



When SolarWinds was compromised in 2020, attackers spent months inside thousands of networks worldwide before anyone noticed. The vector was not a phishing email or a brute-forced password — it was a signed, legitimate software update pushed directly from a trusted vendor. This is the defining characteristic of a supply chain attack: the weapon is the trust you already have in your own tools.
For Indian enterprises today, supply chain threats are escalating beyond software updates. Network hardware itself — routers, firewalls, switches, access points — is increasingly in the crosshairs. Nation-state actors and sophisticated criminal groups are compromising firmware, inserting backdoors into imported equipment, and targeting managed-service update channels. If you are running a medium-to-large enterprise network in India in 2026, this is not a hypothetical risk. It is an active one.
A hardware supply chain attack occurs when an adversary tampers with network equipment — or its firmware — at some point before it reaches your rack. The compromise may happen at the manufacturer, during transit, at a regional distributor, or via a counterfeit device injected into legitimate supply channels. Once the tampered device is installed and trusted by your network, the attacker has persistent access that survives software patches, password resets, and even full factory resets in some cases.
Three attack classes are most relevant to Indian enterprise networks right now:
Several structural factors make Indian enterprise networks a more attractive target than many security teams realise:
Large Indian enterprises — particularly in manufacturing, logistics, BFSI, and IT services — often run networks assembled from equipment sourced across multiple resellers, system integrators, and direct vendor channels over many years. Validating chain-of-custody for every device in a 500-node network is difficult. The wider and less documented the procurement chain, the larger the attack surface.
Indian financial institutions, defence contractors, pharmaceutical companies, and government-adjacent enterprises hold data that is of significant interest to foreign intelligence services. Supply chain implants are a preferred tool of nation-state actors precisely because they are persistent and difficult to attribute.
Enterprise networks in India are expanding fast — new branch offices, acquisitions, cloud integrations. When a firewall needs to be racked urgently to bring a new site online, the thorough firmware-integrity check is the step most likely to be skipped. Attackers count on exactly this.
Under CERT-In’s 2022 directions (amended 2023), Indian entities must report security incidents within six hours of detection. A supply chain implant that exfiltrates data silently for months, then triggers a detectable event, could create a reporting situation that is both legally complex and operationally chaotic — especially if the root cause (a compromised device) is not identified quickly.
Supply chain implants are designed to be invisible. But they are not perfectly invisible, and a well-instrumented network can surface their signatures.
The most direct control is cryptographic firmware verification — confirming that the firmware running on every device matches the vendor’s signed hash. For FortiGate firewalls, this means using execute verify image and comparing against Fortinet’s published hash values. For other vendors, equivalent commands exist. This should be part of your baseline configuration audit, not a one-time exercise.
Implants typically need to communicate — to receive commands, exfiltrate data, or confirm persistence. Look for:
An implant that modifies routing tables, ACLs, or firewall policies to permit attacker traffic will cause configuration drift. Automated configuration-baseline comparison — checking the running config against the last approved snapshot — surfaces these changes immediately rather than at the next manual audit cycle.
Some implants are triggered to activate or phone home during network maintenance windows when monitoring may be reduced. Paradoxically, your maintenance window is a good time to watch for anomalous traffic from infrastructure devices.
The following steps represent a minimum viable programme for Indian enterprises concerned about supply chain risk in their network infrastructure:
Detecting supply chain implants in network hardware requires exactly the kind of integrated, multi-source visibility that point tools struggle to deliver. The challenge is not any single alert — it is correlating weak signals across firmware states, traffic flows, configuration changes, and threat intelligence to surface something that is intentionally designed to look normal.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner, and it is the platform we deploy and operate for clients facing precisely this kind of multi-signal detection problem.
SIEM — log correlation at scale: Ora’s SIEM ingests syslogs, SNMP traps, NetFlow, and API-sourced configuration snapshots from network infrastructure devices alongside endpoint and application logs. Correlation rules are mapped to MITRE ATT&CK techniques — including the supply chain compromise tactic (T1195) — so that a combination of anomalous outbound DNS from a firewall and a configuration change detected in the same 15-minute window surfaces as a single, prioritised storyline rather than two unrelated low-severity alerts. Critically for Indian compliance, Ora’s tiered retention architecture (hot/warm/cold/archive) supports CERT-In’s direction on 180-day in-country log retention without requiring enterprises to overbuild expensive hot storage.
NMS — infrastructure observability: Ora’s network management capability provides unified observability across firewalls, switches, APs, and WAN/SD-WAN links using LLDP/CDP topology discovery and network path tracing. In multi-vendor estates where NOC visibility is often fragmented across vendor-specific consoles, this single pane dramatically reduces the time between a device behaving anomalously and an analyst seeing it. ML-based anomaly detection flags deviations from baseline infrastructure traffic patterns — exactly the signal that a beaconing implant generates.
Video surveillance (VMS) — physical and network under one view: For manufacturing, retail, and multi-site enterprises, Ora’s video surveillance module (ONVIF/Hikvision/Dahua compatible) with video analytics brings physical security events into the same operational view as network events. A supply chain attack that involves physical access to equipment — a tampered device swap at a branch, or an insider accessing a server room — leaves traces in both domains simultaneously.
SOAR — automated response within CERT-In’s 6-hour window: When a suspected infrastructure compromise is detected, Ora’s SOAR module can immediately execute pre-approved response playbooks: isolating the suspected device from the management plane, pushing updated ACLs or blocklists to FortiGate, opening an incident ticket, and pre-populating the CERT-In report template with available artefacts. CERT-In’s 6-hour reporting window is tight; automation is what makes that timeline realistic in the middle of an active incident.
If your current NOC and SOC operations lack unified visibility across infrastructure devices, logs, and physical security, we would be glad to walk through how Ora is deployed in environments similar to yours. Reach out to PJ Networks to start that conversation.
FortiGate NGFWs, which form the core of most networks we manage, have several capabilities that are directly relevant to supply chain risk:
All the detection technology in the world does not fully substitute for upstream procurement controls. The most effective supply chain security programmes combine technical detection with rigorous sourcing practices:
These controls require discipline but not large investment. For most Indian enterprises, the gap is not budget — it is process. Formalising the checklist and making it an auditable part of the network change process is the work that matters most.
Supply chain attacks on network equipment sit at the intersection of traditional NOC work (infrastructure monitoring, device management) and SOC work (threat detection, incident response). In organisations where NOC and SOC operate in separate silos with separate tools and separate escalation paths, supply chain implant signals fall through the gaps — the NOC sees unusual traffic but does not threat-qualify it, the SOC receives threat feeds but cannot correlate them to specific infrastructure devices.
NOC+SOC convergence — the organisational and tooling integration that brings both functions under a unified operational picture — is one of the most impactful structural changes an Indian enterprise can make for this threat class. It is also an area where working with a managed security partner that already runs a converged 24/7 operation provides immediate capability uplift without the multi-year effort of building that convergence internally.
If you want to move immediately on supply chain risk, here are the highest-value actions that do not require a procurement cycle:
PJ Networks operates a 24/7 managed NOC/SOC for Indian enterprises, with deep expertise in FortiGate, Fortinet SD-WAN, ZTNA, and FortiMail. Our managed security service includes:
If you are evaluating your exposure to supply chain attacks on network hardware, or if you want an independent assessment of your current detection coverage, contact PJ Networks for a conversation with our security team. We are based in India, we understand the regulatory landscape, and we have seen what these attacks look like inside enterprise networks.
The threat is real. The defences are known. The gap, for most organisations, is execution — and that is where we can help.