OT and SCADA security fails on the factory floor when plants apply IT security assumptions to control systems never designed for them. PLCs, HMIs, SCADA servers, and historians on Indian factory floors often run 15-25 years, cannot tolerate an unscheduled reboot or a routine vulnerability scan without risking a safety incident or stoppage, and were engineered for availability and physical safety first, confidentiality a distant third. As IT and OT networks converge for remote monitoring, MES integration, and vendor support, that mismatch becomes an attack path: an attacker who lands in the enterprise IT zone via phishing can often pivot straight into the control zone because segmentation was never enforced. The fix: a layered reference architecture (the Purdue model), passive-first assessment discipline, and a prioritised hardening roadmap that respects safety and uptime constraints.
Why IT security assumptions break on the factory floor
Enterprise IT security defaults to patch fast, scan aggressively, and assume endpoints can reboot on short refresh cycles. None of those defaults hold on an OT network.
A PLC controlling a conveyor or chiller may have been commissioned a decade ago, running vendor-unsupported firmware on an operating system that cannot accept modern patches without voiding a safety case. An HMI touchscreen is frequently a thin client with a shared operator login, because individual accounts were judged too slow for shift handovers. A historian server aggregating process data may be the one Windows box IT actually manages — and therefore the one most reachable through a support VPN.
The result is a control environment that is mission-critical yet under-instrumented: little security telemetry, unmanaged legacy assets, operators trained on process safety, not cyber hygiene. Attackers do not need a novel technique to exploit this gap — only to find where IT and OT now touch.
The IT/OT convergence risk
Fifteen years ago most Indian plant control networks were genuinely air-gapped: no routable path existed between the corporate network and the SCADA/DCS environment. That isolation has eroded as plants adopted remote OEM support, cloud production dashboards, predictive-maintenance sensors, and MES/ERP integrations pulling real-time production data into business systems. Each is a legitimate business need — and each is also a new routable path into a control network built with almost no internal authentication.
This is IT/OT convergence, the most consequential trend in industrial security over the past decade. The reference cases the field cites are Stuxnet (2010), which showed a sufficiently resourced actor could reach and manipulate industrial controllers (Siemens PLCs) to cause physical process damage, and the Ukraine power grid attacks of December 2015 and December 2016, where attackers used IT-side compromise — spear-phishing, stolen credentials, remote access tools — to pivot into operational networks and directly manipulate breaker controls, causing real outages.
Industry ICS/OT threat-landscape research consistently documents that ransomware groups increasingly target IT infrastructure at industrial organisations, since a ransomware event on the IT side alone is often enough to force a plant shutdown without the attacker ever touching the control network.
The Purdue model: a segmentation reference for OT and SCADA security
The Purdue Enterprise Reference Architecture is the industry-standard model for laying out zones between enterprise IT and plant-floor control systems, and remains the segmentation framework most widely referenced in NIST SP 800-82 and ISA/IEC 62443 guidance. It is not a product — it is a layered reference for deciding what should and should not be able to talk to what.
The DMZ between Level 4 (business systems) and Level 3 (operations/supervisory) is the single most important control here. It should be the only place data crosses between IT and OT, via brokered flows — historian replication, patch relay servers, jump hosts with logged, time-boxed access — never a direct path from a business-network workstation into a control-zone HMI.
Levels 2 and 1-0 — the control zone and field devices — should never be directly reachable from Level 3 without defined, monitored interfaces, and never reachable from Level 4/5 except through the DMZ broker. This maps onto ISA/IEC 62443's "zones and conduits" concept: each zone has a defined security level, and every conduit is an explicit, documented exception — never a default.
Know your vulnerabilities before attackers do
Run a free VAPT scan — takes 5 minutes, no signup required.
Book Your Free ScanSafe assessment practice: passive first, always
The most damaging mistake an assessor can make on a live plant network is treating it like an IT network. NIST SP 800-82 is explicit that some control devices cannot tolerate active scanning at all.
| Assessment technique | IT network | Live production OT network |
|---|---|---|
| Active vulnerability scanning | Standard practice | Avoid on control-zone assets; only with vendor sign-off, in a maintenance window |
| Passive traffic analysis (span port, tap) | Supplementary | Primary technique — reveals assets and protocols with zero risk to availability |
| Asset inventory via drawings + walkdown | Rarely necessary | Essential — many legacy devices will not respond reliably to network discovery |
| Credentialed authentication testing | Common | High caution — testing shared credentials on a live HMI can lock out an operator mid-shift |
| Firmware/configuration review | Standard | Preferred over live testing — review offline copies or vendor documentation |
| Exploitation attempts | Standard, within scope | Reserve for isolated test/replica environments, never production control devices |
Any assessment on a live plant network needs sign-off from plant operations and safety leadership, not just an IT security mandate — the assessor does not carry the same accountability for a stoppage as the plant engineering team does.
A prioritised hardening roadmap for a mid-sized plant
Most Indian plants cannot re-architect their control network in one project. A realistic roadmap sequences by risk reduction per unit of disruption, starting with the lowest-disruption, highest-leverage steps.
- Build a passive asset inventory first. You cannot segment or protect what you have not mapped.
- Close the flattest, highest-risk paths. Remove any direct route between corporate Wi-Fi and control-zone devices — often the highest-leverage fix, needing only firewall and VLAN correction.
- Establish a real DMZ broker for IT-OT data flows. Historian replication, OEM support, and MES integration should route through a documented DMZ, never a direct connection.
- Eliminate shared and default engineering credentials. A commonly found OT weakness; move to individual, role-based accounts where supported.
- Control and log all remote vendor access. Unmanaged, always-on VPN access is a standing pivot path; move to time-boxed, approval-gated sessions.
- Risk-rank unsupported legacy controllers. Where a device cannot be patched or replaced soon, compensate with network-layer isolation and monitoring.
- Introduce passive OT monitoring. Once segmented, this gives visibility into unusual protocol traffic or new devices.
- Formalise OT change control and incident response, aligned to ISA/IEC 62443 zone-and-conduit documentation, so any future conduit exception is deliberate and logged.
Figures above are illustrative of commonly reported OT weakness categories, not a measured statistic from a single named study — used to show the typical shape of findings, not a precise count.
Where this fits with broader IT security posture
OT hardening does not happen in isolation from IT security posture. Because the most common pivot path starts on the IT side, enterprise IT hygiene — patching, MFA, phishing resistance, endpoint detection — is itself a prerequisite for OT security, not a separate workstream. A plant with strong Purdue-style segmentation but weak IT-side authentication has simply moved the weakest link, not removed it.
ISA/IEC 62443 provides the detailed control catalogue for zones, conduits, and system security levels, and NIST SP 800-82 remains the most complete public guide for operational technology environments; both are referenced extensively by CERT-In advisories covering ICS/SCADA vulnerabilities relevant to Indian manufacturing. See cert-in.org.in and nist.gov for current guidance.
A free VAPT scan from Bachao.AI is a reasonable first step for the IT-side network and remote-access surface most OT compromises pivot through, and the Bachao.AI blog covers related IT/OT risk topics. Dhisattva AI Pvt Ltd, the company behind Bachao.AI, builds continuous vulnerability visibility so manufacturers are not relying on a single point-in-time audit for a network that changes with every new vendor connection.