



India’s industrial backbone — power grids, refineries, water treatment facilities, manufacturing plants, and port logistics — is undergoing rapid digital transformation. Operational Technology (OT) and Industrial Control Systems (ICS) that once ran in complete isolation are now connected to enterprise IT networks, cloud dashboards, and remote access gateways. This convergence brings efficiency, but it also creates a dramatically expanded attack surface that adversaries are actively exploiting.
In 2024 and 2025, we observed a sharp uptick in targeted intrusion attempts against Indian energy and manufacturing organisations. Nation-state aligned threat actors, financially motivated ransomware gangs, and hacktivist groups are all turning their attention toward operational networks — systems where a successful compromise can mean plant shutdowns, safety incidents, regulatory violations, and reputational damage that far exceeds the cost of any ransom.
This post examines the OT/ICS threat landscape facing Indian enterprises, outlines what a modern defence architecture should look like, and explains how PJ Networks’ managed security services address the unique challenges of securing critical infrastructure environments.
Enterprise IT security professionals who move into OT environments quickly discover that the standard playbook does not apply cleanly. The differences are fundamental:
These constraints make OT environments an attractive target precisely because defenders find them hard to instrument and protect.
India’s IT/OT threat landscape has evolved considerably. Here is what our NOC/SOC teams are tracking:
Several well-documented ransomware groups have updated their toolkits to detect and target OT environments after compromising IT networks. The playbook is consistent: establish IT-side persistence, perform lateral reconnaissance to identify historian servers and engineering workstations, deploy ransomware to maximise pressure on the victim. Indian manufacturers in textiles, chemicals, and auto-components have been directly hit by this pattern.
Intelligence agencies and cybersecurity researchers have documented cases of nation-state threat groups pre-positioning access in energy and utilities infrastructure — not necessarily to cause immediate disruption, but to retain leverage. The goal is often to hold the capability to act during a geopolitical crisis. For Indian critical infrastructure operators, this means intrusions that persist quietly for months, evading detection by avoiding noisy lateral movement.
OT environments rely on a web of integrators, equipment vendors, and maintenance contractors who require periodic remote access. These third-party access paths — often under-monitored and granted via flat VPN connections rather than zero-trust tunnels — represent one of the highest-risk entry vectors we observe in the field.
While the PLC itself may be impossible to patch, the engineering workstations, historian servers, and HMI interfaces that sit adjacent to OT often run Windows Server or Windows 10 deployments that are many months behind on patches. Widely exploited vulnerabilities in remote desktop services, VPN appliances, and web-based SCADA interfaces create reliable footholds for attackers.
Securing OT does not mean replacing every legacy device. It means building a layered defence architecture that provides visibility, segmentation, and response capability without disrupting production. Here is the framework we implement for clients:
The foundation is enforcing proper zone boundaries — at minimum, separating the IT network from the OT DMZ, and the OT DMZ from the control network. FortiGate NGFWs deployed as the OT DMZ gateway provide deep packet inspection for OT protocols (Modbus, DNP3, IEC 61850) via Fortinet’s industrial security service package. FortiGate’s Security Fabric allows policy enforcement and visibility across IT and OT zones from a single management plane — critical for organisations that lack dedicated OT security staff.
You cannot protect what you cannot see. In OT environments, active scanning is often prohibited because it can crash legacy PLCs and RTUs. Passive asset discovery — listening to broadcast traffic, LLDP/CDP advertisements, and protocol exchanges — builds an accurate inventory without risking plant disruption. This inventory becomes the baseline against which anomalies are detected.
Once baseline behaviour is established, deviations — a PLC suddenly issuing commands it has never issued, an engineering workstation communicating to an external IP, a new device appearing on the control network — trigger alerts. ML-based anomaly detection dramatically reduces the manual triage burden on NOC analysts who may not have deep OT domain expertise.
Third-party and remote access to OT environments should be governed through a zero-trust access broker — session-specific, time-limited, with full session recording and just-in-time approval workflows. This eliminates the standing VPN tunnels that frequently become the entry path for lateral movement.
OT incident response differs from IT response. Isolating a compromised PLC may require physical actions — pulling network cables, switching to manual control, activating backup systems. IR plans must be developed in collaboration with plant operations teams, not just the CISO’s office, and they must be practised.
One of the persistent challenges in OT security is that visibility is fragmented: the IT SOC sees one set of alerts, plant operations see another, and the two rarely correlate in real time. This is where the platform we deploy and operate for clients — PrahiX Ora, built by PrahiX Tech Pvt Ltd — makes a material difference for Indian manufacturing and utilities enterprises.
