The New Cybersecurity Race: Defending Critical Infrastructure at AI Speed

India recorded 29,44,248 cybersecurity incidents in 2025, compared with 20,41,360 in 2024, according to CERT-In. The increase is significant at a time when the country’s critical infrastructure is becoming more connected. Railway networks, telecom systems, power infrastructure, industrial facilities, ports, and other essential services increasingly depend on digital networks, connected devices, remote monitoring, cloud platforms, and centralised control systems.

The nature of the threat is changing alongside this expansion. Artificial intelligence can accelerate activities that previously demanded considerable time and technical effort from attackers, including reconnaissance, vulnerability discovery, code analysis, credential harvesting, and identification of potential attack paths. CERT-In’s April 2026 advisory on frontier AI-driven cyber risks has highlighted the potential for advanced AI systems to support large-scale software analysis, identification of known and zero-day vulnerabilities, accelerated exploit development, automated reconnaissance, and attack-path discovery.

Srinivas Shekar
Co-founder and CEO
Pantherun Technologies

For critical infrastructure operators, the challenge is particularly complex. Attackers can continuously probe systems, test techniques, and modify their approach, while defenders operate in environments where changes need to be carefully evaluated. A security patch, configuration change, or system shutdown that may be relatively straightforward in a conventional IT environment could have operational consequences when applied to a railway network, industrial control system, telecom infrastructure, or power facility. Cybersecurity therefore has to address two requirements simultaneously: responding faster to evolving threats while ensuring that essential operations remain reliable and available.

AI Is Compressing the Attack Cycle

AI does not necessarily introduce an entirely new category of cyberattack. Its more immediate impact is on the speed and scale at which existing techniques can be executed. Reconnaissance provides a useful example. An attacker traditionally had to gather information about an organisation, examine its technology environment, identify exposed systems, and look for potential vulnerabilities. AI can help process large volumes of publicly available and technical information much faster, allowing potential attack paths to be identified more efficiently.

The same applies to vulnerability analysis. AI-assisted tools can analyse code, configurations, software documentation, and known vulnerability information at a scale that would be difficult to replicate manually. As these capabilities improve, the time between identifying a weakness and attempting to exploit it could become shorter. Attackers can also use AI to modify phishing content, automate aspects of social engineering, analyse defensive responses, and adapt techniques as an attack progresses.

This changes an important part of the cybersecurity equation. Security teams have traditionally worked with a certain amount of time between identifying a vulnerability, understanding the risk, and implementing remediation. When parts of the attack cycle become automated, that window can narrow considerably. For critical infrastructure, where systems often have long operational lifecycles and cannot always be patched or reconfigured immediately, the difference between attacker speed and defender response becomes particularly important.

Why Critical Infrastructure Presents a Different Security Challenge

Much of today’s critical infrastructure was built around reliability, availability, and long operating lifecycles. Operational Technology environments were traditionally separated from enterprise IT networks, and physical access controls and network isolation formed an important part of their security model.

That architecture has changed. Modern infrastructure depends on interaction between OT systems, enterprise applications, cloud platforms, connected sensors, remote monitoring systems, IoT devices, and central control centres. The operational benefits are considerable. Organisations can monitor equipment remotely, use predictive maintenance, analyse performance data, and make faster operational decisions. The same connectivity, however, means that systems which were once relatively isolated now form part of a much broader digital environment.

Railways illustrate this complexity well. A modern railway ecosystem may include signalling and communication systems, surveillance infrastructure, passenger information platforms, maintenance applications, connected sensors, ticketing systems, and central control infrastructure. These systems may perform very different functions, but the connections between them mean that cybersecurity cannot be addressed by looking at each asset independently.

An attacker may not necessarily target the most critical system first. A poorly secured device, an exposed application, compromised credentials, or a weakness in an enterprise network could provide an initial foothold. From there, the concern is whether the attacker can move laterally, gain additional privileges, or reach systems that have operational significance. Understanding these relationships is therefore becoming as important as protecting individual endpoints.

From Periodic Security to Continuous Understanding

Traditional controls such as firewalls, endpoint protection, identity and access management, network segmentation, vulnerability assessments, and security policies remain essential. The challenge is that many security processes were designed around periodic assessment or the identification of known indicators of compromise. That becomes difficult when both the technology environment and attacker behaviour are changing continuously.

Security teams increasingly need to understand what normal behaviour looks like across their infrastructure. Which devices usually communicate with each other? What kind of information moves between them? When do users typically access particular systems? Which applications interact with operational networks? What changes when a device or account behaves differently?

