FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·CriticalBreaking

India Mandates 12-Hour Security Patching

Abstract image of a digital clock counting down from 12 hours, representing a new cybersecurity patching deadline for server vulnerabilities.

TL;DR: India's CERT-In has issued a new guideline for organizations. They must now patch critical vulnerabilities in internet-facing systems within 12 hours of notification, where feasible. This rapid response is required to counter threats from attackers using AI tools to automate and accelerate their attacks.

By Neeraj Dhiman·3h ago·1 min read·updated 59m ago
Source

Key facts

Category
Cybersecurity
Impact
Critical
Published
3h ago
Source
The Hacker News

Full summary

India's cybersecurity agency now requires organizations to patch critical internet-facing vulnerabilities within 12 hours of being flagged, where feasible.

India's Computer Emergency Response Team (CERT-In) has introduced a significant new guideline for organizations. The directive mandates that critical security vulnerabilities in internet-facing systems must be patched within 12 hours of being flagged. This requirement applies "where feasible," offering some operational flexibility for complex scenarios. The new policy represents a major shift towards a more aggressive and proactive national security posture, aiming to drastically shorten the time that critical infrastructure and corporate systems remain exposed to known threats. It underscores the growing urgency among cybersecurity agencies to counter increasingly sophisticated and rapid cyberattacks.

The primary motivation for this accelerated timeline is the rise of AI-assisted attacks. CERT-In highlights that malicious actors are increasingly using artificial intelligence and large language models (LLMs) to automate the discovery and exploitation of software flaws. These tools enable attackers to scan for vulnerable systems and launch attacks at a scale and speed previously unseen, creating a much smaller window for defenders to react. The 12-hour mandate is a direct attempt to outpace these automated threats. For businesses, this means IT and security teams must re-evaluate their incident response and patch management protocols to ensure they can meet the demanding deadline. Compliance will require highly efficient testing and deployment processes.

Why it matters

This mandate sets a new, aggressive standard for patch management, forcing companies to adapt their security operations to counter faster, AI-driven attacks.

Business impact

Companies operating in India must overhaul their patch management and incident response plans to comply with the 12-hour deadline. Failure to do so increases compliance risk and exposure to rapid, automated cyberattacks, potentially leading to significant operational disruption and data breaches.

⚡ Action needed

Organizations with internet-facing systems in India must review and update their security policies and patch management procedures to comply with the new 12-hour mandate.

Action checklist

  1. 1Review CERT-In's new guidelines to understand the full scope.
  2. 2Assess your current patch management process and identify bottlenecks.
  3. 3Update your incident response plan to accommodate the 12-hour timeline.
  4. 4Implement automation for vulnerability scanning and patch deployment where possible.
  5. 5Ensure you have 24/7 monitoring and response capabilities for critical alerts.

Tags

#AI#compliance#cybersecurity#patch management#cert-in#india

Related on Notifire

  • ResearchAI fact-checking for generated content
  • Researchllms.txt
  • ResearchKubernetes security
  • ResearchSoftware supply-chain security

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: The Hacker News

Part of our research on

  • Critical CVEs of 2026 →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube