VAPT Services in Pune · Auto, IT & OT
CERT-In empanelled VAPT for Hinjewadi IT majors, Chakan auto OEMs and Magarpatta GCCs — including IEC-62443-aligned OT/ICS scopes.
How a Macksofy vapt engagement runs in Pune.
Pune VAPT splits across three distinct geographies and three distinct buyer profiles. Hinjewadi Phase I, II and III host the IT-services majors and the GCC delivery centres — Infosys, Tata Technologies, Cognizant, Wipro, Capgemini and a long tail of mid-size product companies. Magarpatta and Kharadi host the BPO / GCC ecosystem with a strong US and European parent footprint. The Chakan, Talegaon and Ranjangaon belt — and the older Pimpri-Chinchwad PCMC industrial corridor — hosts the auto OEMs, Tier-1 suppliers and the OT-heavy manufacturing scope that diverges hardest from the rest of Macksofy's India practice. Connected-vehicle telematics, OEM-to-Tier-1 supplier networks and live shopfloor OT exposure are real engagement scope here, not buzzwords.
For auto OEMs in Chakan (Mercedes-Benz, Volkswagen, Mahindra, Tata Motors) and Tier-1 suppliers in Talegaon and Ranjangaon (Bosch, Magneti Marelli, Continental, Bharat Forge), we run IEC-62443 LSL-3 aligned OT segmentation reviews alongside the IT-side VAPT. The test boundary is explicit: business IT (corporate ERP, MES gateways, engineering EDA workstations), the IT-OT DMZ (Purdue Level 3.5), MES and SCADA at Purdue Levels 3 and 2, and PLC / DCS field devices at Levels 1 and 0. The supplier-VPN attack surface — the inbound connectivity Tier-1 and Tier-2 suppliers have into the OEM corporate segment — has become the favourite ransomware entry path for ALPHV/BlackCat, LockBit and Cl0p affiliates targeting the Indian auto industry; we test that path explicitly with attention to the legacy IPSec site-to-site tunnels still in production.
Manual abuse-case testing on the OT side never runs against live PLCs without explicit HSE clearance. We use passive listening (Wireshark with the OT protocol dissectors — Modbus, EtherNet/IP, Profinet, OPC UA), Nessus Pro with OT-safe scan policies, the Macksofy fork of conpot for PLC fingerprinting in a staging environment, and BloodHound on the engineering-station AD forest. Findings on the OT side are categorised by remediation window — which can close in the next planned maintenance window (a Saturday changeover), which need a longer change-management cycle through the OEM's MES-validation process, and which require a Tier-1-supplier contract renegotiation because the exposure is contractual.
For Hinjewadi IT-services and Magarpatta GCC clients, scopes look more like the Bengaluru SaaS pattern — multi-tenant authz, vendor APIs, SOC 2 Type II evidence — with a strong overlay of client-imposed cyber-control catalogues passed down from US automotive and EU automotive parents (Volkswagen Group's audit catalogue, BMW's information-security requirements, Mercedes-Benz's Group Information Security policy). The same VAPT produces a CERT-In format report plus a TISAX (Trusted Information Security Assessment Exchange) Level 2 or Level 3 readiness pack which is the parent-control-catalogue most German and EU OEMs actually require from their Pune partners.
Senior consultants drive from Mumbai BKC — three hours on the Mumbai-Pune Expressway with same-day arrival the norm. OT scopes always include at least one full day onsite walking the shopfloor with the plant HSE manager and the IT-OT convergence lead. For Chakan, Talegaon and Ranjangaon plants we plan the onsite block around shift changeover so testing weeks do not collide with production peaks. Hinjewadi engagements are easier — onsite at the client campus same-day, remote testing through the rest of the engagement.
Procurement at Pune auto OEMs is unusual: the plant IT head proposes the SoW, the head of QA validates against TISAX or VDA-ISA, and the head of plant operations or HSE signs off if any OT-touching work is in scope. Tier-1 suppliers add their OEM customer's compliance team to the loop because the supplier's audit cycle has to satisfy the OEM. We size proposals to match — fixed-fee SoW with explicit HSE blackout windows around critical production lines, no ad-hoc probes near live PLCs, no scans during shift changeover. The report calls out which findings can be remediated in the next maintenance window and which need a longer change-management cycle.
Pune IT-services procurement closes through the delivery-centre head and the client-account lead, sometimes with the US/EU client's CISO copied for the larger accounts. We sync the VAPT report to the next client-questionnaire cycle and ship a sanitised vendor pack — typically SIG Lite, CAIQ Lite and (for automotive clients) TISAX Level 2 readiness — alongside the technical findings. Where the client also has an Indian regulator overlay (BFSI captive ops in Magarpatta, for example), we add an RBI MD-ITGRC crosswalk to the same evidence base.
