OT/IT Convergence Security: Protecting India’s Manufacturing and Critical Infrastructure

  • Home
  • OT/IT Convergence Security: Protecting India’s Manufacturing and Critical Infrastructure
OT/IT Convergence Security: Protecting India’s Manufacturing and Critical Infrastructure

India’s manufacturing sector is in the middle of a profound transformation. Industry 4.0 adoption — smart factories, connected production lines, predictive maintenance systems — is reshaping how Indian enterprises operate. But this convergence of Operational Technology (OT) with corporate IT networks is creating a security exposure that many CISO offices have not yet fully addressed.

OT environments were traditionally air-gapped: isolated, purpose-built systems running legacy SCADA, PLCs, and DCS that ran independently of enterprise networks. Today, that isolation is dissolving. Business pressure to connect factory floors to ERP systems, remote monitoring requirements post-COVID, and the push for cloud-based analytics have quietly bridged what was once a hard boundary. And threat actors have noticed.

Why OT/IT Convergence Is a Top-Tier Risk for Indian Enterprises

The global picture is stark. Attacks on industrial infrastructure — energy grids, water utilities, manufacturing plants — have escalated sharply since 2021. India has not been immune. The 2020 Mumbai power grid disruption, widely attributed to a threat actor probing OT systems, was a wake-up call. Since then, CERT-In has issued multiple advisories on ICS/SCADA vulnerabilities affecting sectors ranging from oil-and-gas to pharmaceuticals.

The structural risk factors for Indian OT environments are well-understood:

  • Legacy systems with no patch cadence. PLCs and SCADA platforms designed in the 1990s were never built for internet connectivity and cannot run modern endpoint agents.
  • Flat OT networks. Many factory floors have little or no segmentation between the process control network and the corporate LAN.
  • Vendor remote access. OEM engineers frequently access OT systems via VPN tunnels or direct RDP — often with shared credentials and no MFA.
  • Visibility gaps. IT security teams can see corporate endpoints and cloud workloads. The PLC driving the assembly line? Often invisible to the SOC entirely.
  • IT-security tooling that simply doesn’t work on OT. You cannot install an EDR agent on a Siemens S7 PLC or a Rockwell ControlLogix. Passive monitoring is the only viable option.

What Attackers Are Actually Doing

Understanding the threat model is critical before designing a defence. In OT/IT convergence attacks, the typical kill chain looks like this:

  1. IT-side initial access — phishing, exposed RDP, compromised VPN credentials, or a vulnerable perimeter appliance. The attacker lands in the corporate network.
  2. Lateral movement to the OT network — through jump servers, historian nodes, or engineering workstations that straddle both zones. These pivot points are gold for an adversary.
  3. OT reconnaissance — passive enumeration of industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET) to map the environment before taking any disruptive action.
  4. Impact — ranging from ransomware deployed on the historian server that halts production reporting, to more sophisticated interference with process control logic.

MITRE ATT&CK for ICS (the ICS-specific extension of the MITRE framework) documents over 80 techniques specific to industrial environments. Most Indian OT environments have no visibility into whether any of these techniques are being used against them right now.

The Compliance Dimension: CERT-In and Critical Information Infrastructure

Regulatory pressure is tightening. The Indian Computer Emergency Response Team (CERT-In) has designated several industrial sectors as Critical Information Infrastructure (CII). CII operators have heightened obligations under the Information Technology Act, including the mandatory 6-hour incident reporting requirement introduced in CERT-In’s April 2022 directions.

For OT environments, this creates a practical problem: how do you report an incident within six hours when your visibility into OT systems is near-zero? Traditional IT security tools don’t instrument PLCs or SCADA historian nodes. Without structured telemetry from the OT layer, even detecting a breach — let alone reporting it — within the regulatory window is extremely difficult.

The 6-hour CERT-In reporting window assumes you know an incident has occurred. In OT environments with poor visibility, the first sign of compromise is often a production halt — long after the attacker has already accomplished their objective.

A Practical Security Architecture for OT/IT Convergence

The good news is that a structured approach can substantially reduce exposure without requiring a wholesale rip-and-replace of legacy OT infrastructure. Here is the framework PJ Networks recommends and deploys for manufacturing, pharma, and multi-site industrial clients across India.

1. Zone and Conduit Architecture (Purdue Model or ISA-62443)

The foundation is segmentation. OT networks should be divided into clearly defined zones — process control networks, supervision networks, and the DMZ that bridges to IT — with conduits (firewall-enforced paths) controlling all inter-zone traffic. A FortiGate NGFW positioned at the IT/OT boundary can enforce industrial protocol inspection, block unauthorised Modbus or DNP3 traffic, and provide granular visibility into east-west flows between zones.

2. Passive OT Asset Discovery and Protocol Monitoring

You cannot protect what you cannot see. Passive network taps (SPAN ports or network TAPs) at key OT switching points allow a monitoring platform to enumerate assets — PLCs, HMIs, engineering workstations, historian servers — by reading OT protocol traffic without sending a single packet to industrial devices. This is safe even for the most fragile legacy equipment.

3. Privileged Access Management for Vendor Remote Access

OEM vendor access should never be a persistent VPN tunnel with shared credentials. The right model is a PAM-controlled jump host with session recording, time-limited access grants, and MFA enforcement. Every vendor session should be logged and reviewable.

4. OT-Aware Threat Detection and MITRE ICS Mapping

Detection logic for OT environments needs to understand industrial protocols and the specific attack patterns documented in MITRE ATT&CK for ICS. This requires correlation rules purpose-built for Modbus function code abuse, unauthorised engineering commands, and HMI credential attacks — not just generic IT security rules.

