Securing India’s Manufacturing Floor: OT/ICS Cybersecurity, CERT-In Compliance, and Unified SecOps

  • Home
  • Securing India’s Manufacturing Floor: OT/ICS Cybersecurity, CERT-In Compliance, and Unified SecOps
Securing India’s Manufacturing Floor: OT/ICS Cybersecurity, CERT-In Compliance, and Unified SecOps

India’s manufacturing sector is undergoing rapid digital transformation. Factories are deploying Industrial IoT (IIoT) sensors, SCADA systems, programmable logic controllers (PLCs), and remote monitoring dashboards at an unprecedented pace. The ambition behind initiatives like Make in India and Industry 4.0 is real — and so is the attack surface that comes with it.

In 2025 and into 2026, operational technology (OT) and industrial control system (ICS) environments have become prime targets for ransomware groups, nation-state actors, and opportunistic cybercriminals. Unlike a compromised email account, a breach on the factory floor can halt production lines, damage equipment, trigger safety incidents, and cost crores of rupees per hour of downtime.

For Indian CISOs and IT leaders overseeing manufacturing operations, the question is no longer whether to secure OT/ICS networks — it is how to do it effectively while meeting the compliance obligations imposed by CERT-In and the Digital Personal Data Protection (DPDP) Act 2023.

Why OT/ICS Security Is Different — and Why It Matters More Than Ever

Traditional IT security focuses on confidentiality, integrity, and availability — in that order. In OT environments, the priority is reversed: availability comes first. A momentary disruption to a blast furnace control system, a pharmaceutical batch reactor, or an automotive welding line can cascade into physical damage, safety violations, and regulatory penalties.

This priority reversal creates a fundamental tension. Standard IT tools — frequent patch cycles, endpoint agents, deep packet inspection on every flow — can introduce latency or instability that OT equipment simply cannot tolerate. Many PLCs and human-machine interfaces (HMIs) run end-of-life operating systems that cannot be patched without vendor re-certification. Others operate on proprietary protocols like Modbus, DNP3, EtherNet/IP, or PROFINET that generic security tools do not understand.

Meanwhile, the IT-OT convergence trend means these fragile OT assets are no longer air-gapped. Remote maintenance contracts require vendors to dial into machines from outside. ERP integrations pull production data into cloud analytics platforms. Quality management systems share data with logistics partners. Every one of these integration points is a potential attack path.

The Indian Threat Landscape: What Attackers Are Targeting

The threat to Indian manufacturing is not theoretical. Across the Asia-Pacific region — and increasingly within India — industrial environments have faced:

  • Ransomware targeting engineering workstations: Attackers pivot from a phishing email on the corporate network to an engineering workstation that has RDP access to the OT SCADA, then encrypt both environments simultaneously.
  • Supply chain compromise via vendor VPN: Third-party maintenance vendors with persistent VPN tunnels become an entry point when their own endpoints are compromised.
  • Firmware implants on network devices: Attackers with prolonged dwell time have been observed modifying firmware on older switches and routers sitting in the OT DMZ, giving them persistent, hard-to-detect access.
  • Data exfiltration from SCADA historians: Process data — production volumes, quality parameters, recipe files — is commercially valuable. Competitors and nation-state actors have targeted historian servers to steal intellectual property without ever touching the control layer.

CERT-In’s advisories through 2025 have repeatedly flagged vulnerabilities in SCADA platforms, HMI software, and industrial network protocols. Organisations that delay patching or lack visibility into their OT network traffic face the highest exposure.

The CERT-In Compliance Dimension

CERT-In’s April 2022 directions (and subsequent clarifications) created binding obligations for all organisations operating critical digital infrastructure in India. For manufacturing companies, the key requirements are:

  • Mandatory incident reporting within 6 hours of detecting a cyber incident — including ransomware, unauthorised access, or data breaches affecting IT or OT systems.
  • Log retention for 180 days, stored within Indian jurisdiction, covering network devices, servers, and applications.
  • Maintenance of accurate system clocks synchronised with the National Physical Laboratory or National Informatics Centre time servers.
  • Designated Point of Contact (PoC) for CERT-In coordination, with documented escalation procedures.

