Securing OT and ICS Networks in Indian Manufacturing: Protecting the Shop Floor from Cyber Threats

  • Home
  • Securing OT and ICS Networks in Indian Manufacturing: Protecting the Shop Floor from Cyber Threats
Securing OT and ICS Networks in Indian Manufacturing: Protecting the Shop Floor from Cyber Threats

India’s manufacturing sector is undergoing a rapid transformation. From automotive and pharmaceuticals to steel and textiles, factories are embracing Industrial IoT (IIoT), SCADA systems, and cloud-connected PLCs to drive efficiency. But this connectivity comes at a steep price: Operational Technology (OT) and Industrial Control Systems (ICS) that were once air-gapped are now exposed to the same threat actors that target enterprise IT—and they are far less equipped to defend themselves.

For Indian CISOs and plant managers, the question is no longer whether OT networks will be targeted, but when. A successful attack on a manufacturing plant doesn’t just cause a data breach—it can halt production lines, damage physical equipment, endanger workers, and trigger regulatory scrutiny under India’s CERT-In directives and the emerging DPDP Act framework.

Why OT/ICS Security Is a Distinct Challenge

Traditional IT security tools and playbooks do not translate cleanly to OT environments. The differences are fundamental:

  • Availability over confidentiality: In IT, the security triad prioritises confidentiality. In OT, availability is paramount—a 30-second outage on a production line can cost lakhs of rupees. Aggressive patch cycles and intrusive scans can disrupt PLCs, HMIs, and SCADA systems that were never designed for them.
  • Legacy protocols everywhere: Modbus, DNP3, EtherNet/IP, PROFINET—these industrial protocols predate modern security concepts. Many run over flat, unsegmented networks with no authentication or encryption.
  • Extended equipment lifespans: A furnace controller or CNC machine may run the same firmware for 15–20 years. Vendors no longer support it; security patches don’t exist. You cannot simply “update” a legacy PLC the way you update a Windows server.
  • Convergence of IT and OT: As manufacturers connect factory-floor systems to ERP platforms (SAP, Oracle), cloud dashboards, and remote-access portals, the traditional air gap disappears. The IT network becomes a pivot point into OT.

The Indian Manufacturing Threat Landscape in 2026

India’s manufacturing sector has emerged as a target of choice for several threat actor categories:

Ransomware Targeting Production Systems

Ransomware groups are increasingly aware that manufacturers will pay faster than other verticals because every hour of downtime has a direct, calculable cost. Threat actors now specifically seek out Historian servers and SCADA workstations, encrypt them, and demand ransom before a production deadline. Indian pharmaceutical and auto component manufacturers have seen such incidents reported to CERT-In under the 6-hour reporting mandate.

Supply Chain Infiltration

Third-party maintenance vendors, remote-access portals for PLC vendors, and shared engineering workstations are the most common initial access vectors. Attackers compromise a small sub-vendor’s VPN credentials and use them to pivot into the OT network of a tier-1 manufacturer.

Espionage and IP Theft

State-affiliated actors and industrial competitors target R&D workstations, CAD/CAM servers, and quality management systems. For defence-linked manufacturers and MSME exporters supplying global OEMs, IP theft via OT network intrusion is a growing concern.

Hacktivism and Geopolitical Targeting

Geopolitically motivated groups have demonstrated the capability and intent to target critical infrastructure, including ports, power plants, and large industrial facilities. India’s border tensions make domestic manufacturers a non-trivial target for disruption campaigns.

A Practical OT Security Architecture: Five Layers

Securing an OT environment requires a layered, risk-based approach calibrated to production realities. Here is the framework we deploy for manufacturing clients:

1. Network Segmentation and the Purdue Model

The Purdue Enterprise Reference Architecture provides a logical starting point. Segment the OT network into clearly defined zones: Level 0 (field devices), Level 1 (basic control), Level 2 (supervisory control), Level 3 (site operations), and the demilitarised zone (DMZ) that mediates all IT/OT communication.