5. Incident Response Planning with OT Playbooks

IR plans built exclusively for IT environments will fail in an OT incident. OT IR requires coordination between the CISO office, plant operations, OEM vendors, and (for CII operators) CERT-In notification — all under time pressure. Pre-built playbooks with OT-specific decision trees are essential, not optional.

PrahiX Ora: Unified SecOps Visibility Across IT and OT

One of the persistent challenges in OT/IT convergence security is tool fragmentation. The IT security team runs a SIEM and a SOAR platform. The plant operations team uses a network management system for OT device monitoring. Physical security runs video analytics for the factory floor. These three views rarely talk to each other — and threat actors exploit the gaps between them.

The platform we deploy and operate for clients, PrahiX Ora (built by PrahiX Tech Pvt Ltd), addresses this by bringing four capabilities into a single unified SecOps console.

SIEM with MITRE ATT&CK and ICS correlation: PrahiX Ora ingests logs and events from both IT and OT sources — FortiGate firewall logs, Windows Event Logs from engineering workstations, syslog from SCADA historian servers, and OT protocol telemetry from passive taps — and correlates them using rules mapped to MITRE ATT&CK for Enterprise and MITRE ATT&CK for ICS. The graph-based attack storyline reconstruction is particularly valuable in OT incidents: it reconstructs the lateral movement from an IT-side initial access event to the OT-network pivot, giving analysts a complete picture rather than disconnected log entries. Tiered log retention (hot, cold, archive) supports CERT-In’s direction on 180-day in-country log retention for CII operators — a requirement that many organisations are still struggling to meet.

NMS for unified OT/IT observability: The network management module provides unified observability across FortiGate firewalls, managed switches, wireless APs, and WAN/SD-WAN links — but extends this to OT network devices via LLDP/CDP topology discovery and network path tracing. For manufacturing clients with multi-vendor OT estates where NOC visibility has historically been fragmented across multiple single-point tools, this creates a single operational view. ML-based anomaly detection flags deviations from learned OT traffic baselines — useful for identifying reconnaissance activity against industrial protocols before it escalates.

Video surveillance (VMS) integration: PrahiX Ora includes ONVIF-compatible video surveillance management with support for Hikvision and Dahua camera ecosystems, plus video analytics capabilities. For manufacturing and multi-site retail clients, integrating physical security into the same SecOps console as network and log monitoring creates a genuinely unified operations view. A badge access anomaly correlated with a simultaneous network login from an unusual workstation becomes visible as a single connected event, not two separate alerts in two different dashboards.

SOAR with FortiGate response integration: The SOAR module provides playbook automation with pre-built connectors — including direct integration with FortiGate for automated response actions such as pushing blocklists, quarantining hosts, or modifying security policy rules. This matters acutely in OT incident response: CERT-In’s 6-hour reporting window demands speed that manual analyst workflows alone cannot reliably achieve. Automated containment of a compromised engineering workstation — isolating it from OT network zones while preserving forensic evidence — is what makes that regulatory timeline realistic for CII operators.

If your organisation is operating OT infrastructure without this level of unified visibility, the question is not whether you will have an incident — it is whether you will detect it before the attacker achieves their objective.

Practical Steps for Indian Enterprises: Where to Start

If your organisation has begun OT/IT convergence but hasn’t yet conducted a formal security assessment of the resulting exposure, here is a pragmatic starting sequence:

  • OT asset discovery audit: Before you can defend your OT environment, you need to know what is in it. A passive discovery exercise — typically taking two to four weeks for a mid-sized plant — will produce an accurate inventory of OT assets, their protocol communications, and existing network topology. Most Indian manufacturing organisations discover 20-30% more OT assets than their documentation shows.
  • IT/OT boundary review: Map every point where IT and OT networks connect, including jump servers, historian nodes, vendor VPN tunnels, and wireless access points on the plant floor. Every connection point is a potential adversary pivot.
  • FortiGate deployment at the IT/OT DMZ: A FortiGate NGFW with industrial protocol inspection capabilities positioned at the convergence boundary provides immediate visibility and control over cross-zone traffic. This is often the single highest-impact security investment for a converging OT/IT environment.
  • CERT-In compliance gap analysis: For organisations operating in CII-designated sectors, a formal gap analysis against CERT-In directions — covering incident reporting procedures, log retention, and contact protocols — should be a near-term priority, not a longer-term aspiration.
  • OT-specific IR tabletop exercise: Run a scenario-based tabletop that specifically tests your organisation’s response to an OT incident: an engineering workstation compromise, an unauthorised PLC modification attempt, or a ransomware deployment on the process historian. These exercises consistently reveal gaps in OT IR plans that only become visible when tested.

The Bottom Line

OT/IT convergence is not a choice many Indian enterprises are still making — it has already happened. The production monitoring dashboards, the cloud-connected historians, the vendor remote access tunnels: these connections exist. The question is whether the security architecture has kept pace.

For CISO offices managing both IT and OT exposure, the priority should be visibility first. You cannot protect an environment you cannot see, and the tools that work for IT endpoints simply do not translate to PLCs and SCADA systems. A layered approach — segmentation at the IT/OT boundary, passive OT monitoring, privileged access controls for vendor access, and unified detection across IT and OT telemetry — is both achievable and necessary.

PJ Networks works with Indian enterprises in manufacturing, pharma, FMCG, and multi-site retail to design and operate OT/IT security architectures built around FortiGate, Fortinet’s Security Fabric, and the PrahiX Ora platform. If your organisation is navigating OT/IT convergence and wants an honest assessment of where your current exposure sits, reach out to our team for an initial consultation.

Leave a Reply

Your email address will not be published. Required fields are marked *