



The attack surface of a modern enterprise no longer ends at its own perimeter. It extends across every vendor, contractor, cloud service, and integration partner connected to the organisation. For Indian enterprises navigating an increasingly hostile threat landscape—and the compliance expectations of the DPDP Act and CERT-In directives—supply chain cyber risk has moved from theoretical concern to board-level priority.
This guide explores why third-party and supply chain attacks are surging, what India-specific regulatory obligations apply, and how a layered security posture anchored in 24/7 monitoring and automation makes the difference between early detection and a six-week incident.
Threat actors have learned that breaching a well-defended enterprise directly is hard. Breaching a smaller, less-defended supplier—and using that foothold to pivot inward—is far easier. The pattern is consistent: a managed service provider, a SaaS integration, or a firmware update mechanism becomes the initial access vector, and the primary target inherits the breach.
Several factors are accelerating this trend in the Indian market:
The most damaging incidents in recent years—across financial services, manufacturing, and critical infrastructure globally—share one common thread: the initial compromise happened somewhere the victim organisation did not own and could not see.
Indian enterprises face two principal regulatory frameworks that speak directly to supply chain and third-party risk.
The DPDP Act places obligations on Data Fiduciaries not only for their own processing activities, but for the processing conducted by Data Processors acting on their behalf. This creates a direct accountability chain: if a vendor processes personal data of your customers and suffers a breach, your organisation faces exposure as the originating Data Fiduciary.
Practically, this means organisations must:
CERT-In’s directions require organisations to report certain categories of cyber incidents within six hours of detection. Supply chain incidents are particularly challenging in this context: if the compromise originated at a vendor, the primary organisation may not detect the incident—it may only become aware of it when the vendor notifies them, or worse, when indicators appear in their own environment.
Organisations that depend on manual correlation of logs across their own estate and their vendors’ environment will routinely miss the six-hour window. The only realistic path to compliance is automated ingestion, correlation, and alerting.
Additionally, CERT-In’s direction on log retention—requiring organisations to maintain logs within India for 180 days—has direct implications for how event data from third-party integrations is collected and stored. Relying on a vendor’s own log portal does not satisfy this requirement.
Many organisations have third-party risk programmes on paper. Far fewer have programmes that actually reduce breach likelihood or improve detection speed. The gap usually comes down to one word: operationalisation.
Start by tiering vendors based on their access to your environment and the sensitivity of data they handle. Tier 1 vendors—those with privileged access to production systems, customer data, or critical infrastructure—warrant continuous monitoring. Tier 2 vendors with limited access can be reviewed periodically. Tier 3 vendors with no direct access to sensitive assets require only basic contractual assurances.
For Tier 1 vendors, continuous monitoring means:
Every third-party integration is a potential ingress point. Network segmentation ensures that even if a vendor’s credential is compromised, the attacker’s movement within your environment is constrained. Key technical controls include:
Security controls are only as durable as the agreements that require them. Vendor contracts should specify:
When a supply chain incident occurs, the response is complicated by the fact that critical evidence and initial response actions are in someone else’s environment. Preparation is everything.
Before an incident, establish:
During an incident, your SOC’s ability to query retained logs from vendor access sessions is the difference between a rapid scope determination and weeks of uncertainty. Organisations that ingest vendor session logs into their SIEM can query: “What did this vendor account touch in the 48 hours before the reported compromise?” Those without centralised log ingestion cannot answer that question reliably.
Supply chain security ultimately comes down to visibility and speed. You cannot detect what you cannot see, and you cannot respond in six hours without automation. PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd; PJ Networks is its primary field deployment and operations partner, and it is the platform we deploy and operate for clients who need enterprise-grade SecOps without building it from scratch.
Four capabilities make it directly relevant to supply chain risk management:
SIEM — Centralised log ingestion across your estate and vendor integrations. Ora’s SIEM ingests logs from diverse sources—FortiGate firewalls, network devices, cloud workloads, endpoint agents, and vendor-provided log feeds—correlating events against MITRE ATT&CK-mapped detection rules. Graph-based attack storyline reconstruction allows SOC analysts to see a lateral movement chain across your environment and a vendor session in one view, dramatically compressing mean-time-to-understand. Tiered retention (hot, cold, and archive) supports CERT-In’s direction on maintaining logs for 180 days within India, with cost-effective archival for less-accessed historical data.
NMS — Unified observability across your full network estate. Multi-vendor network estates—a common reality in Indian enterprises that have grown through acquisition or run parallel FortiGate and third-party devices—suffer from fragmented NOC visibility. Ora’s NMS provides unified observability across firewalls, switches, wireless access points, and WAN/SD-WAN links, with LLDP/CDP-based topology discovery so your NOC has an accurate, auto-updated map of what is connected where. ML-based anomaly detection surfaces deviations that rule-based monitoring misses—such as a vendor-connected segment initiating unexpected internal scanning.
Video Surveillance (VMS) — Physical and logical security under one operations view. For manufacturing, retail, and multi-site enterprises, physical access events and network events are often investigated in separate silos. Ora’s video surveillance (VMS) module, supporting ONVIF/Hikvision/Dahua camera estates, brings physical surveillance under the same operational view as network and security telemetry. For supply chain risk, this is particularly relevant when vendor personnel have physical access to server rooms or network closets—correlating badge-in events with network activity from that segment becomes straightforward.
SOAR — Automated response that makes CERT-In’s 6-hour window realistic. Manual response workflows cannot reliably meet a six-hour incident reporting deadline when the incident is discovered at 2 a.m. Ora’s SOAR capability provides pre-built playbook automation with connectors that can execute response actions autonomously—including pushing updated blocklists directly to FortiGate. When a vendor-originated IOC is confirmed, the SOAR playbook can isolate the affected segment, block the IOC at the firewall perimeter, and generate a structured incident draft for CERT-In notification, all before a human analyst has finished their first coffee.
If your organisation is assessing SecOps platforms for supply chain visibility or compliance readiness, we are happy to walk through how Ora fits your environment.
For organisations ready to move from awareness to action, here is a prioritised 90-day roadmap:
Days 1–30 (Foundation):
Days 31–60 (Visibility):
Days 61–90 (Automation and Governance):
The uncomfortable truth about supply chain security is that many organisations will not know they have been breached through a vendor until the attacker makes a mistake—or until the vendor notifies them. Neither is an acceptable early-warning system for a CERT-In-regulated enterprise or a DPDP Act Data Fiduciary.
The path forward is not vendor questionnaires and annual audits—it is continuous visibility, automated detection, and pre-built response. That combination is achievable today, with the right platform and the right operations partner.
PJ Networks works with Indian enterprises across manufacturing, BFSI, healthcare, and IT services to deploy and operate 24/7 SOC and NOC capabilities built on FortiGate and PrahiX Ora. If supply chain visibility or CERT-In/DPDP readiness is on your security roadmap, reach out to us for a no-obligation assessment.