Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing

  • Home
  • Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing
Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing
Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing
Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing
Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing
Securing Industrial Control Systems: OT/ICS Cybersecurity for Indian Manufacturing

Indian manufacturing is undergoing a rapid digital transformation. Industry 4.0 initiatives, government schemes such as Make in India and PLI, and the push for smart-factory automation are driving plant operators to connect their Operational Technology (OT) networks to enterprise IT systems — and, increasingly, to the internet. This convergence brings enormous efficiency gains, but it also exposes Industrial Control Systems (ICS), SCADA platforms, and Programmable Logic Controllers (PLCs) to cyber threats that were, until recently, limited to the enterprise IT world.

For Indian CISOs and plant managers, the stakes could not be higher. A successful intrusion into an OT network does not just mean stolen data — it means halted production lines, spoiled batches, damaged machinery, safety incidents, and potentially catastrophic environmental or physical consequences. In regulated sectors such as pharmaceuticals, chemicals, oil and gas, and power distribution, a single OT breach can attract regulatory scrutiny under CERT-In’s 6-hour mandatory reporting directive and civil liability under the emerging DPDP Act framework.

Why OT/ICS Networks Are Under Siege Right Now

Until recently, most industrial networks operated in isolation — the classic “air gap” defence. Today that gap has largely closed. Remote monitoring, predictive maintenance platforms, and ERP integrations mean that PLCs and SCADA servers are routinely reachable from the corporate WAN, cloud tenants, or even contractor VPNs. Threat actors have noticed.

The Threat Landscape in India’s Industrial Sector

  • Ransomware targeting OT environments: Groups such as LockBit, BlackCat, and their successors have specifically developed capabilities to identify and encrypt SCADA historians and HMI workstations, knowing that plant downtime creates enormous negotiating leverage.
  • Living-off-the-land in ICS networks: Attackers increasingly abuse legitimate tools — RDP, WinRM, or industrial protocols such as Modbus and OPC-UA — to move laterally once they establish a foothold in the corporate network, avoiding detection by traditional signature-based tools.
  • Supply-chain and vendor access risk: Many Indian plants rely on overseas OEM vendors for remote diagnostics. Unmanaged third-party access channels — often using weak credentials or outdated VPN clients — represent a primary entry vector.
  • Vulnerable legacy systems: Engineering workstations running Windows XP, Windows 7, or unpatched Windows Server 2008 remain common in older plants. These systems cannot be patched without extensive validation and often cannot run modern endpoint security agents.
  • Targeted espionage: Strategic industrial assets — defence contractors, critical infrastructure operators, pharmaceutical exporters — face nation-state-level adversaries seeking intellectual property, production blueprints, or the ability to disrupt operations at a time of their choosing.

The OT/IT Convergence Challenge

IT security teams typically own firewalls, SIEMs, and endpoint agents. OT teams own PLCs, DCS systems, and SCADA historians. In most Indian manufacturing companies these two groups have separate budgets, separate tooling, and a history of mutual distrust: IT teams often lack knowledge of industrial protocols; OT teams often reject any security change that touches production systems without extensive change-control cycles that can stretch to months.

Bridging this gap requires both a technical architecture and an organisational model. PJ Networks approaches OT/ICS engagements with a structured methodology built on three principles:

  1. Passive visibility first: Before any active scanning, we deploy passive OT asset discovery to build a complete inventory of ICS devices, firmware versions, and communication flows — without sending a single unsolicited packet to a production controller.
  2. Purdue Model segmentation: We use FortiGate Next-Generation Firewalls to implement clear zone-and-conduit segmentation aligned to the IEC 62443 Purdue Reference Model, separating enterprise networks (Level 4/5) from process control networks (Level 2/3) and field devices (Level 0/1) with strict policy enforcement.
  3. Continuous monitoring with OT-aware detection: We instrument the demilitarised zone (DMZ) between IT and OT with sensors that understand industrial protocols, feeding data into our 24/7 SOC for correlation and response.

Practical Security Architecture for Indian Plants

1. Asset Discovery and Inventory

You cannot protect what you cannot see. The first engagement deliverable is always a live OT asset map: every PLC, HMI, engineering workstation, historian server, and network switch — with vendor, model, firmware, and live-communication peers. This inventory typically reveals shadow assets (legacy devices that operations teams forgot existed) and unauthorised connections that IT security was never told about.

