CERT-In Blueprint: Defending Against AI-Assisted Vulnerability Exploitation
Applies to: All entities; emphasis on financial institutions, government, telecom, critical infrastructure
A 38-page, 14-section national blueprint responding to AI-accelerated attacks. It warns that generative AI, LLMs and autonomous agents compress the cyber kill chain — reconnaissance, vulnerability discovery and exploit generation that took weeks now take hours — and pushes organisations from periodic compliance checks to continuous, intelligence-driven defence. Core asks: accelerated patching and continuous exposure management; behaviour-based anomaly detection and threat hunting in the SOC; identity-first security (continuous verification, least privilege); and deepfake-detection readiness. Chapter 12 governs an organisation's own AI use — AI asset inventories, shadow-AI monitoring, restriction of sensitive data on public AI platforms, validation of AI-generated code, and emergency shutdown mechanisms for autonomous and agentic AI. The 6-hour CERT-In incident-reporting direction continues to apply.
Why it matters
This is the most consequential single document CERT-In has produced, and it resets the baseline: detect-mode security is now officially deemed insufficient. The forward signal is Chapter 12 — for the first time an Indian regulator expects you to govern the AI you deploy as rigorously as the AI used against you, including a documented kill-switch for agentic systems. Expect the financial regulators' AI advisories (SEBI 5 May, RBI April) to converge on this language; standing up an AI asset inventory and a shadow-AI policy now is the cheapest way to stay ahead of the sectoral overlay that follows.