Securing OT/ICS Networks in Indian Manufacturing: A Practical Roadmap

  • Home
  • Securing OT/ICS Networks in Indian Manufacturing: A Practical Roadmap
Securing OT/ICS Networks in Indian Manufacturing: A Practical Roadmap

Indian manufacturing is undergoing a rapid digital transformation. Smart factories, Industry 4.0 automation, robotics, and connected SCADA systems are redefining how goods are produced—from auto-component plants in Pune to pharmaceutical facilities in Ahmedabad. But this connectivity is also creating an expanding attack surface that most enterprise security teams were simply not designed to protect.

Operational Technology (OT) and Industrial Control Systems (ICS) were originally built for reliability and uptime, not cybersecurity. Air-gapped networks and proprietary protocols gave them a degree of isolation for decades. That isolation is gone. The convergence of IT and OT means that a ransomware gang that compromises your enterprise network can now pivot directly into your production floor—stopping conveyors, locking HMIs, or worse, manipulating sensor readings in ways that create real-world physical hazards.

This guide is aimed at IT leaders and CISOs at Indian manufacturing organisations who know they have an OT problem but may not yet have a coherent framework for addressing it. We cover the threat landscape, the specific challenges of OT environments, and a practical, phased roadmap to meaningful protection.

Why OT/ICS Security Is Different—and Harder

Standard enterprise security tools and methodologies break when applied to OT environments. Here is why:

  • Availability trumps everything: A patch that requires a 30-minute reboot is routine in IT. In a continuous-process plant, a 30-minute unplanned stop can cost lakhs of rupees or create safety hazards. Vendors routinely warn that patching will void support warranties on legacy PLCs and DCS systems.
  • Long asset lifespans: Industrial control equipment often runs for 15-25 years. It is common to find Windows XP or even Windows 2000 still running an HMI because replacing the associated machinery costs crores. These systems cannot be patched.
  • Proprietary protocols: Modbus, DNP3, EtherNet/IP, PROFINET, and OPC are not protocols that standard NGFW deep-packet inspection understands out of the box. Traffic that looks benign to a corporate firewall may be a malicious command replay attack inside your OT network.
  • No security agents: You cannot install an EDR agent on a PLC. Passive network monitoring is the only viable detection strategy for many OT assets.
  • Flat network architecture: Many OT networks that were never designed with segmentation have everything from engineering workstations to PLCs to historian servers on a single flat subnet.

The Indian Threat Landscape: OT Is Now a Target

OT attacks are no longer theoretical. The 2021 Mumbai power grid incident, which caused a significant voltage drop, was attributed by a US threat intelligence firm to a Chinese APT group that had implanted malware in SCADA systems. While attribution in that case remains disputed, the technical finding—that grid control systems had been compromised—was not. Indian critical infrastructure is actively being surveilled and, in some cases, pre-positioned for disruption.

Beyond nation-state actors, ransomware groups have learned that OT networks are enormously valuable as leverage. Encrypting a manufacturer’s ERP is painful; encrypting the HMI that controls their bottling line creates immediate, existential production pressure to pay. Groups like LockBit, BlackCat, and their successors have demonstrated the willingness to cross the IT-OT boundary and cause physical disruption.

For Indian enterprises, the regulatory stakes are also rising. CERT-In’s 2022 directions mandate reporting of cybersecurity incidents—including those affecting industrial systems—within six hours of detection. The DPDP Act 2023, while primarily focused on personal data, has broader implications for data governance across the enterprise including OT historian data containing process parameters and production records.

A Phased OT Security Roadmap

Phase 1: Visibility — Know What You Have (Weeks 1–8)

You cannot protect what you cannot see. OT environments typically have poor asset inventory because industrial assets were never onboarded into CMDB or IT asset management processes.

  • Passive OT asset discovery: Deploy a passive OT network monitoring sensor (not an active scanner—active scanning can crash PLCs) on SPAN ports at key aggregation switches. Identify every device: IP, MAC, vendor, protocol, firmware version, and communications patterns.
  • Network topology mapping: Understand actual data flows—which PLCs communicate with which historians, which engineering workstations connect to which control segments.
  • Risk prioritisation: Not all OT assets are equal. An HMI controlling a safety-critical process is far more important than a conveyor-monitoring sensor. Build a criticality matrix.

