CERT‑In Advisory | Severity: High
The Indian Computer Emergency Response Team (CERT-In) has released one of its most consequential advisories to date and this time, the threat isn’t a single CVE or a rogue malware strain. It’s the rise of AI-driven threats, fuelled by the convergence of frontier Artificial Intelligence with offensive cyber operations.
Advisory CIAD-2026-0020 signals a tipping point: AI systems have matured to a level where they can autonomously find, exploit, and chain vulnerabilities at a speed and scale that previously demanded entire teams of expert attackers. For CISOs, GRC professionals, and business leaders, this is not a future risk to prepare for; it is a present reality to respond to.
The advisory dedicates specific guidance to Micro, Small, and Medium Enterprises recognising that resource constraints are real but not an excuse. CERT-In recommends MSMEs focus on: enabling automatic OS and application updates, adopting MFA, using managed security services for patching and monitoring, avoiding unverified AI tools in production, and building a structured cyber incident response plan. Regular employee training on AI-generated scams is particularly emphasised.
At CyRAACS, we believe this advisory reinforces something we've long advocated: Governance, Risk, and Compliance is not a checkbox exercise — it is operational infrastructure for cyber resilience.
The six pillars CERT-In recommends map directly to the capabilities our COMPASS GRC platform is built to enable. From continuous vulnerability tracking and vendor risk management, to policy lifecycle governance and incident response workflow automation COMPASS is designed to give organisations the structured visibility they need to respond to exactly the kind of accelerated, AI-driven threat environment CERT-In is now warning about.
The question for every organisation is no longer if they will be targeted by an AI-augmented attack it is whether their GRC posture is mature enough to detect it, contain it, and recover from it faster than the attacker can adapt.