OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025

  • Home
  • OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025
OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025
OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025
OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025
OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025
OT/ICS Security for Indian Manufacturing Enterprises: Protecting Industrial Networks in 2025

India’s manufacturing sector is booming. The Make in India initiative, PLI schemes, and a surge in factory automation have pushed Indian manufacturers to connect their shop floors to corporate IT networks — and increasingly, to the cloud. But this digital transformation carries a hidden cost: the operational technology (OT) and industrial control systems (ICS) that keep production lines running were never designed to be networked, let alone exposed to modern cyber threats.

The consequences of an OT/ICS breach are not limited to data loss. A ransomware infection that shuts down a pharmaceutical filling line, a logic-bomb that sabotages a steel plant’s furnace controls, or a supply-chain compromise that plants malicious firmware in SCADA controllers can cost crores in downtime, trigger regulatory investigations under India’s CERT-In rules, and — in critical infrastructure sectors — endanger lives.

This guide is written for Indian enterprise IT and OT security teams who need a practical, FortiGate-anchored framework for securing industrial environments without stopping production.

Why Indian OT/ICS Environments Are Uniquely at Risk

Indian manufacturers face a threat landscape shaped by three converging factors:

1. Legacy Equipment Running Modern Networks

Many Indian factories run PLCs, DCS controllers, and SCADA historians that are ten to twenty years old — running Windows XP, Windows Server 2003, or proprietary real-time operating systems that haven’t received security patches since the Obama administration. These systems were installed when air-gapping was the security model. Today, pressure to integrate MES, ERP, and cloud analytics has punched holes in those air gaps, often without compensating controls.

2. IT-OT Convergence Without Security Design

When IT teams roll out SD-WAN to connect factories to HQ, they typically manage routing, VLANs, and firewalls. OT teams manage PLCs, historians, and HMIs. Neither team fully owns the boundary between them — and that boundary is exactly where attackers pivot. The 2021 Oldsmar water treatment attack in Florida demonstrated how a poorly secured IT-OT junction can give an attacker direct access to physical process controls.

3. India as a Targeted Manufacturing Hub

India’s growing role in semiconductor, defence, pharmaceutical, and electronics manufacturing makes Indian factories strategically interesting targets for state-sponsored actors and ransomware groups alike. Targeted attacks on Indian critical infrastructure have increased significantly since 2022, with energy, manufacturing, and logistics sectors among the hardest hit.

The OT/ICS Attack Kill Chain: What Adversaries Actually Do

Understanding the attack sequence helps defenders prioritise controls. A typical OT intrusion follows this pattern:

  1. Initial Access via IT network: Spear-phishing, VPN vulnerabilities, or supply-chain compromise gives the attacker a foothold on the corporate IT network.
  2. Lateral movement to the OT DMZ: Attackers pivot through engineering workstations, jump servers, or historian databases that sit between IT and OT zones.
  3. OT reconnaissance: Tools like Nmap, Shodan-like internal scanners, and protocol-aware tools (Modbus, DNP3, EtherNet/IP scanners) map the control network.
  4. Payload delivery: Malicious ladder logic, modified SCADA project files, or ransomware targeting both IT and OT systems are deployed simultaneously to maximise disruption.
  5. Impact: Production halt, physical damage (in sophisticated attacks), or data exfiltration of process IP (formulas, production data, quality parameters).

Key insight: In most Indian OT incidents we respond to, the dwell time between initial IT compromise and OT impact exceeds 30 days. The window for detection and containment is long — if you are monitoring. The problem is that most Indian factories are not monitoring their OT networks at all.

The Five-Zone Security Architecture for Indian Factories

The Purdue Model (ISA-99 / IEC 62443) remains the foundational framework for OT network segmentation. Adapted for Indian manufacturing realities — mixed IT and OT budgets, legacy PLCs, and lean OT teams — here is a practical five-zone model:

Zone 0: Field Level (Sensors, Actuators, PLCs)

Physical security controls, no inbound IP connectivity, strict allowlisting of engineering workstation access. Patch only during scheduled maintenance windows.

