Macksofy Technologies
Pune · VAPT
CERT-In EmpanelledPune

VAPT Services in Pune · Auto, IT & OT

CERT-In empanelled VAPT for Hinjewadi IT majors, Chakan auto OEMs and Magarpatta GCCs — including IEC-62443-aligned OT/ICS scopes.

01
0+
Pune engagements
02
0 hr
Drive from Mumbai BKC
03
IEC-0
OT methodology
04
TISAX L0/L3
Auto-parent ready
VAPT in Pune

How a Macksofy vapt engagement runs in Pune.

Pune VAPT splits across three distinct geographies and three distinct buyer profiles. Hinjewadi Phase I, II and III host the IT-services majors and the GCC delivery centres — Infosys, Tata Technologies, Cognizant, Wipro, Capgemini and a long tail of mid-size product companies. Magarpatta and Kharadi host the BPO / GCC ecosystem with a strong US and European parent footprint. The Chakan, Talegaon and Ranjangaon belt — and the older Pimpri-Chinchwad PCMC industrial corridor — hosts the auto OEMs, Tier-1 suppliers and the OT-heavy manufacturing scope that diverges hardest from the rest of Macksofy's India practice. Connected-vehicle telematics, OEM-to-Tier-1 supplier networks and live shopfloor OT exposure are real engagement scope here, not buzzwords.

For auto OEMs in Chakan (Mercedes-Benz, Volkswagen, Mahindra, Tata Motors) and Tier-1 suppliers in Talegaon and Ranjangaon (Bosch, Magneti Marelli, Continental, Bharat Forge), we run IEC-62443 LSL-3 aligned OT segmentation reviews alongside the IT-side VAPT. The test boundary is explicit: business IT (corporate ERP, MES gateways, engineering EDA workstations), the IT-OT DMZ (Purdue Level 3.5), MES and SCADA at Purdue Levels 3 and 2, and PLC / DCS field devices at Levels 1 and 0. The supplier-VPN attack surface — the inbound connectivity Tier-1 and Tier-2 suppliers have into the OEM corporate segment — has become the favourite ransomware entry path for ALPHV/BlackCat, LockBit and Cl0p affiliates targeting the Indian auto industry; we test that path explicitly with attention to the legacy IPSec site-to-site tunnels still in production.

Manual abuse-case testing on the OT side never runs against live PLCs without explicit HSE clearance. We use passive listening (Wireshark with the OT protocol dissectors — Modbus, EtherNet/IP, Profinet, OPC UA), Nessus Pro with OT-safe scan policies, the Macksofy fork of conpot for PLC fingerprinting in a staging environment, and BloodHound on the engineering-station AD forest. Findings on the OT side are categorised by remediation window — which can close in the next planned maintenance window (a Saturday changeover), which need a longer change-management cycle through the OEM's MES-validation process, and which require a Tier-1-supplier contract renegotiation because the exposure is contractual.

For Hinjewadi IT-services and Magarpatta GCC clients, scopes look more like the Bengaluru SaaS pattern — multi-tenant authz, vendor APIs, SOC 2 Type II evidence — with a strong overlay of client-imposed cyber-control catalogues passed down from US automotive and EU automotive parents (Volkswagen Group's audit catalogue, BMW's information-security requirements, Mercedes-Benz's Group Information Security policy). The same VAPT produces a CERT-In format report plus a TISAX (Trusted Information Security Assessment Exchange) Level 2 or Level 3 readiness pack which is the parent-control-catalogue most German and EU OEMs actually require from their Pune partners.

Senior consultants drive from Mumbai BKC — three hours on the Mumbai-Pune Expressway with same-day arrival the norm. OT scopes always include at least one full day onsite walking the shopfloor with the plant HSE manager and the IT-OT convergence lead. For Chakan, Talegaon and Ranjangaon plants we plan the onsite block around shift changeover so testing weeks do not collide with production peaks. Hinjewadi engagements are easier — onsite at the client campus same-day, remote testing through the rest of the engagement.

Procurement at Pune auto OEMs is unusual: the plant IT head proposes the SoW, the head of QA validates against TISAX or VDA-ISA, and the head of plant operations or HSE signs off if any OT-touching work is in scope. Tier-1 suppliers add their OEM customer's compliance team to the loop because the supplier's audit cycle has to satisfy the OEM. We size proposals to match — fixed-fee SoW with explicit HSE blackout windows around critical production lines, no ad-hoc probes near live PLCs, no scans during shift changeover. The report calls out which findings can be remediated in the next maintenance window and which need a longer change-management cycle.

Pune IT-services procurement closes through the delivery-centre head and the client-account lead, sometimes with the US/EU client's CISO copied for the larger accounts. We sync the VAPT report to the next client-questionnaire cycle and ship a sanitised vendor pack — typically SIG Lite, CAIQ Lite and (for automotive clients) TISAX Level 2 readiness — alongside the technical findings. Where the client also has an Indian regulator overlay (BFSI captive ops in Magarpatta, for example), we add an RBI MD-ITGRC crosswalk to the same evidence base.

For listed Pune-headquartered manufacturers — auto-component listed entities and pharma R&D campuses — the engagement also produces SEBI listing-obligation cyber-security disclosure evidence that the company secretary needs for the next annual report. SEBI's Listing Obligations and Disclosure Requirements (LODR) Schedule II Part B now requires explicit board-level cyber oversight disclosure, and the VAPT report's executive summary is shaped to feed that disclosure rather than require a separate write-up.

