Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Honeywell's 2026 report finds a major gap in OT security readiness, with most leaders overestimating maturity and AI adoption primarily supporting, not replacing, human analysts.
Honeywell's 2026 OT Cybersecurity Benchmark Report reveals a disconnect between perceived OT security maturity and actual preparedness. While 88% of surveyed leaders rated their programs as mature, only 21% maintain a complete OT asset inventory. The report also highlights AI's growing role, with 72% using it for threat detection, though autonomous AI deployment remains rare at 23%.
- Honeywell report finds 88% of OT leaders rate programs mature, but only 21% have full asset inventory.
- 91% of energy & utilities respondents reported a significant OT incident in 12 months.
- 72% of respondents use AI for threat detection, but only 23% use autonomous/agentic AI.
Full article400 words · extracted from securityweek.com · click to collapse
Honeywell released its 2026 OT Cybersecurity Benchmark Report on Tuesday, and the findings point to a disconnect between how industrial organizations rate their operational technology (OT) security programs and how prepared they actually are. The report also examines AI’s impact on OT security.
Among 603 surveyed leaders across critical infrastructure sectors, 88% characterized their OT security programs as mature or design-led, yet only 21% maintain a complete inventory of their OT assets.
Respondents worked across critical infrastructure sectors, including energy, oil and gas, healthcare, maritime, and manufacturing, with participation spanning the Americas, EMEA and APAC regions.
Visibility gaps showed up in monitoring as well as inventory. Just 33% of respondents said OT is fully integrated into a centralized security operations center, and only 20% continuously monitor more than three-quarters of connected IoT devices.
Organizations that experienced a significant OT cybersecurity incident reported an average of 16.2 hours of downtime. Among incident-affected respondents, 21% estimated downtime costs above $100,000 per hour, and 4% put losses above $500,000 per hour.
Incident rates varied sharply by sector. Ninety-one percent of energy and utilities respondents and 87% of maritime respondents reported a significant OT cybersecurity incident in the past 12 months, compared with 54% of oil and gas respondents.
In healthcare, only 19% of respondents said facility and building systems are fully integrated into cybersecurity monitoring and protection.
Advertisement. Scroll to continue reading.
As for AI, 99% of respondents expect it to affect OT security operations within the next 2-3 years.
AI-enabled tools are already common across OT security functions, with 72% of respondents using AI for threat detection, 68% for continuous monitoring, and 59% for asset inventory.
Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference
Still, just 23% currently use autonomous or agentic AI for threat detection, suggesting most deployments so far support human analysts rather than act on their own.
“As AI moves from assisting analysts toward taking action, organizations will need clear decision rights, human oversight and testing that accounts for the operational consequences of an incorrect response,” Honeywell said in its report. “The goal of well-governed AI automation is to strengthen visibility and response without creating new risks to uptime, equipment or safety.”
Related: Only 13% of OT Network Segments Are Fully Isolated
Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Related: Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels