Why OEMs Need to Rethink Cybersecurity as AI Accelerates Threats

AI is changing the cybersecurity challenge for OEMs, making speed, visibility and resilience more important as attackers use automation to discover weaknesses and scale threats across connected systems.

author-image
DQChannels Bureau
New Update
Why OEMs Need to Rethink Cybersecurity as AI Accelerates Threats

Today, the focus of cyber threats in India has shifted towards 'speed and advancement', leveraging Artificial Intelligence (AI) and automated exploitation techniques, where transparent vulnerability disclosure, rapid patch deployment, and continuous testing are becoming operational necessities rather than mere compliance requirements. This AI-speed evolution of threats has also been reinforced in the CERT-In framework and guidelines, which aim to ensure that OEMs and technology providers safeguard digital infrastructure, including all critical software and hardware, from evolving AI threats.

Advertisment

Today’s reality is that AI is dramatically reducing the time between vulnerability discovery and exploitation, often from days to mere hours. By mandating AI-assisted security testing, accelerated patch timelines, immediate zero-day disclosure, and greater supply chain transparency, CERT-In makes it clear that cybersecurity can no longer be treated as a periodic or weekly exercise.

Why Continuous Hardware Assessment Is Important for Enhanced Security

OEMs and technology providers should maintain documented evidence and periodic certifications confirming that security assessments have been conducted and vulnerabilities are being actively managed. They should also establish accelerated patch management and vulnerability remediation processes aligned with the evolving threat landscape and the increasing speed of AI-assisted cyber exploitation. This is particularly important as CERT-In may conduct independent security assessments, vulnerability verification exercises, and patch validation reviews to evaluate the preparedness of OEMs and technology providers.

Continuous assessment can help OEMs maintain visibility into these changing risks and establish a more consistent process for identifying, prioritising, and addressing vulnerabilities before they become larger security incidents.

Advertisment

AI Is Changing the Vulnerability Management Equation

Today’s reality is that AI can significantly accelerate vulnerability discovery, exploit development, reconnaissance and attack execution. CERT-In has highlighted the ability of emerging AI systems to analyse large codebases, identify vulnerabilities, accelerate exploit development and automate multi-stage attack activity.

For OEMs, this changes the traditional vulnerability management cycle. A vulnerability that may previously have provided organisations with weeks or months to respond could potentially become an immediate security concern when automated tools are able to identify and exploit weaknesses at scale.

This is particularly relevant for hardware and connected products. Modern OEM products increasingly combine hardware, firmware, software, APIs, cloud services and third-party components. A vulnerability in any one of these layers can potentially create an entry point into a wider technology environment.

Advertisment

As a result, OEM security can no longer focus only on the security of the physical device. It needs to encompass the entire technology ecosystem surrounding the product, from development and manufacturing to deployment, updates, vulnerability management and eventual retirement.

AI-Exploitable Vulnerabilities Require Faster Remediation

For critical vulnerabilities (CVSS 9.0–10.0) that are likely to be exploited using AI, CERT-In has mandated emergency releases for IT systems and remediation timelines. The intent is clear: OEMs and technology providers must act swiftly before AI-assisted exploitation can scale and impact critical systems. To meet regulatory timelines, organisations have to turn to automated remediation and deploy Agentic AI capabilities that are critical for identifying threats promptly, maintaining compliance, and accelerating patch remediation.

AI-driven threats represent a fundamental shift in how OEMs need to approach vulnerability management. Severity alone is no longer sufficient to determine urgency. Organisations also need to consider how quickly a vulnerability can potentially be discovered, weaponised, and exploited using AI.

Advertisment

Several regulatory clocks run simultaneously. Depending on the sector and the nature of the incident, a breach can trigger reporting obligations under CERT-In, RBI, SEBI, IRDAI, NCIIPC, DoT, ABDM and DPDP. For OEMs, this makes the ability to rapidly validate and hyper-prioritise vulnerabilities, develop patches, test fixes and deploy remediation increasingly important. Where an immediate permanent fix is not possible, organisations also need to consider appropriate interim controls while remediation is being developed.

Global Security Teams Need To Align With Indian Requirements

Organisations headquartered outside India and supplying products, software, firmware, APIs, cloud services, or managed services to Indian entities must align their global security programs with India's evolving cybersecurity requirements.

Critical vulnerabilities must now be remediated within highly compressed timelines. Global Security teams will require stronger automation, real-time vulnerability management capabilities, and AI-enabled defensive measures to keep pace with increasingly automated threat actors.

Advertisment

Given the regulatory changes, this also makes coordination between global product security teams and India-facing teams increasingly important. A vulnerability discovered anywhere in the global product ecosystem could have implications for products and customers deployed in India.

What Should OEM Security Leaders Do?

Organisations should begin by conducting a gap assessment covering vulnerability assessment, patch management, incident response, vulnerability disclosure, security testing and supply chain controls. They should also review whether existing remediation SLAs can support the compressed timelines associated with AI-exploitable vulnerabilities.

Security leaders should ensure that they have:

  • Clear vulnerability disclosure and escalation processes
  • Defined patch management and remediation SLAs
  • Continuous vulnerability assessment across products and platforms
  • Documented evidence of security assessments and remediation activities
  • Visibility into software, hardware and other technology dependencies
  • A defined CERT-In liaison and operational reporting mechanism
  • Processes for communicating vulnerabilities and remediation guidance to affected customers
  • Automated capabilities for asset discovery, vulnerability prioritisation and remediation wherever appropriate
Advertisment

The objective should not simply be to prepare documentation for a compliance review. OEMs need to build operational processes that can function at the speed of the current threat landscape.

Today, organisations have to go beyond compliance and establish clear remediation processes aligned with the increasing speed of AI-assisted cyber exploitation in order to stay secure. The good news is that AI-speed detection, hyper-prioritisation, and autonomous remediation are already possible for organisations, enabling them to respond faster to increasingly automated cyber threats.

Written By: Himanshu Kathpal, Vice President, Product Management, Platform and Technologies, Qualys

Advertisment

Read More: 

USEReady and OpenAI partnership pushes AI into production

12 years of Make in India: Why electronics and Semicon could define the next phase

Canon imagePROGRAF TM targets space-constrained workflows

LTTS and Cognite partnership takes Industrial AI further