CERT-In’s AI-Era Cyber Rules Test Enterprise Reality

InfoRiskToday / ISMG

28 May 2026

Quoted by Rashmi Ramesh in an InfoRiskToday / ISMG article on CERT-In guidance urging organizations to mitigate serious internet-facing flaws within 12 hours as AI compresses attacker timelines.

The Quotes

“Directionally a strong and necessary document” — but it should be read as a strategic aspiration rather than an operational baseline.

“The blueprint largely assumes organizations already possess a certain level of operational maturity, visibility, engineering discipline and remediation capacity.”

“Aggressive remediation timelines can unintentionally turn into compliance theatre where organizations either hide exposure, delay reporting or apply rushed changes without proper validation.”

“AI compresses time, but it does not magically create operational maturity. That is the key challenge organizations now need to solve.”

Anant Shrivastava, Founder & Chief Researcher, Cyfinoid Research

Context

CERT-In’s blueprint warns that AI is shrinking the window between vulnerability discovery and exploitation, and proposes aggressive remediation timelines (including a 12-hour target for known exploited vulnerabilities on internet-facing or critical systems). The article captures practitioner pushback on whether most Indian organizations can realistically meet those expectations without foundational inventory, ownership, and engineering capacity.