



Indian manufacturing is undergoing a rapid digital transformation. Industry 4.0 initiatives, government schemes such as Make in India and PLI, and the push for smart-factory automation are driving plant operators to connect their Operational Technology (OT) networks to enterprise IT systems — and, increasingly, to the internet. This convergence brings enormous efficiency gains, but it also exposes Industrial Control Systems (ICS), SCADA platforms, and Programmable Logic Controllers (PLCs) to cyber threats that were, until recently, limited to the enterprise IT world.
For Indian CISOs and plant managers, the stakes could not be higher. A successful intrusion into an OT network does not just mean stolen data — it means halted production lines, spoiled batches, damaged machinery, safety incidents, and potentially catastrophic environmental or physical consequences. In regulated sectors such as pharmaceuticals, chemicals, oil and gas, and power distribution, a single OT breach can attract regulatory scrutiny under CERT-In’s 6-hour mandatory reporting directive and civil liability under the emerging DPDP Act framework.
Until recently, most industrial networks operated in isolation — the classic “air gap” defence. Today that gap has largely closed. Remote monitoring, predictive maintenance platforms, and ERP integrations mean that PLCs and SCADA servers are routinely reachable from the corporate WAN, cloud tenants, or even contractor VPNs. Threat actors have noticed.
IT security teams typically own firewalls, SIEMs, and endpoint agents. OT teams own PLCs, DCS systems, and SCADA historians. In most Indian manufacturing companies these two groups have separate budgets, separate tooling, and a history of mutual distrust: IT teams often lack knowledge of industrial protocols; OT teams often reject any security change that touches production systems without extensive change-control cycles that can stretch to months.
Bridging this gap requires both a technical architecture and an organisational model. PJ Networks approaches OT/ICS engagements with a structured methodology built on three principles:
You cannot protect what you cannot see. The first engagement deliverable is always a live OT asset map: every PLC, HMI, engineering workstation, historian server, and network switch — with vendor, model, firmware, and live-communication peers. This inventory typically reveals shadow assets (legacy devices that operations teams forgot existed) and unauthorised connections that IT security was never told about.
Fortinet’s FortiGate firewalls are purpose-built for this environment. Features relevant to OT segmentation include:
Traditional patch management — scan, patch, reboot — does not work in OT. A firmware update to a PLC must be validated by the OEM, tested in a replica environment, and scheduled during a planned maintenance window that may occur only once or twice a year. The practical approach is:
A cyber incident that crosses from IT into OT requires a fundamentally different response playbook. Isolating a compromised workstation is straightforward in IT; isolating a compromised DCS controller may mean halting production entirely. OT incident response plans must include:
India’s regulatory environment for OT security is still maturing, but several obligations already apply:
A PJ Networks OT security engagement typically begins with a passive discovery and gap assessment against IEC 62443 — giving leadership a clear, risk-quantified view of exposure before any remediation spend is committed.
Even the best architecture generates alerts that require rapid human and automated response. For manufacturing clients operating 24/7 production schedules, the ability to detect, correlate, and respond to OT threats in near-real-time is what separates a contained incident from a multi-day outage. This is where we deploy and operate PrahiX Ora, a unified SecOps platform built by PrahiX Tech Pvt Ltd, for our clients.
SIEM — log correlation with CERT-In retention: Ora’s SIEM ingests log sources spanning IT and OT — FortiGate syslog, Windows Event Logs from engineering workstations, SCADA historian audit trails, and OT-protocol sensors at the DMZ. Correlation rules are mapped to MITRE ATT&CK for ICS (the ICS-specific ATT&CK matrix), enabling the SOC to reconstruct attack storylines across the IT/OT boundary using graph-based event chaining. Critically for India, Ora’s tiered retention (hot, cold, archive) supports CERT-In’s direction to retain logs for 180 days in-country — a requirement that many organisations have struggled to meet cost-effectively at OT log volumes.
NMS — unified visibility across fragmented OT estates: Many manufacturing plants have accumulated network equipment from multiple vendors over decades — Cisco switches in the IT DMZ, unmanaged switches on the plant floor, Fortinet firewalls at the perimeter. Ora’s Network Management System provides unified observability across this mixed estate, using LLDP/CDP topology discovery to automatically map how devices interconnect, ML-based anomaly detection to flag unusual traffic patterns (such as a PLC suddenly initiating outbound connections), and auto-healing policies to trigger alerts or isolation actions when baselines are violated.
Video surveillance (VMS) — physical and cyber under one view: OT security is inherently physical as well as digital. Tampering with a PLC, inserting a rogue USB device, or tailgating into a restricted control room are physical threats with cyber consequences. Ora’s video surveillance (VMS) module integrates ONVIF, Hikvision, and Dahua IP camera systems, applying video analytics to detect anomalies at physical access points. For multi-site manufacturing and retail estates, having physical security events and network security events visible within the same operations dashboard — correlated by time and location — significantly reduces the mean time to identify a blended physical-cyber attack.
SOAR — meeting CERT-In’s 6-hour window: When a genuine OT incident occurs, the 6-hour CERT-In reporting window is extremely tight. Manual investigation, escalation, and drafting a notification report in that timeframe is nearly impossible without automation. Ora’s SOAR module provides pre-built playbooks for common OT scenarios — ransomware detonation, unauthorised PLC write, lateral movement from IT to OT — with automated response actions including pushing IP blocklists to FortiGate, isolating compromised VLAN segments, and generating draft CERT-In notification reports populated from the incident timeline. Automation does not replace human judgment on OT decisions; it compresses the investigative cycle so analysts spend their six hours making decisions rather than pulling logs.
If your operations team is spending more time chasing alerts across disconnected dashboards than actually investigating threats, PrahiX Ora — deployed and operated by our team — is worth a conversation.
For Indian manufacturers beginning or maturing their OT security journey, a practical phased approach looks like this:
PJ Networks is a managed security provider with deep experience in Fortinet’s OT security portfolio — FortiGate NGFW, FortiSIEM, FortiSOAR, and the FortiGate Rugged series for industrial environments. Our 24/7 NOC/SOC team monitors both IT and OT networks for our manufacturing clients across India, providing the round-the-clock coverage that in-house security teams typically cannot sustain.
Whether you are looking for an initial OT security assessment, a segmentation architecture design, or ongoing managed security services that cover your plant floor as well as your corporate network, our team can scope an engagement to match your risk profile and operational constraints.
Contact us to discuss an OT/ICS security assessment for your manufacturing environment. The first step — a passive discovery and gap analysis — is non-intrusive, requires no production downtime, and gives you the visibility to make informed investment decisions.