That is not a regional average. That is the weekly rate hitting Indian manufacturing organisations, week after week, with no slowdown in sight.

2,786 attacks per week.

India is now the Asia-Pacific epicentre of ransomware activity. 65 percent of affected Indian organisations paid the ransom in 2025, with average payouts reaching $1.35 million. January 2025 alone peaked at 185 ransomware incidents and over 113,000 detections, driven by the Xelera and Weaxor campaigns. Tengu ransomware hit Deck India Engineering, a heat-treatment firm. Raymond Limited, the fabric major, faced ransomware-driven IT disruption in Q1 2025.

The Indian factory floor is the new attack surface.

The architectural defence most Indian manufacturers think they have, the layered Purdue model with its enforced trust boundaries between IT and OT, is not the architectural defence they actually run. Most Indian factories have been operating on a flat network for years, with cosmetic segmentation that does not survive a determined attacker.

This week is about reading the gap between the architecture you have and the architecture you need.

But first, some catch-up on infra this week.

🔍 Purdue, Purdue 2.0, and the Flat-Network Reality

The Purdue Enterprise Reference Architecture has been the federal standard for industrial-control-system segmentation for more than two decades.

Level 0 is physical sensors and actuators on the machine. Level 1 is basic control, the PLC firmware that decides what the actuator does. Level 2 is supervisory control, the HMI screens the operator interacts with. Level 3 is site operations, the MES and process historian. Level 3.5 is the Industrial DMZ, the segmentation buffer between OT and IT. Level 4 is the site business systems. Level 5 is the enterprise network.

The model assumes those layers run on separate network segments with enforced trust boundaries, IT-OT data brokers in the DMZ, and explicit policy at each layer transition.

Flat is the reality.

For most Indian manufacturing plants, the layered Purdue model is the architecture diagram that hangs on a meeting-room wall, not the architecture that runs on the network underneath. The PLCs, HMIs, MES servers, business workstations, and corporate file shares often share a single IP plane with cosmetic VLANs rather than enforced segmentation. The Industrial DMZ exists as a single Windows server that holds the historian database, accessible from both the OT side and the IT side, with credentials shared informally between teams. The attacker who lands a phishing payload on the business workstation has, by 2 a.m., already found their way to the historian.

The 2026 evolution worth knowing.

The traditional Purdue six-layer-fixed model is shifting toward IEC 62443's "zones and conduits" framework, and a "Purdue 2.0" thinking that emphasizes risk-based asset management over fixed levels. The reframe acknowledges what Indian operators already know: cloud-connected SCADA, IIoT, predictive-maintenance agents, and remote-vendor maintenance access have broken the strict layering anyway. The right response is not to defend the Purdue diagram literally. It is to define risk zones around the assets that matter and to enforce conduit-level policy at the data flows between them.

For the Indian plant manager working backward from a 2027 audit:

✔ Inventory every IP-connected asset on the plant network. PLC, HMI, MES, vendor-laptop, IIoT gateway, smart camera, badge reader. All of them.

✔ Group those assets into risk zones (production-critical, safety-critical, business-adjacent, vendor-managed, guest).

✔ Define explicit conduit policy at the boundaries between zones, with logging.

✔ Treat the Industrial DMZ as a discipline, not a single server. Data broker patterns, one-way diodes for safety-critical telemetry, authenticated update channels for firmware.

✔ Map the policy to PESO, DGFASLI, BIS, and CERT-In expectations so the same documentation serves the safety audit and the cyber audit.

The architecture work is not glamorous. The plant whose Purdue diagram and Purdue reality match is the plant that does not appear in next quarter's ransomware victim list.

How we plug in: Our Complete IT Infrastructure Solution practice runs the zone-and-conduit modelling work for Indian manufacturing plants. We do the asset inventory, the risk-zone grouping, the conduit-policy definition, and the documentation that ties OT segmentation to PESO and BIS expectations. We have done this work across pharma, petrochem, textile, and automotive component clients. The architecture diagram you sign off on is the one that survives the regulator inspection.

🔐 Claroty, Nozomi, Dragos: Three Operational Stories

Three OT-security platforms dominate the global enterprise shortlist. Each is selling a different operational story, and the differences matter for the Indian plant.

Threat depth or asset coverage.

Claroty is the asset-and-governance leader. Gartner February 2025 CPS Protection Magic Quadrant Leader, positioned highest for Ability to Execute and furthest for Completeness of Vision. The differentiation: breadth of asset coverage (OT + IoT + IIoT + medical devices in healthcare adjacencies) and mature IT integration with ServiceNow, Splunk, and Palo Alto. The 2026 caveat: per the OT-security market tracking, Claroty's mindshare in the OT category dropped to 15.7 percent from a prior 25.1 percent. Translation: the platform is still the strongest on breadth, but the market is fragmenting and the buyer should ask hard questions about feature velocity over the next 18 months.

