



India’s manufacturing sector is in the middle of a profound transformation. Industry 4.0 adoption — smart factories, connected production lines, predictive maintenance systems — is reshaping how Indian enterprises operate. But this convergence of Operational Technology (OT) with corporate IT networks is creating a security exposure that many CISO offices have not yet fully addressed.
OT environments were traditionally air-gapped: isolated, purpose-built systems running legacy SCADA, PLCs, and DCS that ran independently of enterprise networks. Today, that isolation is dissolving. Business pressure to connect factory floors to ERP systems, remote monitoring requirements post-COVID, and the push for cloud-based analytics have quietly bridged what was once a hard boundary. And threat actors have noticed.
The global picture is stark. Attacks on industrial infrastructure — energy grids, water utilities, manufacturing plants — have escalated sharply since 2021. India has not been immune. The 2020 Mumbai power grid disruption, widely attributed to a threat actor probing OT systems, was a wake-up call. Since then, CERT-In has issued multiple advisories on ICS/SCADA vulnerabilities affecting sectors ranging from oil-and-gas to pharmaceuticals.
The structural risk factors for Indian OT environments are well-understood:
Understanding the threat model is critical before designing a defence. In OT/IT convergence attacks, the typical kill chain looks like this:
MITRE ATT&CK for ICS (the ICS-specific extension of the MITRE framework) documents over 80 techniques specific to industrial environments. Most Indian OT environments have no visibility into whether any of these techniques are being used against them right now.
Regulatory pressure is tightening. The Indian Computer Emergency Response Team (CERT-In) has designated several industrial sectors as Critical Information Infrastructure (CII). CII operators have heightened obligations under the Information Technology Act, including the mandatory 6-hour incident reporting requirement introduced in CERT-In’s April 2022 directions.
For OT environments, this creates a practical problem: how do you report an incident within six hours when your visibility into OT systems is near-zero? Traditional IT security tools don’t instrument PLCs or SCADA historian nodes. Without structured telemetry from the OT layer, even detecting a breach — let alone reporting it — within the regulatory window is extremely difficult.
The 6-hour CERT-In reporting window assumes you know an incident has occurred. In OT environments with poor visibility, the first sign of compromise is often a production halt — long after the attacker has already accomplished their objective.
The good news is that a structured approach can substantially reduce exposure without requiring a wholesale rip-and-replace of legacy OT infrastructure. Here is the framework PJ Networks recommends and deploys for manufacturing, pharma, and multi-site industrial clients across India.
The foundation is segmentation. OT networks should be divided into clearly defined zones — process control networks, supervision networks, and the DMZ that bridges to IT — with conduits (firewall-enforced paths) controlling all inter-zone traffic. A FortiGate NGFW positioned at the IT/OT boundary can enforce industrial protocol inspection, block unauthorised Modbus or DNP3 traffic, and provide granular visibility into east-west flows between zones.
You cannot protect what you cannot see. Passive network taps (SPAN ports or network TAPs) at key OT switching points allow a monitoring platform to enumerate assets — PLCs, HMIs, engineering workstations, historian servers — by reading OT protocol traffic without sending a single packet to industrial devices. This is safe even for the most fragile legacy equipment.
OEM vendor access should never be a persistent VPN tunnel with shared credentials. The right model is a PAM-controlled jump host with session recording, time-limited access grants, and MFA enforcement. Every vendor session should be logged and reviewable.
Detection logic for OT environments needs to understand industrial protocols and the specific attack patterns documented in MITRE ATT&CK for ICS. This requires correlation rules purpose-built for Modbus function code abuse, unauthorised engineering commands, and HMI credential attacks — not just generic IT security rules.
IR plans built exclusively for IT environments will fail in an OT incident. OT IR requires coordination between the CISO office, plant operations, OEM vendors, and (for CII operators) CERT-In notification — all under time pressure. Pre-built playbooks with OT-specific decision trees are essential, not optional.
