OT/ICS Cybersecurity for Indian Manufacturing: Closing the Air-Gap Illusion

  • Home
  • OT/ICS Cybersecurity for Indian Manufacturing: Closing the Air-Gap Illusion
OT/ICS Cybersecurity for Indian Manufacturing: Closing the Air-Gap Illusion

India’s manufacturing sector is undergoing a rapid digital transformation — smart factories, Industry 4.0 deployments, IoT-connected assembly lines, and cloud-linked SCADA systems are becoming the norm from Pune auto-component plants to Chennai petrochemical facilities. But this convergence of Operational Technology (OT) and Information Technology (IT) networks has quietly dismantled the most trusted security assumption in industrial computing: the air gap.

For decades, the mantra in industrial security was simple — “keep it disconnected.” Physical isolation between the plant floor and the corporate network was supposed to guarantee that a ransomware infection in Finance would never reach a PLC managing a blast furnace. That era is over. And for Indian enterprises still operating on this assumption, the risk is not theoretical — it is imminent.

The Convergence Reality: Why the Air Gap Is Gone

The drivers of OT/IT convergence in India mirror global trends but with local intensity:

  • Remote monitoring mandates: Post-pandemic, plant managers and OEM vendors now routinely demand VPN access or cloud dashboards to monitor equipment health, reducing planned downtime. Every remote access point is a potential intrusion vector.
  • ERP-to-SCADA integration: SAP and Oracle ERP systems connected directly to MES and SCADA layers for real-time production data create bidirectional data flows that legacy OT architectures never anticipated.
  • USB and supply-chain exposure: Contractor laptops used for PLC firmware updates, maintenance thumb drives, and vendor-supplied engineering workstations routinely bypass network-level controls entirely.
  • Legacy protocols on modern infrastructure: Modbus, DNP3, and PROFIBUS devices — designed with zero authentication — are increasingly reachable via IP-connected gateways, exposing them to threats they were never designed to resist.

The result: what was once a flat, isolated OT network is now a porous, partially-connected environment — with the detection and response capabilities of neither a modern IT network nor the physical redundancy of a truly air-gapped one.

The Threat Landscape Targeting Indian Industrial Networks

Threat actors — ranging from financially motivated ransomware groups to nation-state APTs — have recognised this window of vulnerability. Several patterns are particularly relevant for Indian enterprises:

Ransomware with OT Awareness

Modern ransomware families no longer stop at encrypting Windows endpoints. Variants actively probe for industrial protocols, disable OT backup systems, and target historian servers holding months of production data. When a manufacturing plant’s historian goes dark, the business impact extends far beyond IT recovery time — it disrupts quality records, compliance audits, and customer SLAs simultaneously.

Living-off-the-Land in OT Environments

Sophisticated attackers increasingly use legitimate tools already present in OT environments — remote desktop utilities, default vendor credentials, and engineering software — to move laterally without triggering signature-based detections. In environments where baseline OT traffic has never been profiled, such activity is virtually invisible.

Supply-Chain Firmware Attacks

Compromised firmware updates delivered through legitimate vendor channels have emerged as a high-impact attack vector. An industrial device accepting an unsigned firmware image from a trusted IP address has no mechanism to detect tampering — and the consequences can include persistent backdoors that survive factory resets.

Physical + Cyber Convergence Incidents

CERT-In advisories have flagged incidents where network intrusions were used to manipulate physical processes — from water treatment chemical dosing to energy substation switching. The physical consequences of cyber incidents in OT environments are categorically different from data breaches, and the incident response playbook must reflect that difference.

The CERT-In Compliance Dimension for Industrial Incidents

CERT-In’s April 2022 direction — mandating that organisations report cybersecurity incidents within six hours of detection — applies with full force to industrial operators. Yet OT environments present a compliance challenge that purely IT-focused organisations don’t face:

  • OT networks often lack centralised log aggregation, making detection timestamps difficult to establish with precision.
  • Industrial incidents may manifest first as process anomalies (unexpected valve positions, sensor drift) rather than classic IT alerts, delaying formal classification as a “cybersecurity incident.”
  • The six-hour window assumes detection capabilities that many plant security teams simply do not have in their OT environment.

