Why this sector is different
Most industries have to be persuaded that a customer might audit them. In pharma that is routine, budgeted and expected. Clients audit suppliers, regulators inspect, and export customers arrive with their own requirements. The commercial case for security work is already understood.
What tends to be missing is the infrastructure underneath. The quality systems are mature; the network they run on frequently is not. We regularly find an environment where document control is rigorous and the network is completely flat.
What we are usually called about
- An export or contract customer has sent a security questionnaire. Increasingly these arrive alongside the quality audit rather than instead of it, and they ask about penetration testing, patching and access control specifically.
- Systems holding batch and quality data sit on the same flat network as everything else. One compromised office laptop can reach them. See network segmentation.
- A firewall installed years ago by a vendor who has moved on, with a rule base nobody has reviewed since.
- Plant, office, warehouse and a second unit connected in ways that grew rather than were designed, which is where SD-WAN usually comes up.
What we do
VAPT producing a report written to be sent onward to a customer or auditor, with an executive summary a non-technical director can read. Segmentation separating manufacturing-adjacent systems from general office traffic. Firewall sizing, deployment and rule rebuilds on Sophos, Fortinet or WatchGuard. And ongoing management so the configuration does not drift back between audits.
The audit conversation, practically
When a customer's auditor or a supplier questionnaire reaches the IT side of the business, the questions are consistent: is remote access protected by multi-factor authentication, is the network segmented, when was the last penetration test, how long are logs retained, and who has administrative access.
Most pharma businesses can answer the quality-side questions immediately and stall on those five. The work to close them is not large, but it is engineering work and it does not happen by writing a policy.
The one that causes the most difficulty is segmentation, because it touches systems people are nervous about. That is a sequencing problem rather than a reason not to do it: policy goes into monitor mode first so you can see exactly what would be blocked, then enforcement proceeds zone by zone with gaps between phases.
Two site patterns we see repeatedly
The single-unit manufacturer with an office upstairs. One building, production below, administration above, one network covering both. The failure mode is that a workstation in accounts sits in the same broadcast domain as the systems recording batch data. Separation here is usually a week of work and removes the largest single risk.
The multi-site operator. A plant at Taloja, an office in Navi Mumbai, sometimes a third unit or a warehouse. These are connected by whatever was available when each site opened, frequently a single VPN tunnel with no failover. When it drops, the office cannot see production data and nobody can dispatch. That is where SD-WAN earns its cost, and it is a connectivity conversation before it is a security one.
In both cases the useful first step is the same: establish what is actually reachable from where, in writing, before deciding what to buy.
Documentation you can hand over
An auditor asking about network security wants to see something, not be told something. We produce a network diagram, a written record of what was changed and why, and where testing was involved, a report structured so the executive summary can be read by someone non-technical and the detail can be handed to whoever implements fixes.
That documentation belongs to you and lives somewhere the business controls. If you change suppliers, it goes with you.
Where we work
We are based in Airoli and attend site across the Navi Mumbai and Thane belt, including the Taloja and Rabale estates, and travel to Tarapur. Remote work is delivered anywhere in India, though for a manufacturing site we usually want to walk the floor at least once.