Nozomi Networks is the distributed-visibility leader. The Guardian sensor architecture supports both passive monitoring and Smart Polling, building comprehensive asset inventory across geographically distributed plants. Guardian Air adds wireless spectrum monitoring for the IIoT and Wi-Fi-attached devices that the Purdue model never anticipated. For an Indian conglomerate running 12 plants across 4 states with one central SOC, Nozomi's multi-site NDR-style monitoring is the natural fit.

Dragos is the threat-intelligence leader. The platform tracks 23 OT-specific threat groups with detailed behavioural profiles, indicators of compromise, MITRE ATT&CK for ICS TTPs, and hunting playbooks built into the operating interface. Dragos's strength is incident-response alignment: if your plant just had an incident and the SOC needs to know whether the attacker fits a known OT-focused group, Dragos's threat-intel depth is the differentiator. May 2026 mindshare: 8.3 percent (down from 11.6 percent), but the threat-depth differentiation is not what the mindshare number measures.

For the Indian buyer evaluating the three, the architectural fit question matters more than the analyst position.

👉 Claroty: asset coverage + governance reporting + IT-stack integration. Best for the regulated buyer whose audit committee wants a single dashboard across IT and OT.

👉 Nozomi: multi-site distributed monitoring. Best for the multi-plant conglomerate with one SOC.

👉 Dragos: threat intelligence + IR playbooks. Best for the plant that has already had an incident or is high-risk for one.

The mistake most procurement memos make is treating the three as ranked alternatives. They are positioned alternatives. The right vendor depends on the buyer's existing SOC capacity, threat profile, and audit-reporting requirements.

How we plug in: Our Cyberdefense practice runs the OT-security platform evaluation matrix for Indian manufacturing buyers. We have sat on the buyer side of Claroty, Nozomi, and Dragos pilots across pharma, petrochem, and textile engagements. The platform is the second decision. The first is the operating model: who in your team will read the alerts, who in your team will own the IR playbooks, and how does the OT signal land in your existing SIEM. We will help you frame the operating-model question before the vendor pitches arrive.

📌 Indian Manufacturing's Compound Pressure: Threat, Mandate, and Convergence

The Indian manufacturing buyer in 2026 faces a compound pressure that no single global manufacturer faces in the same shape.

Threat pressure. The 2,786-attacks-per-week rate and the 65 percent ransom-payment rate establish the baseline. Per the Seqrite India Cyber Threat Report 2026, manufacturing organisations face 3.79 million attacks per year as a sector aggregate. Tengu, Xelera, and Weaxor are the named campaigns, but the long tail of ransomware-as-a-service variants is what most plants actually face.

Mandate pressure. Make in India targets 25 percent smart factories by 2027, with IoT adoption at 15 percent today versus a 40 percent global benchmark. The transition is mid-cycle for most Indian plants, with brownfield-to-smart-factory upgrades happening on legacy network plant alongside live production. The mandate-driven IIoT rollout is, in many plants, what is breaking the Purdue boundary in the first place.

Convergence pressure. Wipro, TCS, Infosys, and HCL are pushing OT-IT convergence integration as part of broader digital-transformation contracts. Wipro's OT-IT convergence offering explicitly markets unified OT security management combined with IT-data analytics. Seqrite (Quick Heal) and eSec Forte target the SMB-and-mid-market manufacturing segment with endpoint-focused offerings. The Indian buyer evaluating the three globals (Claroty / Nozomi / Dragos) often deploys them through one of these Indian SI / MSSP partners, with the operational relationship sitting on the Indian side and the underlying detection platform sitting on the global side.

The four operational priorities Indian manufacturers are working toward for 2026, per TCS's Manufacturing Cyber Threat Outlook:

✔ Maintaining production continuity under attack (the resilience question, not the prevention question)

✔ Protecting digital engineering assets and IP (drawings, recipes, process parameters)

✔ Ensuring trusted supply-chain collaboration (vendor and partner access)

✔ Enabling secure adoption of AI and smart manufacturing (the IIoT and AI-inference workloads driving the IoT-adoption gap-closure)

The reframe matters. The 2024 conversation was about preventing the ransomware attack. The 2026 conversation is about producing through the attack while the IR team works. That is a fundamentally different architectural posture, and it changes the OT-security RFP from a feature-comparison exercise to a resilience-posture exercise.

How we plug in: Our VEMIO™ practice is the cross-stack observability layer that the resilience posture needs. When a ransomware event hits the IT side of the plant and the OT side is producing through it, the operator needs to see in real time which assets are still in their pre-incident state, which assets are degrading, and which conduits between zones are still safe to use. The OT-security platform reports that the attack happened. VEMIO™ reports that production held. We have built this for Indian manufacturing, pharma, and textile books for thirty-five years.

📋 PESO, DGFASLI, BIS: The Indian OT Regulatory Frame

The Indian regulator's reading of OT security is evolving faster than most plant teams have noticed.

For decades, the safety integrity of OT systems and the cyber integrity of the same systems were read as separate audit tracks. PESO inspected the petroleum-and-explosives safety side. DGFASLI inspected the labour-safety side. BIS set the standards for the equipment. Cyber events on the same systems were a CERT-In matter handled by the IT team in a separate office.

That separation is closing.

The cyber-physical reading is increasingly: a cyber event that affects the physical-safety integrity of an OT system is now jointly a PESO matter, a DGFASLI matter, a BIS standards matter, and a CERT-In incident-reporting matter. The Indian plant that has a ransomware event affecting its PLC layer is now potentially looking at four parallel audit tracks rather than one.

For the plant manager working backward from this regulatory reality, three contract clauses worth getting right with the OT-security vendor:

👉 What does the OT-incident reporting artefact look like, and can it be exported in a form that satisfies the PESO and DGFASLI documentation expectation as well as the CERT-In incident-report template?

👉 What is the regulator-grade audit trail for changes to OT segmentation policy, including who approved each policy change and when?

👉 What is the data-residency posture for the OT telemetry, especially given DPDP-adjacent regulator interpretations for OT process data that touches employee or personal data?

The compound regulatory pressure is not a separate workstream from the OT-security RFP. It is the procurement frame that the RFP has to fit inside.

How we plug in: Our Cyberdefense practice reads the joint PESO / DGFASLI / BIS / CERT-In bracket for Indian manufacturing clients. The OT-security vendor will sell you the platform. The compliance team needs the reporting artefacts in the format the regulators will accept. We close the gap.

India becomes APAC's ransomware hotspot, manufacturing sector witnessing surge in cyberattacks
VarIndia.
The 2,786-attacks-per-week primary source. Read for the sectoral breakdown.

Manufacturing absorbs 56% ransomware surge of global attacks in 2025
Industrial Cyber.
The global frame around the Indian number. Useful for the procurement memo that needs the global benchmark before the Indian-specific data lands.

Beyond the Purdue Model: ICS Security in Modern, Complex Network Architectures
Claroty.
The vendor-side primary source on the Purdue 2.0 reframe. Read alongside the IoT Worlds Purdue 2026 guide for the architecture-side balanced view.

TCS Manufacturing Cyber Threat Outlook 2026
TCS.
The Indian SI-side read on the four resilience priorities. Useful for the procurement memo that needs the Indian-services-vendor frame.

Seqrite India Cyber Threat Report 2026
Seqrite (Quick Heal).
The Indian product-vendor read. Read for the 3.79 million attacks per year sectoral aggregate and the named-campaign analysis.

💡 My Take

For most of the last decade, OT security in Indian manufacturing was treated as a separate problem, owned by a separate team, evaluated against a separate procurement budget, and reported to a separate part of the audit committee.

That separation is finishing.

OT is enterprise infrastructure.

The PLC on the machine, the HMI on the operator's screen, the historian in the Industrial DMZ, the MES on the site server, and the corporate file share on the business workstation are now operating on the same IP plane, often the same physical network, increasingly the same cloud-managed visibility platform. The attacker who breaches the corporate workstation finds the PLC two hops away. The attacker who breaches the IIoT vendor's remote-maintenance gateway finds the HMI directly. The architectural separation that the Purdue model assumed has not been there for years on most Indian factory floors.

The procurement question for the 2026-2027 Indian manufacturing buyer is not "should we add an OT-security platform to the security stack."

The procurement question is "what does our actual zone-and-conduit policy look like, what is the asset inventory underneath it, who in our team will own the OT-side alerts, and how does the OT signal land in the SIEM the SOC already runs?"

Once those four questions have answers, the OT-security platform decision (Claroty / Nozomi / Dragos / hybrid via Indian SI) follows. The deployment timeline follows. The PESO / DGFASLI / BIS / CERT-In reporting workflow follows. The audit-committee narrative follows.

The plants that get this sequence right in 2026 are the plants that produce through the next ransomware attack rather than appearing in the next quarterly ransomware-victim list.

VEMIO™ exists because the operational reality of running this kind of zone-and-conduit posture across a multi-plant Indian manufacturer needs an observability layer that the OT-security platform alone does not provide. The platform tells you the attack happened. The plant manager needs to know which production lines are still in their pre-incident state, which conduits between zones are still safe to use, and how to talk to the regulator about both.

The plant whose architecture diagram and operating reality finally match is the plant the attacker walks past.

Reply to this email with the one zone-and-conduit boundary you cannot currently document on your plant network, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.

Until next time,

Ajay Salvi & the Vinay Enterprises team.

Keep Reading