Meeting the CERT-In timeline for OT incidents requires investing in detection — not just incident response — before an event occurs. Organisations that discover an OT intrusion after days of lateral movement have already missed the compliance window before the formal incident response even begins.

Architectural Foundations: Securing the Converged OT/IT Network

Closing the air-gap illusion does not mean accepting permanent exposure. It means engineering security controls that acknowledge the reality of connectivity while maintaining strict boundaries between zones.

Network Segmentation with the Purdue Model

The ISA/IEC 62443 standards and the NIST Cybersecurity Framework for Industrial Control Systems both build on Purdue Model zone architecture: separating enterprise IT (Levels 4–5) from manufacturing operations (Levels 0–3) via a demilitarised zone (DMZ). FortiGate Next-Generation Firewalls are a natural fit for enforcing these boundaries — their deep packet inspection capabilities extend to industrial protocols including Modbus TCP, DNP3, and IEC 60870-5-104, enabling policy-based control at the application layer of OT traffic.

Zero Trust Network Access for Vendor and Remote Sessions

Every contractor, OEM vendor, and remote engineer accessing OT systems should authenticate through a ZTNA framework rather than a conventional VPN. ZTNA enforces least-privilege access — a drive-train OEM vendor gets access only to the specific PLC segment relevant to their equipment, with session recording and time-bounded credentials. This eliminates the “trusted insider with broad access” problem that makes lateral movement so damaging in OT environments.

OT Asset Visibility and Passive Monitoring

You cannot protect what you cannot see. OT asset inventories are notoriously incomplete — many organisations discover unmanaged PLCs, legacy HMIs, and undocumented remote access tools only after an incident. Passive network traffic analysis, which does not require agents on fragile industrial endpoints, is the preferred approach: it maps devices, firmware versions, and communication patterns without any risk of disrupting production.

Anomaly Detection Tuned to Industrial Baselines

OT traffic is highly deterministic — a Modbus master polls its slaves on a precise schedule, a historian server writes data at predictable intervals. This predictability makes anomaly detection far more effective in OT environments than in general enterprise networks. Deviations from baseline — unexpected commands to a PLC, new devices appearing on a segment, unusual timing patterns — are high-confidence indicators of malicious activity that warrant immediate investigation.

PrahiX ORA: Unified SecOps Visibility Across IT and OT

One of the most persistent challenges in converged OT/IT environments is the operational gap between IT security teams (who own the SOC and SIEM) and OT/engineering teams (who own the plant floor). Each team has its own tooling, its own visibility, and — critically — its own blind spots. Security incidents that cross the IT/OT boundary often fall through that gap precisely because neither team has full visibility into the other’s domain.

The platform we deploy and operate for clients — PrahiX ORA, built by PrahiX Tech Pvt Ltd — addresses this through a unified SecOps architecture with four integrated pillars particularly relevant to manufacturing and multi-site industrial estates:

SIEM with MITRE ATT&CK Mapping: ORA’s SIEM ingests log and event data from both IT systems (firewalls, endpoints, cloud) and OT sources (historian logs, industrial protocol event streams, SCADA audit trails), applying correlation rules mapped to the MITRE ATT&CK for ICS framework. The graph-based attack storyline reconstruction connects events across IT and OT tiers — so a suspicious VPN login, a lateral movement event in the DMZ, and an anomalous PLC command are correlated into a single attack narrative rather than three unrelated alerts. For CERT-In compliance, the platform’s tiered retention architecture (hot/cold/archive) supports the 180-day in-country log retention direction — ensuring logs are available when investigators need them.

