Securing OT/ICS Networks in Indian Manufacturing: Bridging the IT-OT Security Gap

  • Home
  • Securing OT/ICS Networks in Indian Manufacturing: Bridging the IT-OT Security Gap
Securing OT/ICS Networks in Indian Manufacturing: Bridging the IT-OT Security Gap

India’s manufacturing sector is undergoing a profound digital transformation. Driven by the Production Linked Incentive (PLI) schemes and the government’s Make in India push, factory floors across automotive, pharmaceuticals, electronics, and steel are rapidly integrating internet-connected machinery, industrial robots, SCADA systems, and Industrial IoT sensors. The efficiency gains are real — but so is the expanded attack surface.

Operational Technology (OT) and Industrial Control Systems (ICS) were originally engineered for reliability and uptime, not cybersecurity. Legacy PLCs, SCADA platforms, and distributed control systems (DCS) often run on decade-old firmware with no patch pathway. When these are networked — even via air-gapped-looking connections — they become reachable targets. And threat actors have taken note.

Why Indian Manufacturers Are Increasingly in the Crosshairs

Global threat intelligence consistently shows manufacturing as one of the top three most targeted sectors by ransomware groups and nation-state actors. In the Indian context, this risk is compounded by several factors:

  • Accelerated connectivity without security uplift: Smart factory initiatives often connect OT systems to corporate IT networks (and sometimes directly to cloud platforms) without corresponding network segmentation or monitoring capabilities.
  • Multi-vendor heterogeneity: A typical Indian production facility might run Siemens SCADA alongside Rockwell PLCs, Honeywell DCS, and a mix of generic IoT sensors — each with its own management interface, protocol, and security posture.
  • Fragmented NOC visibility: IT teams can see servers and laptops; OT teams manage production systems. Nobody owns the seam. Attackers exploit this blind spot to pivot from compromised IT infrastructure into production networks undetected.
  • Critical infrastructure designation: CERT-In has designated sectors including power, pharmaceuticals, and defence manufacturing as critical information infrastructure. A breach that causes production downtime now carries regulatory exposure, not just operational loss.
  • Supply chain linkages: Tier-1 suppliers to global OEMs are required to meet increasingly stringent cybersecurity standards. A security incident at an Indian supplier can trigger contractual penalties and reputational damage far exceeding the cost of remediation.

The Anatomy of an OT Attack: How Intrusions Unfold

Most ICS intrusions do not start in the OT network. They begin in enterprise IT — a phishing email to a purchase manager, a compromised VPN credential, an unpatched edge device. Once inside the enterprise network, attackers conduct reconnaissance to map the IT/OT boundary, identify historian servers, engineering workstations, and remote access paths into the control network.

The defining characteristic of sophisticated OT attacks is patience. Adversaries may maintain persistent access for weeks or months before triggering any operational effect, learning production schedules, understanding failsafes, and mapping dependencies.

Once an attacker reaches OT assets, objectives vary: some seek ransomware deployment to encrypt HMI workstations and force production shutdown; others aim for data exfiltration of process IP or quality parameters; the most dangerous seek to manipulate physical processes — changing setpoints, disabling safety interlocks, or triggering equipment failure.

The IT/OT Security Gap: What Needs to Change

Closing the IT/OT security gap requires action across three domains: network architecture, visibility, and response capability.

Network Architecture: Segmentation and Controlled Access

The Purdue Model remains a useful reference architecture, but modern implementations need to go further. Network segmentation using next-generation firewalls at the IT/OT boundary is the single highest-ROI security control for most Indian manufacturers. A properly configured FortiGate deployed at the demilitarised zone (DMZ) between the enterprise and control networks can enforce application-aware policies — permitting historian data pulls via OPC-UA while blocking unsolicited inbound connections from IT to OT assets.