A single deviation may not indicate an attack. An unusual login, for example, could have a legitimate explanation. A connected device communicating with a different system may also be part of routine maintenance. But when several changes occur together, they can provide context that an isolated security alert cannot.

This is an area where AI can strengthen defence. Behavioural analysis can help establish baselines across large environments and identify deviations that warrant closer investigation. AI can also correlate signals from different parts of the infrastructure, helping security teams understand whether seemingly unrelated events may form part of the same incident. The objective is not simply to generate more alerts, but to improve the quality of information available to security teams.

The role of human expertise remains central. An automated system may identify unusual behaviour, but decisions involving operational infrastructure often require an understanding of engineering processes, safety requirements, business priorities, and the possible impact of containment measures. AI can reduce the burden of analysing large volumes of routine security information, while allowing specialists to concentrate on investigation and response.

Securing Communication Across IT and OT

Visibility alone is not sufficient if communication between connected systems is inadequately protected. As IT and OT converge, information continuously moves between devices, control systems, enterprise applications, operators, cloud platforms, and central infrastructure. Protecting this data while it travels across the network becomes an important part of maintaining the integrity of the overall environment.

Encryption therefore needs to be considered as part of the communication architecture rather than as an additional control introduced after systems have been deployed. Embedded encryption can help protect information as it moves between connected components, reducing the opportunity for an attacker to intercept or manipulate data travelling across the infrastructure.

This is especially relevant for geographically distributed sectors such as railways and telecom, where communication occurs continuously across large numbers of devices and locations. Protecting an endpoint without securing the communication pathways around it leaves another area of exposure. Security architecture needs to consider the complete journey of information, from where it originates to the systems that process, transmit, and act on it.

The same principle supports a broader move towards security-by-design. Identity controls, segmentation, encryption, monitoring, and secure communication are more effective when they are considered during infrastructure design rather than retrofitted after deployment. As India invests in new digital and physical infrastructure, incorporating these controls early can reduce complexity later.

Resilience Requires More Than Preventing an Attack

The financial impact of cyber incidents demonstrates the growing scale of the problem. IBM’s 2026 Cost of a Data Breach Report put the average cost of a data breach in India at ₹25.5 crore, a 15.9% increase over the previous year. In critical infrastructure, however, financial loss is only one part of the risk. A cyber incident can disrupt operations, affect the availability of essential services, and create wider consequences when interconnected systems are involved.

This makes cyber resilience a more useful objective than prevention alone. No organisation can assume that every attempted intrusion will be stopped at the perimeter. Security architecture also needs to determine how quickly suspicious activity can be detected, how effectively its potential impact can be understood, whether an attacker can be contained, and how essential operations can continue while the incident is being addressed.

Preparedness has to be tested rather than assumed. In 2025, CERT-In conducted 122 cybersecurity drills involving around 1,570 organisations across sectors including telecom, power, oil and gas, and transportation. Exercises of this nature are valuable because they test more than individual security products. They examine how technology, processes, and people work together when an organisation is responding under pressure.

For critical infrastructure operators, this also means understanding dependencies before an incident occurs. Teams need to know which systems are essential, what other systems they depend on, how communications can be isolated without interrupting critical operations, and what response actions are appropriate for different levels of risk. These decisions become much harder to make for the first time during an active cyberattack.

Building Defence for an AI-Speed Environment

The response to AI-driven cyber risks cannot be to simply add more security products to an already complex environment. Organisations need architectures that provide continuous visibility across IT and OT, understand changing behaviour, protect communications, control access, and support faster investigation and containment.

AI can help defenders process the scale and complexity of information generated by modern infrastructure, but technology alone will not determine resilience. Security teams also need clearly defined response processes, an understanding of operational dependencies, regular testing, and the ability to make informed decisions without disrupting essential services.

As India’s infrastructure becomes increasingly digital, the distinction between infrastructure and cybersecurity will continue to narrow. Connectivity will remain essential to improving efficiency, automation, and operational visibility, but every new connection also changes the environment that has to be protected.

The cybersecurity race is therefore increasingly about speed, context, and resilience. Attackers can use AI to find weaknesses and adapt techniques faster, while defenders need to identify changes early enough to prevent an intrusion from becoming an operational event. Building that capability will require security to be embedded into the architecture of critical infrastructure itself, with continuous visibility, secure communication, and the ability to respond to threats while keeping essential systems running.

Authored by Srinivas Shekar, Co-founder and CEO, Pantherun Technologies

Author