One of the persistent challenges in OT/IT convergence security is tool fragmentation. The IT security team runs a SIEM and a SOAR platform. The plant operations team uses a network management system for OT device monitoring. Physical security runs video analytics for the factory floor. These three views rarely talk to each other — and threat actors exploit the gaps between them.
The platform we deploy and operate for clients, PrahiX Ora (built by PrahiX Tech Pvt Ltd), addresses this by bringing four capabilities into a single unified SecOps console.
SIEM with MITRE ATT&CK and ICS correlation: PrahiX Ora ingests logs and events from both IT and OT sources — FortiGate firewall logs, Windows Event Logs from engineering workstations, syslog from SCADA historian servers, and OT protocol telemetry from passive taps — and correlates them using rules mapped to MITRE ATT&CK for Enterprise and MITRE ATT&CK for ICS. The graph-based attack storyline reconstruction is particularly valuable in OT incidents: it reconstructs the lateral movement from an IT-side initial access event to the OT-network pivot, giving analysts a complete picture rather than disconnected log entries. Tiered log retention (hot, cold, archive) supports CERT-In’s direction on 180-day in-country log retention for CII operators — a requirement that many organisations are still struggling to meet.
NMS for unified OT/IT observability: The network management module provides unified observability across FortiGate firewalls, managed switches, wireless APs, and WAN/SD-WAN links — but extends this to OT network devices via LLDP/CDP topology discovery and network path tracing. For manufacturing clients with multi-vendor OT estates where NOC visibility has historically been fragmented across multiple single-point tools, this creates a single operational view. ML-based anomaly detection flags deviations from learned OT traffic baselines — useful for identifying reconnaissance activity against industrial protocols before it escalates.
Video surveillance (VMS) integration: PrahiX Ora includes ONVIF-compatible video surveillance management with support for Hikvision and Dahua camera ecosystems, plus video analytics capabilities. For manufacturing and multi-site retail clients, integrating physical security into the same SecOps console as network and log monitoring creates a genuinely unified operations view. A badge access anomaly correlated with a simultaneous network login from an unusual workstation becomes visible as a single connected event, not two separate alerts in two different dashboards.
SOAR with FortiGate response integration: The SOAR module provides playbook automation with pre-built connectors — including direct integration with FortiGate for automated response actions such as pushing blocklists, quarantining hosts, or modifying security policy rules. This matters acutely in OT incident response: CERT-In’s 6-hour reporting window demands speed that manual analyst workflows alone cannot reliably achieve. Automated containment of a compromised engineering workstation — isolating it from OT network zones while preserving forensic evidence — is what makes that regulatory timeline realistic for CII operators.
If your organisation is operating OT infrastructure without this level of unified visibility, the question is not whether you will have an incident — it is whether you will detect it before the attacker achieves their objective.
If your organisation has begun OT/IT convergence but hasn’t yet conducted a formal security assessment of the resulting exposure, here is a pragmatic starting sequence:
OT/IT convergence is not a choice many Indian enterprises are still making — it has already happened. The production monitoring dashboards, the cloud-connected historians, the vendor remote access tunnels: these connections exist. The question is whether the security architecture has kept pace.
For CISO offices managing both IT and OT exposure, the priority should be visibility first. You cannot protect an environment you cannot see, and the tools that work for IT endpoints simply do not translate to PLCs and SCADA systems. A layered approach — segmentation at the IT/OT boundary, passive OT monitoring, privileged access controls for vendor access, and unified detection across IT and OT telemetry — is both achievable and necessary.
PJ Networks works with Indian enterprises in manufacturing, pharma, FMCG, and multi-site retail to design and operate OT/IT security architectures built around FortiGate, Fortinet’s Security Fabric, and the PrahiX Ora platform. If your organisation is navigating OT/IT convergence and wants an honest assessment of where your current exposure sits, reach out to our team for an initial consultation.