



India’s manufacturing sector is undergoing a rapid digital transformation — smart factories, Industry 4.0 deployments, IoT-connected assembly lines, and cloud-linked SCADA systems are becoming the norm from Pune auto-component plants to Chennai petrochemical facilities. But this convergence of Operational Technology (OT) and Information Technology (IT) networks has quietly dismantled the most trusted security assumption in industrial computing: the air gap.
For decades, the mantra in industrial security was simple — “keep it disconnected.” Physical isolation between the plant floor and the corporate network was supposed to guarantee that a ransomware infection in Finance would never reach a PLC managing a blast furnace. That era is over. And for Indian enterprises still operating on this assumption, the risk is not theoretical — it is imminent.
The drivers of OT/IT convergence in India mirror global trends but with local intensity:
The result: what was once a flat, isolated OT network is now a porous, partially-connected environment — with the detection and response capabilities of neither a modern IT network nor the physical redundancy of a truly air-gapped one.
Threat actors — ranging from financially motivated ransomware groups to nation-state APTs — have recognised this window of vulnerability. Several patterns are particularly relevant for Indian enterprises:
Modern ransomware families no longer stop at encrypting Windows endpoints. Variants actively probe for industrial protocols, disable OT backup systems, and target historian servers holding months of production data. When a manufacturing plant’s historian goes dark, the business impact extends far beyond IT recovery time — it disrupts quality records, compliance audits, and customer SLAs simultaneously.
Sophisticated attackers increasingly use legitimate tools already present in OT environments — remote desktop utilities, default vendor credentials, and engineering software — to move laterally without triggering signature-based detections. In environments where baseline OT traffic has never been profiled, such activity is virtually invisible.
Compromised firmware updates delivered through legitimate vendor channels have emerged as a high-impact attack vector. An industrial device accepting an unsigned firmware image from a trusted IP address has no mechanism to detect tampering — and the consequences can include persistent backdoors that survive factory resets.
CERT-In advisories have flagged incidents where network intrusions were used to manipulate physical processes — from water treatment chemical dosing to energy substation switching. The physical consequences of cyber incidents in OT environments are categorically different from data breaches, and the incident response playbook must reflect that difference.
CERT-In’s April 2022 direction — mandating that organisations report cybersecurity incidents within six hours of detection — applies with full force to industrial operators. Yet OT environments present a compliance challenge that purely IT-focused organisations don’t face:
Meeting the CERT-In timeline for OT incidents requires investing in detection — not just incident response — before an event occurs. Organisations that discover an OT intrusion after days of lateral movement have already missed the compliance window before the formal incident response even begins.
Closing the air-gap illusion does not mean accepting permanent exposure. It means engineering security controls that acknowledge the reality of connectivity while maintaining strict boundaries between zones.
The ISA/IEC 62443 standards and the NIST Cybersecurity Framework for Industrial Control Systems both build on Purdue Model zone architecture: separating enterprise IT (Levels 4–5) from manufacturing operations (Levels 0–3) via a demilitarised zone (DMZ). FortiGate Next-Generation Firewalls are a natural fit for enforcing these boundaries — their deep packet inspection capabilities extend to industrial protocols including Modbus TCP, DNP3, and IEC 60870-5-104, enabling policy-based control at the application layer of OT traffic.
Every contractor, OEM vendor, and remote engineer accessing OT systems should authenticate through a ZTNA framework rather than a conventional VPN. ZTNA enforces least-privilege access — a drive-train OEM vendor gets access only to the specific PLC segment relevant to their equipment, with session recording and time-bounded credentials. This eliminates the “trusted insider with broad access” problem that makes lateral movement so damaging in OT environments.
You cannot protect what you cannot see. OT asset inventories are notoriously incomplete — many organisations discover unmanaged PLCs, legacy HMIs, and undocumented remote access tools only after an incident. Passive network traffic analysis, which does not require agents on fragile industrial endpoints, is the preferred approach: it maps devices, firmware versions, and communication patterns without any risk of disrupting production.