For listed Pune-headquartered manufacturers — auto-component listed entities and pharma R&D campuses — the engagement also produces SEBI listing-obligation cyber-security disclosure evidence that the company secretary needs for the next annual report. SEBI's Listing Obligations and Disclosure Requirements (LODR) Schedule II Part B now requires explicit board-level cyber oversight disclosure, and the VAPT report's executive summary is shaped to feed that disclosure rather than require a separate write-up.
Five phases. Pune timeline.
Every Macksofy vapt engagement in Pune runs through the same phased protocol — adapted to Pune-specific procurement, regulator and delivery realities.
- Joint kickoff with plant IT head, QA director and head of plant operations or HSE
- Shift-changeover and critical-line blackout windows agreed and locked into the test schedule
- Purdue-level scope decision — IT-only, IT-OT DMZ, MES/SCADA, field-device or full-stack
- TISAX Level 2 / Level 3 or VDA-ISA crosswalk target confirmed with the OEM parent's audit team
- External attack surface mapping against the OEM / supplier TLD set
- ADCS template enumeration with Certipy, BloodHound shortest-path on the engineering-station AD forest
- Supplier-VPN inbound surface — IPSec site-to-site tunnel review, MFA enforcement on remote access
- Connected-vehicle telematics edge and OEM cloud-backend (AWS Mumbai / Azure India South) testing
- Shopfloor walk-through with plant HSE manager and IT-OT convergence lead
- Passive OT protocol listening (Wireshark with Modbus, EtherNet/IP, Profinet, OPC UA dissectors)
- IEC-62443 LSL-3 zone-and-conduit boundary review at Purdue Level 3.5 (IT-OT DMZ)
- MES gateway and SCADA HMI authentication review without active PLC probing
- CERT-In format VAPT report with IEC-62443 LSL-3 evidence annex
- TISAX Level 2 / Level 3 or VDA-ISA crosswalk for the German / EU automotive parent
- Remediation-window classification per finding — maintenance Saturday, longer MES-validation, supplier-contract
- SEBI LODR Schedule II cyber-oversight evidence for listed Pune-headquartered manufacturers
- Free re-test of Critical and High inside the OEM's next maintenance window
- Plant-handover memo for the HSE manager and IT-OT convergence lead
- CERT-In empanelled closure letter formatted for the OEM's parent audit team
- Supplier-contract memo where exposures require Tier-1 / Tier-2 renegotiation
Which Pune verticals we deliver VAPT for.
Auto OEMs
Chakan and PCMC OEMs — IT, IT-OT DMZ and shopfloor OT segmentation with TISAX Level 2/3 crosswalk.
Tier-1 auto suppliers
Talegaon, Ranjangaon and PCMC Tier-1s — supplier-VPN surface, MES gateway and VDA-ISA readiness.
Hinjewadi IT-services
Phase I / II / III IT-services campuses — parent-client questionnaire and SOC 2 Type II evidence.
Magarpatta & Kharadi GCCs
US / EU enterprise GCCs — parent-control-catalogue VAPT with privilege-path testing to offshore prod.
Pharma R&D campuses
Pune pharma R&D — limited GMP overlay layered on top of the IT-services VAPT methodology.
Listed Pune manufacturers
Auto-component and engineering listed entities — SEBI LODR Schedule II cyber-oversight disclosure evidence.
The Pune deliverable pack.
Every Pune vapt engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.
- VAPT report in CERT-In empanelled format with IEC-62443 LSL-3 evidence annex
- TISAX Level 2 / Level 3 and VDA-ISA crosswalk for German / EU automotive parents
- Shopfloor walk-through memo with HSE-manager and IT-OT convergence-lead sign-off
- Supplier-VPN attack-surface memo with Tier-1 / Tier-2 contractual exposure callouts
- Remediation-window classification per finding — maintenance Saturday, MES-validation cycle, supplier-contract
- SEBI LODR Schedule II cyber-oversight disclosure evidence for listed manufacturers
- Free re-test of every Critical and High inside the OEM's next maintenance window
- CERT-In empanelled closure letter and OEM-parent-audit handover pack
A Pune vapt case study.
ISO 27001:2022 implementation, DPDP RoPA, IT + IT-OT DMZ + MES gateway VAPT across three plants, TISAX Level 3 readiness for the German OEM parent; eight-week engagement with three onsite legs
ISO 27001 certification issued in 18 weeks; TISAX Level 3 readiness pack accepted by the OEM parent at the next vendor-audit cycle; OT/IT zoning hardened to IEC-62443 LSL-3; one supplier-VPN exposure that mirrored the entry path used in the 2022 Bharat-auto ALPHV incident, closed pre-disclosure; supplier-contract memo accepted by the OEM's procurement function as the new template for incoming Tier-2 onboardings.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions Pune buyers ask before signing.
Other Macksofy engagements in Pune.
Same engagement, other Macksofy metros.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