PrahiX Ora is a unified SecOps platform that brings together SIEM, Network Management System (NMS), video surveillance (VMS), and SOAR under one operational view. Here is how each pillar addresses the OT security challenge:
SIEM — Correlated Log Intelligence with CERT-In Retention Compliance: OT environments generate logs from firewalls, historians, engineering workstations, Active Directory (where present), and OT-specific sources. PrahiX Ora’s SIEM ingests these multi-source log streams and applies correlation rules mapped to the MITRE ATT&CK for ICS framework — the industrial-specific variant of the well-known adversary behaviour model. Attack storyline reconstruction using graph-based analysis surfaces attack chains that individual alerts would miss. Critically for Indian operators, the platform’s tiered retention architecture (hot/cold/archive) supports CERT-In’s direction for 180-day in-country log retention — a requirement that many organisations struggle to meet cost-effectively with conventional SIEM deployments.
NMS — Unified Observability Across OT and IT Networks: In multi-site manufacturing and utilities estates, network management is typically fragmented — one tool for the campus switches, another for the WAN, nothing meaningful for the plant floor. PrahiX Ora’s NMS provides unified observability across firewalls, switches, access points, and WAN/SD-WAN links using LLDP/CDP topology discovery. Network path tracing and ML-based anomaly detection flag deviations from baseline traffic patterns. Auto-healing policies can trigger automated containment responses, reducing the window between detection and containment for NOC teams managing complex multi-vendor estates where visibility has historically been fragmented.
Video Surveillance (VMS) — Physical and Cyber Under One View: For manufacturing, retail, and multi-site enterprises, physical security and network security are operationally separate teams that rarely share information. PrahiX Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras with video analytics, and integrates camera alerts alongside network events in the same operational console. Correlating a badge-access anomaly with a spike in authentication attempts gives the SOC a richer picture of incidents unfolding across manufacturing, retail, and multi-site operations.
SOAR — Making CERT-In’s 6-Hour Reporting Window Achievable: CERT-In’s 2022 mandate requires reporting of cyber incidents within six hours of detection. For an organisation whose analysts are manually triaging dozens of alerts across fragmented tools, that window is extremely tight. PrahiX Ora’s SOAR module automates playbook execution — including pre-built connectors that push blocklists to FortiGate firewalls, isolate endpoints, and notify stakeholders — so that when a credible OT-targeted incident is detected, the first containment actions fire automatically and the reporting workflow is triggered in parallel. For the 6-hour window, automation is what makes compliance realistic.
If your organisation is operating OT environments without unified SecOps visibility, we can walk you through a no-commitment assessment of where your current stack has gaps. Contact PJ Networks to schedule a conversation, or explore PrahiX Ora’s capabilities at ora.prahix.com.
Indian OT operators face a dual compliance obligation that IT-centric organisations may not fully appreciate.
CERT-In’s 2022 direction (expanded in subsequent advisories) requires organisations in critical sectors to report security incidents within six hours, maintain system logs for 180 days, and designate a point of contact for CERT-In coordination. The six-hour window is particularly challenging for OT environments where root cause identification — distinguishing a genuine attack from a sensor fault or configuration error — can be slow without proper tooling.
The Digital Personal Data Protection (DPDP) Act 2023 adds a data fiduciary obligation that OT operators may overlook: many industrial systems collect operational data that, when combined with employee records or contractor information, constitutes personal data under the Act. A ransomware incident that exfiltrates historian data or contractor access logs may trigger DPDP notification obligations in addition to CERT-In reporting.
A security architecture that supports compliance with both frameworks requires:
PJ Networks’ managed security engagements are structured to help evidence compliance with these frameworks — not to guarantee certification outcomes, but to ensure that the controls, documentation, and response capabilities are in place when a regulator or auditor asks the question.
If you are at the beginning of an OT security programme, here is a prioritised checklist to guide your roadmap:
PJ Networks is a managed security provider with a 24/7 NOC/SOC, deep Fortinet expertise, and field experience securing OT/ICS environments across Indian manufacturing, utilities, and logistics sectors. Our services relevant to OT security include:
If your organisation is operating OT or ICS infrastructure and has not yet undertaken a structured security assessment, now is the right time. The threat landscape is not standing still, and the regulatory clock is running. Reach out to PJ Networks to begin the conversation.