AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Pharmaceutical cybersecurity · India

In pharma, a breach is also a data-integrity question.

When a pharmaceutical plant is attacked, the systems come back slowly — not because the backups fail, but because validated systems must be shown to be in a validated state again before their records can be trusted. This page maps GxP expectations to the security controls behind them and the evidence an inspector will ask for, explains why recovery takes weeks, and shows how to test without breaking validation.

Reviewed 24 September 2026 · 11 sources cited

The short answer

Pharmaceutical cybersecurity is increasingly a GMP requirement. The July 2025 draft of EU GMP Annex 11 adds a security chapter — segmentation, timely patching, unique accounts, locked audit trails and penetration testing of internet-facing systems. 21 CFR Part 11 already requires access limits and secure audit trails, and India’s revised Schedule M requires controls against unauthorised changes to data. Test on validated replicas under change control, and plan recovery around requalification.

Why pharma

You cannot just restore a validated system.

In most businesses, recovery from ransomware ends when the systems are back. In pharmaceutical manufacturing it ends when Quality can trust the records again. A laboratory system, a quality-management system or a manufacturing execution system is validated: there is documented evidence that it does what it should, in a controlled configuration. Rebuild it after an attack and that evidence has to be re-established before batch records created on it can support release.

Indian manufacturers have lived this. In May 2023 Granules India told the stock exchanges that it had isolated IT assets after a security incident; it later said the attack had a major effect on operations because of changes to its IT systems and “the time needed for meeting the regulatory expectations, qualifications, recertifications, and fine-tuning of quality and production systems”, with delays in clearing material and a significant expected loss of revenue. Two months earlier, Sun Pharmaceutical had isolated its network after a ransomware attack, disclosed the theft of company and personal data, and warned that revenues in some businesses would be reduced.

Regulators are writing security into GMP itself. The draft revision of EU GMP Annex 11, published for consultation in July 2025, adds a chapter of twenty security clauses — security awareness with simulated tests, network segmentation and firewall reviews, supported platforms and timely patching, deactivated ports, anti-virus, and penetration testing of critical internet-facing systems at regular intervals — alongside stricter rules for unique accounts and audit trails that are enabled and locked at all times. 21 CFR Part 11 already requires limited access, authority checks and secure, time-stamped audit trails that do not obscure earlier entries. India’s revised Schedule M requires controls to prevent unauthorised access or changes to data, and a record of every change — the previous entry, who made the change and when.

The threat is steady. A 2026 industry report based on one vendor’s endpoint telemetry counted 3.79 million detections in Indian healthcare and pharmaceuticals between October 2024 and September 2025 — more than one in seven of all its detections. From May 2027, the personal data of patients and trial participants that manufacturers and CROs hold also comes under the DPDP Act.

Requirement by requirement

From GxP expectation to security control to evidence

The places where data-integrity expectations and security controls are the same thing, described in both languages — and what an inspector is likely to ask to see.

GxP expectationThe security control behind itEvidence to have readyWhere it comes from
Attributable — every action traced to one person Unique accounts; no shared or generic logins on instruments, LIMS or chromatography systems User lists per system, and proof that shared accounts were removed Draft Annex 11 §11.1 · Part 11 §11.10(d), §11.100(a)
Only authorised people act Strong authentication, auto-lock, inactivity logout, role-based permissions Access-control configuration, and recurrent access reviews with sign-off Draft Annex 11 §11.6–11.11 · Part 11 §11.10(g)
Audit trails that cannot be switched off Audit trail enabled and locked; no user, administrators included, can edit or disable it Audit-trail configuration, and records of timely, independent audit-trail review Draft Annex 11 §12.2–12.8 · Part 11 §11.10(e) · Schedule M §23
Systems stay in a validated state Supported platforms, timely patching, change control that includes security fixes Patch status per GxP system, with justified exceptions for unpatchable ones Draft Annex 11 §15.10–15.14 · Schedule M §23
GxP networks protected Segmentation between office, laboratory and production networks; firewall rules reviewed Network diagrams, firewall rule reviews, and the result of testing the boundary Draft Annex 11 §15.8–15.9
Internet-facing systems tested Penetration testing of critical systems that face the internet, at regular intervals Test reports, fixes and retests — especially findings that could affect data integrity Draft Annex 11 §15.19
Records survive Regular backups, physically and logically separated, with restore tests Backup schedules and dated restore-test results Draft Annex 11 §16 · Schedule M §23
People recognise attacks Security awareness training with simulated tests Training records and simulated-phishing results Draft Annex 11 §15.3

Clause references are to the July 2025 consultation draft of Annex 11, which may change before it is finalised; to 21 CFR Part 11; and to section 23 of India’s revised Schedule M. SemperWise is not a GMP inspectorate or certification body, and computer-system validation remains your Quality function’s decision.

The attack path

From a phished login to batches waiting on requalification

The composite path behind pharma ransomware. Each step is a place to test — and a place the damage can be contained.

