Securing India’s Manufacturing OT Networks: The Converged IT/OT Threat Landscape

  • Home
  • Securing India’s Manufacturing OT Networks: The Converged IT/OT Threat Landscape
Securing India’s Manufacturing OT Networks: The Converged IT/OT Threat Landscape

India’s manufacturing sector is undergoing its fastest digital transformation in decades. Smart factories, Industry 4.0 platforms, connected PLCs, SCADA systems, and cloud-integrated MES solutions are driving efficiency gains that were unthinkable five years ago. But beneath every productivity milestone lies an uncomfortable truth: operational technology (OT) environments were never designed with cybersecurity in mind, and connecting them to corporate IT networks — or, worse, the internet — has opened a new attack surface that adversaries are actively exploiting.

For Indian CISOs and plant managers, 2025 has been a wake-up call. Ransomware groups that once targeted healthcare and financial services have pivoted hard toward manufacturing. A successful hit on a production line can halt output for days, trigger supply-chain penalties, and — where safety systems are involved — put workers at physical risk. This post maps the threat landscape, explains the regulatory obligations that now apply, and walks through the defensive architecture PJ Networks recommends and deploys for manufacturing clients.

Why OT Networks Are Now Priority Targets

Legacy OT assets — PLCs, DCS controllers, HMIs, historians — were engineered for reliability and determinism, not confidentiality or integrity. Many run outdated Windows variants (Windows XP and 7 remain common on embedded HMIs), communicate over unencrypted industrial protocols (Modbus, DNP3, EtherNet/IP), and have never been patched because the vendor does not provide updates or because downtime costs are prohibitive.

When a manufacturer flattens its network to connect the shop floor to ERP, MES, or cloud analytics, these legacy assets suddenly become reachable from systems that touch the internet. Threat actors understand this. The typical attack chain in recent OT incidents follows a recognisable pattern:

  • Initial access via IT: Phishing, VPN credential stuffing, or exploitation of perimeter-facing services gets the attacker a foothold in the corporate IT environment.
  • Lateral movement to OT: Inadequate IT/OT segmentation — or a jump server with weak credentials — lets the attacker pivot into the OT network.
  • Discovery and dwell: Attackers spend weeks mapping assets, understanding process logic, and identifying the most disruptive targets.
  • Impact: Ransomware deployment, HMI takeover, or historian data exfiltration — sometimes all three simultaneously.

India’s manufacturing exporters face an additional exposure vector: foreign adversaries have demonstrated sustained interest in stealing process IP, production schedules, and supplier data from high-value industries such as pharma, defence components, and semiconductor sub-assembly.

The Regulatory Landscape: CERT-In, DPDP, and Sector Rules

Regulatory obligations for OT security in India have sharpened considerably. Three frameworks now intersect for most manufacturers:

CERT-In Directions (April 2022, Updated)

CERT-In’s mandatory directions require all “service providers, intermediaries, data centres, body corporates and government organisations” to report cybersecurity incidents within six hours of detection. For a manufacturer operating a connected OT environment, a SCADA breach, ransomware on a historian, or a PLC configuration change by an unauthorised user all qualify as reportable incidents. The directions also require maintaining logs for 180 days in India — a requirement that legacy OT systems, which typically log only to local storage (if at all), cannot satisfy without additional infrastructure.

Digital Personal Data Protection (DPDP) Act, 2023

While the DPDP Act focuses on personal data, manufacturing plants routinely process employee biometrics (access control), CCTV footage, and HR data. Any breach of these systems triggers DPDP notification obligations to the Data Protection Board. Plants that operate B2C loyalty programmes or collect customer data on finished goods also fall squarely within scope. Securing OT networks and the data they touch supports compliance with DPDP obligations — no single technical control makes an organisation fully compliant on its own, but visible controls are essential evidence in any inquiry.

Sector-Specific Guidance

The Ministry of Power’s guidelines for critical infrastructure operators, SEBI’s cybersecurity framework for listed entities, and National Critical Information Infrastructure Protection Centre (NCIIPC) advisories are layering additional obligations on manufacturers who operate in sensitive verticals. Defence Public Sector Units and their Tier-1 suppliers face the most prescriptive requirements, including network segmentation mandates and supply-chain due-diligence obligations.

