



India’s manufacturing sector is undergoing rapid digital transformation — Industry 4.0, IoT-connected assembly lines, remote SCADA access, and cloud-integrated ERP systems are now the norm, not the exception. But with that connectivity comes a sharp rise in exposure. Operational Technology (OT) and Industrial Control Systems (ICS) that once operated in air-gapped silos are now networked, patched inconsistently, and increasingly targeted by adversaries who have recognised the asymmetric leverage that attacking a plant floor delivers.
This post is a practical guide for Indian enterprise IT and OT leaders navigating what has become one of the most pressing threat categories of 2026: cyber-physical attacks against manufacturing, utilities, and critical infrastructure.
Global OT attack volumes have grown year-on-year since 2020. India is not insulated. The country’s push toward “Make in India,” PLI schemes, and export-focused manufacturing has placed Indian factories squarely in the sights of nation-state actors, ransomware groups that have pivoted to industrial targets, and opportunistic threat actors who exploit publicly disclosed vulnerabilities in SCADA and HMI software.
A few structural facts make Indian manufacturing environments especially challenging to defend:
The threat actors targeting OT environments in 2026 are more capable and more patient than most IT security teams assume. The patterns we observe are worth understanding in detail.
Early ransomware campaigns targeted IT systems and only accidentally impacted OT when IT/OT networks were connected. That opportunism has been replaced by deliberate OT targeting. Modern ransomware operators conduct reconnaissance to identify historian servers, engineering workstations, and SCADA interfaces before deploying payloads. Their calculus is simple: a manufacturer that cannot ship product faces immediate, quantifiable revenue loss, which dramatically improves ransom payment rates.
The tactical implication for defenders is that securing IT endpoints is necessary but not sufficient. The engineering workstation running an HMI application over an unencrypted serial-over-Ethernet bridge is a target that will not be protected by a standard endpoint detection and response agent.
Third-party OEM and maintenance vendor access is one of the most commonly exploited initial access vectors in OT incidents. Vendors often connect via unmanaged remote-desktop or proprietary remote-access software, using shared credentials, with no session recording or time-bound access controls. This creates persistent, poorly audited pathways that threat actors exploit directly or by compromising the vendor first.
Plant engineers, OT administrators, and SCADA operators are increasingly targeted with highly tailored phishing campaigns. Lures reference specific industrial software (Siemens TIA Portal, Rockwell Studio 5000, Honeywell Experion), vendor communications, or plant-specific procurement terminology. AI-assisted phishing has made these campaigns far more credible than the generic lures of five years ago.
Vulnerability disclosures for OT components — PLCs, HMIs, industrial routers, and protocol gateways — have grown substantially. Unlike IT vulnerabilities, OT vulnerabilities are often left unpatched for months or years because patching requires a maintenance window, vendor support, and sometimes physical access. Threat actors track these disclosures and exploit them against internet-exposed OT management interfaces.
If there is one foundational control that delivers outsized risk reduction in OT environments, it is network segmentation — specifically, the enforcement of a well-defined industrial DMZ (IDMZ) between the corporate IT network and the OT network, with strict controls on what may traverse it.
The Purdue Model for ICS — despite its age — remains a useful reference for segmentation architecture. It defines five levels from the enterprise network down to field devices, with clear demarcation points where traffic should be inspected, restricted, or blocked entirely. In practice, most Indian manufacturing sites have collapsed these boundaries. Rebuilding them requires a combination of network re-architecture and next-generation firewall policy enforcement.
FortiGate Next-Generation Firewalls are well-suited to OT segmentation for several reasons. They support OT-specific deep-packet inspection for protocols including Modbus, DNP3, IEC 61850, and EtherNet/IP — protocols that carry real-time control data and that generic IT firewalls cannot parse. This means you can write policy rules that say “allow Modbus read commands from the historian server to PLCs in zone A, deny all write commands from any IT-zone host” rather than blunt IP/port rules that either over-permit or over-restrict.
FortiGate’s Security Fabric also enables the plant’s network to share threat intelligence with FortiMail (protecting engineering staff from phishing) and with the SOC’s SIEM, creating a unified detection and response posture across IT and OT zones.
The most effective way to close the vendor-access attack surface is to replace unmanaged remote-access tools with a Zero Trust Network Access (ZTNA) architecture. Under ZTNA, remote access is not a persistent VPN tunnel into a flat network. Instead, it is a per-session, per-application grant, conditioned on device posture, user identity, and contextual signals, that expires when the session ends.
For OT environments, a well-implemented ZTNA deployment means:
PJ Networks deploys and operates ZTNA architectures for manufacturing clients across India, using FortiGate’s built-in ZTNA proxy capabilities and integrating with existing Active Directory or LDAP identity infrastructure. The deployment can be structured to cover both IT remote access and OT vendor access from a single policy framework.
OT environments generate a distinct event profile compared to IT networks. SCADA historians, engineering workstations, and PLC communication logs produce data that most SIEM correlation rules — designed for IT — will not correctly interpret. The result is either a flood of false positives (which operators learn to ignore) or genuine OT-specific alerts being missed entirely.
