Decoding the world of cybersecurity

· ·

OT confidence outpaces industrial asset visibility

A Honeywell survey found 88% of industrial security leaders described their OT programmes as mature, while only 21% reported complete operational-technology asset inventories.

OT confidence outpaces industrial asset visibility
Summary
  • Honeywell surveyed more than 600 cyber, risk, compliance, and operations leaders across critical-infrastructure sectors.
  • Eighty-eight per cent described their OT cybersecurity programmes as mature, while 21% reported complete OT asset inventories.
  • Respondents reported an average 16.2 hours of downtime from their most significant cyber incidents.

Industrial organisations are reporting high confidence in the maturity of their operational-technology security programmes despite substantial gaps in basic asset visibility, according to a Honeywell survey of more than 600 cyber, risk, compliance, and operations leaders.

Eighty-eight per cent of respondents described their OT cybersecurity programmes as mature, while only 21% said they had a complete inventory of operational-technology assets.

The gap is consequential because an organisation cannot consistently monitor, patch, segment, or recover equipment it does not know it operates. Industrial estates can also contain legacy systems, building-management equipment, sensors, specialist controllers, and devices maintained outside the central IT function.

Honeywell’s 2026 Operational Technology Cybersecurity Benchmark Report surveyed organisations across the Americas, EMEA, and Asia-Pacific in sectors including energy, oil and gas, healthcare, maritime, and manufacturing.

Respondents reported an average 16.2 hours of downtime from their most significant cyber incidents. Honeywell said losses reached as much as $500,000 an hour in some cases; that upper figure is not an average loss across the survey population.

Visibility gaps extended beyond inventories. Thirty-three per cent of respondents said OT had been fully integrated into a centralised security operations centre, while 20% reported continuous monitoring of connected IoT equipment such as cameras and sensors.

The findings are vendor-commissioned survey data and rely in part on respondents’ assessments of their own programmes. They should not be treated as an independent audit of industrial-security maturity worldwide.

The contrast between confidence and visibility is nevertheless useful because “maturity” can mean different things inside an industrial organisation. A company may have established policies, incident-response processes, specialist staff, or segmented control networks while still lacking comprehensive visibility into every device and dependency.

Operational environments make that inventory problem harder than conventional IT estates. Equipment can remain in production for decades, maintenance windows can be constrained by safety and availability requirements, and specialist systems may be maintained by engineering teams or third-party vendors rather than central technology functions.

That creates a resilience issue as well as a detection problem. Incident response in an industrial environment has to consider which physical processes depend on an affected system, whether equipment can be safely isolated, which replacement components exist, and how long restoration will take.

The reported average of more than 16 hours of downtime therefore has a different character from interruption to an ordinary office application. Depending on the sector, prolonged OT disruption can affect production, logistics, building operations, healthcare facilities, energy delivery, or safety-related systems.

Honeywell also found that 99% of respondents expect AI to affect OT security within the next two to three years, while 23% reported using autonomous or agentic operations for threat detection.

That adds another layer to the visibility problem. Automation can analyse large estates more quickly, but automated detection still depends on reliable information about which assets exist, how they communicate, which processes they support, and what constitutes abnormal behaviour.

European industrial operators are simultaneously facing greater regulatory scrutiny around critical dependencies under frameworks including NIS2. Regulation does not solve asset discovery, but it increases the importance of being able to demonstrate how critical systems, suppliers, and resilience measures are governed.

The benchmark’s most useful finding is therefore the distance between organisations’ perception of maturity and the operational evidence needed to support that perception.

×