IT Brief US - Technology news for CIOs & IT decision-makers
United States
Honeywell flags OT cybersecurity visibility gap in industry

Honeywell flags OT cybersecurity visibility gap in industry

Tue, 22nd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Honeywell has published its 2026 Operational Technology Cybersecurity Benchmark Report, which highlights a gap between how industrial organisations rate their cyber preparedness and the controls they have in place.

The report is based on a survey of more than 600 cybersecurity risk, compliance and operations leaders in energy, utilities, oil and gas, healthcare, maritime and manufacturing across the Americas, EMEA and APAC.

While 88% of respondents said their OT cybersecurity programmes were mature, only 21% said they maintained a complete inventory of their OT assets. This suggests many operators still lack a full view of the systems connected to industrial networks, even as digital tools spread across plants, facilities and infrastructure.

Cyber incidents also had a substantial operational impact. Respondents reported an average of 16.2 hours of downtime after their most significant OT cyber incident, and some estimated losses of more than $500,000 per hour.

Other findings point to gaps in monitoring and oversight. Just 33% of organisations said they had fully integrated OT into a centralised security operations centre, while only 20% said they continuously monitored connected devices such as sensors, cameras and building systems.

The survey also found that 66% had recorded an audit failure or significant compliance finding in the previous year. At the same time, 99% said they expected artificial intelligence to materially affect OT cybersecurity within the next two to three years, although only 23% reported using autonomous or agentic operation for threat detection.

Sector findings

Industry breakdowns showed a heavy recent incident burden across several parts of critical infrastructure. In energy and utilities, 91% of respondents said they had experienced a significant OT cybersecurity incident in the past 12 months.

Among maritime respondents, 87% reported a significant OT cybersecurity incident over the same period. In oil and gas, the figure was 54%.

Healthcare stood out for a different reason: only 19% of healthcare respondents said facility and building systems were fully integrated into cybersecurity monitoring and protection.

The findings come as companies across industrial sectors connect operational systems more closely with corporate IT environments. That shift can improve oversight and efficiency, but it can also expand the number of systems that need to be tracked, monitored and secured.

The results indicate that organisations with stronger visibility were four times better positioned to identify threats, respond to incidents and restore operations more quickly. They also suggest cyber events are increasingly treated not just as technology failures, but as operational problems that can affect safety, customer service and production continuity.

Tim Ager, Head of Cybersecurity, EMEA, Honeywell Technologies, said the operational consequences can spread well beyond IT teams when industrial systems are disrupted.

“When operational systems of mission-critical industries are compromised, whether in a hospital, airport, manufacturing facility or energy network, the consequences can be significant,” Ager said.

He said visibility across industrial environments remains central to resilience. “For critical infrastructure operators, resilience depends on understanding what is connected, maintaining visibility across operations and recovering quickly when disruption occurs. Our priority is keeping operations running safely and maintaining the essential services that people rely on every day,” Ager said.

Jim Masso, President and CEO of Honeywell Technologies Process Automation, also linked cyber resilience to visibility across connected systems. “As cyber threats increasingly impact physical operations, resilience depends on extending cybersecurity across every connected system that supports uptime and business continuity,” Masso said. “Organisations can no longer afford to have this visibility gap.”

The report adds to a growing body of industry research showing that confidence in cyber maturity does not always match operational readiness. In OT environments, where legacy systems often sit alongside newer connected assets, even basic controls such as complete asset inventories and continuous monitoring remain unevenly deployed.

That matters because OT incidents can have direct physical and financial effects. Unlike many breaches in office IT environments, disruption in industrial settings can halt production lines, affect building operations, interrupt transport activity or disrupt energy and healthcare services.

Among the clearest findings in the survey was how few respondents said they had complete knowledge of their OT estate: 21%.