New data from Honeywell Technologies reveals a significant disconnect between organizations’ perception of cybersecurity maturity and their actual operational readiness, despite rising artificial intelligence (AI)-enabled critical infrastructure threats. In its ‘2026 OT Security Benchmark Report,’ 88% described their OT cybersecurity programs as mature, yet only 21% reported maintaining a complete inventory of their OT assets, a critical foundation for effective security management across critical infrastructure.
Based on a survey of over 600 global industrial cybersecurity leaders, Honeywell’s inaugural 2026 OT Security Benchmark Report reveals critical vulnerabilities in industrial cybersecurity readiness across sectors. In the energy and utilities sector, 91% of respondents reported experiencing a significant OT cybersecurity incident in the past 12 months, while 87% of maritime respondents experienced similar incidents. Among oil and gas organizations affected by incidents, 28% reported effects spanning multiple regions, demonstrating the widespread impact of OT security breaches.
“As cyber threats increasingly impact physical operations, resilience depends on extending cybersecurity across every connected system that supports uptime and business continuity,” Jim Masso, president and CEO of Honeywell Technologies Process Automation, said in a Tuesday media statement. “Organizations can no longer afford to have this visibility gap.”
“Our findings confirm that there is a noteworthy gap between how organizations perceive their cybersecurity resilience and their actual capabilities,” said Paul Smith, Honeywell Technologies global portfolio director for cybersecurity. “Some of the sector-specific answers – such as 91% of energy and utilities respondents reporting that they experienced a significant OT cybersecurity incident in the past 12 months – really show why operational preparedness is essential right now across critical infrastructure.”
The 30-page report documents significant gaps between perceived and actual security maturity. Although 88% of respondents described their OT security programs as planned or design-led, only 33% say OT is fully integrated into an enterprise security operations center (SOC) with centralized visibility. Recovery readiness metrics similarly reveal misalignment: 92% placed their organizations in the top two tiers of recovery readiness, yet only 31% indicated they were fully ready for incidents.
Financial and operational consequences of incidents remain severe. Among incident-affected respondents, 21% estimated downtime costs exceeding $100,000 per hour, with 4% reporting costs above $500,000 per hour. Average downtime from respondents’ most significant OT cybersecurity incidents reached 16.2 hours. Organizations with reactive or tool-by-tool security programs experienced higher impact, with 21% reporting downtime of at least one day compared to 12% for those with planned or design-led programs.
Healthcare sector findings underscore safety risks. Only 19% of healthcare respondents reported that facility and building systems were fully integrated into cybersecurity monitoring and protection, while 67% stated that a significant cyber incident could severely affect caregiver or patient safety or damage physical equipment. Additionally, only 20% of respondents continuously monitored more than three-quarters of connected IoT devices such as cameras and thermostats. Organizations with stronger asset visibility demonstrated better incident recovery, with 42% reporting downtime of six hours or less compared to 25% among those with weaker asset visibility.
“Recent attacks on U.S. water utilities show that this kind of OT risk is not hypothetical. By early August 2026, attacks were reported against water systems in at least seven states,” according to the 2026 OT Security Benchmark Report. “The FBI and EPA said attackers had remotely accessed internet-facing programmable logic controllers, causing loss of monitoring or control and, in some cases, degraded water operations. Federal investigators are examining possible links to Iran-backed hackers.”
It added, “That’s the shift in risk industrial organizations now have to measure. OT security increasingly extends beyond traditional production systems. Process controls and field devices now operate alongside connected building, safety and physical security systems that can affect operations, equipment and people.”
Another interesting point that the Honeywell report raised is that when these systems are poorly governed or monitored, exposure can extend from a single asset to the entire operation it supports. That makes security coverage a critical maturity question for organizations: Are all connected systems identified, integrated into security operations and actively monitored? Can these critical systems be quickly and safely restored when a disruption occurs?
Clearly, OT security maturity matters because cyber incidents can affect physical operations and worker safety. They can also disrupt service delivery and create compliance pressure. But the high cost of downtime also makes maturity a business concern.
Honeywell noted that many organizations have taken steps to broaden OT security coverage. For example, 64% of respondents say their organizations include safety systems; 57% include physical security systems; and 56% include facility infrastructure, a category that can include chillers, switchgear and fire panels. Yet many organizations still leave connected systems outside the security program. That creates gaps in visibility and protection across the wider operational environment.
The stakes are often physical as 64% of respondents say a significant incident could have a severe or high impact on physical equipment and worker or customer safety. In operational environments, safety is part of OT security maturity, not a separate concern.
The impact of an incident can extend beyond the initial site. Among respondents whose organizations experienced a significant OT cybersecurity incident in the past 12 months, 40% report that it affected multiple sites in one region and 16% report effects across regions. A weakness at one facility can become an enterprise-wide operational risk.
