Twelve Hours, or Else: India's New Patch Clock Starts Ticking

CERT-In tells operators of internet-facing systems to close critical flaws within half a day, citing AI-assisted exploit chains that compress the attacker's runway to minutes.

ThreatVectr Newsdesk· 2 min read
Twelve Hours, or Else: India's New Patch Clock Starts Ticking
Share

The advisory landed on a Tuesday in New Delhi, slipped into inboxes alongside the usual traffic of vendor bulletins and quarterly compliance notes. By Wednesday morning, the security lead at a Mumbai-listed bank was reading it twice. Twelve hours. That was the new window. Twelve hours to find a critical vulnerability on anything exposed to the public internet, test a fix, and push it to production — "where feasible," the document said, in the way regulators leave themselves room.

The Indian Computer Emergency Response Team issued the directive this week, tightening expectations for how fast organisations must close critical, internet-facing flaws. The justification is blunt: attackers are now using large language models and AI agents to automate the slog of vulnerability discovery and exploit-building, and the older 48-to-72-hour patching cadence has become a luxury no defender can afford.

The shift is real. In the past year, researchers at firms including Palo Alto Networks and GreyNoise have logged mass exploitation of newly disclosed bugs within hours of public PoC release. The Citrix Bleed Two flaw, CVE-2025-5777, saw opportunistic scanning before some affected customers had even read the advisory. Ivanti, Fortinet, SonicWall — the same pattern, again and again. AI didn't invent the n-day problem. It just put a turbocharger on it.

CERT-In's guidance asks organisations to maintain a live inventory of internet-exposed assets, subscribe to vendor and CERT-In feeds, and define an internal SLA that maps to the 12-hour expectation for critical-rated bugs. Lower-severity issues get longer windows, scaled by risk. Boards are expected to see the metrics.

And here is where the room gets quiet. Most large Indian enterprises do not patch internet-facing kit in 12 hours. Some cannot patch it in 12 days. A senior incident responder at a Bengaluru consultancy, who asked not to be named because client work was active, put it plainly: "The directive is correct. The operational reality is that change-approval boards meet on Thursdays."

There is also the question of what "feasible" means in an audit. CERT-In has not yet published enforcement detail, and the agency's existing six-hour incident-reporting rule, in force since 2022, has been applied unevenly. Lawyers at Indian firms are already drafting memos on documentation: log the discovery, log the decision, log the reason a patch could not ship inside the window.

The Mumbai security lead closed the PDF and opened a spreadsheet of 1,400 external assets. He started counting the ones he could actually patch by lunch tomorrow. He stopped at forty.

© 2026 Threat Vectr