news.mlab.sh
Back to the feed
threat-intel

Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

Medium
Summary

A Honeywell report reveals a significant gap between how industrial organizations perceive their OT security maturity and their actual preparedness. Despite widespread adoption of AI-powered security tools, true autonomy in threat detection and response remains rare, with most deployments still relying on human analysts. The report highlights substantial visibility issues and varying incident rates across critical infrastructure sectors.

A recent Honeywell report, the 2026 OT Cybersecurity Benchmark Report, indicates a disconnect between the perceived maturity of operational technology (OT) security programs and the actual state of readiness within industrial organizations. The study surveyed 603 leaders across sectors including energy, oil and gas, healthcare, maritime, and manufacturing, spanning the Americas, EMEA, and APAC regions. The report found that while 88% of respondents described their OT security programs as mature or design-led, only 21% maintain a complete inventory of their OT assets – a key indicator of effective security posture.

Significant visibility gaps were identified, particularly in monitoring and asset inventory. Only 33% of respondents indicated that OT is fully integrated into a centralized security operations center, and only 20% continuously monitor more than three-quarters of connected IoT devices. Organizations that experienced a significant OT cybersecurity incident reported an average of 16.2 hours of downtime, with 21% estimating downtime costs above $100,000 per hour and 4% exceeding $500,000 per hour. Incident rates varied considerably by sector, with energy and utilities (91%) and maritime (87%) reporting the highest incidence of significant incidents, compared to 54% in oil and gas.

In healthcare, only 19% of respondents stated that facility and building systems are fully integrated into cybersecurity monitoring and protection. The report emphasizes the growing influence of AI in OT security, with 99% of respondents anticipating its impact within the next 2-3 years. AI is currently utilized across various OT security functions, including threat detection (72%), continuous monitoring (68%), and asset inventory (59%). However, only 23% currently employ autonomous or agentic AI for threat detection, suggesting that most deployments still require human oversight.

“As AI moves from assisting analysts toward taking action, organizations will need clear decision rights, human oversight and testing that accounts for the operational consequences of an incorrect response,” Honeywell stated in the report. “The goal of well-governed AI automation is to strengthen visibility and response without creating new risks to uptime, equipment or safety.”

Read the full article at SecurityWeek