Phase 2: Segmentation — Create Defensible Zones (Weeks 8–20)

The Purdue Model and IEC 62443 both prescribe zone-and-conduit network architecture. In practice, this means:

  • IT/OT firewall with OT-aware DPI: A FortiGate NGFW positioned between your enterprise IT network (Level 4) and your OT DMZ (Level 3.5) with FortiGuard OT Security Service enabled. This provides deep-packet inspection of Modbus, DNP3, IEC 104, and other industrial protocols—understanding not just that traffic is present but whether it contains valid vs. anomalous commands.
  • Purdue zone segmentation: Use VLANs and inter-zone firewalling to separate enterprise IT (Level 4), OT DMZ/historian/jump hosts (Level 3.5), supervisory SCADA (Level 3), control networks (Level 2), and field devices (Level 1/0).
  • Secure remote access: Replace VPN-based remote access for OT (used by equipment vendors and maintenance contractors) with ZTNA-based access controls that enforce identity verification, device health checks, and time-limited session grants. Every vendor session should be recorded.
  • OT data diode: For particularly sensitive segments, a data diode ensures historian data flows one-way from OT to IT without creating a path back into the control network.

Phase 3: Detection and Response — Monitor Continuously (Ongoing)

Segmentation reduces risk but does not eliminate it. Insider threats, supply chain compromise, and zero-days can all bypass perimeter controls. Continuous OT network monitoring is essential:

  • Detect command injection, replay attacks, unusual polling frequencies, or connections to unexpected IP addresses.
  • Baseline normal industrial process behaviour and alert on deviations—a PLC that normally only receives commands from one engineering workstation suddenly accepting commands from a historian server is an anomaly worth investigating.
  • Integrate OT alerts into your SOC alongside IT alerts so incident responders have a unified view and can correlate a phishing email that landed in HR on Tuesday with a strange Modbus write command on the production floor Thursday.

Phase 4: Incident Response Planning for OT

Your standard IT incident response playbook will not work in OT. You need a specialised OT-IR plan that addresses:

  • How to isolate a compromised OT segment without shutting down the entire production line.
  • Who has authority to take a PLC offline during a security incident (a security decision that has safety implications).
  • Forensic procedures for OT systems—OT forensics requires different tooling and expertise than IT forensics.
  • How to meet the CERT-In 6-hour reporting requirement when the incident spans both IT and OT domains.

OT Security Checklist for Indian Manufacturing CISOs

  • ☐ Complete passive OT asset inventory with criticality classification
  • ☐ Network topology diagram documenting IT/OT interconnections
  • ☐ IT/OT firewall with OT-protocol-aware DPI deployed and tuned
  • ☐ Purdue zone segmentation implemented with documented conduits
  • ☐ ZTNA-based vendor remote access replacing legacy VPN
  • ☐ Continuous passive OT network monitoring active
  • ☐ OT security events correlated in enterprise SOC/SIEM
  • ☐ OT-specific incident response playbook documented and tested
  • ☐ CERT-In 6-hour reporting procedure covering OT incidents
  • ☐ Annual OT-focused penetration test (passive/segmentation validation)
  • ☐ Vendor and supply chain access controls reviewed and enforced
  • ☐ Engineering workstation hardening (application whitelisting, USB control)

PrahiX Ora: Unified SecOps Visibility Across IT and OT

One of the most common gaps in OT security programmes is the disconnect between what the OT monitoring tool sees and what the enterprise SOC sees. A threat actor who spends two weeks traversing from a phishing email in the corporate network to the OT historian, and then writes a malicious command to a PLC, will leave artefacts in both domains. If your IT SIEM and your OT monitoring tool do not talk to each other, that attack path is invisible as a whole even if parts of it are visible in isolation.

This is the problem that PrahiX Ora, the unified SecOps platform we deploy and operate for clients, is designed to solve. PrahiX Ora is built by PrahiX Tech Pvt Ltd; PJ Networks is its primary field deployment and operations partner, bringing both the platform and the 24/7 NOC/SOC operations capability to manage it.

