



Operational Technology (OT) and Industrial Control Systems (ICS) now sit squarely in the crosshairs of nation-state actors and ransomware groups. For Indian manufacturers, pharmaceutical companies, and critical infrastructure operators, a single compromise in a SCADA controller or PLC can halt production lines, trigger safety incidents, and expose organisations to regulatory liability under CERT-In’s mandatory incident-reporting directive. Yet most enterprise security teams still treat OT networks as an afterthought—segregated by a legacy firewall, visited only when something breaks.
This guide walks Indian enterprise IT and OT security leaders through a structured approach to hardening industrial networks—without disrupting uptime or alienating the engineering teams who run them.
IT security teams operate in an environment designed for patching, rebooting, and rapid change. OT environments are the opposite: availability trumps confidentiality, devices run for 10–20 years without updates, and a five-minute maintenance window requires weeks of planning with plant managers. This fundamental tension creates gaps that attackers exploit relentlessly.
Several trends are accelerating the risk for Indian organisations specifically:
You cannot protect what you cannot see. Yet asset inventory in OT environments is notoriously incomplete. Start here:
The Purdue Model—Levels 0 through 5—remains the reference architecture for OT network segmentation, but most deployments treat it as aspirational rather than operational. Effective segmentation means:
OT networks are highly predictable: a PLC sends the same Modbus read every 500ms, always to the same historian, always with the same payload size. This predictability is your greatest detection advantage. Any deviation—new source IP, new protocol, unusual write command—is immediately suspicious.
Key monitoring principles for OT:
One of the most persistent problems in OT security is the gap between IT security operations (SIEM/SOC) and OT monitoring tools. Engineers use OT-specific platforms; security teams use enterprise SIEM. The result: the correlation that would catch an IT-to-OT lateral movement stays hidden because no single team sees both sides.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner—we deploy and operate the platform for clients across manufacturing, healthcare, and multi-site retail estates in India.
Ora addresses the IT/OT visibility problem through four integrated pillars:
SIEM with MITRE ATT&CK Mapping: Ora ingests logs from OT historians, IT firewalls, endpoint agents, and cloud services into a single correlation engine. Rules are mapped to the MITRE ATT&CK for ICS framework—so an alert isn’t just “anomaly detected” but “Stage: Lateral Movement / Technique: Default Credentials.” Graph-based attack storyline reconstruction stitches individual events into a narrative, dramatically reducing analyst fatigue. Tiered retention (hot/cold/archive) supports CERT-In’s 180-day in-country log retention direction without blowing the storage budget on expensive hot storage for all logs.
Network Management System (NMS): Unified observability across FortiGate firewalls, managed switches, wireless APs, WAN links, and SD-WAN overlays—all in one view. LLDP/CDP topology discovery automatically builds a live network map; when a device drops or a link degrades, the NOC sees it in context, not as an isolated alert. ML-based anomaly detection flags baseline deviations and, for pre-authorised scenarios, auto-healing policies can push a configuration remediation automatically. For Indian manufacturers running multi-vendor estates where NOC visibility is fragmented across five different vendor portals, this single-pane-of-glass approach cuts mean-time-to-diagnose significantly.
Video Surveillance (VMS): Ora’s video surveillance (VMS) module integrates ONVIF-compliant cameras alongside Hikvision and Dahua deployments—common in Indian manufacturing and retail—and adds video analytics (motion zones, loitering detection, perimeter breach). The key differentiator for security operations is convergence: a physical perimeter breach alert and the network anomaly detected on the same subnet at the same time are correlated in the same platform. For multi-site manufacturing or retail estates, operating physical security and network security from one operations view reduces the coordination overhead between security guards, facility managers, and the SOC.
SOAR and Playbook Automation: CERT-In’s 6-hour incident reporting window is not achievable through manual processes when an incident strikes at 2 AM. Ora’s SOAR module provides pre-built playbooks with connectors to FortiGate (automatic blocklist push), endpoint agents, and ticketing systems. When the SIEM fires a confirmed ransomware lateral movement alert, the playbook can isolate the affected segment, push updated blocklists to FortiGate, open a ticket, and draft the CERT-In notification—all within minutes, not hours. Automation is what makes the 6-hour window realistic.
If your organisation is evaluating unified SecOps or struggling with IT/OT correlation visibility, we’re happy to walk you through how we deploy Ora for clients similar to yours. Speak to a PJ Networks specialist.
Patch management in OT is not like IT patch management. You cannot push a firmware update to a running PLC without a maintenance window, vendor validation, and often a full regression test of the control logic. Accept this constraint and build a compensating-controls strategy:
OT incident response is meaningfully different from IT IR. Isolating a compromised IT server takes seconds; isolating a compromised PLC segment may require stopping a production line and notifying safety engineers before any action is taken.
Build an OT IR playbook that explicitly addresses:
The following actions help evidence compliance with CERT-In’s directions for organisations operating critical information infrastructure:
It is important to note that no single product or platform makes an organisation “CERT-In compliant.” Compliance requires documented processes, trained staff, and evidenced controls—technology supports that evidence but does not substitute for it.
Days 1–30 (Visibility): Deploy passive network taps and a protocol-aware discovery tool on your highest-risk OT segments. Complete a physical asset walkthrough. Establish the asset inventory baseline.
Days 31–60 (Segmentation and Remote Access): Audit all remote access paths into the OT network; decommission unused VPN accounts. Deploy or harden the IT/OT boundary firewall policy. Implement ZTNA for OEM vendor access.
Days 61–90 (Detection and Response): Deploy continuous monitoring on OT segments. Integrate OT alerts into the SOC workflow. Run a tabletop exercise against an IT-to-OT lateral movement scenario. Validate the CERT-In 6-hour reporting chain end-to-end.
PJ Networks provides managed security services to Indian enterprises across manufacturing, pharmaceuticals, BFSI, and critical infrastructure. Our OT security practice combines FortiGate NGFW deployment at IT/OT boundaries, ZTNA implementation for vendor remote access, and 24/7 NOC/SOC monitoring with OT-aware detection rules.
For organisations that need unified visibility across IT, OT, and physical security, we deploy and operate the PrahiX Ora platform, providing a single operational view from the SIEM through to FortiGate response automation.
If your organisation is beginning an OT security programme, or has an existing programme that needs a maturity assessment, contact PJ Networks for a structured evaluation of your current posture and a prioritised remediation roadmap.