Meeting the 6-hour reporting window is the most operationally demanding requirement. Without automated detection and alert correlation across both IT and OT environments, security teams face an impossible task: manually sifting through logs from PLCs, SCADA servers, firewalls, and endpoints within a few hours to determine the scope and nature of an incident.

DPDP Act 2023: An OT Angle Often Overlooked

The Digital Personal Data Protection Act 2023 is often discussed in the context of HR systems, customer databases, and marketing platforms. But manufacturing organisations should not overlook the OT angle.

Modern smart factories capture biometric data (fingerprint/facial recognition for access control), CCTV footage of employees and contractors, and location data from worker-worn IoT devices. All of this constitutes personal data under the DPDP Act. A breach of factory surveillance systems or access control databases could trigger both DPDP data breach obligations and CERT-In incident reporting — simultaneously.

Organisations that bring physical and cyber security under a unified operations view are better positioned to manage these overlapping obligations.

Building the Defence: A Layered OT Security Architecture

Effective OT/ICS security is not a single product or policy — it is a discipline built on layers. Here is the framework PJ Networks implements for manufacturing clients:

1. Network Segmentation with FortiGate NGFW

The first and most impactful control is rigorous network segmentation. The Purdue Model provides the reference architecture: Level 0 (field devices), Level 1 (basic control), Level 2 (supervisory control), Level 3 (site operations), and the IT/OT DMZ separating these from the corporate network.

FortiGate next-generation firewalls are deployed as the enforcement points at each zone boundary. FortiGate’s OT-aware application identification can recognise and control industrial protocols (Modbus TCP, EtherNet/IP, DNP3, IEC 61850) without requiring full deep packet inspection that could disrupt real-time control traffic. Policy enforcement is configured to allow only the specific communications that each integration point requires — a historian pulling data from Level 2 does not need bidirectional RDP access to Level 1 controllers.

2. Zero Trust Network Access for Remote Maintenance

Vendor remote access is one of the most common initial access vectors in OT breaches. Traditional VPN solutions create a tunnel that, once authenticated, provides broad network access. ZTNA changes this: access is granted per-application, per-session, based on device posture and identity, and revoked immediately at session end.

PJ Networks deploys ZTNA solutions that give maintenance vendors access to only the specific HMI or engineering workstation they need, for only the duration of the maintenance window, with full session recording. This eliminates the persistent, broad-access VPN tunnel as an attack surface.

3. Asset Discovery and OT-Specific Visibility

You cannot protect what you cannot see. Many manufacturing organisations discover they have far more OT devices on the network than their asset registers suggest — unauthorised PLCs added during a production expansion, legacy HMIs forgotten after a line upgrade, test equipment left connected after a vendor visit.

Passive network monitoring using span ports or network taps — never active scanning, which can crash OT devices — provides a safe way to enumerate every device communicating on the OT network, build a topology map, and baseline normal behaviour. Deviations from that baseline (a PLC communicating on a port it never used before, an HMI initiating an outbound connection) become high-fidelity alerts.

4. Vulnerability Management Without Disruption

Patching in OT is complex: vendor approval, change management windows, production downtime scheduling, and re-validation are all required before any patch is applied. The realistic posture for most manufacturing OT environments is compensating controls rather than rapid patching.

This means: identifying all known vulnerabilities in OT software and firmware, documenting them in a register, implementing network-level controls (firewall rules, IPS signatures) to block exploitation paths, and scheduling patching for the next planned maintenance shutdown. CERT-In’s vulnerability disclosure advisories should be reviewed against this register as they are published.

PrahiX ORA: Unified SecOps for Manufacturing Environments

Running a 24/7 security operations function across a complex manufacturing environment — with OT networks, IT systems, physical access control, and CCTV all generating data — requires a platform built for that scale. PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd; PJ Networks is its primary field deployment and operations partner, and we operate it for clients across manufacturing, pharma, and logistics sectors.