Designing a Defensible IT/OT Architecture

The Purdue Model for Industrial Control Systems remains the foundational reference for IT/OT segmentation, though modern variants are adapted for cloud-integrated environments. A defensible architecture for an Indian manufacturer should incorporate all of the following:

1. Hard Segmentation at the IT/OT Boundary

A purpose-built industrial demilitarised zone (IDMZ) separates corporate IT from OT. Traffic crossing the IDMZ should be proxied and inspected — never routed directly. PJ Networks deploys FortiGate Next-Generation Firewalls as the primary enforcement point at this boundary, with application-aware policies that allow only specified industrial protocols in specified directions and deny everything else by default. The FortiGate NGFW platform provides deep packet inspection for OT protocols including Modbus, DNP3, and EtherNet/IP, making it well-suited to this segmentation role.

2. OT Network Visibility and Asset Inventory

You cannot defend what you cannot see. Many manufacturers discover, during an initial assessment, that their OT network contains assets they did not know existed: decommissioned but still-running HMIs, shadow IoT devices installed by line technicians, and unmanaged switches with open ports. Passive OT discovery tools — which listen without injecting traffic — build an asset inventory without risking process disruption. This inventory feeds directly into vulnerability management and change-detection workflows.

3. Micro-Segmentation Within OT

Not every PLC needs to communicate with every historian. Not every HMI needs internet access. Applying least-privilege networking inside the OT environment — using industrial-grade managed switches and VLANs or purpose-built OT firewalls — contains the blast radius of any single compromised asset. This approach is especially important in multi-line manufacturing environments where a breach in one production cell should not automatically compromise adjacent cells.

4. Privileged Access Management for Remote and Vendor Access

Vendor remote access is one of the most frequently abused IT/OT attack vectors. “Always-on” VPNs granted to equipment OEMs create persistent, often unmonitored tunnels into OT. Zero-trust network access (ZTNA) replaces these with time-limited, identity-verified, session-recorded connections. PJ Networks deploys ZTNA solutions — including Fortinet’s ZTNA capability integrated with FortiGate — to give vendors the minimum access they need, when they need it, with full session logging retained for audit purposes.

5. Continuous Monitoring and Anomaly Detection

OT processes are highly deterministic. A PLC that normally communicates with one historian at a consistent rate should almost never initiate a new connection to an unknown IP. Behavioural anomaly detection — tuned to the specific process baseline — spots deviations that signature-based tools miss. PJ Networks’ 24/7 NOC/SOC monitors OT environments alongside IT environments, with escalation procedures designed to reach plant operations teams, not just IT, when an alert fires.

PrahiX Ora: Unified SecOps Across IT, OT, and Physical Security

One of the most persistent challenges in OT security is operational fragmentation. The IT security team monitors firewalls and endpoints through one console; the OT team watches SCADA alarms through another; physical security — cameras, access control — sits in a third system entirely. When an incident crosses these boundaries, critical detection time is lost stitching together events from disconnected tools.

PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd that addresses this fragmentation directly. PJ Networks is Ora’s primary field deployment and operations partner — we deploy and operate the platform for clients who need a single operations view across their entire security posture. For manufacturing environments specifically, Ora’s four pillars map precisely onto the problems described above:

SIEM — Correlated Visibility, CERT-In Ready: Ora ingests logs from disparate sources — FortiGate firewalls, OT data historians, Windows Event logs from HMI workstations, Active Directory, and cloud services — and correlates them against MITRE ATT&CK for ICS rules. Its graph-based attack storyline reconstruction surfaces the full kill chain rather than isolated alerts, allowing analysts to see how a phishing email on the corporate network ultimately enabled anomalous PLC access days later. Tiered log retention (hot/cold/archive) satisfies CERT-In’s 180-day in-country log retention direction without requiring organisations to store everything on expensive high-IOPS storage.

NMS — Network Observability Across Multi-Vendor Estates: Ora provides unified observability across firewalls, switches, wireless access points, and WAN/SD-WAN links — exactly the kind of multi-vendor estate that characterises a manufacturer with multiple plants, remote sites, and a mix of legacy and modern networking gear. LLDP/CDP topology discovery automatically maps the network as it actually exists, not as it was documented years ago. ML-based anomaly detection flags unusual traffic patterns — a new device communicating on an industrial port, a historian suddenly generating outbound HTTP — before a human analyst would notice.