Key architecture principles:

  • Establish a dedicated industrial DMZ (iDMZ) with a dual-firewall design. No direct routing between IT and OT VLANs.
  • Use FortiGate’s industrial protocol inspection capabilities to deep-inspect Modbus, DNP3, EtherNet/IP, and IEC 61850 traffic at the boundary.
  • Restrict remote access to engineering workstations through a jump server with multi-factor authentication and session recording — never direct RDP or VNC exposure to OT assets.
  • Segment production cells by process criticality. A compromised quality-inspection camera should not have network adjacency to the DCS managing a high-pressure reactor.

Visibility: You Cannot Defend What You Cannot See

The most common gap in Indian manufacturing security programmes is not technology — it is visibility. Security teams cannot correlate an endpoint alert in IT with unusual traffic on a SCADA historian because the two systems live in separate tools, monitored by separate teams, with no common operational picture.

Achieving unified observability across the IT/OT estate requires passive asset discovery (active scanning can crash fragile OT devices), protocol-aware traffic analysis, and integration between IT security event feeds and OT telemetry sources.

Response Capability: Speed Matters More Than Ever

CERT-In’s 6-hour mandatory incident reporting requirement, established under the April 2022 directions, applies to all entities — including manufacturing companies operating critical infrastructure. When a production network incident is detected, the clock starts immediately. Manual triage, analyst escalation chains, and siloed tools make that timeline almost impossible to meet without automation.

PrahiX Ora: Unified SecOps Visibility for Complex Industrial Estates

For organisations managing the complexity of a multi-site, multi-vendor industrial estate, the core challenge is operational convergence: bringing IT security events, network health metrics, physical security feeds, and automated response into a single operating picture. PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner, and it is the platform we deploy and operate for clients facing exactly this challenge.

The platform is built around four pillars, each directly relevant to the OT/ICS security problem:

SIEM — Security Event Correlation with MITRE ATT&CK for ICS: PrahiX Ora’s SIEM ingests logs and events from heterogeneous sources — IT endpoints, Active Directory, FortiGate firewalls, FortiMail, and OT data sources — applying correlation rules mapped to the MITRE ATT&CK for ICS framework. The graph-based attack storyline reconstruction capability is particularly valuable in OT contexts, where an intrusion may involve dozens of subtle steps across the IT/OT boundary before any operational effect is visible. On the compliance side, CERT-In’s direction on 180-day in-country log retention is addressed through the platform’s tiered hot/cold/archive retention architecture, keeping event data available for forensic investigation without requiring prohibitive storage investment.

NMS — Converged Network and OT Device Observability: The Network Management System pillar provides unified observability across firewalls, switches, wireless access points, WAN and SD-WAN links — and OT network segments. LLDP/CDP topology discovery automates asset mapping, reducing the manual effort of maintaining accurate network inventories. ML-based anomaly detection identifies deviations from established communication baselines — the kind of unusual lateral movement or new device connections that precede OT intrusion events. For Indian manufacturers running multi-vendor estates where NOC visibility is fragmented across vendor-specific tools, this single-pane observability is transformative.

Video Surveillance (VMS) — Physical and Network Security Convergence: PrahiX Ora’s video surveillance (VMS) pillar manages ONVIF-compliant cameras including Hikvision and Dahua deployments, with integrated video analytics. For manufacturing and multi-site retail estates, this creates a unified operations view that correlates physical access events (a contractor badging into the server room outside business hours) with network security events (a new device connecting to the OT network segment) — closing a gap that exists when physical and cyber security operations are entirely separate. This convergence is particularly relevant for Indian manufacturers with distributed production campuses where physical perimeter security and network security have historically been siloed.

SOAR — Automated Response for the CERT-In 6-Hour Window: The Security Orchestration, Automation and Response pillar includes pre-built playbooks and connectors for automated response actions, including pushing blocklists and policy updates directly to FortiGate. In the context of CERT-In’s 6-hour incident reporting obligation, automation is not a convenience — it is what makes the timeline operationally realistic. A detected C2 communication from an engineering workstation can trigger automatic network isolation, firewall rule updates, and the structured data collection needed for a CERT-In report, all within minutes rather than hours.

If your organisation is managing a complex industrial estate and wants to understand how PrahiX Ora can be deployed and operated within your environment, speak with our team at PJ Networks.

