Skip to main content
Manufacturing

Manufacturing Cybersecurity

CERT-In empanelled cybersecurity services for Manufacturing organisations. 6,700+ assessments delivered since 2006.

6,700+
Assessments Delivered
1,000+
Enterprise Clients
150+
Security Professionals
Since 2006
Founded · CERT-In 2008

Challenges

Security challenges in Manufacturing

1

OT/ICS security — SCADA, PLC, DCS, and MES systems never designed for internet-era threat models

2

IT/OT convergence creating bridges between corporate networks and production-floor systems

3

Intellectual property protection — product designs, manufacturing processes, and trade secrets

4

Supply chain risk management across raw material suppliers, logistics partners, and distributors

5

Legacy industrial systems running unsupported operating systems with known vulnerabilities

6

Regulatory compliance across IEC 62443, ISO 27001, and industry-specific standards

Trusted by

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The divide

One incident, three accounts of what happened

IT and OT do not disagree about the facts. They disagree about which facts matter, and an assessment that only hears one of them produces a report the other cannot use.

The same event

An engineering workstation is compromised

What IT sees
A managed endpoint with malware on it. Isolate it, reimage it, rotate the user's credentials, close the ticket. Mean time to recovery, measured in hours.
What OT sees
The machine that holds the only copy of the current PLC programme, is licensed to one vendor dongle, and cannot be reimaged without a commissioning visit. Isolating it stops the line.
What the assessment has to establish
Whether that workstation could reach the controllers at all, what stands between it and them, and whether anything would have detected the traffic if it had. That question is answerable without touching a single controller.

The estate

Where the boundary is supposed to be, and where it actually is

The reference architectures put a hard line between enterprise and control networks. Assessments find crossings, and the crossings are usually there for a reason someone can defend.

LayerWhat lives thereHow the boundary gets crossed
Enterprise IT ERP, email, file shares, the corporate identity provider and the internet-facing estate. Production reporting and scheduling need plant data, so a path exists by design. The question is whether it is the only one.
The industrial DMZ Historians, jump hosts, patch and antivirus distribution, remote-access brokers. This is the sanctioned crossing. It is also where a single compromised jump host converts an IT incident into an OT one.
Supervisory SCADA servers, HMIs, engineering workstations and the historian collectors feeding upward. Vendor remote support, frequently through a tool the vendor chose, sometimes always-on, occasionally unknown to the security team.
Third-party maintenance access is the most consistently under-governed path in an industrial estate, and it is contractually justified, which is why it survives review.
Control PLCs, RTUs, DCS controllers and the protocols between them — most of which authenticate weakly or not at all by design. A flat plant network. Segmentation that exists on the diagram and not in the switch configuration is the most common finding at this layer.
Process Sensors, actuators and safety instrumented systems. Rarely reached directly, and it is the layer where testing stops. Safety systems are established by review and by design analysis, never by active testing.

Enterprise IT

What lives there
ERP, email, file shares, the corporate identity provider and the internet-facing estate.
How the boundary gets crossed
Production reporting and scheduling need plant data, so a path exists by design. The question is whether it is the only one.

The industrial DMZ

What lives there
Historians, jump hosts, patch and antivirus distribution, remote-access brokers.
How the boundary gets crossed
This is the sanctioned crossing. It is also where a single compromised jump host converts an IT incident into an OT one.

Supervisory

What lives there
SCADA servers, HMIs, engineering workstations and the historian collectors feeding upward.
How the boundary gets crossed
Vendor remote support, frequently through a tool the vendor chose, sometimes always-on, occasionally unknown to the security team.

Third-party maintenance access is the most consistently under-governed path in an industrial estate, and it is contractually justified, which is why it survives review.

Control

What lives there
PLCs, RTUs, DCS controllers and the protocols between them — most of which authenticate weakly or not at all by design.
How the boundary gets crossed
A flat plant network. Segmentation that exists on the diagram and not in the switch configuration is the most common finding at this layer.

Process

What lives there
Sensors, actuators and safety instrumented systems.
How the boundary gets crossed
Rarely reached directly, and it is the layer where testing stops. Safety systems are established by review and by design analysis, never by active testing.

The driver

No regulator is coming, and the deadline is real anyway

Indian manufacturing has no sector cyber instrument equivalent to the ones RBI and SEBI issue, which is often read as an absence of deadline. The pressure arrives from three other directions instead, and it is less negotiable than a regulator because it is attached to revenue. Customers impose security requirements through supply-contract clauses and audit rights, and an automotive or aerospace customer will send an auditor. Insurers ask questions before writing cyber cover, and increasingly price on the answers. And the CERT-In Directions of 2022 apply to every organisation in the country, with a six-hour incident reporting window and 180-day log retention within India, whether or not anyone has written to you about it. A plant that cannot answer a customer questionnaire loses the contract on a schedule set by the customer, which is a harder deadline than most regulatory ones.

How we work here

Nothing gets touched until it is established that it can be

Passive first, always

Traffic capture and protocol analysis to build the inventory and the reachability map. A controller that responds badly to an ordinary scan is not an edge case in OT — it is the normal case.

Test the crossing, not the controller

The valuable finding is almost never a controller vulnerability. It is a path from a phishing email to a jump host to the supervisory layer, and that path can be tested without touching the plant floor.

The corporate estate at full strength

Everything on the enterprise side gets a conventional assessment, because that is where the intrusion starts and where no availability constraint applies.

Vendor access as a scope item

Named explicitly, because it is the path most likely to be excluded by default and most likely to be permanently open.

Findings a plant manager can act on

A recommendation to patch a controller during production is not a recommendation. Segmentation, monitoring and access-path changes are what can actually be scheduled against a maintenance window.

Safety systems out of scope, in writing

Established by design review rather than by testing, and stated as such — so the boundary is a documented decision rather than an omission somebody has to explain later.

Compliance

Frameworks that matter to Manufacturing

Frequently Asked Questions

Will testing stop the line?

No, because the work is sequenced so the answer to that question comes before anything active happens. Discovery in control networks is passive — traffic capture and protocol analysis rather than scanning. Active testing is confined to the enterprise and industrial DMZ layers, where a fault does not stop production, and to plant equipment only during an agreed maintenance window with the plant team present. Safety instrumented systems are assessed by design review and are never tested actively.

No regulator requires this of us. Why do it now?

Because the requirement usually arrives from a customer, and on their timetable. Supply-contract security clauses with audit rights are now routine in automotive, aerospace and pharmaceutical supply chains, and failing one is a commercial loss rather than a compliance finding. Cyber insurers ask the same questions before binding cover. And the CERT-In Directions of 2022 already apply to every organisation in the country regardless of sector, including the six-hour incident reporting window and the 180-day log retention requirement.

Secure Your Manufacturing Organisation

One scoping call to align on scope, methodology, and timing.

Request a Scoping Call →