Zone 1: Control Level (DCS, SCADA, HMI)

Unidirectional data diodes or strictly controlled firewalls with application-aware rules (only allow required industrial protocols — Modbus TCP, OPC-UA, EtherNet/IP — with explicit deny-all default). FortiGate ICS-aware IPS signatures should be active here.

Zone 2: Supervisory Level (Historians, MES, Engineering Workstations)

This is the OT DMZ. All traffic between Zone 1 and Zone 3 must pass through a FortiGate NGFW. Application-layer inspection of OPC-UA, Modbus, and DNP3 traffic. Strict user authentication with MFA for engineering access. Regular integrity checks on HMI and SCADA project files.

Zone 3: Enterprise IT DMZ

ERP interfaces, remote access jump servers, data historians that feed BI tools. This zone must be isolated from general IT traffic by another firewall layer. Remote access should use ZTNA (Zero Trust Network Access) rather than VPN, enforcing device health checks before allowing OT-adjacent access.

Zone 4: Corporate IT and Cloud

Standard enterprise security controls apply. The critical point is that Zone 4 must never have direct layer-3 routed access to Zone 1 or Zone 2. Every cross-zone communication must pass through a firewall with explicit rules, logging, and IPS.

FortiGate NGFW Controls Specific to OT/ICS

FortiGate firewalls, deployed and managed by PJ Networks across Indian manufacturing clients, include a set of capabilities purpose-built for OT environments:

  • Industrial Protocol Deep Packet Inspection: FortiGate can inspect and enforce policies on Modbus, DNP3, EtherNet/IP, IEC 60870-5-104, and OPC-UA at the application layer — not just port-based rules.
  • FortiGuard ICS/SCADA Threat Signatures: Continuously updated signatures for known OT malware families (Triton/TRISIS, Industroyer, EKANS, Pipedream) and protocol anomalies.
  • SD-WAN with OT Traffic QoS: Real-time process data and historian replication can be traffic-shaped to ensure control-critical traffic always gets priority over IT traffic on shared WAN links.
  • Micro-segmentation via Security Fabric: FortiGate integrates with FortiSwitch and FortiAP to enforce dynamic VLAN policies, isolating compromised endpoints without manual intervention.

PrahiX Ora: Unified SecOps Visibility Across IT and OT

One of the persistent gaps in Indian OT security is the absence of unified visibility. IT teams use SIEMs that don’t understand Modbus or OPC-UA. OT teams use historian tools that don’t generate security alerts. The result is that attackers can move between zones with no detection.

The platform we deploy and operate for clients — PrahiX Ora, built by PrahiX Tech Pvt Ltd — addresses this gap by bringing IT and OT telemetry under a single SecOps view:

SIEM with CERT-In Compliance Posture: PrahiX Ora’s SIEM ingests logs from FortiGate firewalls, Windows engineering workstations, SCADA historians, Active Directory, and network taps on industrial protocols. Correlation rules mapped to the MITRE ATT&CK for ICS framework surface attack storylines across IT and OT zones together — not in silos. For Indian manufacturers, CERT-In’s direction on 180-day in-country log retention is supported through tiered hot/cold/archive storage, helping evidence compliance without the cost of retaining everything on expensive fast storage.

NMS for Multi-Vendor OT Estates: Most Indian factories have a patchwork of OT vendors — Rockwell PLCs, Siemens SCADA, legacy Wonderware historians, and modern Ignition servers all coexisting. Ora’s Network Management System provides unified observability across firewalls, switches, APs, and WAN/SD-WAN links through LLDP/CDP topology discovery and network path tracing. ML-based anomaly detection flags unusual polling behaviour, unexpected new devices on the OT network, and bandwidth anomalies that can indicate data exfiltration — all critical for fragmented multi-vendor NOC environments.

Video Surveillance (VMS) Integration: Physical and cyber security converge in manufacturing. PrahiX Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras with video analytics — unusual movement in restricted plant areas, after-hours access to engineering workstations — giving operations and security teams a single pane of glass for both physical intrusion and network threats. For multi-site manufacturing and retail estates, this eliminates the need for separate physical security monitoring infrastructure.