  1. 1

    A foothold in IT

    A phished login, a reused password, or an internet-facing VPN or remote-access tool with a known flaw.

    External perimeter, remote access and phishing resilience

  2. 2

    Domain administrator

    Weak Active Directory permissions turn one account into control of every Windows server — including the ones that run GxP applications and were joined to the office domain.

    Active Directory privilege paths

  3. 3

    The GxP servers

    Laboratory, quality, manufacturing-execution and document-management servers are ordinary Windows machines holding regulated records. Shared admin accounts and flat networks make them easy to reach.

    Segmentation of GxP networks and accounts, tested from the office side

  4. 4

    Records in doubt

    Encrypted servers can be rebuilt; the question is whether the records and audit trails can be shown to be complete and unaltered. Backups that were reachable from the domain may not be trustworthy.

    Backup separation and a real restore test

  5. 5

    Requalification before release

    Rebuilt systems must be shown to be back in a validated state before their records support release — the delay Granules India described in 2023.

The cost of a pharma incident is set less by the encryption than by the requalification. Keeping GxP systems off the office domain, and backups out of the attacker’s reach, shortens the part that takes the longest.

Evidence

The numbers that frame the problem

Threat volume from an Indian industry report, and the size and timing of the regulatory changes. Each is linked in the sources.

3.79M Malware detections in Indian healthcare and pharma, October 2024 to September 2025, in one vendor’s telemetry [7]
14.24% Share of all detections in that report accounted for by healthcare and pharma [7]
20 Security clauses in the draft revision of EU GMP Annex 11, from segmentation and patching to penetration testing [1]
17 Chapters in the draft Annex 11 — covering access, audit trails, e-signatures, security, backup and archiving [1]
₹250 cr Turnover at or below which Indian manufacturers could seek until 31 December 2025 to meet revised Schedule M [5]
6 hours To report a cyber incident to CERT-In from the moment it is noticed [8]

The detection figures come from a single vendor’s endpoint telemetry and measure detections, not successful attacks.

Where manufacturers get hurt

Three patterns in pharma incidents

Two from Indian manufacturers’ own stock-exchange disclosures. The third is the finding inspectors and attackers both look for.

01

The network pulled offline

  1. Way inRansomware, with file systems breached and company and personal data taken.
  2. ThenThe company isolated its own network to contain it and began recovery.
  3. CostBusiness operations affected and revenues expected to fall in some businesses — Sun Pharmaceutical, March 2023.

What we test: Segmentation that lets you isolate part of the estate rather than all of it, and a recovery plan built around your most critical systems.

02

The systems back, the plant still waiting

  1. Way inA security incident that forced changes across IT systems.
  2. ThenRebuilt systems needed qualification and recertification, and quality and production systems had to be tuned again.
  3. CostDelays in clearing material, backlogs, and a significant expected loss of revenue — Granules India, 2023.

What we test: A recovery rehearsal that includes Quality: which systems need requalification, in what order, and what evidence proves each is back in a validated state.

03

The shared admin account

  1. Way inOne generic administrator login on a chromatography or laboratory system, known to several people and never changed.
  2. ThenNo way to tell who changed a method, a result or an audit-trail setting — for an inspector or an intruder.
  3. CostA data-integrity observation waiting to happen, and a password an attacker only needs to find once.

What we test: Account and privilege review across GxP systems, and whether audit trails can be disabled by anyone at all.

Next step

Test the GxP estate without breaking validation.

A 30-minute call with a practitioner who works alongside QA, not around it. No charge, and no obligation.

  • Where your GxP systems fall short of the draft Annex 11 security chapter
  • What can be tested on replicas and test instances, under your change control
  • How to rehearse a recovery that includes requalification
  • A fixed price, with a retest of every fix included
Book the call We reply within 24 business hours.

Where SemperWise fits

What we do for pharma manufacturers

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Validated production systems are never actively tested without your written instruction and your change control.

“The office-to-GxP boundary.”

Service

Network and Active Directory testing from the office side, to find every path to laboratory, quality and production servers.

Network penetration testing

“Our internet-facing GxP systems.”

Service

Penetration testing of portals and remote-access routes to critical systems, on validated test instances where production cannot be touched.

VAPT

“Could they get to the plant?”

Service

A red-team exercise with agreed objectives — reaching a GxP server, disabling an audit trail — to test detection and response.

Red team assessment

“Evidence an inspector can read.”

SemperWise One™

In SemperWise One, access reviews, patch exceptions, test results and restore tests kept with collection and expiry dates, mapped to your controls.

Compliance automation

“Our suppliers and CROs.”

SemperWise One™

Vendor assessments for the service providers and partners that touch your GxP data, with their evidence kept and dated.

Vendor and questionnaire tooling

“Our people.”

Service

Security awareness with simulated phishing — the draft Annex 11 asks for both, and for their effectiveness to be evaluated.

