Securing the Industrial Edge: OT/IT Convergence and Cyber Threats Facing Indian Manufacturers

  • Home
  • Securing the Industrial Edge: OT/IT Convergence and Cyber Threats Facing Indian Manufacturers
Securing the Industrial Edge: OT/IT Convergence and Cyber Threats Facing Indian Manufacturers

India’s manufacturing sector is undergoing a seismic shift. The government’s Production Linked Incentive (PLI) scheme, “Make in India,” and the rapid adoption of Industry 4.0 technologies have pushed Indian factories onto smart, connected platforms. Sensors monitor assembly lines in real time. PLCs communicate via IP networks. ERP systems talk directly to SCADA. The benefits are significant — but so is the attack surface.

In 2024 and 2025, we saw a sharp rise in ransomware, espionage, and sabotage attacks targeting operational technology (OT) environments globally — and India has not been spared. For Indian CISOs and IT heads in manufacturing, automotive, pharmaceuticals, and energy, the convergence of OT and IT networks is now the single most critical cybersecurity challenge of the decade.

Why OT/IT Convergence Creates a Dangerous New Attack Surface

Operational technology — the systems that control physical processes — was traditionally “air-gapped.” Isolated from the corporate IT network, these environments ran proprietary protocols (Modbus, DNP3, Profibus) on hardware that was expected to operate for 15–25 years with minimal patching. Security through obscurity was the de facto strategy.

That model is obsolete. Today:

  • Manufacturing Execution Systems (MES) sync with ERP in real time
  • Remote access for vendor support is routine (and routinely exploited)
  • PLCs and HMIs ship with Ethernet interfaces and web dashboards
  • Wi-Fi covers shopfloors to avoid cable runs in dynamic production layouts
  • Cloud-based predictive maintenance aggregates telemetry from thousands of sensors

Each of these integrations creates a pathway from the corporate network — with its email-borne phishing, browser exploits, and SaaS vulnerabilities — into the OT environment where a compromised controller means a halted production line, or worse, a safety incident.

The Threat Landscape: What Indian Manufacturers Are Actually Facing

Ransomware Groups Targeting OT

Groups such as LockBit, Cl0p, and their successors have developed specific “OT-aware” capabilities. Rather than simply encrypting files on Windows servers, modern ransomware recognises industrial software processes (Siemens TIA Portal, Rockwell FactoryTalk, GE iFIX) and either halts them or corrupts their configuration databases. The business impact is not just data loss — it is production stoppage, which costs an order of magnitude more per hour than a typical IT ransomware event.

Indian automotive component manufacturers, textile mills, and pharmaceutical formulation plants have all reported incidents in 2024–25 where attackers moved laterally from a phished employee’s laptop into the factory’s historian server, and from there into process control segments.

Supply Chain and Third-Party Access

OEM engineers, system integrators, and remote monitoring vendors all require periodic access to OT networks. In many Indian factories, this is managed through shared VPN credentials, jump hosts with weak passwords, or — in the worst cases — directly exposed RDP on a SCADA machine. These unmanaged access paths are consistently among the top initial access vectors.

Legacy Unpatched Systems

The 15-year lifecycle of OT hardware means that much of India’s shopfloor infrastructure runs on Windows XP, Windows 7, or embedded Linux kernels from the mid-2010s. These systems cannot be patched without vendor certification, and even then, patching windows are rare. A single unpatched OT machine exposed to the corporate network is a persistent, high-value target.

Insider Threat and Disgruntled Workers

India’s manufacturing workforce has seen significant restructuring as automation replaces roles. Disgruntled employees — or former contractors who retain valid credentials — represent a non-trivial risk. The CERT-In advisory CA-2024-0039 specifically called out insider-enabled sabotage in the critical infrastructure sector.

