Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats

  • Home
  • Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats
Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats
Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats
Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats
Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats
Securing India’s Critical Infrastructure: How AI-Driven Threat Detection and FortiGate NGFW Stop Advanced Persistent Threats

India’s critical infrastructure — power grids, water treatment facilities, manufacturing plants, financial networks, and telecom backbone — has become the most consequential battleground in modern cybersecurity. Over the past two years, threat intelligence reports have documented a sustained surge in Advanced Persistent Threat (APT) campaigns specifically targeting Indian industrial control systems, SCADA environments, and enterprise OT/IT converged networks. The attackers are patient, well-resourced, and increasingly using AI-assisted techniques to evade traditional perimeter defences.

For Indian enterprise IT leaders and CISOs, this is not a theoretical risk. The question is no longer whether your organisation will face a sophisticated intrusion attempt — it is whether your detection and response capabilities will catch it before damage is done. This article examines the anatomy of modern APT campaigns targeting Indian infrastructure, the role of AI-driven threat detection in closing the visibility gap, and how PJ Networks combines FortiGate NGFW capabilities with 24/7 SOC operations and the PrahiX Ora SecOps platform to deliver enterprise-grade protection.

The Evolving APT Threat Landscape in India

Advanced Persistent Threats distinguish themselves from opportunistic ransomware through three characteristics: extended dwell time (weeks to months inside a network before triggering an impact), highly targeted lateral movement, and the use of legitimate administrative tools to blend into normal network traffic — a technique often called “living off the land.”

Threat intelligence from multiple sources points to a consistent targeting pattern against Indian organisations:

  • Energy sector: Spear-phishing campaigns impersonating power ministry communications, designed to drop remote access trojans on engineering workstations connected to SCADA systems.
  • Manufacturing: Supply chain attacks through OEM vendor portals, pivoting from IT networks into OT environments controlling production lines.
  • BFSI (Banking, Financial Services and Insurance): Credential-harvesting campaigns targeting treasury and payment gateway access, with extended reconnaissance phases lasting 60–90 days before any visible action.
  • Government and defence adjacent suppliers: Persistent intrusions targeting procurement systems and sensitive project documentation stored on unencrypted file shares.

What makes modern APT campaigns particularly dangerous is the deliberate effort to stay beneath the threshold of traditional rule-based alert systems. Attackers study the organisation’s normal behaviour — which accounts log in at what hours, which servers talk to which endpoints, what volumes of data traverse which paths — and conduct their operations within those baselines. Static firewall rules and signature-based detection miss most of this activity entirely.

Why Traditional Perimeter Defence Is Not Enough

Many Indian enterprises still rely on a perimeter-centric security model: a firewall at the edge, antivirus on endpoints, and a SIEM that generates thousands of alerts per day that the internal team cannot meaningfully triage. This model has three critical gaps when facing APT-grade adversaries:

1. The Flat Network Problem

Once an attacker compromises a single endpoint — typically through a phishing email or an unpatched VPN appliance — a flat network architecture allows lateral movement with minimal friction. Without micro-segmentation and Zero Trust Network Access (ZTNA) enforcement, an attacker can traverse from a marketing workstation to a finance server to a domain controller without encountering a meaningful checkpoint.

2. Alert Fatigue and Triage Gaps

A medium-sized enterprise generates tens of thousands of security events per day. Without machine learning-based correlation and automated triage, security analysts spend the majority of their time investigating false positives — and genuine threat signals get buried. Studies consistently show that the average dwell time for APT intrusions detected by internal teams is measured in months, not days. By the time a human analyst finds the needle, the attacker has already exfiltrated what they came for.

3. OT/IT Visibility Blindspot

Operational technology environments — PLCs, SCADA controllers, industrial IoT sensors — were designed for reliability, not security. They often run legacy protocols (Modbus, DNP3, BACnet) that traditional security tools cannot inspect. When an APT actor pivots from the corporate IT network into an OT environment, most security stacks lose visibility entirely.

The FortiGate NGFW Advantage: Deep Inspection at Scale

PJ Networks deploys FortiGate Next-Generation Firewalls as the core enforcement layer in our client environments — and for good reason. FortiGate’s Security Processing Units (SPUs) deliver hardware-accelerated deep packet inspection, SSL/TLS decryption, and application-layer controls without the throughput penalty that cripples software-based inspection at enterprise scale.