Security training

Terms

GxP and security terms, side by side

GxP
The family of “good practice” regulations — manufacturing (GMP), laboratory (GLP), clinical (GCP) — that govern regulated records and systems.
ALCOA+
Data-integrity principles: attributable, legible, contemporaneous, original and accurate, plus complete, consistent, enduring and available.
Data integrity
The assurance that records are complete, consistent and accurate throughout their life — the point where GxP and security meet.
Audit trail
A secure, time-stamped record of who created, changed or deleted a record, and why; required to be on and protected.
EU GMP Annex 11
The EU’s GMP annex on computerised systems; a revised draft published in July 2025 adds a full security chapter.
Annex 22
A new draft EU GMP annex, published with the Annex 11 draft, on the use of artificial intelligence in GMP.
21 CFR Part 11
The US FDA rule on electronic records and electronic signatures, including access controls and audit trails.
Revised Schedule M
India’s updated GMP requirements under the Drugs Rules, including a section on computerised systems.
CSV
Computer system validation — documented evidence that a computerised system does what it should, consistently.
CSA
Computer software assurance — a risk-based approach to that evidence; the FDA finalised its CSA guidance for device production and quality-system software in September 2025.
GAMP 5
ISPE’s widely used guide to a risk-based approach to compliant GxP computerised systems.
LIMS · CDS · MES · QMS
Laboratory information management, chromatography data, manufacturing execution and quality management systems — the GxP systems attackers reach most often.
Requalification
Re-establishing that a rebuilt or changed system is back in a validated state before its records are relied on.

Questions

Pharmaceuticals security — answered.

What buyers in this sector ask us before they commit to anything.

Is cybersecurity a GMP requirement?

Increasingly, yes. The July 2025 draft revision of EU GMP Annex 11 adds a chapter of security requirements — segmentation, firewall reviews, timely patching, anti-virus, security awareness with simulated tests and penetration testing of critical internet-facing systems — and tells regulated users to keep up with new security threats to GMP systems. 21 CFR Part 11 requires limited access, authority checks and secure audit trails, and India’s revised Schedule M requires controls to prevent unauthorised access or changes to data.

What does the draft Annex 11 say about security?

Its security chapter has twenty clauses. Among them: a security system that is continuously improved; security awareness training with simulated tests and evaluation of effectiveness; physical access controls; disaster recovery; network segmentation and reviewed firewalls; supported platforms and timely patching, with controls for any that cannot be patched; deactivated unused ports; anti-virus; penetration testing of critical internet-facing systems at regular intervals; and encrypted remote connections. The draft may change before it is finalised.

How does 21 CFR Part 11 relate to security?

Part 11 is largely a set of security controls in GxP language: limiting system access to authorised individuals, authority checks on who can sign, alter records or operate the system, secure computer-generated time-stamped audit trails that do not obscure earlier entries, and electronic signatures unique to one person and never reassigned. Testing those controls — and whether they can be bypassed — is ordinary security work.

Can you penetration-test validated GxP systems without breaking validation?

Yes, if it is planned with Quality. We test validated test or replica instances configured like production, review production configuration read-only, and test network boundaries from the office side. Anything that would touch validated production goes through your change control and needs your written instruction first. Plant-floor systems are reviewed passively — see our manufacturing page.

What does India’s revised Schedule M say about computerised systems?

Its section on computerised systems expects validation proportionate to complexity and criticality, changes made through a change procedure, a backup system so records are not permanently lost, controls to prevent unauthorised access or changes to data, and a record of every data change — the previous entry, who changed it and when. Manufacturers with turnover of ₹250 crore or less could seek an extension to 31 December 2025, so the revised schedule now applies across the industry.

Why do pharma companies take so long to recover from ransomware?

Because recovery includes showing that rebuilt systems are back in a validated state. Granules India described exactly this in 2023: the time needed for meeting regulatory expectations, qualifications and recertifications, and fine-tuning quality and production systems. Keeping GxP systems off the office domain, keeping backups out of an attacker’s reach and rehearsing requalification in advance all shorten it.

Does the FDA’s computer software assurance guidance apply to pharma?

The final guidance, issued in September 2025, addresses software used in medical-device production and quality systems. Many pharmaceutical quality teams draw on its risk-based thinking — concentrating assurance effort where a failure would affect product quality or patient safety — but check with your own regulatory function how it applies to your products and markets.

Does the DPDP Act affect pharmaceutical companies?

Yes, from about 13 May 2027, wherever a manufacturer, CRO or distributor holds personal data — patients in support programmes, trial participants, healthcare professionals and employees. Health data needs particular care. The Act adds consent and notice, security safeguards and breach notice to the Data Protection Board and affected people, alongside CERT-In’s six-hour reporting.

All 17 industries we serve

Next step

Security that QA can sign off on.

A 30-minute call, no charge. You leave knowing where your GxP systems fall short of the draft Annex 11 security chapter, what can be tested without touching validated production, and how to rehearse a recovery that includes requalification — with a written scope and fixed price if the work makes sense.