Resilience Focus Driven by Major Attacks, Geopolitical Tensions, Fresh Regulations
Mathew J. Schwartz (euroinfosec) •
September 22, 2026

Image: Shutterstock
Serious cybersecurity incidents involving operational technology systems carry a cost, averaging over 16 hours of downtime and losses of up to $500,000 per hour. As a result, more industrial organizations report putting plans and capabilities in place designed specifically to prevent such downtime, or to minimize operational disruption when it does occur.
See Also: What Are Your Maps Not Showing You?
Those findings come from Honeywell Technologies’ inaugural 2026 Operational Technology Cybersecurity Benchmark Report, based on studies conducted by ISMG advisory firm CyberTheory.
The vast majority of the more than 600 cybersecurity risk, compliance and operations professionals surveyed, across energy, healthcare, manufacturing, oil and gas, maritime, and other critical infrastructure sectors, characterize their organization as having a mature OT cybersecurity program.
Where technology-driven thinking once dominated, a business-driven discussion focused on resilience is becoming much more common, not least as digital connectivity across OT environments continues to increase, said Tim Ager, head of cybersecurity for EMEA at Honeywell Technologies, a publicly traded, pure-play automation company that serves the building, industrial and process sectors.
“The narrative has moved on from network segmentation and protecting industrial control systems. Today the discussion is much broader and focuses on business outcomes and impact such as operational resilience, recovery readiness, service continuity, safety implications, regulatory obligations and digital transformation,” Ager told ISMG.
Such discussions continue to be required: Respondents said serious OT cybersecurity incidents remain relatively common. An average of 73% surveyed critical infrastructure organizations experienced at least one such incident in the past year, as did 90% of the hardest-hit sectors: energy and utilities and maritime.
Recent, high-profile attacks on critical infrastructure, some tied to geopolitical tensions, have also helped focus boards’ and senior executives’ thinking, as have regulatory developments such as the EU’s Network and Information Security Directive 2, or NIS2, which includes incident reporting and executive accountability, Ager said.
Keeping tabs on the entire OT estate isn’t easy, given the range of physical control processes, operations and safety technologies they can comprise. These include industrial control and SCADA systems, field devices and controllers, elevators, plus heating, ventilation, and air conditioning – aka HVAC – systems. They can also include physical security systems, ranging from access controls and CCTV, to building management systems, plus internet of things devices, internet of medical things – aka IoMT – as well as industrial IoT equipment.
Visibility Challenge
Maintaining visibility of OT assets carries multiple upsides, not least from a management, governance and agility perspective. Organizations with the most mature capabilities report being four times faster at threat detection, incident response and restoring operations. In many cases, these capabilities are driven from the top down, by senior executives who view them as comprising not just technology, but broader employee safety, production uptime and customer service business capabilities.
“Operational readiness is defined by whether teams can see the systems that keep equipment running and restore it quickly if a disruption occurs,” said James Masso, president and CEO of Honeywell Process Automation.
Organizations with the most mature OT security programs, which exhibited the shortest average downtime following an incident – categorized as an outage lasting six hour or less – often attribute their speed to continuous monitoring for threats combined with strong asset inventories, allowing them to pinpoint attacks and respond more quickly. Respondents also cite robust backup and recovery capabilities, as well as network segmentation, as critical components of their rapid-response capability.
Many organizations report that their attempts to maintain full visibility of their OT technology, not to mention monitoring, to facilitate everything from maintaining asset inventories to detecting, responding and mitigating unfolding attacks, as well as undertaking backup and recovery when required, continues to be a challenge.
Only one-third of organizations report having integrated all OT systems with a centralized security operations center, and just one in five continuously monitor IoT or devices in their environment, including sensors, card readers and cameras.
“Resilience depends on extending cybersecurity across every connected system that supports uptime and business continuity. Organizations can no longer afford to have this visibility gap,” Masso said.
Only 21% of respondents report having a complete asset inventory, despite 88% of organizations saying their OT programs are planned or design-led. “This is a common experience and suggests that many organizations have made real progress on strategy and governance, but visibility has not yet reached every layer of the operational environment,” Ager said.
Making this happen remains key. “Visibility is arguably the foundation of any cybersecurity program. If an organization doesn’t know every operational asset connected to its environment, it becomes difficult to assess risk, prioritize remediation, respond to incidents or recover effectively,” Ager said.
GRC Imperatives
Critical sector entities with mature governance, risk and compliance programs are arguably better situated to recover from incidents more quickly.
Not all organizations excel at GRC. Overall, two-thirds of organizations report an audit failure or significant finding being reported to them. But among the one-third that passed every audit in the past 12 months, 87% predict being able to recover from any given incident within 24 hours, compared to 75% of organizations that failed at least one audit control.
Legacy systems, meaning they no longer enjoy vendor support or benefit from security patches, continue to pose a threat. “Considering the expected life cycle of industrial assets and the drive to make OT environments accessible through IT/OT initiatives this is naturally going to be a risk,” Ager said.
In fact, half of all organizations say legacy systems pose the single biggest cyber exposure risk to their organization, while also being one of the top contributors to downtime. Other major challenges, each cited by one-third of respondents, included budget constraints and staffing or skills shortages.
The challenges are especially acute in more remote or harsh environments, such as on oil rigs and maritime vessels, for which organizations report difficulty maintaining not only visibility but also adequate OT security staffing levels, complicating efforts to respond quickly.
Cautious AI Adoption
To help manage OT security challenges, organizations report being strong adopters of artificial intelligence, with 72% using it for threat detection, 68% for continuous monitoring and 59% for maintaining asset inventories. Adopting fully automated AI processes, including agentic AI, has been more cautious, with less than one-quarter of organizations using it for any of the three aforementioned capabilities.
Automation isn’t being applied evenly. One-third of organizations say they still rely on manual controls to manage third-party access to their OT and facility systems.
“It is encouraging that AI is already being seen as an enabler by our defenders but what’s interesting is that autonomous or agentic security capabilities remain much less common than AI-assisted functions. That suggests organizations are embracing AI while still exercising caution regarding automated decision-making in operational environments,” Ager said.