Eighty-eight percent of industrial security leaders put their OT cybersecurity program in the top two maturity tiers. Twenty-one percent have a complete inventory of their OT assets. Those two numbers come from the same 603 people, answering the same questionnaire, in the same six weeks.
That is the finding in Honeywell Technologies' 2026 OT Cybersecurity Benchmark, published on 22 September 2026 (Honeywell, Industrial Cyber, SecurityWeek). It is worth reading not as a scoreboard but as a measurement of how industrial organisations are currently mis-scoring themselves, because the shape of the error repeats in every section of the report.
What was actually measured
The study was fielded in May and June 2026 and captured 603 respondents: CISOs and OT security leaders, compliance and risk executives, plant and operations managers, and cybersecurity architects. Sectors covered oil and gas, energy and utilities, maritime, healthcare and manufacturing, across the Americas, EMEA and APAC. The report is explicit that, unless otherwise noted, findings reflect self-reported practices, experiences and assessments.
That caveat is the point rather than a footnote. Self-assessment is the instrument most OT programmes are actually governed by, through board reporting, insurance questionnaires and customer security reviews. What makes this survey useful is that it asked the factual questions alongside the self-assessment, so the two answers can be laid side by side.
Maturity models measure process. Inventories measure reality.
A maturity tier describes whether you have a policy, whether it is applied consistently, and whether it is reviewed. You can score well on all three while holding an asset register that was accurate at commissioning and has been drifting ever since. Nothing in the maturity question requires the register to be right.
An asset inventory is the opposite kind of claim. Either you can enumerate what is on the network or you cannot, and 79 percent of these organisations say they cannot do it completely. Every downstream control inherits that gap. Patch coverage is a percentage of a denominator you do not know. Segmentation is a policy applied to a device list that is missing entries. Risk assessment ranks consequences for assets you have written down, which is a different population from the assets that are running.
Maturity models are not useless. They simply belong in the same report as an inventory completeness number, because one of the two can be improved by writing documents and the other cannot.
Two thirds of OT is outside the SOC
Only 33 percent of respondents said OT is fully integrated into a centralised security operations centre. That is the number to take to a budget conversation.
Integration here is not about tooling aesthetics. It decides whether an anomaly on a control network reaches a human being who is awake, trained and empowered to act, within minutes rather than at the next shift handover. In the two thirds of organisations where OT sits outside the SOC, detection depends on an operator noticing that a process is behaving oddly, which means the first indicator is usually a physical symptom rather than a network one. By then the useful window has closed.
The incident data in the same report shows what that window is worth. Respondents reported an average of 16.2 hours of downtime from their most significant incident. Twenty-one percent estimate downtime costs above 100,000 US dollars per hour, and a smaller group put it above 500,000. At the midpoint of that first band, a single average incident is a seven-figure event. Continuous monitoring is usually argued for on the grounds of risk. It is more persuasive argued on the grounds of hours.
Incident frequency is not evenly distributed either. In energy and utilities, 91 percent of respondents reported a significant OT cybersecurity incident in the previous 12 months. Maritime reported 87 percent. These are not sectors where the question is whether an incident arrives.
Scope grew faster than visibility
The report's other genuinely useful finding is that OT security programmes have widened their definition of OT. Sixty-four percent now include safety systems in the OT cybersecurity programme, 57 percent include physical security systems, and 56 percent include facility infrastructure.
Then the monitoring numbers. Only 20 percent continuously monitor more than three quarters of connected IoT assets such as cameras and thermostats. Only 16 percent continuously monitor more than three quarters of building automation systems.
So the scope expanded on the org chart and in the policy document, and the visibility did not follow. A building management system that is formally inside the OT security programme but is not monitored is arguably worse than one that was never claimed, because the claim closes the question. Someone has ticked the box that says it is covered.
Recovery confidence has the same shape
Ninety-two percent of respondents place themselves in the top two tiers of recovery readiness. Thirty-one percent say they are fully ready. That gap has the same shape as 88 against 21, and it recurs in every section of the report.
Nearly half of respondents named legacy systems and infrastructure constraints as the primary barrier to better outcomes, which is a real and honest answer. It is also the answer most likely to be used as a reason to stop. Legacy equipment is precisely why passive, non-intrusive monitoring exists as a discipline: you cannot patch a controller that has not had firmware since 2011, but you can watch what it talks to.
AI is being layered on top of the unknown
Adoption is high. Seventy-two percent use AI-enabled threat detection, 68 percent use AI-assisted continuous monitoring and 59 percent use AI-enabled asset inventory. Only around 23 percent report autonomous or agentic operation, so in practice these systems are assisting analysts rather than replacing them.
The cautious autonomy posture is the right one. The sequencing is the problem. An AI-enabled asset inventory running over a network you have never fully enumerated will produce a confident, well-formatted list that is still incomplete, and it will be harder to argue with than the spreadsheet it replaced. Automation applied to an unmeasured environment does not fix the measurement. It raises the cost of noticing that the measurement was wrong.
What to do with this
- Report inventory completeness next to your maturity score. One number, refreshed quarterly, stated as a percentage with a defined denominator. If you cannot state the denominator, that is the finding.
- Count the assets you do not manage. Safety systems, building automation, cameras, badge readers and connected instrumentation are in scope on paper for most organisations now. Confirm whether anything is actually watching them.
- Answer the 2 a.m. question in writing. If a controller starts talking to something new at 2 a.m. on a Sunday, name the person who finds out and the interval in which they find out. If the honest answer is the next shift, you are in the 67 percent.
- Price your own downtime hour. Not the survey's. Yours, from your own production data. Then multiply by 16.2 and compare it against what continuous OT monitoring costs for a year.
- Start passive where you cannot patch. Legacy constraints rule out agents and scanning, not visibility. Network-level observation gets you an inventory and a behavioural baseline without touching the controllers.
- Sequence AI after enumeration. Use it to reduce analyst load on a scope you have already established, not to establish the scope.
Where MBCTG fits
The two findings that matter here, incomplete inventories and OT outside the SOC, are the two problems our OT security services are built around. Passive asset visibility produces the enumeration the maturity score assumes you already have, without adding traffic or risk to the control network, which is what makes it workable on equipment that cannot be touched.
Closing the SOC gap is the harder half, because it is an operating commitment rather than a deployment. Our 24/7 SOC exists to put an analyst who understands industrial protocols between the anomaly and the shift handover, which is the interval the 16.2 hour figure is really describing. Where the work is establishing scope, evidencing it and keeping it defensible in front of an auditor or an insurer, that is compliance and GRC.
If your programme would score well on a maturity questionnaire and you are not certain it would survive an asset count, talk to an MBCTG expert. The count is the cheaper way to find out.