Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Indian cyber firms use AI to cut testing time to hours

Indian cybersecurity firms including Indusface and Astra Security are using AI agents built on large language models to cut software vulnerability testing from days or weeks to hours.

The shift comes as attackers move faster and AI tools begin identifying exploits on their own. Companies are adopting automated testing to keep pace with evolving threats.

Large client assessments that once took four to five days or up to 20 days for bigger applications now finish within hours, said Ashish Tandon, CEO of Indusface.

CrowdStrike said the average attacker breakout time fell to 48 minutes in 2025.

Gartner projects annual documented vulnerabilities will top 1 million by 2030 from about 277,000 in 2025.

Proofpoint, which expanded in India last year, said AI agents help review thousands of threat alerts daily as companies face tighter data rules and a shortage of security analysts.

🔗 Source: The Economic Times

🧠 Food for thought

Implications, context, and why it matters.

AI now finds software flaws on its own and can sometimes turn them into attacks

  • Use of AI in vulnerability testing is growing, including at Indian firms. Claude Mythos Preview found a bug in OpenBSD, an open-source operating system, that had gone unnoticed for 27 years, said Anthropic 1.
  • The same model can also turn known vulnerabilities into working exploits on its own. It reached a 72.4% success rate in the same benchmark, up from 14.4% for Opus 4.6, an earlier Anthropic model, said Anthropic 2.
  • That speed could shrink the gap between finding a flaw and using it in an attack. Security teams may face more pressure to use AI to keep up 3.

Security work is moving from finding flaws to fixing them

  • AI can uncover weaknesses faster, but that solves only part of the problem. The slow step is now remediation, the process of fixing security issues, which still often needs human review plus approval 4.
  • Many organizations already miss known problems. Across its incident response cases, 76% of compromises involved one or more of 10 known vulnerabilities that had patches available before exploitation, said Arctic Wolf, a cybersecurity company 5.
  • This could widen the gap across the security landscape. Large companies may use AI to spot flaws plus fix them, while smaller businesses may struggle with the volume because they lack staff or budget 4.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.