Honeywell’s 2026 OT Cybersecurity Benchmark Report found that industrial organizations significantly overestimate their operational-technology security maturity: 88% of 603 critical-infrastructure security, risk and operations leaders rated their programs mature or design-led, but only 21% maintained a complete OT asset inventory and 33% had fully integrated OT telemetry and response into a centralized SOC. Legacy controllers without authentication or encryption were identified as the principal readiness obstacle, while connected building-automation and IoT assets often remain outside continuous monitoring.
The exposure has operational consequences. Significant OT incidents caused an average 16.2 hours of downtime, and some respondents estimated losses above $100,000 per hour; organizations with more complete inventories reported faster recovery. The findings follow remote compromises of internet-facing PLCs at water systems in at least seven U.S. states, which disrupted monitoring or controls and degraded operations, with the FBI and EPA investigating potential Iran-backed involvement. AI is widely used to support analysts, but autonomous use remains limited: only 23% reported using agentic AI for threat detection.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Honeywell released its 2026 OT Cybersecurity Benchmark Report, which found that 88% of surveyed leaders described their OT-security programs as mature or design-led, while only 21% reported a complete OT asset inventory. The report also found significant OT incidents caused an average of 16.2 hours of downtime among affected organizations.
The FBI and EPA said they were investigating whether the water-system PLC intrusions were linked to Iran-backed hackers.
By early August, attackers had remotely accessed internet-facing programmable logic controllers used to operate pumps and valves at water systems in at least seven U.S. states. Some operators lost monitoring or control capabilities, and some water operations degraded.
Honeywell surveyed 603 security, risk, and operations leaders in critical-infrastructure organizations during May and June for its OT cybersecurity benchmark research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.