Video Surveillance (VMS) — Physical and Cyber Under One View: Ora’s video surveillance module manages ONVIF-compatible cameras — including Hikvision and Dahua deployments common in Indian plants — and applies video analytics (motion zones, object detection, access-point monitoring) from the same console used to manage network and security events. For manufacturing, retail, and multi-site estates, this brings physical and network security under one operations view. A security operations analyst can correlate a network anomaly with camera footage from the same time window without switching applications — critical for insider-threat investigations and post-incident forensics.

SOAR — Automation That Makes the 6-Hour Window Realistic: Ora’s playbook automation connects directly to FortiGate and other enforcement points. When the SIEM fires a high-confidence alert for a known OT threat pattern — say, lateral movement from IT into OT — a SOAR playbook can automatically push a blocklist update to the FortiGate IDMZ firewall, isolate the affected segment, and open an incident ticket, all within seconds. Without this automation, CERT-In’s six-hour reporting window is extremely difficult to meet under the pressure of an active incident; with it, the timeline becomes achievable.

If your operations team currently manages network, security, and physical surveillance through separate tools with no single operations view, contact our team about how we deploy and operate Ora for manufacturing clients.

Practical Checklist: Hardening Your OT Network

The following checklist is drawn from OT security assessments conducted across Indian manufacturing sites. Use it as a starting point for a gap analysis:

  • Asset inventory: Do you have a complete, current list of every device on your OT network, including firmware versions and patch levels?
  • Network segmentation: Is there a documented, enforced boundary between IT and OT with explicit allow rules and default-deny policies?
  • Remote access: Have you replaced always-on OEM VPNs with time-limited, identity-verified, logged ZTNA sessions?
  • Log collection: Are OT event logs being collected, centralised, and retained for at least 180 days in India?
  • Incident response plan: Do you have a tested OT-specific IR plan that covers CERT-In’s 6-hour reporting requirement?
  • Vulnerability management: Are you tracking and prioritising vulnerabilities affecting your specific OT software and firmware versions?
  • Backup and recovery: Are PLC configurations and historian data backed up offline and tested for restorability?
  • Third-party risk: Have you reviewed and right-sized the access granted to equipment OEMs and maintenance contractors?
  • Physical security integration: Is physical access to server rooms and control cabinets monitored and correlated with logical access events?
  • Security awareness: Have plant engineers and line supervisors received training on social engineering and phishing targeted at OT environments?

How PJ Networks Helps Manufacturing Clients

PJ Networks brings together the technology stack and the operational expertise needed to secure converged IT/OT environments across India. Our engagements typically begin with an OT security assessment — passive discovery, architecture review, and a gap analysis against CERT-In directions and relevant sector frameworks — followed by a phased remediation roadmap that prioritises actions by risk and operational impact.

For ongoing protection, we provide 24/7 NOC/SOC monitoring that spans both IT and OT environments on a unified platform. Our FortiGate-based NGFW deployments at the IT/OT boundary deliver granular application and protocol visibility without requiring process interruption. Where clients operate multiple plants or remote sites, our SD-WAN expertise ensures consistent security policy enforcement regardless of the underlying transport — MPLS, broadband, or LTE failover.

Managed security for OT is not a set-and-forget proposition. Threat actors adapt continuously, new vulnerabilities emerge in OT software and firmware, and regulatory requirements evolve. PJ Networks provides the continuous coverage and expertise that most Indian manufacturers cannot replicate with an in-house team alone.

If you are a manufacturing CISO or plant IT manager looking to understand your current OT exposure, or if a recent incident has highlighted gaps in your defences, PJ Networks offers an initial consultation to discuss your environment and options. Reach us at pjnetworks.com/contact.

The shop floor is now part of your attack surface. Securing it requires the same discipline and continuous attention that corporate IT security has demanded for years — and the operational reality of manufacturing demands even more care in how that security is implemented.

Leave a Reply

Your email address will not be published. Required fields are marked *