Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.

AI security OT

Honeywell released its 2026 OT Cybersecurity Benchmark Report on Tuesday, and the findings point to a disconnect between how industrial organizations rate their operational technology (OT) security programs and how prepared they actually are. The report also examines AI’s impact on OT security.

Among 603 surveyed leaders across critical infrastructure sectors, 88% characterized their OT security programs as mature or design-led, yet only 21% maintain a complete inventory of their OT assets.

Respondents worked across critical infrastructure sectors, including energy, oil and gas, healthcare, maritime, and manufacturing, with participation spanning the Americas, EMEA and APAC regions.

ICS Cybersecurity Conference

Visibility gaps showed up in monitoring as well as inventory. Just 33% of respondents said OT is fully integrated into a centralized security operations center, and only 20% continuously monitor more than three-quarters of connected IoT devices.

Organizations that experienced a significant OT cybersecurity incident reported an average of 16.2 hours of downtime. Among incident-affected respondents, 21% estimated downtime costs above $100,000 per hour, and 4% put losses above $500,000 per hour.

Incident rates varied sharply by sector. Ninety-one percent of energy and utilities respondents and 87% of maritime respondents reported a significant OT cybersecurity incident in the past 12 months, compared with 54% of oil and gas respondents. 

In healthcare, only 19% of respondents said facility and building systems are fully integrated into cybersecurity monitoring and protection.

Advertisement. Scroll to continue reading.

As for AI, 99% of respondents expect it to affect OT security operations within the next 2-3 years.

AI-enabled tools are already common across OT security functions, with 72% of respondents using AI for threat detection, 68% for continuous monitoring, and 59% for asset inventory.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

Still, just 23% currently use autonomous or agentic AI for threat detection, suggesting most deployments so far support human analysts rather than act on their own.

“As AI moves from assisting analysts toward taking action, organizations will need clear decision rights, human oversight and testing that accounts for the operational consequences of an incorrect response,” Honeywell said in its report. “The goal of well-governed AI automation is to strengthen visibility and response without creating new risks to uptime, equipment or safety.”

Related: Only 13% of OT Network Segments Are Fully Isolated

Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Related: Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.

AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.