NMS for Converged Network Observability: In multi-vendor OT estates — where FortiGate firewalls coexist with Cisco switches, Hirschmann OT switches, and third-party WAN appliances — NOC visibility is typically fragmented across multiple management consoles. ORA’s NMS provides unified topology discovery (via LLDP/CDP), network path tracing, and ML-based anomaly detection across all layers. Auto-healing policies can respond to detected anomalies — isolating a switch port or rerouting traffic — without requiring manual intervention at 2 AM during the night shift.

Video Surveillance (VMS) Under One Operations View: Physical security and network security have traditionally been managed by separate teams with no shared data. ORA’s video surveillance (VMS) module brings ONVIF-compatible cameras — including Hikvision and Dahua devices common in Indian industrial facilities — under the same operational view as the network and security data. For manufacturing plants, retail chains, and multi-site logistics operators, this means a physical perimeter breach and a concurrent network anomaly can be correlated in a single dashboard rather than discovered independently hours apart.

SOAR Automation for the Six-Hour Window: Playbook automation is what makes CERT-In’s 6-hour incident reporting window achievable in practice. ORA’s SOAR module includes pre-built connectors and automated response actions — including pushing blocklists directly to FortiGate — so that containment begins within minutes of detection, not after a chain of manual approvals. For an OT incident where the window between initial intrusion and process disruption may be measured in minutes, automation is not a convenience: it is an operational requirement. Incident reports can be pre-populated from playbook execution logs, turning a compliance deadline into a manageable process.

If your OT visibility is fragmented — or if your IT SOC and plant operations teams are working from separate toolsets — contact PJ Networks to discuss how PrahiX ORA can be deployed and operated as a unified SecOps layer for your environment.

A Practical OT Security Checklist for Indian CISOs

For IT leaders undertaking or planning an OT security review, the following checklist provides a structured starting point:

  • Asset inventory: Do you have a complete, current inventory of all OT devices, firmware versions, and network connections — including devices managed by third-party contractors?
  • Network segmentation: Are OT networks segmented from corporate IT networks with an enforced DMZ? Are industrial protocols blocked from traversing the DMZ without explicit policy?
  • Remote access controls: Is all remote access to OT systems authenticated through ZTNA or equivalent least-privilege mechanisms? Are generic or shared vendor credentials in use anywhere?
  • Visibility and detection: Is OT network traffic being passively monitored for anomalies? Are IT and OT security alerts being correlated in a unified platform?
  • Incident response for OT: Does your incident response plan cover OT-specific scenarios — process safety assessment, OEM notification, production continuity during containment?
  • CERT-In readiness: Are log retention mechanisms in place for a minimum 180 days in-country? Does your SOC have a playbook for the 6-hour reporting timeline covering OT incidents?
  • Firmware and patch management: Is there a process for validating firmware update integrity before applying to industrial devices? Are vendor-supplied update packages verified?
  • Supply-chain access controls: Are contractor and vendor access sessions time-bounded, recorded, and reviewed? Is privileged access management enforced for all OT administrative access?

How PJ Networks Can Help

PJ Networks brings together the FortiGate NGFW ecosystem, 24/7 NOC/SOC operations, ZTNA deployment expertise, and the PrahiX ORA unified SecOps platform to address the specific challenges of converged OT/IT environments in Indian enterprises. Our approach starts with an OT network assessment — passive discovery, segmentation gap analysis, and detection capability review — and builds toward a continuously monitored, CERT-In-aligned security posture.

Whether you are a manufacturing CISO looking to establish baseline OT visibility, a corporate IT head tasked with integrating plant networks into enterprise security monitoring, or an operations director concerned about production continuity during a cyber incident — we can help you move from the air-gap illusion to a real, defensible security architecture.

To schedule an OT Security Assessment or discuss managed OT/IT security for your organisation, contact PJ Networks through pjnetworks.com/contact.

Leave a Reply

Your email address will not be published. Required fields are marked *