A Practical OT Security Roadmap for Indian Manufacturers

For security leaders beginning or maturing an OT security programme, a phased approach yields results without disrupting production continuity:

Phase 1: Visibility (Months 1–3)

  • Deploy passive OT asset discovery — enumerate all devices on production network segments without active scanning.
  • Establish network traffic baselines. What protocols are normal? Which assets communicate with which? What volumes?
  • Integrate OT device logs and network telemetry into a central SIEM. Correlate with IT security events for the first time.
  • Identify and document the IT/OT boundary. Confirm segmentation is actually enforced, not just designed.

Phase 2: Control (Months 3–6)

  • Deploy next-generation firewall at the IT/OT boundary with industrial protocol inspection enabled.
  • Establish privileged access management for all remote and engineering workstation access to OT assets.
  • Develop and test an OT-specific incident response playbook. Assign clear ownership for CERT-In reporting.
  • Patch engineering workstations and historian servers — these are attacker pivot points but are often patchable unlike embedded OT devices.

Phase 3: Resilience (Months 6–12)

  • Implement SOAR playbooks for the highest-priority OT incident scenarios: ransomware on HMI, C2 from engineering workstation, new device on OT segment.
  • Integrate physical access and video analytics with cyber security event feeds.
  • Conduct tabletop exercises for OT incident scenarios involving production shutdown and CERT-In reporting obligations.
  • Build supplier security requirements for OEM and integrator access to production networks.

FortiGate at the IT/OT Boundary: Purpose-Built Capability

Fortinet’s FortiGate NGFW deserves specific mention in the OT/ICS context. The platform includes dedicated industrial protocol inspection for Modbus, DNP3, EtherNet/IP, IEC 61850, and other industrial protocols — enabling deep-packet inspection at the IT/OT boundary without requiring a separate industrial intrusion detection appliance. FortiGate also participates in Fortinet’s Security Fabric, sharing threat intelligence with FortiMail, FortiAnalyzer, and FortiEDR — creating a coordinated response capability across the enterprise that extends to OT boundary enforcement.

For Indian manufacturers managing geographically distributed plants connected via MPLS or SD-WAN, FortiGate SD-WAN with per-application policy enforcement provides both the connectivity and the security posture management needed to extend consistent OT security controls across all sites.

Compliance Considerations: DPDP Act and CERT-In in the Manufacturing Context

The Digital Personal Data Protection (DPDP) Act 2023 and CERT-In’s mandatory reporting directions create a compliance framework that manufacturing CISOs must now navigate alongside operational risk. While OT data is often not personal data in the DPDP sense, manufacturing companies that collect employee biometric data for shop floor access control, customer data via warranty registration systems, or worker health data for safety compliance are squarely within DPDP scope.

CERT-In’s 6-hour reporting obligation applies to cybersecurity incidents broadly — including ransomware events that cause production downtime, unauthorised access to SCADA or historian systems, and data exfiltration from production networks. Organisations that have not built structured incident detection and reporting capability will find this obligation extremely difficult to meet when an incident occurs under pressure. The investment in SOC capability and automation is, in part, a compliance investment.

How PJ Networks Supports Indian Manufacturers

PJ Networks provides managed security services purpose-built for the complexity of Indian enterprise environments. Our 24/7 NOC/SOC team monitors client environments round the clock, with OT/ICS security expertise that bridges the gap between IT security operations and industrial network management.

Our engagements with manufacturing clients typically begin with an OT network assessment — establishing an accurate inventory, mapping the IT/OT boundary, and identifying the highest-priority exposure points. From there, we deploy and manage FortiGate at the IT/OT boundary, integrate OT telemetry into PrahiX Ora for unified visibility, and provide the managed SOC capability to detect, investigate, and respond to threats across both IT and OT environments.

If your organisation is evaluating its OT security posture or looking to build the monitoring and response capability needed to meet CERT-In obligations, our team is ready to help. Contact PJ Networks for an OT security assessment.

Leave a Reply

Your email address will not be published. Required fields are marked *