FortiGate next-generation firewalls with OT-aware inspection profiles enforce these zone boundaries. IEC 62443 compliant rulesets allow SCADA traffic while blocking reconnaissance patterns. Critically, any remote access to OT assets should be mediated through a secure jump server in the DMZ—never a direct VPN tunnel into Level 2.

2. Asset Inventory and Vulnerability Visibility

You cannot protect what you cannot see. Many Indian plants have never produced a complete inventory of OT assets—PLCs, HMIs, historians, SCADA servers, and the protocols running between them. Passive network discovery tools (which observe traffic rather than probing devices) build this inventory without disturbing production systems.

3. Privileged Access Management for OT

Remote access is the most common OT intrusion vector. Every vendor, contractor, and remote engineer who can reach a PLC is a potential entry point. Implement just-in-time privileged access: access is granted only for a defined window, with full session recording, and auto-revoked on expiry. This is achievable through ZTNA principles extended to OT—replacing always-on VPN tunnels with zero-trust access brokers that authenticate the user, the device posture, and the specific OT resource requested.

4. Continuous Monitoring with OT-Aware Detection

Signature-based antivirus is largely ineffective against OT-specific malware (Industroyer, TRITON, FrostyGoop). Effective detection relies on behavioural baselines: what commands does this PLC normally issue? What is the typical polling frequency on this Modbus address? Deviations from baseline—a new device on the network, a change in HMI logic, an unusual write command to a safety controller—are high-fidelity signals of compromise.

5. Incident Response Rehearsed for OT Realities

An OT incident response plan must account for production continuity. Isolating a compromised SCADA server may mean gracefully handing control back to manual operation. Forensics must be performed on live systems where possible, since powering down equipment can itself cause physical damage. Runbooks should be tested in tabletop exercises with both security and plant operations teams.

CERT-In Compliance for Manufacturing OT Environments

The CERT-In Directions of 2022 and subsequent updates impose specific obligations on Indian organisations, including manufacturers operating critical infrastructure or connected OT systems:

  • 6-hour reporting window: Any cyber incident—including ransomware, unauthorised access, or data breach—must be reported to CERT-In within 6 hours of detection. For OT environments where incidents can be detected first by plant alarms rather than SIEM alerts, ensuring your detection-to-notification pipeline meets this window requires tight integration between OT monitoring and your security operations centre.
  • 180-day log retention: ICT infrastructure logs must be retained for 180 days within India. This applies to OT historian logs, HMI event logs, firewall logs at the IT/OT boundary, and remote access logs. Log compression, tiered storage, and in-country data residency are all requirements to plan for.
  • System clocks synchronised to NTP: OT networks frequently have clock drift issues due to legacy devices. CERT-In requires NTP synchronisation—critical for any forensic reconstruction of attack timelines across mixed IT/OT environments.
  • Vulnerability scanning and patching: While OT patching is constrained, organisations must demonstrate awareness of vulnerabilities and compensating controls where patching is not feasible.

The Role of PrahiX Ora in OT/IT Security Convergence

One of the operational challenges manufacturing CISOs consistently raise is fragmented visibility: the IT SOC sees the enterprise network; the plant team watches OT alarms via their own SCADA console; and nobody has a unified view that correlates IT threat indicators with OT anomalies. This gap is precisely where the platform we deploy and operate for clients—PrahiX Ora, developed by PrahiX Tech Pvt Ltd—provides measurable value.

SIEM: PrahiX Ora ingests logs from firewalls, active directory, SCADA historians, and endpoint agents into a unified correlation engine with detection rules mapped to MITRE ATT&CK for ICS (ATT&CK-ICS). When a Windows workstation in the OT DMZ attempts lateral movement to a Historian server, the platform reconstructs the attack storyline in a graph view, linking the initial phishing email to the OT pivot in a single alert. The platform’s tiered retention (hot, cold, archive) helps manufacturing clients meet CERT-In’s 180-day in-country log retention direction without prohibitive storage costs.

