



In the first half of 2026, threat intelligence teams across Asia Pacific flagged a sustained campaign targeting enterprise-grade firewall appliances—including FortiGate NGFW deployments—in Indian manufacturing, BFSI, and logistics organisations. The pattern is not new, but the scale and sophistication have accelerated. Adversaries are now chaining authentication-bypass weaknesses, exposed management interfaces, and weak segmentation to pivot from perimeter devices deep into operational networks within hours of initial access.
For Indian enterprise IT leaders and CISOs, the message is clear: a firewall that is not actively managed, patched, and monitored is not a security control—it is a liability. This post examines the threat landscape, the defensive posture Indian organisations should adopt, and how a converged NOC/SOC model underpinned by the right technology stack turns reactive patching into proactive resilience.
Over the past eighteen months, several high-severity vulnerabilities have been disclosed across enterprise firewall platforms. Attackers have rapidly weaponised these findings, sometimes within 24 to 72 hours of public disclosure. The attack chain typically unfolds in three stages:
Indian organisations face compounding risk factors: many mid-market enterprises still run end-of-life firmware versions due to change-management constraints; management interfaces are sometimes accessible from internet-facing VLANs for remote administration convenience; and the internal security team is often too thinly staffed to conduct continuous threat hunting on network device telemetry.
India’s rapid digital expansion—accelerated by the government’s push for paperless processes, GST digitisation, and UPI-driven financial inclusion—has created a vast and growing attack surface. Enterprises in tier-2 and tier-3 cities that have deployed FortiGate or similar NGFW platforms often lack the in-house expertise to run continuous vulnerability management programmes. The gap between “we have a firewall” and “our firewall is secure and monitored” is where attackers operate.
Three structural vulnerabilities are particularly common in the Indian enterprise context:
Regardless of your current patch status, the following configuration controls significantly reduce your attack surface. These are not theoretical best practices—they are the baseline that PJ Networks enforces on day one of any managed FortiGate engagement.
admin account. Create named accounts with the minimum required privilege profile for each administrator role.diagnose autoupdate versions regularly to confirm IPS, AV, and application control signatures are current.India’s Computer Emergency Response Team (CERT-In) direction issued in April 2022—effective since June 2022—mandates that organisations report cybersecurity incidents to CERT-In within six hours of detection. For a firewall exploitation event, “detection” is only possible if the telemetry is flowing and being analysed. Organisations that are not forwarding FortiGate logs to a SIEM face two compounding risks: first, they may not detect the incident at all until significant damage has been done; second, even when they do detect it, the six-hour clock will have run out long before the incident is formally classified.
The DPDP Act (Digital Personal Data Protection Act, 2023) adds further regulatory weight. Any breach that involves personal data—customer records, employee data, transaction logs—triggers both CERT-In reporting obligations and, as implementing rules are finalised, notification obligations to the Data Protection Board of India. Proactive monitoring of network perimeter devices is foundational to meeting these obligations.
The six-hour CERT-In reporting window is not a documentation exercise—it is a detection and response capability test. If your SOC cannot identify and classify a FortiGate compromise event within that window, the regulatory penalty is the least of your concerns.
Traditional IT operations models treat the NOC and SOC as separate functions: the NOC watches availability and performance; the SOC watches for threats. For firewall-class devices, this separation is a blind spot. A firewall that is under active exploitation will often show availability anomalies—unexpected CPU spikes, connection table exhaustion, unusual traffic volumes—before any security alert fires. When NOC and SOC are converged on a single operational platform, these early signals are correlated and escalated before the attacker completes their objective.
PJ Networks operates a 24/7 converged NOC/SOC for managed FortiGate clients across India. Our model ingests both performance telemetry and security events into a single operational view, enabling analysts to spot the combination of “management CPU at 95% at 2 AM” and “five failed admin login attempts from an unknown IP” as a single potential attack scenario, not two separate unrelated tickets.