2. Network Segmentation with FortiGate

Fortinet’s FortiGate firewalls are purpose-built for this environment. Features relevant to OT segmentation include:

  • Industrial protocol deep-packet inspection: FortiGate can inspect Modbus/TCP, DNP3, and OPC-UA at Layer 7, allowing policies that permit only legitimate engineering commands while blocking anomalous writes or read sweeps.
  • Ruggedised hardware options: The FortiGate Rugged series is rated for industrial environments — extended temperature ranges, DIN-rail mounting, and immunity to electromagnetic interference found near heavy machinery.
  • ZTNA-based remote access: Rather than extending legacy VPN into the OT zone, ZTNA allows vendor access to be scoped to a specific device, time window, and protocol — with full session recording for audit purposes.
  • SD-WAN for multi-plant connectivity: For manufacturers with multiple facilities, FortiGate SD-WAN provides encrypted, QoS-prioritised WAN connectivity between plants without exposing ICS traffic to the public internet.

3. Patch and Vulnerability Management for OT

Traditional patch management — scan, patch, reboot — does not work in OT. A firmware update to a PLC must be validated by the OEM, tested in a replica environment, and scheduled during a planned maintenance window that may occur only once or twice a year. The practical approach is:

  • Classify vulnerabilities by exploitability and blast radius, not just CVSS score.
  • Apply compensating controls (firewall rules, protocol-level filters) for vulnerabilities that cannot be patched immediately.
  • Maintain an up-to-date risk register with residual risk acceptance signed off by both IT and OT leadership.
  • Track vendor advisories from Siemens, Schneider Electric, Honeywell, Rockwell, and ABB — all of whom publish security bulletins for their ICS product lines.

4. Incident Response Planning for OT

A cyber incident that crosses from IT into OT requires a fundamentally different response playbook. Isolating a compromised workstation is straightforward in IT; isolating a compromised DCS controller may mean halting production entirely. OT incident response plans must include:

  • Pre-authorised network isolation playbooks that OT operators can execute without waiting for IT approval.
  • Manual operating procedures (MOPs) for running critical processes in degraded-mode if automation is unavailable.
  • Forensic procedures that preserve evidence without disrupting a running plant — passive memory acquisition, log export, and network capture from the DMZ rather than from field devices.
  • Notification timelines compliant with CERT-In’s 6-hour window for reportable incidents.

Compliance Context: CERT-In, DPDP, and Beyond

India’s regulatory environment for OT security is still maturing, but several obligations already apply:

  • CERT-In Directions (April 2022): Mandatory 6-hour notification for cyber incidents affecting critical infrastructure, including industrial control systems in power, transport, water, and manufacturing. Covered entities must also maintain logs for 180 days in India.
  • DPDP Act 2023: Where OT systems process personal data — such as biometric access control integrated with production MES — the DPDP Act’s data-breach notification requirement (timeframe to be specified in rules) will apply.
  • IEC 62443: The international standard for industrial cybersecurity provides a risk-based framework covering security levels, zones and conduits, and supplier security requirements. Many global customers and insurance underwriters are beginning to require IEC 62443 alignment from their Indian suppliers.
  • NCIIPC Guidelines: For operators of Critical Information Infrastructure, NCIIPC issues sector-specific guidelines that often go beyond CERT-In requirements, covering physical security integration, supply-chain risk, and resilience testing.

A PJ Networks OT security engagement typically begins with a passive discovery and gap assessment against IEC 62443 — giving leadership a clear, risk-quantified view of exposure before any remediation spend is committed.

How PrahiX Ora Supports OT/ICS Security Operations

Even the best architecture generates alerts that require rapid human and automated response. For manufacturing clients operating 24/7 production schedules, the ability to detect, correlate, and respond to OT threats in near-real-time is what separates a contained incident from a multi-day outage. This is where we deploy and operate PrahiX Ora, a unified SecOps platform built by PrahiX Tech Pvt Ltd, for our clients.

SIEM — log correlation with CERT-In retention: Ora’s SIEM ingests log sources spanning IT and OT — FortiGate syslog, Windows Event Logs from engineering workstations, SCADA historian audit trails, and OT-protocol sensors at the DMZ. Correlation rules are mapped to MITRE ATT&CK for ICS (the ICS-specific ATT&CK matrix), enabling the SOC to reconstruct attack storylines across the IT/OT boundary using graph-based event chaining. Critically for India, Ora’s tiered retention (hot, cold, archive) supports CERT-In’s direction to retain logs for 180 days in-country — a requirement that many organisations have struggled to meet cost-effectively at OT log volumes.

