



India’s manufacturing sector is undergoing a rapid transformation. From automotive and pharmaceuticals to steel and textiles, factories are embracing Industrial IoT (IIoT), SCADA systems, and cloud-connected PLCs to drive efficiency. But this connectivity comes at a steep price: Operational Technology (OT) and Industrial Control Systems (ICS) that were once air-gapped are now exposed to the same threat actors that target enterprise IT—and they are far less equipped to defend themselves.
For Indian CISOs and plant managers, the question is no longer whether OT networks will be targeted, but when. A successful attack on a manufacturing plant doesn’t just cause a data breach—it can halt production lines, damage physical equipment, endanger workers, and trigger regulatory scrutiny under India’s CERT-In directives and the emerging DPDP Act framework.
Traditional IT security tools and playbooks do not translate cleanly to OT environments. The differences are fundamental:
India’s manufacturing sector has emerged as a target of choice for several threat actor categories:
Ransomware groups are increasingly aware that manufacturers will pay faster than other verticals because every hour of downtime has a direct, calculable cost. Threat actors now specifically seek out Historian servers and SCADA workstations, encrypt them, and demand ransom before a production deadline. Indian pharmaceutical and auto component manufacturers have seen such incidents reported to CERT-In under the 6-hour reporting mandate.
Third-party maintenance vendors, remote-access portals for PLC vendors, and shared engineering workstations are the most common initial access vectors. Attackers compromise a small sub-vendor’s VPN credentials and use them to pivot into the OT network of a tier-1 manufacturer.
State-affiliated actors and industrial competitors target R&D workstations, CAD/CAM servers, and quality management systems. For defence-linked manufacturers and MSME exporters supplying global OEMs, IP theft via OT network intrusion is a growing concern.
Geopolitically motivated groups have demonstrated the capability and intent to target critical infrastructure, including ports, power plants, and large industrial facilities. India’s border tensions make domestic manufacturers a non-trivial target for disruption campaigns.
Securing an OT environment requires a layered, risk-based approach calibrated to production realities. Here is the framework we deploy for manufacturing clients:
The Purdue Enterprise Reference Architecture provides a logical starting point. Segment the OT network into clearly defined zones: Level 0 (field devices), Level 1 (basic control), Level 2 (supervisory control), Level 3 (site operations), and the demilitarised zone (DMZ) that mediates all IT/OT communication.
FortiGate next-generation firewalls with OT-aware inspection profiles enforce these zone boundaries. IEC 62443 compliant rulesets allow SCADA traffic while blocking reconnaissance patterns. Critically, any remote access to OT assets should be mediated through a secure jump server in the DMZ—never a direct VPN tunnel into Level 2.
You cannot protect what you cannot see. Many Indian plants have never produced a complete inventory of OT assets—PLCs, HMIs, historians, SCADA servers, and the protocols running between them. Passive network discovery tools (which observe traffic rather than probing devices) build this inventory without disturbing production systems.
Remote access is the most common OT intrusion vector. Every vendor, contractor, and remote engineer who can reach a PLC is a potential entry point. Implement just-in-time privileged access: access is granted only for a defined window, with full session recording, and auto-revoked on expiry. This is achievable through ZTNA principles extended to OT—replacing always-on VPN tunnels with zero-trust access brokers that authenticate the user, the device posture, and the specific OT resource requested.
Signature-based antivirus is largely ineffective against OT-specific malware (Industroyer, TRITON, FrostyGoop). Effective detection relies on behavioural baselines: what commands does this PLC normally issue? What is the typical polling frequency on this Modbus address? Deviations from baseline—a new device on the network, a change in HMI logic, an unusual write command to a safety controller—are high-fidelity signals of compromise.
An OT incident response plan must account for production continuity. Isolating a compromised SCADA server may mean gracefully handing control back to manual operation. Forensics must be performed on live systems where possible, since powering down equipment can itself cause physical damage. Runbooks should be tested in tabletop exercises with both security and plant operations teams.
The CERT-In Directions of 2022 and subsequent updates impose specific obligations on Indian organisations, including manufacturers operating critical infrastructure or connected OT systems:
One of the operational challenges manufacturing CISOs consistently raise is fragmented visibility: the IT SOC sees the enterprise network; the plant team watches OT alarms via their own SCADA console; and nobody has a unified view that correlates IT threat indicators with OT anomalies. This gap is precisely where the platform we deploy and operate for clients—PrahiX Ora, developed by PrahiX Tech Pvt Ltd—provides measurable value.
SIEM: PrahiX Ora ingests logs from firewalls, active directory, SCADA historians, and endpoint agents into a unified correlation engine with detection rules mapped to MITRE ATT&CK for ICS (ATT&CK-ICS). When a Windows workstation in the OT DMZ attempts lateral movement to a Historian server, the platform reconstructs the attack storyline in a graph view, linking the initial phishing email to the OT pivot in a single alert. The platform’s tiered retention (hot, cold, archive) helps manufacturing clients meet CERT-In’s 180-day in-country log retention direction without prohibitive storage costs.
NMS: In multi-vendor OT/IT estates—FortiGate firewalls, Cisco switches, legacy SCADA hardware, and wireless APs across a sprawling plant floor—NOC visibility is often fragmented across five or six different consoles. Ora’s Network Management System uses LLDP/CDP topology discovery to build a live map of the entire estate, with network path tracing and ML-based anomaly detection that flags unusual traffic patterns between IT and OT zones. Auto-healing policies can quarantine a suspicious endpoint without requiring a human to log into a firewall management console at 2 AM.
Video Surveillance (VMS): Physical access to OT assets—server rooms, PLC cabinets, substation control panels—is as important as network security. Ora’s video surveillance (VMS) module supports ONVIF/Hikvision/Dahua camera integration with video analytics, bringing physical and logical security under one operations view. For manufacturing and retail clients with multi-site estates, this means a single operator can correlate a door-access event at a remote facility with a network anomaly from the same location—something impossible when physical security and cyber security run on separate platforms.
SOAR: The CERT-In 6-hour incident reporting window is not achievable through manual processes alone when your OT environment generates thousands of events per day. Ora’s SOAR module provides pre-built playbooks with automated response actions—for example, pushing a new blocklist to FortiGate the moment a malicious IP is identified, or automatically isolating a compromised jump server from the OT DMZ. This automation does not replace human judgment for high-consequence OT actions; instead, it handles the initial triage, evidence collection, and notification steps so your analysts can focus on decisive response rather than ticket management.
If your plant environment currently lacks unified visibility across IT and OT, get in touch with our team to discuss what an Ora deployment would look like for your specific estate.
Use this checklist as a starting point for an OT security gap assessment:
PJ Networks is a managed security services provider with deep Fortinet expertise and 24/7 NOC/SOC operations serving Indian enterprise clients. Our OT security engagements typically include:
The manufacturing sector is at an inflection point. Connectivity that drives efficiency also creates attack surface. The organisations that build security into their OT convergence strategy today will be far better positioned than those who wait for an incident to force the conversation.
If you are a plant manager, IT head, or CISO at an Indian manufacturing company and want to understand your current OT security posture, contact PJ Networks for a no-obligation assessment. We operate across India, with 24/7 support and a team experienced in Fortinet, ICS security, and CERT-In compliance.