For organisations managing multi-site, multi-vendor estates—common in Indian manufacturing, retail, and logistics sectors—fragmented tooling is itself a security risk. When your SIEM, your network monitoring, your camera surveillance, and your incident response workflows run on separate platforms with separate alert queues, critical correlation is missed, response is delayed, and CERT-In timelines become nearly impossible to meet.
PrahiX Ora, built by PrahiX Tech Pvt Ltd, is the unified SecOps platform that PJ Networks deploys and operates for clients who need this kind of convergence. It brings four core capabilities into one operational view:
Ora’s SIEM ingests log and event data from FortiGate firewalls, switches, authentication systems, endpoint agents, and cloud platforms, then applies correlation rules mapped to the MITRE ATT&CK framework. When a threat actor pivots from an exploited firewall management interface toward an internal Active Directory server, the SIEM reconstructs the full attack storyline as a graph—not as a sequence of unrelated alerts—so your analysts see the campaign, not the noise. Tiered log retention (hot, cold, and archive tiers) directly supports CERT-In’s direction on 180-day in-country log retention, a compliance requirement that many organisations are still struggling to meet cost-effectively.
Indian enterprises with distributed manufacturing plants or retail chains frequently operate a patchwork of FortiGate firewalls at branch offices, Cisco switches in older facilities, and various wireless AP vendors across sites. Ora’s Network Management System provides unified observability across all of these, using LLDP/CDP topology discovery to build an accurate map of how devices connect, network path tracing to identify where traffic is actually flowing, and ML-based anomaly detection to flag deviations before they become outages or breach indicators. For NOC teams that currently receive alerts from five or six different vendor portals, the operational efficiency gain is immediate.
Manufacturing plants, retail distribution centres, and multi-site logistics operations share a common challenge: CCTV systems and IT networks are managed by different teams with no operational overlap. Ora’s video surveillance (VMS) module manages ONVIF-compatible cameras including Hikvision and Dahua deployments, with video analytics capabilities for motion, intrusion, and object detection. For security operations at a manufacturing site, correlating a physical intrusion alert from a camera with an anomalous network login event from the same zone—at the same timestamp—is the kind of cross-domain intelligence that a unified platform enables and that siloed tools cannot.
Without automation, CERT-In’s six-hour incident reporting mandate requires a security team to detect, triage, investigate, classify, and draft a report in a window that most organisations take days to complete. Ora’s SOAR module provides pre-built playbooks and automated response actions—including pushing updated blocklists to FortiGate appliances automatically when an IOC is confirmed—so the heavy-lifting of initial response is handled by the platform, not the analyst. The analyst’s job shifts from manual evidence collection to reviewing and approving actions, which is the level of human oversight that makes the six-hour window realistic rather than aspirational. If you are evaluating how to support compliance with CERT-In’s incident reporting direction, automation is not optional—it is the mechanism that makes the timeline achievable.
If your organisation is evaluating converged SecOps platforms for multi-site Indian operations, the team at PJ Networks can walk you through how we deploy and operate Ora in environments similar to yours.
If you are responsible for FortiGate deployments in an Indian enterprise and you have not reviewed your management plane hardening in the last quarter, treat the following as your starting checklist for this week:
PJ Networks provides managed FortiGate services across India, including 24/7 NOC/SOC monitoring, firmware lifecycle management, configuration hardening assessments, and converged network and security operations for complex multi-site estates. We partner with Fortinet as a certified solution provider and operate PrahiX Ora as our primary SecOps platform for clients who need unified SIEM, NMS, video surveillance management, and SOAR in a single operational framework.
If your organisation is dealing with firewall security debt—delayed patches, uncertain log coverage, or a SOC that cannot meet CERT-In timelines—we would welcome the opportunity to assess your current posture and propose a managed security roadmap aligned to your risk profile and regulatory obligations.
Reach out to the PJ Networks team to arrange a no-obligation conversation with one of our senior security architects.