NMS — unified visibility across fragmented OT estates: Many manufacturing plants have accumulated network equipment from multiple vendors over decades — Cisco switches in the IT DMZ, unmanaged switches on the plant floor, Fortinet firewalls at the perimeter. Ora’s Network Management System provides unified observability across this mixed estate, using LLDP/CDP topology discovery to automatically map how devices interconnect, ML-based anomaly detection to flag unusual traffic patterns (such as a PLC suddenly initiating outbound connections), and auto-healing policies to trigger alerts or isolation actions when baselines are violated.

Video surveillance (VMS) — physical and cyber under one view: OT security is inherently physical as well as digital. Tampering with a PLC, inserting a rogue USB device, or tailgating into a restricted control room are physical threats with cyber consequences. Ora’s video surveillance (VMS) module integrates ONVIF, Hikvision, and Dahua IP camera systems, applying video analytics to detect anomalies at physical access points. For multi-site manufacturing and retail estates, having physical security events and network security events visible within the same operations dashboard — correlated by time and location — significantly reduces the mean time to identify a blended physical-cyber attack.

SOAR — meeting CERT-In’s 6-hour window: When a genuine OT incident occurs, the 6-hour CERT-In reporting window is extremely tight. Manual investigation, escalation, and drafting a notification report in that timeframe is nearly impossible without automation. Ora’s SOAR module provides pre-built playbooks for common OT scenarios — ransomware detonation, unauthorised PLC write, lateral movement from IT to OT — with automated response actions including pushing IP blocklists to FortiGate, isolating compromised VLAN segments, and generating draft CERT-In notification reports populated from the incident timeline. Automation does not replace human judgment on OT decisions; it compresses the investigative cycle so analysts spend their six hours making decisions rather than pulling logs.

If your operations team is spending more time chasing alerts across disconnected dashboards than actually investigating threats, PrahiX Ora — deployed and operated by our team — is worth a conversation.

Building Your OT Security Roadmap

For Indian manufacturers beginning or maturing their OT security journey, a practical phased approach looks like this:

Phase 1: Visibility (Months 1-3)

  • Deploy passive OT asset discovery to build inventory.
  • Map existing network topology and identify uncontrolled IT/OT connections.
  • Conduct a gap assessment against IEC 62443 SL-1 baseline.
  • Enable logging on all IT/OT boundary devices; begin shipping to Ora SIEM.

Phase 2: Segmentation (Months 3-9)

  • Design and implement FortiGate-based zone segmentation aligned to the Purdue Model.
  • Replace legacy VPN vendor access with ZTNA-controlled, session-recorded remote access.
  • Establish a patch and vulnerability management process with OT-appropriate timelines.
  • Run tabletop incident response exercises including OT-specific scenarios.

Phase 3: Continuous Monitoring and Response (Month 9+)

  • Integrate OT monitoring into 24/7 NOC/SOC coverage.
  • Tune SIEM correlation rules for OT-specific attack patterns.
  • Activate SOAR playbooks and test automated response against simulated incidents.
  • Conduct annual penetration testing of the IT/OT DMZ.
  • Review and update incident response plan to reflect current CERT-In reporting obligations.

How PJ Networks Can Help

PJ Networks is a managed security provider with deep experience in Fortinet’s OT security portfolio — FortiGate NGFW, FortiSIEM, FortiSOAR, and the FortiGate Rugged series for industrial environments. Our 24/7 NOC/SOC team monitors both IT and OT networks for our manufacturing clients across India, providing the round-the-clock coverage that in-house security teams typically cannot sustain.

Whether you are looking for an initial OT security assessment, a segmentation architecture design, or ongoing managed security services that cover your plant floor as well as your corporate network, our team can scope an engagement to match your risk profile and operational constraints.

Contact us to discuss an OT/ICS security assessment for your manufacturing environment. The first step — a passive discovery and gap analysis — is non-intrusive, requires no production downtime, and gives you the visibility to make informed investment decisions.

Leave a Reply

Your email address will not be published. Required fields are marked *