NMS: In multi-vendor OT/IT estates—FortiGate firewalls, Cisco switches, legacy SCADA hardware, and wireless APs across a sprawling plant floor—NOC visibility is often fragmented across five or six different consoles. Ora’s Network Management System uses LLDP/CDP topology discovery to build a live map of the entire estate, with network path tracing and ML-based anomaly detection that flags unusual traffic patterns between IT and OT zones. Auto-healing policies can quarantine a suspicious endpoint without requiring a human to log into a firewall management console at 2 AM.

Video Surveillance (VMS): Physical access to OT assets—server rooms, PLC cabinets, substation control panels—is as important as network security. Ora’s video surveillance (VMS) module supports ONVIF/Hikvision/Dahua camera integration with video analytics, bringing physical and logical security under one operations view. For manufacturing and retail clients with multi-site estates, this means a single operator can correlate a door-access event at a remote facility with a network anomaly from the same location—something impossible when physical security and cyber security run on separate platforms.

SOAR: The CERT-In 6-hour incident reporting window is not achievable through manual processes alone when your OT environment generates thousands of events per day. Ora’s SOAR module provides pre-built playbooks with automated response actions—for example, pushing a new blocklist to FortiGate the moment a malicious IP is identified, or automatically isolating a compromised jump server from the OT DMZ. This automation does not replace human judgment for high-consequence OT actions; instead, it handles the initial triage, evidence collection, and notification steps so your analysts can focus on decisive response rather than ticket management.

If your plant environment currently lacks unified visibility across IT and OT, get in touch with our team to discuss what an Ora deployment would look like for your specific estate.

A Practical OT Security Checklist for Indian Manufacturers

Use this checklist as a starting point for an OT security gap assessment:

  • [ ] Complete OT asset inventory documented (every PLC, HMI, historian, network device)
  • [ ] IT/OT network segmentation enforced at the DMZ with next-generation firewall (FortiGate recommended)
  • [ ] Remote access to OT mediated through a secure jump server—no direct VPN to Level 2
  • [ ] All vendor and contractor remote access governed by just-in-time access policies
  • [ ] OT-aware behavioural monitoring deployed (passive, non-intrusive)
  • [ ] SCADA and historian logs ingested into SIEM with 180-day in-country retention
  • [ ] NTP synchronisation enforced on all OT devices where feasible
  • [ ] OT incident response runbook documented and tested in a tabletop exercise
  • [ ] CERT-In 6-hour reporting pipeline tested end-to-end (detection → triage → notification)
  • [ ] Third-party vendor security assessments conducted annually
  • [ ] Patch status documented for all OT systems; compensating controls defined where patching is infeasible
  • [ ] Plant operations team included in cyber incident response training

How PJ Networks Supports Manufacturing OT Security

PJ Networks is a managed security services provider with deep Fortinet expertise and 24/7 NOC/SOC operations serving Indian enterprise clients. Our OT security engagements typically include:

  • OT network assessment and segmentation design using FortiGate NGFW with IEC 62443-aligned policies
  • ZTNA implementation for secure remote access to OT assets, replacing legacy VPN
  • SD-WAN with OT traffic prioritisation for multi-site manufacturing facilities
  • 24/7 managed SOC monitoring of both IT and OT environments, with CERT-In reporting support
  • PrahiX Ora deployment and operations for unified SIEM, NMS, video surveillance (VMS), and SOAR
  • FortiMail-based email security to block phishing—the most common OT network entry vector

The manufacturing sector is at an inflection point. Connectivity that drives efficiency also creates attack surface. The organisations that build security into their OT convergence strategy today will be far better positioned than those who wait for an incident to force the conversation.

If you are a plant manager, IT head, or CISO at an Indian manufacturing company and want to understand your current OT security posture, contact PJ Networks for a no-obligation assessment. We operate across India, with 24/7 support and a team experienced in Fortinet, ICS security, and CERT-In compliance.

Leave a Reply

Your email address will not be published. Required fields are marked *