Eighty-Eight Percent Have A Plan. Twenty-One Percent Have An Inventory.

Estimated reading time: 7 minutes

Eighty-eight percent of industrial security leaders describe their OT security program as planned or design-led. Twenty-one percent report a complete asset inventory. A program cannot protect equipment nobody has counted. Honeywell Technologies has now put a number on what that gap costs in hours.

Its inaugural OT Cybersecurity Benchmark Report surveyed 603 respondents across critical infrastructure. Organizations reported an average of 16.2 hours of downtime from their most significant OT cybersecurity incident.

What OT Cybersecurity Incidents Cost In Hours

Sixteen hours of stopped production is the figure to carry into an underwriting conversation. Business interruption attaches on a clock, and this one runs long.

The cost estimates spread widely. Among respondents whose organizations had an incident, 21 percent put downtime costs above 100,000 dollars per hour. Four percent put them above 500,000 dollars per hour.

Confidence runs ahead of readiness elsewhere too. Ninety-two percent place their organizations in the top two tiers of recovery readiness. Thirty-one percent say they are fully ready.

Sixty-six percent report an audit failure or significant finding during the past year.

The OT Cybersecurity Finding Underwriters Have Been Waiting For

Honeywell links practice to outcome, with numbers attached.

Take respondents whose organizations had a significant incident. Forty-two percent with stronger asset visibility reported downtime of six hours or less. Among those with weaker visibility, the figure was 25 percent.

Bar chart comparing OT incident downtime and restoration times by asset visibility and audit performance from the Honeywell 2026 benchmark. Cyber Insurance News created chart for article on anyone writing critical infrastructure cyber insurance..
Honeywell reports an association between stronger practice and faster recovery. The findings are self-reported and correlational.

Program design shows a similar pattern. Reactive or tool-by-tool programs recorded 21 percent with downtime of at least a day. Planned or design-led programs recorded 12 percent.

Audit performance tracks recovery. Among organizations passing every audit, 87 percent expect restoration within 24 hours. Among those with audit failures or findings, 75 percent do.

Three caveats belong with those figures. The findings are self-reported. They show correlation rather than cause. And Honeywell sells OT security services.

Even so, this is a vendor publishing control-to-outcome numbers rather than an exposure map. Most of this year’s research has offered the map alone.

Where OT Cybersecurity Meets Physical Loss

Sixty-four percent of respondents expect physical consequences from a significant incident. They name severe or high impact on equipment and on worker or customer safety.

See also  Cyber Incidents 2025: 10 Costly Shocks That Redefined Cyber Liability Insurance

That sentence sits on a seam in the cyber insurance market. Beazley published last week that property policies usually exclude cyber-caused physical damage without a specific endorsement. It also noted that business interruption cover often pays only where physical damage occurs.

Honeywell describes the mechanism. Its report opens on a manufacturing plant with an on-site data center. The servers stay online only while the chillers run. The chiller controls sit on a facility network behind an unsecured remote access path. Shut down the cooling and the servers fail.

Coverage for that loss depends on which policy the adjuster reaches for.

The report notes attacks on US water utilities across at least seven states by early August 2026. Honeywell cites the FBI and EPA on remote access to internet-facing programmable logic controllers. Those incidents caused loss of monitoring or control. Some degraded water operations.

Where Industrial Cyber Risk Sits Unmonitored

Coverage of connected systems remains partial.

Sixty-four percent of OT security programs include safety systems. Fifty-seven percent include physical security systems. Fifty-six percent include facility infrastructure such as chillers, switchgear and fire panels.

Continuous monitoring lags well behind inclusion. Twenty percent continuously monitor more than three-quarters of connected IoT devices such as cameras and thermostats. Sixteen percent say the same for building automation systems.

Thirty-five percent still use manual or procedural controls for third-party access to OT and facility systems.

Incidents do not stay put. Among respondents whose organizations had a significant incident, 40 percent report effects at multiple sites in one region. Sixteen percent report effects across regions.