SOAR for CERT-In’s 6-Hour Reporting Window: When a security incident is detected in an OT environment, the pressure to respond quickly is compounded by CERT-In’s mandatory 6-hour reporting requirement for critical infrastructure operators. Ora’s SOAR module provides pre-built playbooks with automated response actions — including pushing updated blocklists directly to FortiGate to isolate compromised OT DMZ segments — making the CERT-In timeline realistic rather than aspirational. Without automation, manual containment and evidence packaging within 6 hours is practically impossible for lean security teams.

For Indian manufacturers exploring unified IT/OT SecOps, ora.prahix.com has platform capability details. PJ Networks can scope a deployment aligned to your factory’s zone architecture and compliance requirements.

Practical OT Security Checklist for Indian Manufacturers

If your organisation is starting its OT security journey, use this checklist to prioritise the highest-impact actions:

Immediate (0-30 Days)

  • Inventory all OT assets: PLCs, HMIs, SCADA servers, historians, engineering workstations. Know what you have before you can protect it.
  • Identify all network paths between IT and OT zones. Any flat network with no firewall between corporate IT and the factory floor is a critical gap to close immediately.
  • Disable remote desktop (RDP) direct access to OT zone systems. Replace with ZTNA-based remote access with MFA.
  • Change all default vendor passwords on PLCs, SCADA servers, and network switches in OT zones.

Short-Term (30-90 Days)

  • Deploy a FortiGate NGFW at the IT-OT boundary with ICS-aware IPS enabled and industrial protocol DPI rules active.
  • Implement network monitoring on OT VLANs — even basic NetFlow analysis will surface anomalies that are currently invisible.
  • Establish a patch management process for OT systems: identify patching windows during scheduled maintenance, prioritise critical vulnerabilities on internet-facing or IT-adjacent OT systems.
  • Run a tabletop exercise simulating an OT ransomware incident. Identify gaps in your response plan before a real incident forces you to discover them.

Medium-Term (90-180 Days)

  • Implement full Purdue Model zone segmentation with firewalls at each zone boundary.
  • Integrate OT log sources into your SIEM for cross-domain correlation and CERT-In retention compliance.
  • Deploy an OT-aware intrusion detection system on industrial network taps.
  • Establish a formal OT incident response plan and register with CERT-In as a critical infrastructure operator if applicable to your sector.

CERT-In and DPDP Compliance Considerations for OT Environments

Indian OT operators need to be aware of two overlapping regulatory frameworks:

CERT-In 6-Hour Reporting: The 2022 CERT-In directions require organisations in critical sectors — including power, manufacturing, and transportation — to report cyber incidents within 6 hours of detection. OT incidents (ransomware, unauthorised access to control systems, data exfiltration from process historians) fall squarely within scope. Organisations need both the detection capability (SIEM/NDR) and the response playbooks (SOAR) to meet this timeline.

DPDP Act 2023: Manufacturing operations increasingly capture personal data — employee biometrics for shop floor access, CCTV footage, visitor management systems. The Digital Personal Data Protection Act applies to this data. OT security breaches that expose employee personal data also trigger DPDP notification obligations. A unified security architecture that spans IT and OT helps evidence compliance with both frameworks from a single operations centre rather than managing separate compliance programmes.

Getting Started: PJ Networks OT Security Assessment

Securing OT environments is not a one-time project — it is an ongoing operational discipline. PJ Networks offers a structured OT Security Assessment that covers asset discovery, zone segmentation review, FortiGate policy audit, OT monitoring gap analysis, and CERT-In readiness evaluation. For Indian manufacturers at any stage of their OT security maturity — from starting from scratch to hardening an existing programme — our 24/7 NOC/SOC team provides continuous monitoring with OT-aware threat detection.

Connect with us at pjnetworks.com to discuss your factory’s security architecture. Industrial security is not optional in 2025 — it is the difference between production continuity and a costly, reputation-damaging incident.

Leave a Reply

Your email address will not be published. Required fields are marked *