Honeywell Benchmark Report Finds Critical Gaps in OT Cybersecurity Visibility

Author photo: Larry O'Brien
ByLarry O'Brien
Category:
Industry Trends

Honeywell recently released its inaugural OT Cybersecurity Benchmark Report, delivering an important message for industrial organizations: OT cybersecurity maturity is no longer limited to protecting traditional production environments. The survey of 603 cybersecurity and operational leaders across critical infrastructure sectors shows that organizations must broaden cybersecurity programs to include building automation systems, physical security systems, safety systems, and connected IoT devices that increasingly affect operational continuity, safety, and resilience.

The benchmark findings highlight a concerning gap between perceived readiness and actual preparedness. Although 92 percent of respondents place themselves in the top two tiers of recovery readiness, only 31 percent claim to be fully ready. More troubling, only 21 percent report maintaining a complete asset inventory, even though 88 percent describe their cybersecurity programs as planned or design-led. This disconnect suggests that many organizations believe their OT cybersecurity programs are mature while significant portions of their operational environments remain outside effective visibility and governance.

According to Paul Smith, Honeywell’s global portfolio director for cybersecurity, the findings show a noteworthy gap between how organizations perceive their cybersecurity resilience and their actual capabilities. He noted that 91 percent of energy and utilities respondents reported experiencing a significant OT cybersecurity incident in the past 12 months, underscoring the need for operational preparedness across critical infrastructure.

As industry analysts, we can sometimes assume that everyone already understands industrial cybersecurity fundamentals and fail to emphasize the basics of a successful OT cybersecurity program. Instead, the focus often shifts to newer technologies, even as many end users are still establishing their OT cybersecurity programs. This report highlights those concerns. Although many end users may believe they have solid programs, persistent gaps remain and must be addressed. The report also addresses the critical issue of unplanned manufacturing downtime caused by cybersecurity incidents. Users must get a handle on the fundamentals, including continuous monitoring and coherent response plans.

OT Security Is Expanding Beyond Traditional Operations

One of the report's most important findings is that operational technology now extends far beyond industrial control systems. Modern operational environments increasingly include HVAC systems, chillers, building management systems, badge readers, video surveillance systems, fire panels, elevators, and connected IoT devices that interact directly with physical operations and worker safety.

Honeywell reports that 64 percent of organizations include safety systems within their OT cybersecurity programs, 57 percent include physical security systems, and 56 percent include facility infrastructure. However, only 16 percent continuously monitor more than three-quarters of building automation systems, while only 20 percent continuously monitor connected IoT assets such as cameras and thermostats. These findings suggest that organizations have expanded cybersecurity scope conceptually but have not yet achieved comprehensive visibility across connected operational environments.

From ARC's perspective, this trend reflects an important shift in industrial cybersecurity priorities. Cyber adversaries increasingly seek pathways into operational environments through overlooked infrastructure components. A compromised HVAC controller, physical security system, or remote maintenance connection may provide indirect access to critical production assets. As industrial organizations increase connectivity, cybersecurity programs must evolve to address cyber-physical systems holistically rather than focusing solely on traditional control networks.

Visibility Drives Better Recovery Outcomes

The report's most compelling finding concerns the relationship between asset visibility and operational resilience. Organizations with stronger asset visibility consistently report superior incident outcomes.

Among organizations experiencing significant cybersecurity incidents, those with stronger visibility are 17 percentage points more likely to report downtime of six hours or less than organizations with weaker visibility. They are also significantly more effective at identifying root causes during incident investigations. Conversely, organizations with weaker visibility experience longer disruptions and greater difficulty understanding the operational impact of incidents.

ARC has consistently observed that comprehensive asset visibility represents the foundation of effective OT cybersecurity. Organizations cannot protect assets they cannot identify. An accurate, continuously updated asset inventory enables effective monitoring, vulnerability management, incident response, and recovery planning. This finding supports ARC's long-standing position that cybersecurity maturity begins with discovery and visibility, not advanced security technologies alone.

