Honeywell released its 2026 OT Cybersecurity Benchmark Report on Tuesday, and the findings point to a disconnect between how industrial organizations rate their operational technology (OT) security programs and how prepared they actually are. The report also examines AI’s impact on OT security.
Among 603 surveyed leaders across critical infrastructure sectors, 88% characterized their OT security programs as mature or design-led, yet only 21% maintain a complete inventory of their OT assets.
Respondents worked across critical infrastructure sectors, including energy, oil and gas, healthcare, maritime, and manufacturing, with participation spanning the Americas, EMEA and APAC regions.
Visibility gaps showed up in monitoring as well as inventory. Just 33% of respondents said OT is fully integrated into a centralized security operations center, and only 20% continuously monitor more than three-quarters of connected IoT devices.
Organizations that experienced a significant OT cybersecurity incident reported an average of 16.2 hours of downtime. Among incident-affected respondents, 21% estimated downtime costs above $100,000 per hour, and 4% put losses above $500,000 per hour.
Incident rates varied sharply by sector. Ninety-one percent of energy and utilities respondents and 87% of maritime respondents reported a significant OT cybersecurity incident in the past 12 months, compared with 54% of oil and gas respondents.
In healthcare, only 19% of respondents said facility and building systems are fully integrated into cybersecurity monitoring and protection.
As for AI, 99% of respondents expect it to affect OT security operations within the next 2-3 years.
AI-enabled tools are already common across OT security functions, with 72% of respondents using AI for threat detection, 68% for continuous monitoring, and 59% for asset inventory.
Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference
Still, just 23% currently use autonomous or agentic AI for threat detection, suggesting most deployments so far support human analysts rather than act on their own.
“As AI moves from assisting analysts toward taking action, organizations will need clear decision rights, human oversight and testing that accounts for the operational consequences of an incorrect response,” Honeywell said in its report. “The goal of well-governed AI automation is to strengthen visibility and response without creating new risks to uptime, equipment or safety.”
Related: Only 13% of OT Network Segments Are Fully Isolated
Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Related: Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels


