Compliance

CERT-In Guidelines on AI-Accelerated Vulnerability Protection: What Organizations Need to Know

June 29, 2026·6 minutes·By



The Indian Computer Emergency Response Team (CERT-In) has introduced cybersecurity recommendations for Original Equipment Manufacturers (OEMs) and technology providers to strengthen protection against modern cyber threats. These guidelines focus on improving vulnerability management, secure software development, faster incident response, and protection against AI-enabled cyber attacks.

As organizations increasingly adopt cloud platforms, artificial intelligence (AI), APIs, digital services, and connected technologies, cyber risks are also increasing. Attackers are using AI-based tools to discover vulnerabilities, automate attacks, generate malicious code, and target digital infrastructure more efficiently.

To address these challenges, CERT-In recommends that technology providers follow stronger security practices throughout the product lifecycle.

AI-Based Vulnerability Detection and Security Testing
Technology providers should regularly assess their products, applications, software, firmware, APIs, and cloud services for security weaknesses. Security testing should include vulnerability assessments, penetration testing, source code reviews, dependency analysis, threat modelling, and AI-assisted security testing methods.

Organizations should also evaluate risks associated with AI-powered services and automation tools. Proper security measures such as monitoring, logging, access controls, and human oversight should be implemented to reduce risks like data leakage, unauthorized access, prompt injection attacks, and misuse of AI systems.

Continuous Vulnerability Monitoring and Reporting
CERT-In recommends maintaining continuous vulnerability monitoring mechanisms. When critical or high-risk vulnerabilities are identified, affected customers and relevant authorities should be informed quickly with details about the risk, temporary protection measures, and recommended solutions.

For zero-day vulnerabilities or active exploitation cases, technology providers should provide immediate notifications, indicators of compromise, and guidance to help organizations reduce potential damage.

Faster Patch Management
Security updates and patches should be developed and released based on the severity of vulnerabilities. Critical security issues require faster response because attackers may exploit them before organizations can apply fixes.

If immediate patch deployment is not possible, organizations should implement temporary security measures such as:

  • Restricting access to vulnerable services
  • Applying firewall and security monitoring rules
  • Improving network segmentation
  • Enabling multi-factor authentication
  • Strengthening system configurations

Secure Software Development Practices
CERT-In highlights the importance of Secure Development Lifecycle (SDL) practices. Technology providers should include security at every stage of software development, from design and coding to testing and deployment.

Security practices should include:

  • Secure coding standards
  • Code reviews
  • Security testing before release
  • Software dependency checks
  • Supply chain security management
  • Software Bill of Materials (SBOM) maintenance

Products should avoid security weaknesses such as default passwords, hardcoded credentials, exposed administrative interfaces, and insecure configurations.

Identity and Access Security
Strong access management is essential to prevent unauthorized system access. Technology providers should implement security controls such as:

  • Multi-Factor Authentication (MFA)
  • Role-Based Access Control (RBAC)
  • Privileged access management
  • Regular credential reviews
  • Secure management of API keys and security tokens

Regular checks should be performed to ensure that sensitive credentials are not exposed in public repositories or unauthorized systems.

Incident Response and Transparency
Organizations should maintain proper incident response processes to quickly detect, manage, and recover from cybersecurity incidents.

In case of a security breach, technology providers should:

  • Inform affected customers
  • Preserve security logs and forensic evidence
  • Identify indicators of compromise
  • Support investigation and recovery activities
  • Provide regular updates until resolution

As per CERT-In directions, applicable cyber incidents must be reported to CERT-In within the required timeline.

Key Security Deliverables Expected from Technology Providers

CERT-In recommends that technology providers maintain:

  • Updated security posture assessments
  • Vulnerability remediation plans
  • Continuous security assessment reports
  • Vulnerability Assessment and Penetration Testing (VAPT) records
  • Secure Development Lifecycle compliance evidence
  • Updated Software Bill of Materials (SBOM)

Conclusion
AI-driven cyber threats are evolving rapidly, making proactive security practices essential for organizations. CERT-In’s recommendations encourage technology providers to improve vulnerability management, strengthen software security, respond faster to threats, and build greater trust with customers.

Following these practices can help organizations create a more secure digital ecosystem and reduce risks from emerging AI-powered cyber attacks.

NOTE:
This article is a simplified explanation based on cybersecurity guidelines issued by the Indian Computer Emergency Response Team (CERT-In).
Reference: CERT-In Official Website

Need help with this topic?

Our security experts can assess your specific situation and provide actionable recommendations.

Talk to an Expert

Secure Your Business Today.

Talk to our security experts. No sales pitch — just an honest assessment.