Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide

  • Home
  • Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide
Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide
Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide
Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide
Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide
Strengthening OT/ICS Security in Indian Manufacturing: A CISO’s Practical Guide

India’s manufacturing sector is undergoing rapid digital transformation. Smart factories, Industry 4.0 automation, and integrated supply chains are delivering competitive advantages — but they are also exposing Operational Technology (OT) and Industrial Control Systems (ICS) to threats that were once confined to IT networks. For CISOs and IT leaders in Indian manufacturing, pharma, energy, and process industries, securing OT/ICS environments is no longer optional; it is a regulatory and business continuity imperative.

This guide walks through the specific threat landscape facing Indian OT environments, the compliance obligations under CERT-In and India’s DPDP Act, and a practical framework for hardening your industrial networks — with a focus on what managed security partners like PJ Networks deliver on the ground.

Why OT/ICS Security Demands a Different Approach

Traditional IT security treats availability as secondary to confidentiality and integrity. In OT environments — think PLCs controlling assembly lines, SCADA systems managing power distribution, or DCS running chemical processes — availability is paramount. A misconfigured firewall rule or an overzealous patch cycle can halt production lines worth crores per hour.

This fundamental tension shapes every decision in OT security:

  • Legacy equipment: Many OT devices run Windows XP, Windows 2003, or embedded OS versions with no patch support. They cannot be updated without vendor validation cycles that take months.
  • Air-gap myths: True air gaps have all but disappeared. Remote monitoring, vendor VPN access, cloud SCADA dashboards, and IT/OT integration for ERP data flows mean almost every OT network has an IP path to the internet.
  • Proprietary protocols: Modbus, DNP3, PROFINET, OPC-UA, and EtherNet/IP are not TCP/IP in disguise. Standard IDS signatures don’t understand them; standard firewalls can’t inspect them meaningfully without OT-aware engines.
  • Extended uptime requirements: A typical IT server can be rebooted during maintenance windows. A reactor coolant pump controller cannot be disrupted on a schedule.

The Indian OT Threat Landscape in 2025–2026

Global threat intelligence increasingly points to Indian critical infrastructure as a target. Nation-state actors and financially motivated ransomware groups have demonstrated persistent interest in energy, manufacturing, and logistics sectors. Key patterns observed across the industry:

IT-to-OT Lateral Movement

Attackers compromise enterprise IT networks — typically via phishing, exposed RDP, or vulnerable VPN appliances — and then pivot to OT segments through poorly segmented networks. The Purdue Model boundary between Level 3 (MES/ERP) and Level 2 (SCADA/HMI) is often the weakest link. Many Indian plants have flat networks where an infected Windows workstation in the accounts department can reach a historian server in the control room without traversing a single firewall.

Remote Access Exploitation

COVID-era decisions to enable vendor remote access to OT equipment — often through unmanaged jump servers or directly exposed RDP — created persistent attack surfaces that many organisations have not closed. Threat actors routinely scan for exposed ICS ports and weak credentials on remote access gateways.

Supply Chain Compromise

Vendors who provide OEM maintenance, calibration software updates, or hardware firmware to Indian manufacturers present third-party risk. A compromised update package from a trusted vendor bypasses most perimeter controls.

Ransomware Targeting OT Historians and HMIs

Ransomware operators have discovered that encrypting SCADA historian databases — which store weeks of process data critical for regulatory compliance and production analytics — creates enormous leverage. The prospect of losing production records, quality certifications, and batch traceability forces rapid ransom decisions in regulated industries like pharma and food processing.

India Regulatory Obligations for OT Environments

CERT-In Directions (April 2022, updated)

CERT-In’s 2022 directions apply broadly to any entity operating “critical information infrastructure” — a category that includes energy, manufacturing, and logistics companies at scale. Key obligations that directly affect OT environments:

  • 6-hour incident reporting: Any ransomware attack, data breach, or ICS/SCADA compromise must be reported to CERT-In within six hours of detection. This requires pre-built workflows, not improvisation during an active incident.
  • 180-day log retention: All ICT system logs — including logs from network devices, servers, and applications connected to OT networks — must be retained for 180 days, within India. OT historians, SCADA event logs, and firewall logs traversing IT/OT boundaries fall in scope.
  • Synchronised and accurate time: All systems must synchronise with the Indian Standard Time (IST) NTP servers. Forensic correlation across OT events demands accurate timestamps.
  • Vulnerability disclosure coordination: Organisations must designate a point of contact for CERT-In coordination in the event of a vulnerability disclosure.

