Background
KEC International Ltd., part of the RPG Group and headquartered in Mumbai, India, is the world’s second largest manufacturer of electric power transmission towers. The manufacturer also provides products and services to infrastructure sectors, such as railways, civil engineering, oil and gas, and renewable energy. It operates across India, the UAE, and the Americas, with a workforce of 7,500 people. To date, the company has delivered cutting-edge manufacturing projects in over 110 countries. It prides itself on offering innovative designs and superior engineering and manufacturing capabilities.
Head of IT and Global CISO Pradipta Patro is responsible for securing the organization’s 5,000 assets, which are dispersed across 65 countries globally. He oversees a team of 54 people, with each plant having its own IT manager. A central IT team provides guidance on best practices to the plant IT managers.
The Challenge
KEC’s assets include industrial components such as transmission distributions, manufacturing system subfloors, and other operational technology (OT), which are converged with IT in a single environment. As Patro pointed out, cybercriminals are increasingly targeting physical infrastructure, due to the high impact of a breach in these environments, potentially disrupting production, damaging equipment, creating safety hazards, and impacting the supply chain.
“The key driver for us is to avoid production losses,” he explained. “If one of my assembly lines is cut off, processes are impacted.” Ensuring operational stability, continuity, and business predictability were his top priorities in seeking a modern solution with automated capabilities to identify, classify, and prioritize asset vulnerabilities and exposures in real time to accelerate risk mitigation.
Challenges
-
Monitoring and preventing threats to critical infrastructure in real time -
Gaining complete asset visibility, including legacy systems, across OT and IT -
Ensuring business continuity and operational reliability -
Securing remote access for OEMs to perform preventive maintenance and system configuration -
Identifying, classifying, prioritizing, and mitigating vulnerabilities -
Improving compliance monitoring and adherence to ISO and ISA/IEC 62443 frameworks
The Results
-
Eliminated manual asset management processes -
Decreased mean-time-to-respond (MTTR) by 20% to 30% -
Gained comprehensive visibility into assets across the IT/OT estate -
Improved overall security posture -
Prioritized vulnerabilities for targeted mitigation efforts -
Provided clean data to AI/ML models that boost system reliability and sustainability -
Supported effort to become a Global Lighthouse manufacturer