Key FortiGate capabilities that directly address APT-grade threats include:

  • Intrusion Prevention System (IPS): FortiGate’s IPS engine, updated through FortiGuard threat intelligence, identifies known APT toolsets, command-and-control (C2) communication patterns, and exploit attempts against unpatched vulnerabilities in real time.
  • SSL Deep Inspection: A growing majority of C2 traffic and data exfiltration operates over encrypted HTTPS channels. FortiGate decrypts, inspects, and re-encrypts traffic at line rate — exposing threats that hide inside TLS tunnels.
  • Application Control and DNS Filtering: APT actors frequently use DNS-over-HTTPS (DoH) and obscure application protocols for C2 communications. FortiGate’s application control layer identifies and blocks these channels without impacting legitimate business traffic.
  • ZTNA Integration: FortiGate integrates natively with Fortinet’s ZTNA framework, enabling identity-aware, context-sensitive access policies that restrict lateral movement even if credentials are compromised.
  • SD-WAN with Security Posture: For distributed Indian enterprises with multiple sites, FortiGate’s integrated SD-WAN with security enforcement ensures consistent policy across branches — including remote manufacturing sites and regional offices that are often the softest targets for initial access.

Critically, FortiGate’s integration with the broader Fortinet Security Fabric means that threat intelligence, policy changes, and incident response actions propagate across the entire deployed estate simultaneously — not site by site.

PrahiX Ora: The SecOps Platform We Deploy and Operate for Clients

Deploying strong hardware is necessary but not sufficient. The capability that separates mature security operations from checkbox compliance is what happens after FortiGate generates an alert — how fast it is correlated, contextualised, and acted upon. For this, PJ Networks deploys and operates PrahiX Ora, a unified SecOps platform built by PrahiX Tech Pvt Ltd.

Ora integrates SIEM, Network Management (NMS), Video Surveillance (VMS), and Security Orchestration and Automated Response (SOAR) into a single operational view. Here is what each pillar delivers in practice:

SIEM: Correlation That Finds APT Signals in the Noise

Ora’s SIEM ingests log and event data from across the client environment — firewalls, endpoints, servers, cloud workloads, authentication systems, and application logs — and applies correlation rules mapped to the MITRE ATT&CK framework. When an analyst looks at an alert, they see not just a single event but a graph-based attack storyline reconstruction: which account was involved, which systems it touched, what lateral movement occurred, and how it maps to known adversary techniques.

For Indian enterprises, a particularly significant capability is the platform’s tiered log retention architecture — hot storage for active investigation, cold storage for recent history, and archive for long-term retention. This directly supports CERT-In’s direction on maintaining security logs in-country for a minimum of 180 days, providing the audit trail that compliance teams need without requiring organisations to build and manage their own log infrastructure.

NMS: Unified Visibility Across Complex Multi-Vendor Estates

Most mid-to-large Indian enterprises operate a heterogeneous network estate — Fortinet firewalls alongside Cisco or Aruba switches, a mix of Wi-Fi vendors, leased MPLS circuits alongside SD-WAN overlays. Fragmented visibility across these layers is one of the primary reasons that lateral movement goes undetected.

Ora’s Network Management System provides unified observability across all of this: LLDP/CDP-based topology discovery, network path tracing, and ML-based anomaly detection that baselines normal traffic patterns and flags deviations. When an APT actor begins moving laterally — even using legitimate protocols and credentials — the anomaly engine surfaces the behaviour. Auto-healing policies can isolate affected segments automatically while the SOC investigates.

Video Surveillance (VMS): Physical and Network Security Under One View

For manufacturing sites, retail chains, and multi-location enterprises, physical security events are often the precursor or accompaniment to network intrusions. Ora’s video surveillance module integrates ONVIF, Hikvision, and Dahua camera management with video analytics, bringing physical surveillance into the same operational console as network and endpoint monitoring.

This matters because sophisticated threat actors sometimes combine physical access — tailgating into data centres, planting hardware keyloggers — with remote intrusion campaigns. Having both visibility streams in one platform means that a physical security event can automatically trigger a network security investigation, and vice versa. For Indian enterprises managing manufacturing or retail estates across multiple sites, this consolidated view under one operations centre is a significant operational advantage.