Regulatory Context: DPDP Act, CERT-In Directions, and Sector Guidance

For Indian manufacturers, the regulatory environment is tightening:

  • CERT-In Directions (April 2022): Any reportable cyber incident must be notified to CERT-In within six hours of detection — including OT incidents involving supervisory control systems that affect production availability. Log retention for 180 days is mandatory.
  • DPDP Act 2023: If your OT environment processes any personal data (biometric access, employee time-and-attendance fed from shopfloor systems), the Digital Personal Data Protection Act obligations apply. A breach triggering production downtime that also exposes personal data invokes dual reporting — CERT-In (for the incident) and the Data Protection Board (for the personal data breach).
  • NCIIPC Sector Guidance: The National Critical Information Infrastructure Protection Centre has classified several manufacturing sub-sectors (defence, pharmaceuticals, energy equipment) as critical. Companies in these sectors face additional obligations around vulnerability disclosure and incident cooperation.

The six-hour CERT-In reporting window is particularly demanding for OT incidents because detection itself is harder — most factories lack the event correlation capability to distinguish a slow-burn intrusion from normal process variability until significant damage has already occurred.

What a Robust OT Security Programme Looks Like

1. Network Segmentation and the Purdue Model

The ISA/IEC 62443 standard and the Purdue Enterprise Reference Architecture remain the foundational framework. Level 0 (process), Level 1 (control), Level 2 (supervisory), Level 3 (operations) and Level 4 (enterprise IT) should each be separated by industrial firewalls or demilitarised zones (DMZ) with explicit permit-lists, not default-allow. In practice, many Indian manufacturers have collapsed these levels in the rush to connect MES to ERP — a configuration that requires immediate remediation.

FortiGate NGFWs deployed at the IT/OT boundary can inspect industrial protocols (Modbus, DNP3, OPC-UA) at Layer 7, apply geo-based policies to restrict lateral movement, and generate structured logs that feed into a SIEM for correlation. The FortiGate’s Industrial Security Service is purpose-built for exactly this boundary enforcement role.

2. Zero Trust Network Access for Vendor and Remote Connectivity

Replacing legacy VPN with ZTNA for third-party and remote access eliminates the “trusted insider” assumption that makes shared-credential VPN so dangerous. With ZTNA, every access request is authenticated, the connecting device’s posture is checked, and the session is limited to the specific resource being accessed — not the entire OT segment. This is the fastest, highest-ROI control an Indian manufacturer can deploy today to reduce third-party risk.

3. 24/7 OT-Aware Monitoring

Detecting OT-targeted attacks requires monitoring that understands industrial protocol anomalies — an unexpected Modbus write to a PLC register is not the same as an unexpected TCP connection. Without protocol-aware inspection and correlation, most OT incidents go undetected until the production impact is visible.

4. Incident Response Planning for OT

A standard IT incident response playbook is not sufficient for OT. Isolating an infected SCADA server may stop a ransomware spread — but it may also halt production. OT-specific playbooks must define pre-approved isolation procedures, manual fallback processes (can operators continue in manual mode?), vendor notification trees, and the specific point at which safety systems take precedence over confidentiality-driven isolation.

5. Vulnerability Management on a Realistic Patching Cycle

Given that OT systems cannot be patched on a standard 30-day cadence, vulnerability management for OT focuses on compensating controls: virtual patching at the network layer (using IPS signatures on the FortiGate), network micro-segmentation to isolate unpatched assets, and risk-ranked prioritisation so that CVEs with known OT exploits are addressed first.

PrahiX Ora: Unified SecOps for OT/IT Convergence Environments

Indian manufacturers deploying OT security controls face a practical problem: they end up with multiple siloed tools — a separate SIEM for IT logs, a different NMS for OT network visibility, a standalone video management system for physical security, and manual processes for incident response. This fragmentation slows detection and makes CERT-In’s six-hour reporting window almost impossible to meet reliably.

PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd, designed to bring IT security operations, network management, video surveillance, and response automation under a single operations view. PJ Networks is PrahiX Ora’s primary field deployment and operations partner — we deploy the platform for clients and run it as part of our 24/7 managed SOC/NOC service.

