CERT-In Orders 12-Hour Critical Patch Windows for Internet-Facing Systems

India’s cybersecurity agency cites AI-assisted attack automation as driver for accelerated patching requirements.

Illustration: CERT-In Orders 12-Hour Critical Patch Windows for Internet-Facing Systems

India’s cybersecurity agency cites AI-assisted attack automation as driver for accelerated patching requirements.

  • CERT-In mandates 12-hour patching for critical vulnerabilities on internet-exposed systems where feasible
  • New guidelines respond to threat actors using AI and large language models to automate attacks
  • Requirements apply specifically to systems with internet-facing exposure to reduce attack surface

The Indian Computer Emergency Response Team (CERT-In) has introduced mandatory 12-hour patching requirements for critical security vulnerabilities affecting internet-facing systems, citing the growing threat of AI-assisted attack automation.

The new guidelines require organisations to apply security patches within 12 hours of vulnerabilities being flagged, where technically feasible. The directive specifically targets systems exposed to the internet, recognising their elevated risk profile in the current threat landscape.

CERT-In’s decision responds directly to observations that threat actors are increasingly leveraging artificial intelligence tools and large language models to automate vulnerability exploitation processes. This technological shift has compressed the window between vulnerability disclosure and active exploitation attempts.

The 12-hour timeframe represents a significant acceleration from traditional patching cycles, which typically allow days or weeks for critical updates. However, the guidelines include a “where feasible” provision, acknowledging that some systems may require longer maintenance windows due to operational constraints.

Internet-facing systems present particular risk because they are accessible to external attackers without requiring initial network penetration. Critical vulnerabilities in these systems can provide immediate entry points for malicious actors seeking to establish footholds in target networks.

The directive aligns with global trends toward more aggressive patching requirements as automation tools lower the skill barriers for vulnerability exploitation. Security agencies worldwide have observed shortened attack timelines as threat actors deploy AI-assisted scanning and exploitation techniques.

Why It Matters

CISOs operating in India must now implement processes capable of delivering critical patches within 12-hour windows for internet-facing infrastructure. This requirement demands pre-positioned patch management capabilities, accelerated change control processes, and clear escalation procedures for emergency updates.

The regulatory mandate creates compliance obligations that may require board-level awareness, particularly for organisations with limited patching automation. CISOs should prepare to report on patch deployment capabilities and any technical constraints that prevent 12-hour compliance windows.

What To Do Now

  • Review current patch management processes to identify capabilities for 12-hour deployment windows as outlined in CERT-In guidelines
  • Inventory internet-facing systems to determine scope of new requirements
  • Establish emergency change control procedures for critical vulnerability patches
  • Document technical constraints that may prevent 12-hour compliance for regulatory reporting

Sources