



India’s manufacturing sector—buoyed by the Production Linked Incentive (PLI) scheme and Make in India—is racing to digitise shop floors, connect legacy PLCs to ERP systems, and deploy Industrial IoT sensors at scale. The efficiency gains are real. So is the expanded attack surface.
Operational Technology (OT) and Industrial Control System (ICS) networks were once isolated by design—air-gapped, proprietary protocols, physical access controls. That era is over. Today, the same network that carries SCADA traffic to a DCS controller may also route engineer laptops to cloud maintenance portals. The results of that convergence, when it goes wrong, are front-page news: production stoppages, safety incidents, extortionate ransomware demands from groups that specifically target industrial targets.
This guide is for IT and OT leaders at Indian manufacturing, pharma, logistics, and energy firms who need a practical framework—not vendor brochures—to harden their industrial environments against modern cyber threats.
Attackers choose industrial targets for a simple reason: pressure works faster than in IT. A factory floor that cannot run costs lakhs per hour. A chemical plant that cannot confirm sensor integrity must halt production on safety grounds. Hospitals running SCADA-controlled HVAC or medical gas systems face patient risk. The economics of extortion are brutally efficient.
Several threat patterns are rising in India:
CERT-In’s 2024 sectoral advisories highlighted manufacturing and energy as high-priority targets receiving increased threat actor attention. The 6-hour incident reporting mandate (effective May 2022) applies unambiguously to OT incidents affecting critical infrastructure and means that organisations without automated detection cannot meet their legal obligations.
Traditional IT security is built on the CIA triad—Confidentiality, Integrity, Availability—with confidentiality often treated as the primary concern. OT security inverts this: Availability and Integrity come first; a momentary availability interruption on a running blast furnace is a safety event, not just a service ticket.
This difference has practical consequences:
Security controls must be designed around these realities, not imposed from an IT template.
The Purdue Enterprise Reference Architecture divides OT networks into zones: the Enterprise Zone (Level 4–5), Manufacturing Operations Zone (Level 3), Control Zone (Levels 0–2), and the critical OT DMZ that mediates between them. Proper segmentation means these zones communicate through enforced chokepoints, never through flat Layer 2 adjacency.
In practice, this means:
You cannot defend what you cannot see. Most Indian industrial sites we engage have no accurate, current inventory of OT assets. PLCs, RTUs, HMIs, engineering workstations, and historian servers accumulate over years without consistent documentation.
Passive network traffic analysis tools—which listen without injecting packets—can build an asset inventory from protocol traffic without touching devices. FortiGate’s OT/ICS application signatures can identify industrial protocols (Modbus, EtherNet/IP, OPC-UA) traversing zone boundaries and flag anomalous commands.
Shared credentials (“the plc password”) and standing remote access are among the most common findings in OT security assessments. Remediation steps:
Industrial environments benefit from behavioural baselines. A PLC that has issued the same 12 Modbus function codes for three years should not suddenly issue function code 06 (Write Single Register) from an unexpected source IP. SIEM correlation rules tuned for OT protocols can flag these deviations in near-real-time.
Log sources that matter in OT environments:
An IT incident response playbook is insufficient for OT. Isolating a compromised server is straightforward; isolating a compromised DCS controller mid-production batch may not be safe to do immediately. OT IR playbooks need explicit decision trees: “If anomalous traffic is detected on the control network, who has authority to isolate the affected segment? What is the safe-state procedure?”
Under CERT-In’s 6-hour reporting mandate, this decision tree must execute fast. Organisations without pre-defined playbooks and automated alerting routinely miss the reporting window—not because they chose to, but because they did not know they had an incident until it was too late.
Fortinet’s FortiGate NGFW is uniquely positioned for OT environments because it ships with industrial protocol application signatures and IPS signatures specifically developed for OT threats (available in Fortinet’s FortiGuard Industrial Security Service). This means a FortiGate placed at an OT DMZ boundary can:
PJ Networks deploys FortiGate across OT DMZ segments with custom OT security profiles, working with plant engineers to ensure that aggressive threat-prevention settings are calibrated to avoid false positives that could interrupt production.
One of the persistent challenges in industrial security is that IT and OT operations teams work from different tools, different data, and often different incident queues. An IT SOC analyst seeing anomalous lateral movement on an engineering workstation may not know that the workstation connects to a control zone PLC. Context is missing, and response is slow.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner, and it is the platform we deploy and operate for clients who need to bring IT and OT visibility under a single operational view.
Four capability pillars make it relevant for OT-heavy organisations:
SIEM — Multi-Source Correlation with MITRE ATT&CK Mapping: Ora’s SIEM ingests logs from OT firewalls, SCADA historians, engineering workstations, and cloud connectors simultaneously. Correlation rules mapped to MITRE ATT&CK for ICS (a separate technique matrix for industrial threats) allow analysts to see attack storylines reconstructed as graphs—not raw log lines. CERT-In’s direction on 180-day in-country log retention is addressed through tiered hot/cold/archive storage, keeping forensic data available without ballooning storage costs.
NMS — Unified Network Observability Across Multi-Vendor OT Estates: Most Indian manufacturing sites run a mix of Cisco, Fortinet, Hirschmann, and vendor-specific switches in their OT networks. Ora’s NMS uses LLDP/CDP topology discovery and ML-based anomaly detection to build a unified view of network behaviour—flagging unusual traffic patterns between OT zones before they become incidents. For NOC teams managing fragmented multi-vendor visibility today, this convergence substantially reduces mean-time-to-detect.
Video Surveillance (VMS) — Physical and Cyber Under One Operations View: Ora’s video surveillance (VMS) module manages ONVIF, Hikvision, and Dahua cameras with integrated video analytics. For manufacturing and multi-site retail estates, this means physical access events—an after-hours door badge, a camera detecting unauthorised entry to a server room—are correlated with network security events in the same platform. A physical breach that correlates with a simultaneous network login from an OT asset is a very different alert than either event in isolation.
SOAR — Playbook Automation That Makes CERT-In 6-Hour Reporting Realistic: Ora’s SOAR module ships with pre-built connectors and automated response actions, including pushing blocklists directly to FortiGate. For OT incidents, this is the capability that makes CERT-In’s 6-hour reporting window achievable. Manual analysis at 2 a.m. cannot consistently meet that threshold; automated playbooks that triage, enrich, and draft the initial incident report can. Clients operating under CERT-In compliance obligations should evaluate whether their current response tooling can deliver that timeline at scale.
Indian OT operators face an evolving regulatory landscape:
For organisations starting their OT security journey, here is a pragmatic sequence:
PJ Networks provides managed security services specifically designed for Indian enterprises with OT/ICS environments. Our capabilities relevant to manufacturing and industrial clients include:
If your organisation is assessing OT security maturity or preparing for a CERT-In audit, our team is available to conduct a no-obligation OT security assessment. Contact PJ Networks to schedule a conversation with our industrial security practice.