



India’s manufacturing sector is undergoing a seismic shift. The government’s Production Linked Incentive (PLI) scheme, “Make in India,” and the rapid adoption of Industry 4.0 technologies have pushed Indian factories onto smart, connected platforms. Sensors monitor assembly lines in real time. PLCs communicate via IP networks. ERP systems talk directly to SCADA. The benefits are significant — but so is the attack surface.
In 2024 and 2025, we saw a sharp rise in ransomware, espionage, and sabotage attacks targeting operational technology (OT) environments globally — and India has not been spared. For Indian CISOs and IT heads in manufacturing, automotive, pharmaceuticals, and energy, the convergence of OT and IT networks is now the single most critical cybersecurity challenge of the decade.
Operational technology — the systems that control physical processes — was traditionally “air-gapped.” Isolated from the corporate IT network, these environments ran proprietary protocols (Modbus, DNP3, Profibus) on hardware that was expected to operate for 15–25 years with minimal patching. Security through obscurity was the de facto strategy.
That model is obsolete. Today:
Each of these integrations creates a pathway from the corporate network — with its email-borne phishing, browser exploits, and SaaS vulnerabilities — into the OT environment where a compromised controller means a halted production line, or worse, a safety incident.
Groups such as LockBit, Cl0p, and their successors have developed specific “OT-aware” capabilities. Rather than simply encrypting files on Windows servers, modern ransomware recognises industrial software processes (Siemens TIA Portal, Rockwell FactoryTalk, GE iFIX) and either halts them or corrupts their configuration databases. The business impact is not just data loss — it is production stoppage, which costs an order of magnitude more per hour than a typical IT ransomware event.
Indian automotive component manufacturers, textile mills, and pharmaceutical formulation plants have all reported incidents in 2024–25 where attackers moved laterally from a phished employee’s laptop into the factory’s historian server, and from there into process control segments.
OEM engineers, system integrators, and remote monitoring vendors all require periodic access to OT networks. In many Indian factories, this is managed through shared VPN credentials, jump hosts with weak passwords, or — in the worst cases — directly exposed RDP on a SCADA machine. These unmanaged access paths are consistently among the top initial access vectors.
The 15-year lifecycle of OT hardware means that much of India’s shopfloor infrastructure runs on Windows XP, Windows 7, or embedded Linux kernels from the mid-2010s. These systems cannot be patched without vendor certification, and even then, patching windows are rare. A single unpatched OT machine exposed to the corporate network is a persistent, high-value target.
India’s manufacturing workforce has seen significant restructuring as automation replaces roles. Disgruntled employees — or former contractors who retain valid credentials — represent a non-trivial risk. The CERT-In advisory CA-2024-0039 specifically called out insider-enabled sabotage in the critical infrastructure sector.
For Indian manufacturers, the regulatory environment is tightening:
The six-hour CERT-In reporting window is particularly demanding for OT incidents because detection itself is harder — most factories lack the event correlation capability to distinguish a slow-burn intrusion from normal process variability until significant damage has already occurred.
The ISA/IEC 62443 standard and the Purdue Enterprise Reference Architecture remain the foundational framework. Level 0 (process), Level 1 (control), Level 2 (supervisory), Level 3 (operations) and Level 4 (enterprise IT) should each be separated by industrial firewalls or demilitarised zones (DMZ) with explicit permit-lists, not default-allow. In practice, many Indian manufacturers have collapsed these levels in the rush to connect MES to ERP — a configuration that requires immediate remediation.
FortiGate NGFWs deployed at the IT/OT boundary can inspect industrial protocols (Modbus, DNP3, OPC-UA) at Layer 7, apply geo-based policies to restrict lateral movement, and generate structured logs that feed into a SIEM for correlation. The FortiGate’s Industrial Security Service is purpose-built for exactly this boundary enforcement role.
Replacing legacy VPN with ZTNA for third-party and remote access eliminates the “trusted insider” assumption that makes shared-credential VPN so dangerous. With ZTNA, every access request is authenticated, the connecting device’s posture is checked, and the session is limited to the specific resource being accessed — not the entire OT segment. This is the fastest, highest-ROI control an Indian manufacturer can deploy today to reduce third-party risk.
Detecting OT-targeted attacks requires monitoring that understands industrial protocol anomalies — an unexpected Modbus write to a PLC register is not the same as an unexpected TCP connection. Without protocol-aware inspection and correlation, most OT incidents go undetected until the production impact is visible.
A standard IT incident response playbook is not sufficient for OT. Isolating an infected SCADA server may stop a ransomware spread — but it may also halt production. OT-specific playbooks must define pre-approved isolation procedures, manual fallback processes (can operators continue in manual mode?), vendor notification trees, and the specific point at which safety systems take precedence over confidentiality-driven isolation.
Given that OT systems cannot be patched on a standard 30-day cadence, vulnerability management for OT focuses on compensating controls: virtual patching at the network layer (using IPS signatures on the FortiGate), network micro-segmentation to isolate unpatched assets, and risk-ranked prioritisation so that CVEs with known OT exploits are addressed first.
Indian manufacturers deploying OT security controls face a practical problem: they end up with multiple siloed tools — a separate SIEM for IT logs, a different NMS for OT network visibility, a standalone video management system for physical security, and manual processes for incident response. This fragmentation slows detection and makes CERT-In’s six-hour reporting window almost impossible to meet reliably.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd, designed to bring IT security operations, network management, video surveillance, and response automation under a single operations view. PJ Networks is PrahiX Ora’s primary field deployment and operations partner — we deploy the platform for clients and run it as part of our 24/7 managed SOC/NOC service.
For OT/IT convergence environments specifically, PrahiX Ora’s four capabilities work as a system:
If your operations team is currently running separate tools with limited integration, ask us about a PrahiX Ora deployment assessment — we can map the platform’s capabilities to your specific OT/IT environment and existing tooling.
For an Indian manufacturer beginning an OT security programme, the following sequence is both practical and maximally risk-reducing:
PJ Networks is a managed security services provider with deep Fortinet expertise and a 24/7 NOC/SOC operation. We help Indian manufacturers across automotive, pharmaceuticals, FMCG, and process industries with:
If you are navigating OT/IT convergence security and want a practical conversation about where your programme stands, contact PJ Networks for an initial assessment.