Effective OT security monitoring requires analysts who understand both the IT threat landscape and the operational norms of industrial environments. A spike in Modbus write commands at 3 AM on a Sunday is an anomaly worth investigating — but only if the analyst knows that normal production schedules mean write commands should not occur outside of shift hours.
PJ Networks’ 24/7 NOC/SOC team monitors OT networks alongside IT infrastructure, with alert thresholds and correlation rules tuned to the client’s specific production schedules, equipment baselines, and industrial protocols. This combined NOC/SOC model means that a network anomaly detected by the NOC — an unexpected new device connecting to the plant LAN — can be immediately escalated to SOC analysts for threat investigation, without the handoff delays that plague separate NOC and SOC teams.
One of the structural challenges in OT security is that IT security teams work in SIEMs and ticketing systems, while OT teams work in historian consoles and SCADA dashboards. There is rarely a single pane of glass that gives a CISO visibility across both environments simultaneously. The platform we deploy and operate for clients — PrahiX Ora, built by PrahiX Tech Pvt Ltd — addresses this directly through four integrated capabilities, each of which has specific relevance to OT/IT convergence in Indian manufacturing environments.
SIEM: Ora’s SIEM ingests log and event data from both IT sources (firewalls, endpoints, mail gateways, cloud workloads) and OT sources (SCADA servers, historians, industrial routers, and protocol converters). Correlation rules are mapped to the MITRE ATT&CK for ICS framework, covering adversary techniques specific to industrial environments — not just the enterprise ATT&CK matrix. When an attack storyline spans both an IT phishing event and an OT network anomaly, Ora reconstructs the full attack graph with tiered log retention (hot, cold, and archive tiers). Crucially for Indian enterprises, this architecture supports CERT-In’s direction for 180-day in-country log retention, which applies to critical sectors including manufacturing.
NMS (Network Management System): The NMS pillar provides unified observability across the entire estate — FortiGate firewalls, switches, wireless access points, SD-WAN links, and OT network components. LLDP/CDP topology discovery maps the network automatically, which is especially valuable in manufacturing environments where asset inventories are often incomplete or out of date. ML-based anomaly detection flags deviations from baseline behaviour — a new device appearing on the OT segment, a PLC communicating with an unexpected IP, or bandwidth spikes on a historian link. For multi-site manufacturers with plants in multiple states, the NMS aggregates visibility across all sites into a single dashboard, eliminating the fragmented, per-site NOC visibility that is the norm in many Indian enterprise estates.
Video Surveillance (VMS): Physical security and cybersecurity are often managed by entirely separate teams in Indian manufacturing. Ora’s video surveillance (VMS) pillar integrates ONVIF/Hikvision/Dahua IP camera management with video analytics — motion detection, perimeter alerts, people counting — alongside network and security data in a single operations view. For manufacturing and retail clients with multi-site estates, this means a security operations team can correlate a physical intrusion event at a server room with a simultaneous network access anomaly, rather than treating them as unrelated incidents managed in separate tools.
SOAR (Security Orchestration, Automation and Response): In an OT incident, minutes matter. CERT-In’s mandatory 6-hour incident reporting window leaves very little time for manual triage, investigation, and notification. Ora’s SOAR pillar automates response actions through pre-built playbooks and connectors — including the ability to push blocklists to FortiGate firewalls automatically when a threat is confirmed. This means that when a compromised device is identified on the plant network, isolation can happen in seconds rather than the tens of minutes that manual firewall rule changes typically require. Automation is not a convenience in the context of CERT-In’s timeline — it is what makes compliance with that window achievable at scale.
If your team is dealing with fragmented OT/IT visibility or struggling to meet CERT-In’s reporting timelines, speak with our team about how we deploy and operate PrahiX Ora for manufacturing clients across India.
For IT and OT leaders ready to improve their posture today, the following checklist covers the highest-priority actions:
Indian manufacturers who suffer a cyber incident affecting OT systems face clear obligations under CERT-In’s April 2022 directions. The 6-hour reporting window for incidents in specified categories — including ransomware attacks, data breaches, and attacks on critical information infrastructure — applies regardless of whether the affected system is IT or OT. Many manufacturers have invested in IT incident response capabilities but have not extended those capabilities to OT incidents.
The practical implication: if a ransomware payload encrypts engineering workstations or historian servers, the clock starts immediately. Having pre-drafted report templates, established CERT-In communication channels, and automated isolation playbooks ready before an incident is not optional for a compliant organisation — it is a prerequisite.
PJ Networks works with clients to extend their IT incident response plans into OT environments, ensuring that the people, processes, and tools needed to meet the 6-hour reporting window are in place well before they are needed.
PJ Networks provides end-to-end managed security services suited to the IT/OT convergence challenge facing Indian manufacturers:
If your organisation is expanding industrial connectivity and wants to do so without introducing unacceptable cyber risk, we would welcome a conversation. Contact the PJ Networks team to discuss your OT security posture and how a managed approach can address the specific challenges of your manufacturing environment.