Digital Personal Data Protection (DPDP) Act 2023

While the DPDP Act primarily governs personal data, its security obligations extend into OT contexts where production systems handle employee data, biometric access records, contractor PII, or customer-linked batch data. Security safeguards that support compliance with the DPDP Act include access controls, audit logs, and breach notification capabilities — all areas where OT security programmes are frequently weak.

Note: PJ Networks’ managed security programmes are designed to help organisations evidence alignment with CERT-In and DPDP Act obligations. Compliance is a continuous operational discipline, not a one-time certification.

A Practical OT Security Framework for Indian Enterprises

1. Network Segmentation and the Purdue Model

Begin with a network architecture review. Map every path between your enterprise IT network and OT segments. The goal is to enforce explicit, inspected boundaries at the Purdue Level 3.5 (DMZ) — the layer that governs data flow between MES systems and SCADA. Practical steps:

  • Deploy next-generation firewalls (FortiGate with OT-specific profiles) at IT/OT boundaries with application-layer inspection for OT protocols.
  • Create a DMZ for data historians, jump servers, and vendor access terminals — these should never sit inside the OT segment proper.
  • Eliminate flat routes between enterprise VLANs and OT VLANs. Every cross-boundary session should be proxied and logged.
  • Deploy unidirectional security gateways (data diodes) for truly critical segments where data must flow out of OT but no traffic should ever flow in.

2. Zero Trust Network Access for OT Remote Access

Replace legacy VPN-based vendor access with ZTNA controls. Rather than granting a vendor VPN access to a broad OT subnet, ZTNA solutions like Fortinet’s ZTNA enforce least-privilege: the vendor authenticates, their device posture is assessed, and they are granted access only to the specific OEM system they need — for the duration of the maintenance window, logged end-to-end.

PJ Networks deploys and operates ZTNA implementations built on FortiGate and FortiClient EMS that integrate directly with Active Directory, enabling granular time-bound policies for OT vendor access — a significant improvement over shared VPN credentials that never expire.

3. Asset Inventory and Vulnerability Management

You cannot protect what you cannot see. Many Indian OT environments lack a reliable asset register of all IP-addressable devices. A passive OT asset discovery approach — using traffic mirroring to a sensor that analyses network traffic without actively probing devices — builds this inventory safely without risking disruption to live control systems.

Once the inventory is established, vulnerability management for OT follows different rules than IT:

  • Patching is coordinated with vendors and plant shutdown windows, not monthly patch cycles.
  • Compensating controls — virtual patching through IPS rules, network segmentation, and enhanced monitoring — are the primary defence for legacy systems that cannot be patched.
  • Firmware updates for PLCs and controllers must be sourced exclusively from verified vendor channels and verified against published hashes.

4. OT-Aware Monitoring and Incident Response

Standard SIEM solutions that ingest Windows event logs and syslog are insufficient for OT. Meaningful OT monitoring requires:

  • Passive capture and deep packet inspection of OT protocol traffic (Modbus, DNP3, OPC-UA) to baseline normal engineering commands and detect anomalous activity — unexpected writes to PLC registers, engineering workstation connections at unusual hours, protocol transitions.
  • Integration of OT alerts with enterprise SIEM for unified incident correlation — so that a suspicious login on the IT network followed by a lateral connection to an OT historian is seen as a single attack sequence, not two unrelated events.
  • Pre-built OT incident response playbooks: isolation procedures for compromised HMIs, communication protocols with plant operations teams, and documented escalation paths to CERT-In within the 6-hour window.

5. Privileged Access Management for OT

Many OT incidents are enabled by weak privileged access controls: shared local administrator accounts on HMIs, default vendor credentials never changed, engineering workstations with domain admin privileges. Hardening privileged access in OT means:

  • Rotating and vaulting all privileged credentials for OT systems, including PLC programming accounts and historian admin accounts.
  • Requiring MFA for all remote access to OT systems, including vendor connections.
  • Recording all privileged sessions on OT systems for audit trail purposes — critical for post-incident forensics and CERT-In reporting.

PrahiX Ora: Unified SecOps Visibility Across IT and OT

One of the persistent operational challenges in OT security is fragmented visibility. A NOC team watching enterprise firewalls often has no sight into OT network events. The SOC team correlating IT security alerts has no context about what a PLC register write means. And physical security (CCTV, access control) sits in a completely separate silo. Connecting these domains is where a unified SecOps platform makes a meaningful difference.

PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner — we deploy and operate the platform for clients across manufacturing, retail, and multi-site enterprise estates.

