Cyble and DRONA Launch AI Cyber Defense Initiative
Cyble and DRONA Cyber Solutions launched an AI-powered cyber defense initiative on Tuesday at DRONA's Command and Control Centre in Ahmedabad, demonstrating a security workflow from threat detection through endpoint containment. The Cyber Express reported that the managed-security model combines criminal-marketplace threat intelligence, investigation, and endpoint enforcement, with a human analyst authorizing the final containment action.
Cyble and DRONA Cyber Solutions launched an AI-powered cyber defense initiative on Tuesday at DRONA's Command and Control Centre in Ahmedabad, demonstrating a workflow from threat detection through endpoint containment.
According to The Cyber Express, the joint initiative combines Cyble's threat-intelligence, investigation, and endpoint-security capabilities with DRONA's security operations analysts in a managed-security model. IT Security News, which indexed the announcement, likewise described the launch as a complete security chain spanning detection and containment.
Demonstration used human-authorized containment
The Cyber Express reports that the live demonstration began with material recovered from logs circulating on a criminal forum and a lookalike domain registered to impersonate a target organization. Analysts traced the associated infrastructure, identified a pattern of prior activity linked to the same actor, and demonstrated detection and containment of an endpoint intrusion attempt.
The workflow used Cyble Hawk for investigation and attribution and Cyble Titan for endpoint enforcement, according to The Cyber Express. The outlet reported that Cyble Titan used hardware-level integrity checks as part of its assessment. Crucially, a DRONA human analyst authorized the final containment action rather than allowing the system to execute that action independently.
Operational implications
This demonstration reflects a common security-operations pattern: AI-assisted tools can shorten the path from external threat telemetry to an investigation, but organizations often retain human approval at high-consequence response points. In comparable managed detection and response deployments, that separation can help teams balance faster triage against the operational risk of automatically isolating legitimate endpoints.
The Cyber Express framed the initiative against unequal cybersecurity capacity across Indian organizations, reporting that large enterprises and banks more frequently have dedicated security teams while manufacturers, hospital chains, schools, and mid-sized firms can have fewer resources. The reported design places DRONA analysts at the decision point, making the initiative relevant to teams evaluating how threat-intelligence feeds, endpoint controls, and analyst workflows can be integrated without fully autonomous remediation.
Key Points
- 1Cyble and DRONA demonstrated a managed-security workflow that links external threat intelligence, investigation, endpoint assessment, and containment in Ahmedabad.
- 2The reported workflow reserves final containment authorization for human analysts, maintaining operator control over a high-consequence endpoint response action.
- 3The initiative combines threat intelligence, investigation, endpoint enforcement, and analyst decision-making in a managed-security model.
Scoring Rationale
The launch is a practical AI-assisted security-operations deployment rather than a broadly available model or platform release. It is relevant to security and ML practitioners designing human-in-the-loop detection and response workflows, particularly for managed-security environments.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


