for cybercrime” by allowing less-skilled actors to launch more sophisticated attacks.
There are risks around AI-generated malware, automated scripting and semi-autonomous attack execution workflows that can operate at a larger scale than traditional attacks.
At the same time, AI is making phishing and impersonation attacks harder to detect.
CERT-In identified deepfake voice and video fraud, hyper-personalised phishing and executive impersonation attacks as growing enterprise risks as generative AI tools become more accessible.
The agency said organisations should strengthen “behaviour-based monitoring, threat hunting and continuous detection capabilities” as attackers increasingly use automation and AI-assisted techniques to evade traditional security controls.
The blueprint also pushes organisations towards identity-first security models, including continuous verification, least-privilege access and stronger access governance.
CERT-In said enterprises should assume breach scenarios and focus on reducing detection and containment timelines instead of relying solely on preventive controls.
The blueprint expands focus to AI governance and continuous validation
Beyond AI-assisted attacks, the blueprint also expands focus towards risks emerging from enterprise AI adoption itself.
CERT-In warned that AI systems are becoming attack surfaces through prompt injection, model manipulation, training data poisoning and insecure AI orchestration pipelines.
It also highlighted risks around unauthorised AI usage, shadow AI deployments and exposure of sensitive enterprise data through public AI platforms.
The document said organisations should establish AI governance structures, maintain visibility into AI systems and integrations, monitor AI APIs and define approval and review mechanisms for AI deployments.
CERT-In has called for tighter controls around sensitive data exposure in public AI systems, human validation of AI-generated outputs and operational boundaries for autonomous AI systems.
The blueprint places strong emphasis on AI-aware security operations.
Organisations should strengthen telemetry correlation, behavioural analytics, deepfake detection readiness and cloud and AI incident handling capabilities as part of modern security operations.
The document pushes enterprises towards continuous validation of security posture through red teaming, adversarial simulations, penetration testing and AI security assessments.
This includes prompt injection testing, AI API assessments, model integrity reviews and validation of AI workflows.
CERT-In also called for continuous security assurance across cloud environments, AI systems, privileged access and monitoring infrastructure.
The agency said organisations should conduct cyber resilience testing, ransomware simulations and backup restoration exercises to strengthen operational readiness against evolving AI-assisted threats.
Supply-chain exposure and interconnected systems increase cyber risk
CERT-In said increasing dependence on cloud platforms, software supply chains, APIs and third-party services is expanding enterprise attack surfaces and creating cascading risk across interconnected digital ecosystems.
The agency warned that vulnerabilities in a single component or dependency can propagate across enterprise environments and impact multiple organisations.
This increases “pressure on enterprises, service providers and channel partners” managing multi-vendor infrastructure and integrated environments.
The blueprint also places stronger focus on third-party assurance, dependency reviews and supply-chain validation as part of cybersecurity operations.
CERT-In outlined a phased implementation roadmap focused on immediate risk reduction, operational strengthening and advanced resilience validation.
The roadmap includes foundational governance and exposure reduction measures within the first seven days, followed by continuous monitoring, AI governance and threat hunting capabilities within 30 days.
The final phase focuses on adversarial simulations, automation-assisted defence operations, continuous control validation and AI security testing.
Now, organisations are expected to continuously monitor, validate and reduce exposure as AI-driven attacks become faster, automated and increasingly scalable.