For Indian OT environments, the four pillars of PrahiX Ora address specific operational challenges:

  • SIEM: Multi-source log and event ingestion with correlation rules mapped to the MITRE ATT&CK for ICS framework, graph-based attack storyline reconstruction, and tiered retention (hot, cold, and archive). This directly supports CERT-In’s 180-day in-country log retention direction — OT event logs, historian logs, and network device logs are ingested, correlated, and retained within India-based infrastructure, ready for regulatory queries or forensic review.
  • NMS (Network Management System): Unified observability across firewalls, switches, access points, WAN/SD-WAN links, and OT network segments. LLDP/CDP topology discovery builds an automatic map of connected assets; network path tracing isolates faults; ML-based anomaly detection flags unusual traffic patterns; and auto-healing policies can isolate or reroute segments in response to detected issues. For manufacturing and logistics clients with multi-vendor OT estates — where NOC visibility is traditionally fragmented across OEM-specific dashboards — this provides a single operational view without replacing existing OT tooling.
  • Video Surveillance (VMS): ONVIF, Hikvision, and Dahua camera management with video analytics brings physical security into the same operations view. For manufacturing plants, retail chains, and multi-site logistics estates, correlating a physical access event at a server room door with a simultaneous IT authentication anomaly — all within one platform — is the kind of context that makes the difference between a missed alert and a contained incident. Physical and network security under one operations pane of glass is increasingly how enterprise security teams are structured.
  • SOAR: Playbook automation with pre-built connectors and automated response actions — including pushing updated IP blocklists or quarantine rules directly to FortiGate — dramatically compresses response timelines. CERT-In’s 6-hour incident reporting requirement is only achievable if the detection-to-containment workflow is largely automated. Manual alert-by-alert triage cannot meet that SLA at scale. SOAR-driven playbooks ensure that once a confirmed OT threat is identified, the containment and documentation steps run automatically, and the CERT-In notification is pre-populated and ready for human review within the window.

If your security operations team is managing IT and OT environments from separate dashboards, handling CERT-In obligations manually, and still relying on legacy VPN for vendor access, the operational overhead is both high and unnecessary. PJ Networks can assess your current posture and walk through how PrahiX Ora is configured and operated for environments like yours — reach us at pjnetworks.com/contact.

Building a 90-Day OT Security Roadmap

For organisations starting or accelerating their OT security journey, a phased approach prevents disruption while making measurable progress:

Days 1–30: Visibility and Baseline

  • Commission a passive OT asset discovery exercise — no active scanning.
  • Map all IT/OT network interconnections, including vendor remote access paths.
  • Audit privileged account inventories: identify all shared accounts, default credentials, and accounts with unnecessary access.
  • Confirm that 180-day log retention is in place for all in-scope OT-adjacent systems.

Days 31–60: Segmentation and Access Controls

  • Deploy or harden firewalls at the IT/OT boundary with OT protocol inspection.
  • Migrate vendor remote access from legacy VPN to a ZTNA solution with time-bound, MFA-enforced policies.
  • Implement credential rotation and vaulting for OT privileged accounts.
  • Establish a jump server DMZ for historian and data aggregation systems.

Days 61–90: Detection, Response, and Reporting Readiness

  • Onboard OT event sources into your SIEM platform with OT-specific correlation rules.
  • Build and test a CERT-In 6-hour notification playbook — simulate a ransomware scenario on paper and walk through the notification workflow.
  • Conduct tabletop exercises with plant operations, IT, and security teams to align on isolation procedures and communication protocols.
  • Define regular vulnerability management cadence for OT systems, aligned with vendor maintenance windows.

How PJ Networks Supports OT Security Programmes

PJ Networks has operated 24/7 NOC and SOC services for Indian enterprises for over a decade. Our OT security capabilities are built on FortiGate next-generation firewalls with OT-specific IPS profiles, Fortinet’s ZTNA portfolio for secure remote access, and FortiMail for protecting the IT communication layers that connect to OT environments. We operate PrahiX Ora for clients who require unified IT/OT/physical security visibility under one managed service.

Our engagements typically begin with an OT security assessment — a structured review of network architecture, asset inventory, access controls, and logging posture. This produces a prioritised remediation plan aligned with CERT-In obligations and your plant’s operational constraints.

Indian manufacturing, energy, and process industries are facing a threat landscape that rewards preparation. The organisations that build OT security foundations now — visibility, segmentation, controlled remote access, automated response — are the ones that will meet the 6-hour reporting window, recover faster from incidents, and avoid the production shutdowns that make ransomware operators so effective.

To discuss your OT security posture or learn more about how PJ Networks manages OT environments for Indian enterprises, visit pjnetworks.com/contact or call our 24/7 operations centre.

Leave a Reply

Your email address will not be published. Required fields are marked *