SOAR: Making CERT-In’s 6-Hour Reporting Window Achievable

CERT-In’s 2022 directive mandating incident reporting within six hours of detection is widely acknowledged as one of the most demanding requirements in any national cybersecurity framework. For an organisation without automated response capabilities, meeting that window requires a SOC analyst to manually identify the incident, confirm it is not a false positive, escalate through internal approval chains, draft the report, and submit — all within six hours, including potentially in the middle of the night.

Ora’s SOAR engine makes this realistic. Pre-built playbooks automate the initial response steps: when a confirmed incident is detected, the platform can automatically push blocklists to FortiGate firewalls, isolate affected endpoints, capture forensic snapshots, and pre-populate the CERT-In incident report template with the event data it has already collected. The analyst’s job becomes reviewing and confirming an automated workflow rather than building it from scratch under time pressure. For organisations that have experienced the stress of a real incident, this automation is not a nice-to-have — it is the difference between meeting the regulatory requirement and explaining to CERT-In why you missed it.

Building a Layered Defence: The PJ Networks Approach

Our managed security model for Indian enterprises combines the detection and enforcement capabilities described above with 24/7 human-led SOC operations. The architecture works in layers:

Layer 1: Perimeter and Segmentation

FortiGate NGFW at the perimeter and between network segments, with ZTNA enforcement for remote access. All internet-bound traffic inspected including SSL. SD-WAN with integrated security for multi-site organisations.

Layer 2: Continuous Monitoring

PrahiX Ora ingesting logs and events from across the estate, with MITRE ATT&CK-mapped correlation running continuously. NMS providing topology awareness and anomaly detection. Video surveillance integrated where relevant to physical security.

Layer 3: 24/7 SOC Operations

PJ Networks SOC analysts triaging Ora-generated alerts around the clock. Escalation playbooks for high-severity incidents. Direct integration with client IT teams for confirmed incidents. Monthly threat reports contextualised to the client’s industry sector and threat profile.

Layer 4: Compliance Evidencing

Log retention meeting CERT-In’s 180-day in-country requirement. SOAR-assisted incident reporting supporting CERT-In’s 6-hour window. Documentation and reporting to support DPDP Act compliance for organisations handling personal data of Indian residents.

Practical Steps for Indian CISOs

If you are assessing your organisation’s readiness against APT-grade threats, consider these concrete actions:

  • Audit your network segmentation: Map the lateral movement paths an attacker could take from your most exposed endpoints (email, VPN, external-facing web servers) to your most critical systems. Flat networks are APT actors’ best friend.
  • Validate your SSL inspection coverage: If your firewall is not decrypting and inspecting TLS traffic, you have a significant blind spot. Most modern C2 and exfiltration traffic is encrypted.
  • Test your detection dwell time: Commission a purple team exercise or tabletop simulation. How long does it take your current tooling and team to detect simulated lateral movement? The honest answer often drives immediate priority changes.
  • Review your log retention posture: Are you retaining 180 days of security-relevant logs in-country? Do you have a clear chain of custody for those logs that would satisfy a CERT-In inquiry?
  • Stress-test your incident response timeline: Walk through your current process for detecting, confirming, escalating, and reporting an incident. Map it against the 6-hour CERT-In window. Identify where automation would close the gap.

Conclusion: Detection Speed Is the Decisive Variable

Against APT adversaries who are willing to spend months inside a network before triggering impact, the decisive variable is not whether you get breached — it is how quickly you detect the intrusion and how effectively you contain it. Every day an attacker dwell inside your network undetected is another day of reconnaissance, credential harvesting, and preparation for the actual impact event.

The combination of FortiGate NGFW enforcement, AI-driven correlation through PrahiX Ora, and 24/7 human-led SOC operations is designed specifically to compress that detection window — and to give your team the automated tools to respond at machine speed when a confirmed threat is identified.

PJ Networks works with Indian enterprises across manufacturing, BFSI, healthcare, and government-adjacent sectors to design and operate managed security programmes that are calibrated to both the threat landscape and India’s specific regulatory requirements. If you are evaluating your current APT readiness or looking to accelerate your CERT-In compliance posture, we welcome a technical conversation with your security team.

Get in touch with PJ Networks to discuss a security posture assessment for your organisation.

Leave a Reply

Your email address will not be published. Required fields are marked *