The platform addresses four capabilities that are directly relevant to manufacturing security:

SIEM — correlated visibility across IT and OT: PrahiX Ora’s SIEM ingests logs from FortiGate firewalls, SCADA servers, historians, Active Directory, and OT-specific sources into a single correlation engine. Detection rules are mapped to MITRE ATT&CK for ICS, enabling graph-based attack storyline reconstruction that shows, for example, the chain from a phishing email to lateral movement into the OT DMZ. Tiered log retention (hot, cold, and archive) supports CERT-In’s direction for 180-day in-country log retention — a requirement that affects every OT-connected organisation in India.

NMS — unified OT and IT network observability: In manufacturing estates, the NOC team often has fragmented visibility: one tool for IT switches, another for OT equipment, a third for WAN links. PrahiX Ora’s NMS consolidates all of this — firewalls, managed switches, access points, SD-WAN links, and OT-adjacent network nodes — into one topology view using LLDP/CDP discovery and network path tracing. ML-based anomaly detection flags unusual traffic patterns at the network layer, and auto-healing policies can isolate a compromised segment without manual intervention during an active incident.

Video Surveillance (VMS) — physical and cyber under one roof: Manufacturing and multi-site retail estates increasingly need physical security and cyber security to speak to each other. PrahiX Ora’s video surveillance (VMS) module manages ONVIF-compliant cameras, including Hikvision and Dahua devices, with video analytics capabilities. For a security operations team, this means that a physical intrusion alert from a camera near a server room can be correlated with a simultaneous login anomaly flagged by the SIEM — the full picture in one view rather than two separate systems that never talk to each other.

SOAR — making the 6-hour window realistic: CERT-In’s 6-hour incident reporting requirement is operationally demanding. Without automation, the team must manually triage, investigate, scope, and draft a report — all within six hours of detection. PrahiX Ora’s SOAR engine runs pre-built playbooks for common incident types (ransomware containment, OT anomaly escalation, data exfiltration response). Automated response actions — such as pushing blocklist entries to FortiGate, quarantining an endpoint, or revoking a ZTNA session — cut response time from hours to minutes, leaving the team time to complete the CERT-In notification accurately and on time.

If your OT environment lacks unified SecOps visibility, speak to the PJ Networks team to understand how PrahiX Ora is deployed and operated in manufacturing contexts.

A Practical Checklist: Where to Start

For CISOs who are beginning or maturing their OT security programme, here is a prioritised starting list:

  • Asset inventory: Conduct a passive OT asset discovery exercise to enumerate every device on the OT network. No security programme works without knowing what needs to be protected.
  • Network segmentation audit: Map your current zone architecture against the Purdue Model. Identify any flat network segments where OT and corporate IT traffic are mixed.
  • Remote access review: List every vendor with remote access to OT systems. Audit the method (VPN, direct RDP, jump host) and replace broad-access VPN with ZTNA where possible.
  • Log retention baseline: Verify that all network devices, servers, and OT applications are sending logs to a centralised SIEM, and that retention meets CERT-In’s 180-day direction.
  • Incident response tabletop: Run a tabletop exercise specifically for an OT ransomware scenario. Validate that your team can generate a CERT-In-compliant incident report within 6 hours.
  • Vulnerability register: Create or update an OT vulnerability register aligned with CERT-In advisories. For each known vulnerability, document the compensating control in place until patching is feasible.
  • DPDP data mapping: Identify all personal data captured in the manufacturing environment — biometrics, CCTV, worker IoT — and map it to DPDP Act obligations for breach notification and data processing consent.

How PJ Networks Supports Manufacturing Cybersecurity

PJ Networks has been delivering managed security to Indian enterprises for over two decades. Our OT/ICS security engagements typically begin with a network segmentation and visibility assessment, followed by a FortiGate deployment for zone enforcement and a ZTNA rollout for vendor remote access. Our 24/7 NOC/SOC team monitors both IT and OT environments under one operations centre, with CERT-In incident reporting built into the SOC playbook.

We work with organisations across automotive components, pharmaceuticals, textiles, and food processing — sectors where operational continuity is non-negotiable and where the regulatory environment is tightening. Whether you are building an OT security programme from scratch or looking to mature an existing one, we can help you structure the right architecture and operate it reliably.

Ready to assess your manufacturing cybersecurity posture? Contact PJ Networks to schedule a conversation with our OT security team.

Leave a Reply

Your email address will not be published. Required fields are marked *