Honeywell: OT Security Teams Embrace AI, Autonomy Still Rare
Honeywell’s 2026 OT Cybersecurity Benchmark Report reveals significant gaps between industrial organizations’ self-assessments of their operational technology (OT) security programs and their actual preparedness.
Key Findings
The study, which surveyed 603 leaders across critical infrastructure sectors, highlights persistent challenges in asset visibility, incident response, and the integration of emerging technologies like artificial intelligence. The report underscores a stark contrast between perceived maturity and practical implementation.
Asset Visibility and Monitoring
While 88% of respondents described their OT security programs as mature or design-led, only 21% maintain a comprehensive inventory of their OT assets. This lack of visibility extends to monitoring practices, with 33% of organizations reporting full integration of OT into centralized security operations centers and 20% continuously monitoring more than three-quarters of connected IoT devices.
Financial and Operational Impacts
Financial and operational impacts of OT cybersecurity incidents are substantial. Organizations that experienced major breaches reported an average of 16.2 hours of downtime, with 21% estimating costs exceeding $100,000 per hour and 4% citing losses above $500,000 per hour.
Challenges in OT Security
Sector-specific vulnerabilities further complicate the landscape, as 91% of energy and utilities respondents and 87% of maritime sector participants reported significant incidents within the past year, compared to 54% in oil and gas and 19% in healthcare.
AI Adoption in OT Security
AI adoption in OT security is widespread but limited in scope. Ninety-nine percent of respondents anticipate AI’s influence on security operations within 2-3 years, with 72% already using AI for threat detection, 68% for continuous monitoring, and 59% for asset inventory. However, only 23% employ autonomous or agentic AI for threat detection, indicating that most implementations currently support human analysts rather than operate independently.
Governance and Risk Mitigation
Honeywell emphasizes that as AI transitions from analytical support to autonomous decision-making, organizations must establish clear governance frameworks. This includes defining decision rights, ensuring human oversight, and conducting rigorous testing to mitigate risks to system uptime, equipment integrity, and safety.
The report stresses that effective AI automation should enhance visibility and response capabilities without introducing new operational vulnerabilities.
Implications for Industrial Cybersecurity
The findings reflect broader challenges in securing industrial environments, where rapid technological adoption often outpaces foundational security measures. As AI becomes more integrated into OT workflows, the need for robust governance, continuous monitoring, and sector-specific risk management strategies will grow increasingly critical.
