Honeywell Technologies has released its 2026 Operational Technology (OT) Cybersecurity Benchmark Report, highlighting significant differences between how industrial organizations perceive their cybersecurity maturity and the level of visibility and operational readiness they actually have.
The report is based on a survey of more than 600 cybersecurity, risk, compliance and operations leaders across manufacturing, energy, oil and gas, healthcare, maritime and other critical infrastructure sectors.

OT Visibility Remains a Major Challenge
One of the report’s most notable findings is that 88% of respondents consider their OT cybersecurity programs mature, while only 21% report having a complete inventory of their OT assets.
This gap is particularly important for industrial environments because modern facilities often contain a mixture of PLCs, DCS controllers, HMIs, industrial networks, sensors, remote-access systems and legacy equipment.
Without a complete inventory, security teams may have difficulty identifying which devices are connected to operational networks and determining which systems require additional protection.
Honeywell’s report also found that only 33% of organizations have fully integrated OT into a centralized security operations center, while just 20% continuously monitor connected IoT devices such as sensors and cameras.
Cyber Incidents Can Directly Affect Production
OT cybersecurity incidents can have consequences beyond the loss of digital information.
According to the report, organizations experienced an average of 16.2 hours of downtime from their most significant OT cybersecurity incidents, with reported losses reaching as much as $500,000 per hour.
For industrial manufacturers, an interruption to automation systems can potentially affect production lines, process equipment, safety systems and supply-chain operations.
This makes cybersecurity increasingly connected with traditional industrial reliability and maintenance strategies.
AI Is Becoming Part of OT Security
Artificial intelligence is another major theme in the report.
99% of respondents expect AI to affect OT cybersecurity within the next two to three years. However, only 23% currently report using autonomous or agentic operation for threat detection.
AI-enabled security tools can analyze large quantities of operational and network information, helping security teams identify unusual behavior and prioritize potential threats.
However, the current adoption pattern indicates that AI is still largely being used to assist human cybersecurity professionals rather than operate independently.
Asset Visibility Supports Industrial Resilience
Complete asset visibility is becoming increasingly important as factories and process facilities connect more equipment to digital networks.
A modern industrial cybersecurity architecture may need to monitor:
- PLC and DCS controllers
- Industrial Ethernet networks
- HMIs and engineering stations
- Remote-access systems
- Sensors and IoT devices
- Building and facility systems
- Edge computing equipment
- Legacy automation hardware
Honeywell’s findings indicate that organizations with stronger visibility were better positioned to identify threats, respond to incidents and restore operations.
For automation engineers, this means cybersecurity is increasingly becoming part of the overall lifecycle management of industrial control systems.
Different Industries Face Different Challenges
The report also shows significant differences between industrial sectors.
Energy and utilities organizations reported particularly high exposure, with 91% saying they had experienced a significant OT cybersecurity incident during the previous 12 months.
The maritime sector reported an 87% incident rate, while 54% of oil and gas respondents reported a significant incident during the same period.
These environments can be especially challenging because they often combine geographically distributed assets, legacy control systems and increasingly connected digital infrastructure.
Cybersecurity Moves Closer to Automation
Honeywell’s latest report illustrates how industrial cybersecurity is becoming an integral component of automation modernization.
As manufacturers adopt industrial AI, cloud connectivity, remote monitoring, IIoT, PLC networking and advanced DCS technologies, the number of connected operational assets continues to increase.
Future OT security strategies will therefore require more than network protection alone. Complete asset visibility, continuous monitoring, vulnerability management, AI-assisted threat detection and rapid recovery are becoming increasingly important parts of modern industrial automation.
For manufacturers and critical infrastructure operators, the growing convergence of automation, AI and cybersecurity is likely to make OT security a central element of long-term digital transformation.