Engagement workflow

Five phases. Pune timeline.

Every Macksofy vapt engagement in Pune runs through the same phased protocol — adapted to Pune-specific procurement, regulator and delivery realities.

01
Phase 01
HSE-Aware Scope
  • Joint kickoff with plant IT head, QA director and head of plant operations or HSE
  • Shift-changeover and critical-line blackout windows agreed and locked into the test schedule
  • Purdue-level scope decision — IT-only, IT-OT DMZ, MES/SCADA, field-device or full-stack
  • TISAX Level 2 / Level 3 or VDA-ISA crosswalk target confirmed with the OEM parent's audit team
02
Phase 02
IT-Side & AD
  • External attack surface mapping against the OEM / supplier TLD set
  • ADCS template enumeration with Certipy, BloodHound shortest-path on the engineering-station AD forest
  • Supplier-VPN inbound surface — IPSec site-to-site tunnel review, MFA enforcement on remote access
  • Connected-vehicle telematics edge and OEM cloud-backend (AWS Mumbai / Azure India South) testing
03
Phase 03
OT-Side Walk-Through
  • Shopfloor walk-through with plant HSE manager and IT-OT convergence lead
  • Passive OT protocol listening (Wireshark with Modbus, EtherNet/IP, Profinet, OPC UA dissectors)
  • IEC-62443 LSL-3 zone-and-conduit boundary review at Purdue Level 3.5 (IT-OT DMZ)
  • MES gateway and SCADA HMI authentication review without active PLC probing
04
Phase 04
Dual Reporting
  • CERT-In format VAPT report with IEC-62443 LSL-3 evidence annex
  • TISAX Level 2 / Level 3 or VDA-ISA crosswalk for the German / EU automotive parent
  • Remediation-window classification per finding — maintenance Saturday, longer MES-validation, supplier-contract
  • SEBI LODR Schedule II cyber-oversight evidence for listed Pune-headquartered manufacturers
05
Phase 05
Re-test & Plant Handover
  • Free re-test of Critical and High inside the OEM's next maintenance window
  • Plant-handover memo for the HSE manager and IT-OT convergence lead
  • CERT-In empanelled closure letter formatted for the OEM's parent audit team
  • Supplier-contract memo where exposures require Tier-1 / Tier-2 renegotiation
Industries served

Which Pune verticals we deliver VAPT for.

Auto OEMs

Chakan and PCMC OEMs — IT, IT-OT DMZ and shopfloor OT segmentation with TISAX Level 2/3 crosswalk.

Tier-1 auto suppliers

Talegaon, Ranjangaon and PCMC Tier-1s — supplier-VPN surface, MES gateway and VDA-ISA readiness.

Hinjewadi IT-services

Phase I / II / III IT-services campuses — parent-client questionnaire and SOC 2 Type II evidence.

Magarpatta & Kharadi GCCs

US / EU enterprise GCCs — parent-control-catalogue VAPT with privilege-path testing to offshore prod.

Pharma R&D campuses

Pune pharma R&D — limited GMP overlay layered on top of the IT-services VAPT methodology.

Listed Pune manufacturers

Auto-component and engineering listed entities — SEBI LODR Schedule II cyber-oversight disclosure evidence.

What ships

The Pune deliverable pack.

Every Pune vapt engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.

  • VAPT report in CERT-In empanelled format with IEC-62443 LSL-3 evidence annex
  • TISAX Level 2 / Level 3 and VDA-ISA crosswalk for German / EU automotive parents
  • Shopfloor walk-through memo with HSE-manager and IT-OT convergence-lead sign-off
  • Supplier-VPN attack-surface memo with Tier-1 / Tier-2 contractual exposure callouts
  • Remediation-window classification per finding — maintenance Saturday, MES-validation cycle, supplier-contract
  • SEBI LODR Schedule II cyber-oversight disclosure evidence for listed manufacturers
  • Free re-test of every Critical and High inside the OEM's next maintenance window
  • CERT-In empanelled closure letter and OEM-parent-audit handover pack
Recent Pune engagement

A Pune vapt case study.

Pune-headquartered Tier-1 Auto Supplier (Talegaon + Ranjangaon plants)
Scope

ISO 27001:2022 implementation, DPDP RoPA, IT + IT-OT DMZ + MES gateway VAPT across three plants, TISAX Level 3 readiness for the German OEM parent; eight-week engagement with three onsite legs

Outcome

ISO 27001 certification issued in 18 weeks; TISAX Level 3 readiness pack accepted by the OEM parent at the next vendor-audit cycle; OT/IT zoning hardened to IEC-62443 LSL-3; one supplier-VPN exposure that mirrored the entry path used in the 2022 Bharat-auto ALPHV incident, closed pre-disclosure; supplier-contract memo accepted by the OEM's procurement function as the new template for incoming Tier-2 onboardings.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
IK
Inspector K. Joshi
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions Pune buyers ask before signing.

Yes. OT-side testing runs against passive listening (Wireshark with the OT protocol dissectors) and HSE-cleared zone-and-conduit reviews, never active PLC probing on live lines. The onsite block is planned around shift changeover and explicit blackout windows around critical production lines.
More services in Pune

Other Macksofy engagements in Pune.

VAPT in other cities

Same engagement, other Macksofy metros.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements
Human verification· Cloudflare Turnstile

By submitting this form you agree to be contacted by Macksofy. We typically respond within a few business hours and never share your details. Protected by Cloudflare Turnstile and rate limiting.