SIEM with CERT-In-aligned retention: OT syslog, historian events, firewall logs, and enterprise endpoint telemetry are all ingested into a single correlation engine. Correlation rules are mapped to MITRE ATT&CK for ICS (the OT-specific extension of the ATT&CK framework), so alerts are contextualised against known OT adversary techniques. Graph-based attack storyline reconstruction helps analysts understand the full kill chain across IT and OT domains. Critically, tiered log retention (hot/warm/cold/archive) supports CERT-In’s direction on 180-day in-country log retention—a requirement that many organisations are struggling to meet cost-effectively for high-volume OT log sources.

NMS with full OT topology visibility: The network management pillar provides unified observability across FortiGate firewalls, managed switches, access points, WAN links, and OT-adjacent infrastructure. LLDP/CDP topology discovery automatically builds and maintains network maps. ML-based anomaly detection flags unusual bandwidth patterns or new device-to-device communication paths that may indicate lateral movement. For manufacturing organisations with multi-vendor OT estates where NOC visibility is fragmented across half a dozen vendor consoles, the unified view is a significant operational improvement.

Video surveillance (VMS) integration: Physical security and network security are increasingly interconnected threats—a badge-in at 2 AM followed by a USB insertion event on an engineering workstation 10 minutes later is a correlation that matters. PrahiX Ora’s video surveillance (VMS) module supports ONVIF, Hikvision, and Dahua camera management with video analytics, bringing physical and network security events under one operations view. For manufacturing, retail, and multi-site estates where physical access to OT equipment is a real threat vector, this unified view supports faster, more complete incident investigation.

SOAR automation for CERT-In compliance: When an OT security alert fires, the clock is running. CERT-In’s 6-hour incident reporting window is not generous, and manually collecting evidence, assessing severity, escalating, and drafting a report in that window is extremely challenging without automation. The SOAR module provides pre-built playbooks with connectors to FortiGate (for automated blocklist pushes), ticketing systems, and notification channels. Playbook automation is what makes the 6-hour CERT-In timeline realistic at scale—without it, every significant incident becomes a race against the clock that the SOC team frequently loses.

If your OT security programme needs the visibility layer to bring IT and OT together, speak with the PJ Networks team about a PrahiX Ora assessment for your environment.

FortiGate as the OT/IT Boundary Firewall

For Indian manufacturing organisations looking for a proven, enterprise-grade solution at the IT/OT boundary, FortiGate NGFWs with the FortiGuard OT Security Service are the platform PJ Networks has deployed across multiple industrial environments. Key capabilities include:

  • Industrial protocol DPI: FortiGate understands Modbus, DNP3, IEC 61850, EtherNet/IP, and other OT protocols—going beyond port and IP to inspect whether commands are valid within the protocol specification.
  • Virtual patching: For those unpatched legacy OT systems that cannot be updated, FortiGate IPS signatures provide virtual patching—blocking known exploits at the network level without touching the endpoint.
  • FortiDeceptor integration: Deception-based detection using honeypots that mimic OT assets can detect lateral movement before an attacker reaches real production systems.
  • FortiNAC for OT device profiling: Automated device profiling and network access control ensures that only authorised and properly categorised devices can connect to OT segments.

Getting Started: What to Do This Month

The single most important first step in OT security is passive network visibility. Until you know what is on your OT network and what it is communicating with, every other security control is built on guesswork.

For Indian manufacturing CISOs who want to move forward this month, we recommend starting with a focused OT Network Assessment. This is a 2-4 week engagement that deploys passive monitoring sensors to build an accurate asset inventory, identify IT/OT interconnections, and surface the highest-risk exposures. The output is a prioritised remediation roadmap with effort and cost estimates—enough to build a business case for the capital investment that deeper OT security work requires.

PJ Networks has experience across a range of Indian manufacturing sectors, including auto components, pharmaceuticals, food and beverage, and discrete manufacturing. Our team includes OT security specialists who understand the operational constraints that make “just patch everything” an impossible instruction in industrial environments.

If OT security is on your agenda for this financial year—and given the current threat landscape, it should be—connect with the PJ Networks team to discuss an OT Network Assessment for your facilities.

Leave a Reply

Your email address will not be published. Required fields are marked *