OT traffic is highly deterministic — a Modbus master polls its slaves on a precise schedule, a historian server writes data at predictable intervals. This predictability makes anomaly detection far more effective in OT environments than in general enterprise networks. Deviations from baseline — unexpected commands to a PLC, new devices appearing on a segment, unusual timing patterns — are high-confidence indicators of malicious activity that warrant immediate investigation.
One of the most persistent challenges in converged OT/IT environments is the operational gap between IT security teams (who own the SOC and SIEM) and OT/engineering teams (who own the plant floor). Each team has its own tooling, its own visibility, and — critically — its own blind spots. Security incidents that cross the IT/OT boundary often fall through that gap precisely because neither team has full visibility into the other’s domain.
The platform we deploy and operate for clients — PrahiX ORA, built by PrahiX Tech Pvt Ltd — addresses this through a unified SecOps architecture with four integrated pillars particularly relevant to manufacturing and multi-site industrial estates:
SIEM with MITRE ATT&CK Mapping: ORA’s SIEM ingests log and event data from both IT systems (firewalls, endpoints, cloud) and OT sources (historian logs, industrial protocol event streams, SCADA audit trails), applying correlation rules mapped to the MITRE ATT&CK for ICS framework. The graph-based attack storyline reconstruction connects events across IT and OT tiers — so a suspicious VPN login, a lateral movement event in the DMZ, and an anomalous PLC command are correlated into a single attack narrative rather than three unrelated alerts. For CERT-In compliance, the platform’s tiered retention architecture (hot/cold/archive) supports the 180-day in-country log retention direction — ensuring logs are available when investigators need them.
NMS for Converged Network Observability: In multi-vendor OT estates — where FortiGate firewalls coexist with Cisco switches, Hirschmann OT switches, and third-party WAN appliances — NOC visibility is typically fragmented across multiple management consoles. ORA’s NMS provides unified topology discovery (via LLDP/CDP), network path tracing, and ML-based anomaly detection across all layers. Auto-healing policies can respond to detected anomalies — isolating a switch port or rerouting traffic — without requiring manual intervention at 2 AM during the night shift.
Video Surveillance (VMS) Under One Operations View: Physical security and network security have traditionally been managed by separate teams with no shared data. ORA’s video surveillance (VMS) module brings ONVIF-compatible cameras — including Hikvision and Dahua devices common in Indian industrial facilities — under the same operational view as the network and security data. For manufacturing plants, retail chains, and multi-site logistics operators, this means a physical perimeter breach and a concurrent network anomaly can be correlated in a single dashboard rather than discovered independently hours apart.
SOAR Automation for the Six-Hour Window: Playbook automation is what makes CERT-In’s 6-hour incident reporting window achievable in practice. ORA’s SOAR module includes pre-built connectors and automated response actions — including pushing blocklists directly to FortiGate — so that containment begins within minutes of detection, not after a chain of manual approvals. For an OT incident where the window between initial intrusion and process disruption may be measured in minutes, automation is not a convenience: it is an operational requirement. Incident reports can be pre-populated from playbook execution logs, turning a compliance deadline into a manageable process.
If your OT visibility is fragmented — or if your IT SOC and plant operations teams are working from separate toolsets — contact PJ Networks to discuss how PrahiX ORA can be deployed and operated as a unified SecOps layer for your environment.
For IT leaders undertaking or planning an OT security review, the following checklist provides a structured starting point:
PJ Networks brings together the FortiGate NGFW ecosystem, 24/7 NOC/SOC operations, ZTNA deployment expertise, and the PrahiX ORA unified SecOps platform to address the specific challenges of converged OT/IT environments in Indian enterprises. Our approach starts with an OT network assessment — passive discovery, segmentation gap analysis, and detection capability review — and builds toward a continuously monitored, CERT-In-aligned security posture.
Whether you are a manufacturing CISO looking to establish baseline OT visibility, a corporate IT head tasked with integrating plant networks into enterprise security monitoring, or an operations director concerned about production continuity during a cyber incident — we can help you move from the air-gap illusion to a real, defensible security architecture.
To schedule an OT Security Assessment or discuss managed OT/IT security for your organisation, contact PJ Networks through pjnetworks.com/contact.