Jim Masso, president and chief executive of Honeywell Technologies Process Automation, framed the finding. Organizations “can no longer afford to have this visibility gap,” he said.

Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!

Where Critical Infrastructure Cyber Insurance Concentrates

The concentrations matter for anyone writing critical infrastructure cyber insurance.

Ninety-one percent of energy and utilities respondents report a significant OT cybersecurity incident in the past 12 months. Among maritime respondents, the figure is 87 percent.

See also  Cyber Risk Underestimation: Why Business Confidence Is Outpacing Cyber Reality

Cyber Insurance News has reported this exposure before. Research last year found nearly nine in ten utility companies hacked over three years. Separately, an extreme OT attack carries an estimated cost above 300 billion dollars.

Healthcare shows the widest coverage gap. Nineteen percent of healthcare respondents say cybersecurity monitoring and protection fully cover facility and building systems. Sixty-seven percent say a significant incident could severely affect caregiver or patient safety. Forty-four percent cite legacy or unsupported medical devices as a major challenge.

Among healthcare organizations that experienced an incident, 47 percent credit early threat detection with helping them restore operations quickly.

Our podcast conversation on healthcare ransomware resilience runs through the same pattern. There, the cost of a lost head start shows up in patient care, not only in downtime.

Segmentation is the other half of the answer. Another podcast, What’s Your Blast Radius Worth? examines how far an intruder travels once inside, which is precisely the question Honeywell’s cooling-system scenario poses.

What Underwriters Can Ask

Critical infrastructure cyber insurance rests on evidence rather than description, three questions follow from the data.

  1. Can the insured produce a complete OT asset inventory, and when was it last reconciled?
  2. Does the security program cover facility infrastructure, safety systems, and physical security? Which of those receive continuous monitoring?
  3. How does the insured grant and revoke third-party access to OT systems, and is that process technical or procedural?

Each has a documentary answer. Each maps to a Honeywell finding where the gap between program and practice showed up in hours of downtime.

Methodology

Honeywell Technologies fielded the benchmark study in May and June 2026, capturing 603 respondents. The sample covered CISOs, OT security leaders, risk and compliance executives, plant managers and security architects. Sectors ran across oil and gas, energy and utilities, maritime, healthcare and manufacturing. Respondents came from the Americas, EMEA and APAC. This is the inaugural edition, so no year-on-year comparison exists. Findings reflect self-reported practices and assessments unless otherwise noted. Honeywell sells OT cybersecurity services.

FAQ – OT Cybersecurity

How long does an OT cybersecurity incident stop operations?

Honeywell reports an average of 16.2 hours of downtime from respondents’ most significant OT cybersecurity incident, based on 603 industrial security leaders surveyed in May and June 2026.

See also  Affluent Families Shift Toward Proactive Risk Strategies as Personal Cyber Insurance Demand Rises

What does that downtime cost?

Estimates vary widely. Among respondents whose organizations had an incident, 21 percent put downtime costs above 100,000 dollars per hour, and 4 percent put them above 500,000 dollars per hour.

Does better asset visibility shorten downtime?

The survey shows an association. Among incident-affected respondents, 42 percent with stronger asset visibility reported downtime of six hours or less, against 25 percent with weaker visibility. The findings are self-reported and correlational.

Which sectors report the most OT incidents?

Ninety-one percent of energy and utilities respondents and 87 percent of maritime respondents report a significant OT cybersecurity incident in the past 12 months.

Why does this matter for critical infrastructure cyber insurance?

Sixty-four percent say a significant incident could severely affect physical equipment and worker or customer safety. Cyber-caused physical damage and the business interruption that follows sit across the boundary between cyber and property wordings.

How complete is monitoring of connected systems?

Twenty percent continuously monitor more than three-quarters of connected IoT devices such as cameras and thermostats. Sixteen percent say the same for building automation systems.

Leave a Comment

×