Legacy Systems Continue to Challenge Security Programs

The report identifies legacy infrastructure as the most persistent obstacle to OT cybersecurity maturity. Nearly half of respondents cite legacy systems and infrastructure constraints as the primary barrier to improved cybersecurity outcomes. Forty-seven percent identify legacy or unsupported systems as a major source of cyber risk exposure, while 45 percent rank legacy systems among the top contributors to post-incident downtime.

These findings are not surprising. Most industrial facilities continue operating equipment designed decades ago for isolated environments. Many controllers, sensors, and operational assets were never intended to connect to enterprise networks or support remote access. Organizations face difficult choices because replacing these systems often requires expensive modernization efforts and potentially disruptive downtime.

The report emphasizes that organizations must manage legacy risk rather than simply attempting to eliminate it. Segmentation, continuous monitoring, compensating controls, and comprehensive recovery planning remain essential strategies for safely operating aging infrastructure within modern connected environments.

Recovery Readiness Matters More Than Compliance Alone

Another noteworthy observation involves compliance and recovery performance. Organizations passing all compliance audits report cyber incidents at nearly the same frequency as organizations that experience audit findings. However, organizations with successful audit performance demonstrate significantly stronger recovery readiness and operational resilience.

Respondents whose organizations passed all audits are substantially more likely to consider themselves fully recovery-ready and to believe they can restore critical OT systems within 24 hours. The implication is important: compliance alone does not prevent attacks, but disciplined governance processes appear to contribute to stronger recovery outcomes.

ARC believes this finding reinforces the need to view cybersecurity as an operational resilience discipline rather than a compliance exercise. Regulatory requirements can help establish baseline practices, but organizations ultimately succeed or fail based on their ability to restore operations safely and quickly after a disruption occurs.

AI Becomes a Core OT Security Capability

The survey reveals broad adoption of artificial intelligence in OT cybersecurity operations. Seventy-two percent of respondents report using AI-enabled threat detection capabilities, while 68 percent use AI-assisted continuous monitoring and 59 percent employ AI-enabled asset inventory solutions.

Although AI adoption is widespread, fully autonomous operation remains relatively uncommon. Only about 23 percent report autonomous or agentic capabilities for threat detection and monitoring. Meanwhile, 99 percent of respondents expect AI to significantly influence OT cybersecurity within the next two to three years.

ARC sees AI increasingly becoming an operational necessity for managing growing numbers of assets, alerts, vulnerabilities, and security events. However, organizations must ensure appropriate governance, transparency, and human oversight as AI technologies shift from decision-support tools to increasingly autonomous operational capabilities.

ARC Recommendations

The findings point to five priorities for industrial organizations seeking to improve OT cybersecurity maturity:

  1. Establish comprehensive visibility across all connected operational assets, including facility systems, physical security systems, and IoT infrastructure.

  2. Expand cybersecurity governance beyond traditional production systems to encompass all cyber-physical systems affecting operations and safety.

  3. Develop structured approaches for managing legacy infrastructure through monitoring, segmentation, and compensating controls.

  4. Regularly test recovery and restoration procedures under realistic operational conditions.

  5. Implement AI capabilities carefully, with strong governance, oversight, and well-defined decision authority.

ARC Conclusions

Honeywell's benchmark study highlights a significant transition across industrial cybersecurity programs. The issue is no longer simply protecting production systems. Organizations must secure an increasingly interconnected ecosystem of operational, facility, safety, physical security, and IoT assets that collectively determine business continuity and operational resilience.

The most important takeaway from this research is that cybersecurity maturity starts with visibility. Organizations that maintain comprehensive inventories, understand system dependencies, and continuously monitor their broader operational environments consistently demonstrate stronger resilience and faster recovery. As cyber threats continue to target critical infrastructure and cyber-physical systems become increasingly interconnected, industrial organizations must broaden their cybersecurity scope and strengthen their operational resilience accordingly. The organizations that succeed will be those that can see, govern, protect, and recover their entire operational environment, not just their production systems.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients