OT Security Assessment: Securing 180 OT Assets Across 3 Pharma Plants

A WHO-GMP certified pharmaceutical manufacturer processing sterile injectables and solid oral dosage forms commissioned a passive IEC 62443 security assessment of their OT environment. The engagement covered 180 OT assets across 3 plants — without a single disruption to GMP batch processing.

180
OT assets assessed
3
Manufacturing plants
0
Batch processing disruptions
IEC 62443
Framework applied

The Challenge

The client's IT/OT convergence initiative — connecting plant historians to a cloud-based MES — had introduced new attack surface without a corresponding security review. Their regulatory team flagged the risk during an EU-GMP inspection, where the inspector questioned whether the SCADA and DCS systems had adequate cyber controls.

The assessment had to be completely passive (no active scanning of OT networks), GMP-compliant in methodology documentation, and had to produce a network segmentation design that could be implemented without requiring a plant shutdown — an impossibility in sterile manufacturing with 30-day batch cycles.

Our Approach

  • Passive asset discovery: Deployed Claroty passive sensors on span ports at each plant's OT switch. 180 assets identified across SCADA HMIs, PLCs, DCS controllers, batch servers, and historians — including 12 assets the client's IT team were unaware of.
  • IEC 62443-2-1 zone and conduit modelling: Mapped all OT communication flows. Defined 6 security zones (corporate IT, DMZ, plant supervisory, control, safety, lab). Identified 14 uncontrolled conduits violating zone boundaries.
  • Vulnerability assessment (passive): Identified 47 known CVEs across OT devices based on passive fingerprinting, including 3 critical CVEs in legacy PLC firmware with no available patches (risk-accepted with compensating controls).
  • GMP documentation: All assessment activities and findings documented in a format compatible with 21 CFR Part 11 and EU GMP Annex 11, suitable for regulatory review.

Key Findings

  • 12 shadow OT assets discovered (unmanaged switches, legacy HMIs connecting directly to plant historian)
  • 3 PLCs running firmware with critical CVEs (Siemens S7-300 family) — vendor patching not available; compensating controls designed
  • 14 uncontrolled zone boundary conduits — highest risk: direct RDP access from corporate IT to plant supervisory layer
  • Batch servers communicating with cloud MES without MES traffic inspection or DMZ isolation
  • No OT-specific incident response procedure — corporate IT runbooks not applicable to GMP manufacturing context

Outcomes & Impact

The network segmentation design was implemented over 18 months in a phased approach aligned to planned maintenance windows — zero batch disruptions. The uncontrolled conduits were eliminated through a combination of firewall rule changes, VPN replacement of direct RDP, and a purpose-built DMZ for MES/historian traffic.

The client's EU-GMP re-inspection accepted the OT security assessment report as adequate evidence of cyber risk management. The client subsequently used the IEC 62443 zone model as the basis for a company-wide OT security standard across their 7 global plants.

“The passive methodology was non-negotiable — we couldn't risk a scan disrupting a batch in a sterile suite. eNeoteric's approach was perfectly calibrated for a GMP environment, and the IEC 62443 documentation satisfied our EU inspector.”
VP Quality & RegulatoryWHO-GMP Pharmaceutical Manufacturer, Hyderabad

Related services

← All Case Studies Discuss your use case →

Request a Callback

Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead
Chat on WhatsApp