The Honeywell 2026 OT Security Benchmark Report noted that when asked about the consequences of cyber incidents, 54% of respondents report operational downtime and production disruption. That puts the spotlight on recovery speed and effectiveness, which are key measures of an organization’s operational resilience. For their most significant incidents, respondents report an average of 16.2 hours of downtime. Among incident-affected organizations, 13% report downtime of at least one day.
Moreover, the financial impact is also material, with 38% report direct financial loss or revenue impact, while 21% estimate downtime costs above $100,000 per hour. For 4%, those costs exceed $500,000 per hour.
When it comes to incident exposure and expected recovery, the Honeywell report diverges significantly across critical infrastructure sectors. Energy and utilities respondents report the highest incident exposure at 91%, paired with equally strong confidence in 24-hour recovery, reflecting substantial exposure alongside operational resilience. Oil and gas presents a vulnerability gap: 54% report experiencing significant incidents, yet only 52% expect to restore critical systems within 24 hours, one of the weakest recovery rate among the sectors surveyed. Water and wastewater organizations report the lowest incident exposure at 37%, with 68% confident in 24-hour recovery capabilities.
Honeywell reported that legacy systems emerge as a consistent fault line in OT security, ranking highest across three measures of risk. Nearly half of respondents (48%) identified legacy systems and infrastructure constraints as the top barrier to improving OT security, while 47% cited legacy or unsupported systems as a leading source of cyber risk exposure. Among organizations affected by incidents, 45% ranked legacy systems among the top three contributors to downtime.
The challenge also spans sectors, with 44% of healthcare respondents identifying legacy or unsupported medical devices as their top challenge, while 40% of maritime respondents cited legacy onboard systems. In oil and gas, power grid and other energy sectors, 45% pointed to aging or legacy infrastructure. The report links the persistent risk to the long service lives of industrial systems, many of which were designed for isolated operation and lack modern security features such as authentication and encryption. As these systems become connected to wider networks or remote-access pathways, their legacy design can increase exposure to cyber threats.
“Compliance remains an important part of OT security maturity. Respondents whose organizations passed all compliance audits report significant incidents at nearly the same rate as those whose organizations had audit failures or findings: 74% versus 73%,” according to the Honeywell 2026 OT Security Benchmark Report. “That comparison does not show that compliance lacks preventive value. It shows only that audit status did not distinguish reported incident experience in this survey. Recovery measures show a clearer difference. Among respondents whose organizations passed all audits, 44% say they are fully recovery-ready, compared with 26% of those whose organizations had audit failures or findings, an 18 percentage-point difference.”
The report acknowledged that AI-enabled capabilities are already widely used in OT security operations. AI-enabled threat detection leads at 72%, followed by continuous monitoring at 68% and asset inventory at 59%. Full autonomy is more unusual. Most AI capabilities still assist human analysts, rather than acting independently. In total, 23% report autonomous or agentic operation for threat detection, and 23% also report it for continuous monitoring. Separately, 19% report autonomous or agentic operation for asset inventory. This adds another dimension to the OT security maturity question of how much authority AI systems are given, how their actions are governed and whether operators can trust them in live production environments.
Honeywell identified that OT security maturity depends on more than compliance or audit performance, with organizations first needing visibility into connected assets to determine whether critical systems are monitored, protected and included in recovery plans. The report identifies four linked capabilities, including asset identification, expanding security beyond traditional production systems, monitoring and governing connected environments, and protecting and recovering critical operations, supported by clear ownership, OT expertise and incident response capacity.
Audit status alone is not a reliable indicator, as organizations that passed all audits reported significant incidents at nearly the same rate as those with audit failures or findings. AI is increasingly used for detection, monitoring and asset inventory, while autonomous capabilities remain less common, highlighting the need for clear decision rights, human oversight and operational testing as AI autonomy expands.
The Honeywell report called upon CISOs and OT security leaders to strengthen OT resilience by integrating monitoring across operational environments, maintaining a complete and continuously updated inventory of connected systems, managing legacy risk in place, testing incident response and recovery under operational conditions, and arranging specialized expertise before it is needed.
This includes bringing OT visibility together with relevant facility data and physical security signals, extending asset discovery beyond production systems to safety, facility, building, physical security and connected IoT systems, applying compensating controls such as segmentation and continuous monitoring to aging or unsupported systems, validating recovery across sites and scenarios, defining incident ownership and involving operations, engineering, facilities and external response partners in planning and exercises, and ensuring control-system expertise and incident response support can be activated quickly across mixed environments.
The Honeywell report comes as foreign hackers targeted critical U.S. infrastructure across water and maritime sectors, compromising two Colorado water utilities in late August by manipulating pumping cycles, disabling alarms, and disrupting remote access while simultaneously attacking oil tankers, with one vessel losing communications for 30 hours in the Strait of Gibraltar. The USCG and FBI investigated both incidents amid broader activity by Iranian-backed groups probing water systems nationwide. Though no operational disruptions or safety impacts resulted, the attacks signal a strategic escalation in nation-state tactics from reconnaissance to active operational testing across vulnerable critical infrastructure sectors.


