Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

A Stark Reality Check for OT Cybersecurity Programs: Honeywell Report Exposes Disparities Between Perceived Maturity and Actual Readiness

A recent report by Honeywell highlights a concerning disconnect between how industrial organizations rate their operational technology (OT) security programs and how prepared they actually are. The 2026 OT Cybersecurity Benchmark Report surveyed over 600 leaders across critical infrastructure sectors, revealing that despite claims of maturity, many organizations struggle with basic tasks such as maintaining an accurate inventory of OT assets.

The report found that only 21% of respondents maintain a complete inventory of their OT assets, leaving the majority vulnerable to attacks. This lack of visibility is further exacerbated by the fact that just one-third (33%) of respondents said OT is fully integrated into a centralized security operations center, making it difficult to monitor and respond to potential threats.

The consequences of these gaps in preparedness can be severe. Organizations that experienced a significant OT cybersecurity incident reported an average of 16.2 hours of downtime, with some estimating losses above $500,000 per hour. Sector-specific data reveals that energy and utilities organizations were disproportionately affected, with 91% reporting a significant OT cybersecurity incident in the past 12 months.

The report also sheds light on the growing use of artificial intelligence (AI) in OT security operations. While 99% of respondents expect AI to impact OT security within the next two to three years, current deployments are largely focused on assisting human analysts rather than acting autonomously. Only 23% currently use autonomous or agentic AI for threat detection, suggesting that most organizations still rely heavily on human oversight.

Honeywell’s report emphasizes the need for well-governed AI automation that strengthens visibility and response without creating new risks to uptime, equipment, or safety. As AI continues to evolve in OT security, organizations must prioritize clear decision rights, human oversight, and testing that accounts for operational consequences.

For industrial organizations looking to strengthen their OT cybersecurity posture, this report serves as a stark reality check. Rather than relying on perceived maturity, organizations should focus on building robust visibility and monitoring capabilities, including maintaining accurate asset inventories and integrating OT into centralized security operations centers. By doing so, they can mitigate the risks associated with OT cybersecurity incidents and ensure the continued reliability of critical infrastructure systems.

Ultimately, this report highlights the importance of prioritizing OT security and investing in solutions that support human analysts while also enabling autonomous AI decision-making. As the role of AI continues to grow in OT security, organizations must strike a balance between leveraging its benefits and minimizing its risks.


Source: SecurityWeek — 2026-09-23