Securing OT/ICS Networks in Indian Manufacturing: A Practical Guide

  • Home
  • Securing OT/ICS Networks in Indian Manufacturing: A Practical Guide
Securing OT/ICS Networks in Indian Manufacturing: A Practical Guide

India’s manufacturing sector is on the cusp of a major transformation. Industry 4.0 initiatives, smart factories, and government-backed programmes like Make in India are accelerating the convergence of Operational Technology (OT) and Information Technology (IT) networks across steel plants, auto-component factories, pharmaceutical units, and petrochemical refineries. That convergence is generating enormous efficiency gains — and an equally enormous attack surface that most organisations are not yet equipped to defend.

In 2024–25, threat intelligence from multiple sources confirmed a sharp rise in targeted intrusions against industrial control systems (ICS) in the Asia-Pacific region, with several incidents touching Indian critical infrastructure. Unlike IT breaches, a compromise of an OT network does not stop at stolen data — it can halt production lines, trigger safety incidents, and, in critical sectors like power and water, have consequences that extend far beyond the enterprise perimeter.

Why OT Security Is Different — and Why Indian Factories Are Exposed

Traditional OT environments were designed for availability and safety, not confidentiality. SCADA systems, PLCs, DCS controllers, and HMIs often run operating systems that haven’t been patched in years — sometimes decades — because the vendor’s certification requires a specific firmware version or because a maintenance window costs more than the perceived breach risk. This creates a structural vulnerability that no simple firewall rule can close.

Several factors specific to the Indian manufacturing landscape amplify this risk:

  • Legacy equipment with no patching path. Many mid-market plants run Siemens S7, Allen-Bradley, or Schneider Electric PLCs that shipped with insecure-by-design protocols like Modbus/TCP and OPC-DA. Vendors either no longer support these versions or require costly on-site upgrades.
  • IT-OT convergence without segmentation. Business pressure to connect shop-floor data with ERP systems (SAP, Oracle) has eliminated the “air gap” that previously provided informal protection. In many sites we assess, OT and IT share the same flat network segment.
  • Third-party remote access. Equipment OEMs and maintenance contractors routinely connect to PLCs via VPN or, in some cases, direct internet-exposed jump servers. These vendor access paths are a primary initial-access vector in ICS intrusions.
  • Limited OT-specific security skills. Most enterprise security teams are trained on IT tooling. OT protocols — Profinet, EtherNet/IP, DNP3, IEC 61850 — require specialist knowledge that few Indian SOC teams currently possess.
  • Regulatory ambiguity. CERT-In’s 2022 directive and the DPDP Act focus primarily on data. NCIIPC guidelines cover critical infrastructure sectors but enforcement and awareness remain uneven in mid-market manufacturing.

The Threat Landscape: What Attackers Are After

Understanding adversary intent helps prioritise where to defend. Across OT-targeted campaigns observed globally and in the Indian context, three primary motivations stand out:

1. Ransomware with OT Pivot

Ransomware groups increasingly move from compromised IT networks into OT environments to maximise pressure on victims. Once a group can threaten production stoppage — not just data exfiltration — the leverage for extortion multiplies. The playbook typically involves an initial IT foothold via phishing or exposed RDP, lateral movement to the IT/OT boundary, and then deployment of ransomware that encrypts historian servers and engineering workstations.

2. Nation-State Reconnaissance

Advanced Persistent Threat (APT) groups with interests in India’s defence, energy, and pharmaceutical supply chains have demonstrated persistent interest in mapping OT environments. The goal is not always immediate disruption — often it is pre-positioning: planting implants in historian servers or engineering workstations that can be activated during a geopolitical crisis.

3. Destructive Sabotage

Less common but most severe — adversaries deliberately triggering unsafe operating conditions in chemical plants, power grids, or water treatment facilities. The Triton/TRISIS malware, which targeted safety instrumented systems (SIS) in the Middle East, demonstrated that threat actors are willing to cross the line into potential physical harm.

A Practical OT Security Framework for Indian Manufacturers

The IEC 62443 standard provides the industry-accepted framework for industrial cybersecurity. Combined with NIST SP 800-82 and NCIIPC guidelines, it offers a risk-based approach that is achievable even for mid-market manufacturers. Here is a practical implementation roadmap:

Phase 1: Asset Inventory and Network Visibility (Weeks 1–4)

  • Deploy passive OT network monitoring (Claroty, Dragos, or Nozomi Networks agents) to enumerate every device communicating on the OT network without disrupting live processes.
  • Identify all active OT protocols, firmware versions, and unencrypted communication paths.
  • Map all remote access paths — vendor VPNs, modems attached to PLCs, cellular gateways.
  • Document which OT assets communicate with IT systems and classify the data flows.

Phase 2: Network Segmentation and the Purdue Model (Weeks 4–12)

  • Implement a proper Purdue Model hierarchy: separate Level 0–2 (field devices, controllers) from Level 3 (site operations) and Level 3.5 (industrial DMZ) from Level 4 (enterprise IT).
  • Deploy FortiGate NGFW at the IT/OT boundary as a ruggedised industrial firewall with OT-aware deep packet inspection for Modbus, DNP3, and EtherNet/IP protocols.
  • Enforce unidirectional data flows using data diodes or strict firewall policies for historian replication to the enterprise tier.
  • Eliminate all direct internet access from OT networks — route all external communication through a monitored industrial DMZ.

Phase 3: Secure Remote Access (Weeks 8–16)

  • Replace all unsecured vendor VPNs with a privileged access management (PAM) solution that requires multi-factor authentication and records all sessions.
  • Implement Zero Trust Network Access (ZTNA) principles for contractor access: just-in-time provisioning, least-privilege, and automatic session termination on task completion.
  • Enforce FortiClient-based endpoint checks before any remote session can reach OT equipment.

Phase 4: Continuous Monitoring and Incident Response (Ongoing)

  • Feed OT network telemetry into a SIEM that understands industrial protocols — standard IT SIEMs generate excessive false positives when processing OT traffic.
  • Define OT-specific incident response playbooks that account for the “safety first, security second” constraint: some response actions acceptable in IT (isolating a segment, killing a process) can cause physical harm in OT.
  • Conduct tabletop exercises that simulate a ransomware pivot from IT to OT, including production-line recovery procedures.
  • Maintain offline, air-gapped backups of PLC configurations, HMI projects, and historian data — these are the crown jewels in OT recovery.

PrahiX Ora: Unified SecOps for IT and OT Environments

One of the operational challenges IT/OT convergence creates is a fragmented visibility problem: your IT team sees the enterprise network; your OT team (if you have one) monitors the shop floor; and neither team sees the full picture. This is precisely the gap that unified SecOps platforms are designed to close.

The platform we deploy and operate for clients in manufacturing and critical infrastructure is PrahiX Ora, built by PrahiX Tech Pvt Ltd. It is designed to bring IT and OT telemetry under a single operations lens — which matters enormously when an attacker is traversing the IT/OT boundary in real time.

SIEM — correlated detection across both domains: PrahiX Ora’s SIEM ingests logs from FortiGate firewalls, switches, OT historians, and Windows engineering workstations, applying correlation rules mapped to MITRE ATT&CK for ICS (in addition to the standard enterprise ATT&CK matrix). When an anomalous lateral movement pattern touches both an enterprise host and an OT historian within the same kill chain, the platform reconstructs the attack storyline using graph-based event correlation. For Indian manufacturers, this directly supports CERT-In’s direction on 180-day in-country log retention — logs are tiered into hot, cold, and archive storage without manual intervention.

NMS — single-pane visibility for fragmented estates: Multi-vendor manufacturing environments are notoriously difficult to monitor holistically. Ora’s Network Management System provides unified observability across FortiGate firewalls, managed switches, wireless APs, WAN links, and SD-WAN overlays. LLDP/CDP topology discovery automatically maps the live network graph, and ML-based anomaly detection flags deviations from baseline traffic patterns — including the kind of slow reconnaissance traffic that precedes an OT intrusion.

Video surveillance (VMS) — physical and cyber under one view: For manufacturing, retail, and multi-site estates, physical security is part of the threat model. Ora’s video surveillance module manages ONVIF, Hikvision, and Dahua camera estates with built-in video analytics. The practical benefit for a NOC/SOC team is that a physical intrusion alert and a simultaneous network anomaly on the same site arrive in the same operational console — reducing response time and eliminating the blind spot between physical and cyber domains.

SOAR — making CERT-In’s 6-hour window achievable: CERT-In’s 2022 directive requires organisations to report cyber incidents within six hours of detection. In a manufacturing environment dealing with an active OT compromise, manually coordinating containment actions across FortiGate firewalls, endpoint agents, and OT monitoring tools while simultaneously drafting an incident report is close to impossible. Ora’s SOAR module automates this workflow: pre-built playbooks push blocklists to FortiGate, quarantine affected endpoints, and generate draft incident reports — so the analyst focuses on decisions, not on copy-pasting IP addresses between consoles.

If your organisation is navigating the shift from isolated OT monitoring to a converged IT/OT security operations model, we can walk you through how we have deployed Ora in similar environments.

CERT-In and DPDP Compliance Considerations for OT

India’s regulatory environment is evolving faster than most OT security programmes can track. A few points worth highlighting for manufacturers:

  • CERT-In 2022 Directions: The 6-hour incident reporting requirement applies to operators of critical infrastructure sectors, which includes power, telecom, and certain manufacturing verticals. The 180-day log retention direction requires that logs not be stored exclusively in foreign-jurisdiction cloud services — a point many organisations have addressed incompletely.
  • DPDP Act 2023: While primarily focused on personal data, manufacturing environments that collect worker biometric data, CCTV footage linked to individuals, or customer PII through connected products must implement appropriate technical safeguards. An OT breach that exposes this data carries both operational and regulatory consequences.
  • NCIIPC Guidelines: Organisations classified as critical information infrastructure operators have additional obligations. If your manufacturing facility falls under defence, energy, or strategic sectors, engage with NCIIPC’s sector-specific guidelines as a compliance baseline.

A note on compliance language: no security platform or service makes an organisation “DPDP compliant” — compliance is a business and governance outcome, not a product feature. What the right tools and processes do is support compliance and help you evidence your security posture to regulators and auditors.

A Checklist for IT Leaders Starting the OT Security Journey

If your organisation is at the beginning of the OT security journey, here is a pragmatic starting checklist:

  • ☐ Conduct a passive OT asset discovery exercise — you cannot protect what you cannot see
  • ☐ Map all IT/OT network connection points and document each data flow and its business justification
  • ☐ Audit all remote access paths to OT equipment, including vendor modems and cellular gateways
  • ☐ Enforce MFA on every remote access path to OT systems, without exception
  • ☐ Deploy a FortiGate NGFW at every IT/OT boundary with OT protocol inspection enabled
  • ☐ Establish air-gapped backups of all PLC configurations and HMI projects
  • ☐ Define an OT-specific incident response playbook with production-line recovery steps
  • ☐ Conduct a tabletop exercise simulating a ransomware pivot from IT to OT
  • ☐ Validate 180-day log retention with in-country storage for CERT-In compliance
  • ☐ Review NCIIPC guidelines if your facility operates in a designated critical sector

Where to Start: PJ Networks’ OT Security Assessment

PJ Networks’ 24/7 NOC/SOC team works with Indian manufacturers to build IT/OT security programmes that are proportionate to their risk profile and operational constraints. We start with a non-intrusive OT network assessment — passive monitoring only, no agent deployment on PLCs — that gives you a clear picture of your current exposure before you commit to a remediation roadmap.

Our engagements are structured around FortiGate-based network segmentation, ZTNA implementation for secure remote access, and the deployment of PrahiX Ora for unified IT/OT visibility and incident response. We understand both the technical constraints of legacy OT equipment and the business realities of manufacturing operations that cannot afford extended downtime.

If you are an IT leader or CISO in Indian manufacturing and you are navigating the shift from air-gapped OT to connected Industry 4.0 operations, we would welcome a conversation. The attack surface is growing; the window to build a defensible architecture before a significant incident occurs is narrowing.

PJ Networks provides managed security services — FortiGate/Fortinet deployment, 24/7 NOC/SOC operations, ZTNA, and MSSP services — to Indian enterprise clients. We deploy and operate the PrahiX Ora unified SecOps platform for clients requiring integrated SIEM, NMS, video surveillance, and SOAR capabilities. Contact us at pjnetworks.com to discuss your OT security requirements.

Leave a Reply

Your email address will not be published. Required fields are marked *