Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

A concerning disconnect between industrial organizations’ perceptions of their operational technology (OT) security programs and their actual preparedness has been revealed in a recent report by Honeywell. The 2026 OT Cybersecurity Benchmark Report surveyed 603 leaders across critical infrastructure sectors, including energy, oil and gas, healthcare, maritime, and manufacturing, and found that despite 88% of respondents claiming to have mature or design-led OT security programs, significant visibility gaps exist.

One area where this disconnect is particularly evident is in asset inventory management. A mere 21% of respondents reported maintaining a complete inventory of their OT assets, suggesting that many organizations lack a clear understanding of what devices and systems they have connected to their networks. This is problematic because it makes it difficult for security teams to identify vulnerabilities and prioritize remediation efforts.

Furthermore, the report highlights a concerning trend in monitoring and incident response. Only 33% of respondents said that OT is fully integrated into a centralized security operations center (SOC), and only 20% continuously monitor more than three-quarters of connected IoT devices. This lack of visibility and oversight can leave organizations exposed to attacks, with 16.2 hours of average downtime reported among those who experienced a significant OT cybersecurity incident.

The consequences of such incidents can be severe. Among respondents who experienced significant OT cybersecurity incidents in the past year, 21% estimated that their losses exceeded $100,000 per hour, and 4% put losses above $500,000 per hour. The sector with the highest incident rates was energy and utilities, where 91% of respondents reported experiencing a significant OT cybersecurity incident.

The report also sheds light on the use of AI in OT security operations. A whopping 99% of respondents expect AI to affect OT security operations within the next two to three years, with 72% already using AI for threat detection, 68% for continuous monitoring, and 59% for asset inventory. However, most deployments so far are focused on augmenting human analysts rather than enabling autonomous or agentic AI.

As Honeywell notes in its report, “The goal of well-governed AI automation is to strengthen visibility and response without creating new risks to uptime, equipment or safety.” To achieve this goal, organizations will need to establish clear decision rights, implement human oversight, and conduct thorough testing that accounts for the operational consequences of an incorrect response.

For security teams looking to improve their OT security posture, one key takeaway from this report is the importance of developing a comprehensive asset inventory management strategy. This involves not just identifying and documenting devices and systems but also ensuring that all connected assets are properly monitored and secured. By prioritizing visibility and oversight, organizations can reduce their risk exposure and respond more effectively to potential threats.

Ultimately, the Honeywell report serves as a reminder that OT security is an ongoing challenge that requires sustained attention and effort from industrial organizations. By acknowledging the disconnect between perception and reality and taking steps to address it, these organizations can build stronger defenses against cyber threats and ensure the reliability and safety of their operations.


Source: SecurityWeek — 2026-09-23