For OT/IT convergence environments specifically, PrahiX Ora’s four capabilities work as a system:

  • SIEM — Multi-source log ingestion aggregates events from FortiGate firewalls at the IT/OT boundary, from OT historians, from endpoint detection tools, and from cloud services into a single correlation engine. Detection rules mapped to the MITRE ATT&CK for ICS framework identify attack patterns specific to OT environments — including anomalous protocol commands and lateral movement between IT and OT segments. Graph-based attack storyline reconstruction shows analysts the full kill chain rather than a flood of individual alerts. Tiered hot/cold/archive retention supports CERT-In’s 180-day in-country log retention direction without unbounded storage costs.
  • NMS (Network Management System) — Unified observability across FortiGate firewalls, managed switches, access points, SD-WAN links, and OT network segments — including protocol-level visibility where industrial devices support SNMP or syslog. LLDP/CDP-based topology discovery automatically maps what’s connected to what, critical in multi-site manufacturing estates where network documentation is often out of date. ML-based anomaly detection flags deviations from established baselines — an OT asset suddenly communicating with an external IP is surfaced immediately, not buried in log noise. For NOC teams managing multi-vendor estates where visibility is fragmented across vendor-specific tools, the NMS layer is typically the highest-impact capability to deploy first.
  • Video Surveillance (VMS) — ONVIF-compatible camera management with support for Hikvision and Dahua hardware — the dominant brands in Indian industrial deployments. Video analytics capabilities (motion detection, zone intrusion, person detection) run at the edge. For manufacturing and multi-site retail, consolidating physical and network security under a single operations view means that a physical access event can be correlated with a concurrent network anomaly — a capability that standalone VMS and network SIEM tools cannot deliver separately.
  • SOAR (Security Orchestration, Automation and Response) — Pre-built playbook automation with connectors for FortiGate (pushing block policies), FortiMail (quarantine actions), and ticketing systems. When a threat is detected, the SOAR layer can automatically push an IP or domain blocklist to the FortiGate at the IT/OT boundary within seconds — not the hours it takes for a manual response process. For CERT-In’s six-hour incident reporting window, automated response and evidence aggregation are what make that timeline realistic at scale. Playbooks can also auto-generate the incident report structure required by CERT-In, pre-populated with timeline, affected assets, and initial indicators of compromise.

If your operations team is currently running separate tools with limited integration, ask us about a PrahiX Ora deployment assessment — we can map the platform’s capabilities to your specific OT/IT environment and existing tooling.

Where to Start: A Practical Roadmap for Indian Manufacturers

For an Indian manufacturer beginning an OT security programme, the following sequence is both practical and maximally risk-reducing:

  1. Asset discovery and network mapping — You cannot protect what you cannot see. Passive OT asset discovery (using network tap or span port, not active scanning that can crash legacy PLCs) should precede any other control.
  2. Segment first — If a true flat network exists between IT and OT, place a firewall at the boundary immediately, even if in monitor mode initially. The risk of an uncontrolled IT-to-OT lateral movement is too high to defer.
  3. Replace VPN with ZTNA for all third-party access — This is a directly measurable risk reduction with a well-understood deployment path.
  4. Deploy 24/7 OT-aware monitoring — Either build an internal OT-SOC capability (expensive and difficult to staff) or engage a managed SOC provider with OT experience.
  5. Develop and test OT-specific IR playbooks — Including manual fallback procedures and the dual-reporting flow for incidents that trigger both CERT-In and DPDP obligations.
  6. Conduct a tabletop exercise annually — Tested playbooks degrade if they’re never exercised. A tabletop that walks through a realistic ransomware-in-OT scenario surfaces gaps before a real incident does.

How PJ Networks Supports Indian Manufacturers

PJ Networks is a managed security services provider with deep Fortinet expertise and a 24/7 NOC/SOC operation. We help Indian manufacturers across automotive, pharmaceuticals, FMCG, and process industries with:

  • OT/IT boundary design and FortiGate deployment for industrial environments
  • ZTNA rollout for vendor and remote access to OT networks
  • 24/7 managed NOC/SOC with OT-aware monitoring through PrahiX Ora
  • CERT-In incident reporting support and DPDP compliance readiness assessment
  • Tabletop exercises and OT-specific incident response playbook development

If you are navigating OT/IT convergence security and want a practical conversation about where your programme stands, contact PJ Networks for an initial assessment.

Leave a Reply

Your email address will not be published. Required fields are marked *